Well.....
To be precice, you are only taking a risk if you fail to comply with the data protection legislation. To comply there are a few fairly straight forward things you have to