Cannabis Businesses Collect More PII Than Most Retailers. Can They Protect It?
Updated August 20, 2026
Cannabis Businesses Collect More PII Than Most Retailers. Can They Protect It?

A cannabis purchase may look like a simple retail transaction. Behind the counter, however, the business may be handling identity records, dates of birth, loyalty data, transaction histories, medical cannabis information, and sensitive government identification documents.
That makes cannabis businesses different from most retailers. Operators such as Curaleaf, Trulieve, Verano, Cresco Labs and its Sunnyside stores, Rise, Zen Leaf, Apothecarium, Breakwater, The Botanist, Cannabist, AYR, and others collect sensitive information every day.
Marketplaces and technology platforms such as Weedmaps and Leafly add another layer of data collection and third-party risk. New York operators such as Gotham demonstrate how quickly a multi-state cannabis technology and retail ecosystem can expand.
The question for New Jersey operators is straightforward:
If your business collects high-value personal information, can your cybersecurity controls protect it while supporting your regulatory obligations?
A Real-World Warning: The STIIIZY Data Breach
In late 2024, STIIIZY customers learned that a compromise involving a third-party point-of-sale and identity-verification vendor exposed information connected to approximately 380,000 individuals across four California locations.
According to STIIIZY’s incident FAQ and reporting by SecurityWeek, the affected information included names, addresses, dates of birth, transaction histories, and scanned government identification documents. Some records included driver’s licenses, passports, medical cannabis cards, photographs, and signatures.
The incident was reportedly claimed by the Everest ransomware group. More importantly for cannabis operators, the attack path reportedly involved a vendor: not simply the dispensary’s own network.
That is the lesson: your customer data may be exposed through a POS provider, loyalty platform, delivery application, payment system, cloud service, or API integration.
Why It Matters
Cannabis businesses can hold unusually valuable PII
Depending on the state, business model, and customer workflow, cannabis operators may collect or store:
- Names and addresses
- Dates of birth and contact information
- Government-issued identification details
- Scanned driver’s licenses or passports
- Medical cannabis card information
- Patient records and health-related information
- Purchase and transaction histories
- Loyalty program and marketing data
- Delivery addresses and order histories
Age-verification rules create a unique challenge. Operators must confirm that a customer is legally permitted to purchase cannabis. In some workflows and jurisdictions, that process can involve scanning or retaining government identification information.
Medical cannabis programs introduce additional sensitivity. Patient records, medical cannabis card details, physician-related information, or other health data may create state and federal privacy obligations. HIPAA does not automatically apply to every dispensary, but it may apply when an organization qualifies as a covered entity or business associate and handles protected health information in covered transactions.
New Jersey adds specific responsibilities
New Jersey’s Cannabis Regulatory Commission rules require cannabis businesses to protect both their physical premises and their electronic systems.
Under N.J.A.C. 17:30-9.10, businesses must use effective controls against unauthorized access, theft, diversion, and electronic record tampering. The rule also addresses continuously monitored alarms, video surveillance, remote Commission access, and a 30-day video archive.
Under N.J.A.C. 17:30-9.7, businesses must maintain complete, accurate, confidential sales records for at least four years. Retailers are also restricted from collecting and retaining consumer personal information beyond what is typically acquired in an alcohol retail financial transaction, with government identification used for age verification.
Under N.J.A.C. 17:30-9.8, personnel must receive training addressing privacy, confidentiality, security controls, and emergency procedures. The New Jersey Cannabis Regulatory Commission business resources provide additional regulatory information and guidance.
A cyber incident can therefore affect more than customer trust. It can create:
- Register and POS downtime
- Lost sales and damaged EBITDA
- Regulatory investigation and response costs
- Insurance coverage questions
- Vendor disputes and legal expenses
- Customer notification obligations
- Potential exposure of medical or health-related information
- Operational and licensing risk
No cybersecurity firm can guarantee a licensing, insurance, or compliance outcome. But a disciplined program can help an operator become better prepared, better documented, and more closely aligned with applicable requirements.

New Jersey Rules in Plain Language
Think of your cannabis business as a castle.
The building, vault, cameras, alarms, POS systems, employee accounts, cloud applications, and customer records are all part of the castle. A strong front door is not enough if a vendor has an unguarded side entrance.
1. N.J.A.C. 17:30-9.10: Protect the castle and its records
New Jersey expects operators to protect the premises and electronic systems from unauthorized access and tampering.
That means physical security and cybersecurity must work together. Cameras, panic buttons, alarms, access control systems, network equipment, cloud video storage, and remote monitoring tools are connected cyber assets: not separate from the IT environment.
The rule also requires 24/7 monitoring, remote Commission access to video, and at least 30 days of archived recordings.
2. N.J.A.C. 17:30-9.7: Keep accurate records, but do not over-collect
A retailer must keep confidential sales records for four years. At the same time, New Jersey limits the amount of consumer information a retailer may collect and retain.
This is a data-minimization principle: do not build a larger customer database than the business and the law require.
Think of it like carrying cash. You would not hand every employee the entire cash drawer when they only need change for one transaction. Data access and data retention should work the same way.
3. N.J.A.C. 17:30-9.8: Train the team
Technology cannot protect information if employees do not know how to use it.
Staff should understand privacy expectations, confidentiality, phishing, password security, approved procedures for handling IDs, and what to do when something looks wrong. A well-trained team is like a sports team that knows the play before the pressure arrives.
4. METRC and API confidentiality
METRC and connected seed-to-sale systems create another important control point.
For providers and integrations that access, process, or store state data, the New Jersey METRC API Confidentiality Agreement addresses authorized access, data integrity, API key protection, and incident reporting.
The agreement includes notification expectations for unintended access or attacks within 24 hours of discovery and unauthorized use or disclosure of confidential data within one business day. A provider’s incident can quickly become an operator’s regulatory and operational problem.
The 8 Layers of Protection for Cannabis Operators
A practical cybersecurity program should resemble layered security around a facility: not a single lock on one door.
Identify every device, application, cloud service, camera system, POS terminal, API, vendor, and data store. You cannot protect what you do not know exists.
- Asset inventory
Harden computers, routers, firewalls, POS systems, cloud services, and surveillance devices. Default passwords and unnecessary services are open windows.
- Secure configuration
Use individual employee accounts, strong authentication, and prompt removal of access when a worker leaves or changes roles.
- Account management
Give each person only the access required for the job. A budtender, store manager, finance employee, and system administrator should not have identical permissions.
- Access control
Patch systems, replace unsupported devices, and test exposed applications. A vulnerability is like a weak section of a perimeter fence; attackers will eventually find it.
- Vulnerability management
Review activity across POS, cloud applications, APIs, endpoints, and networks. Logs help identify unusual access, tampering, and attempted account takeover.
- Log monitoring
Maintain a written plan for ransomware, POS outages, lost devices, vendor incidents, suspected data disclosure, and regulatory notifications.
- Incident response
Assign responsibility, document policies, review vendors, test controls, and report risk to leadership. Cybersecurity should support EBITDA and strategic goals: not operate as an isolated technical project.
- Governance

How We Deliver It
PROACTIVE RISK helps cannabis operators, dispensaries, MSOs, and cannabis technology businesses turn cybersecurity and compliance expectations into practical operating controls.
Our approach can include:
- MEASURERISK: A compliance and risk gap assessment aligned with New Jersey CRC readiness, HIPAA considerations where PHI is involved, NIST, NY DFS 500, and other applicable requirements.
- CATSCAN®: Adversarial attack-surface testing that examines how an attacker may discover and exploit weaknesses across systems, applications, vendors, and exposed services.
- vCISO leadership: Executive-level cybersecurity guidance, risk prioritization, policy development, board and leadership reporting, and strategic planning without requiring a full-time CISO.
- ManageIT and MSOC 24/7 monitoring: Continuous monitoring, managed technology support, detection, and response capabilities designed to help identify threats before they become business interruptions.
- RISKWatch: Third-party and vendor risk management for POS providers, payment platforms, loyalty systems, delivery services, SaaS applications, and technology partners.
- PhishIT: Security awareness and phishing-resistance training for employees and contractors.
- CyberTrain: Incident-response rehearsal so leadership and staff can practice decisions before a real ransomware or data breach event.
Physical security systems: including cameras, alarms, panic buttons, and access control: are also reviewed as connected cyber assets where appropriate. This blended view is secondary to the core cybersecurity program, but it matters because a compromised camera server or access-control platform can create both physical and digital risk.
A Practical Starting Point
Cannabis leadership should be able to answer five questions:
- What customer, patient, employee, and business data do we collect?
- Where is that data stored and transmitted?
- Which vendors and applications can access it?
- How quickly would we detect unauthorized access?
- Who makes decisions during a cyber incident?
For breach updates, notification considerations, and related legal obligations, operators can also consult the Breach Intelligence Hub.
Summary: Protect the Data That Supports the Business
Cannabis businesses are retailers, technology users, regulated entities, and: sometimes: handlers of sensitive health information. Their risk is amplified by cash-heavy operations, complex third-party systems, seed-to-sale reporting, identity verification, and high regulatory scrutiny.
The STIIIZY incident showed how a vendor compromise can expose a large volume of customer information. New Jersey’s rules reinforce the need to protect electronic systems, preserve confidential records, train employees, monitor security systems, and report certain incidents promptly.
The goal is not to create fear or add unnecessary technology. The goal is to build practical, layered protection that keeps systems operating, reduces avoidable exposure, and supports the organization’s EBITDA and strategic goals.
Secure the Future of Your Strategic Goals.
For a complimentary 30-minute Cannabis Cyber & Business Risk Review, contact:
PROACTIVE RISK Intelligence-Led Cybersecurity & Risk Management ANTICIPATE. DEFEND. PREVAIL.
36 First Avenue, Suite 203, Denville, NJ 07834 973-298-1160 https://proactiverisk.com
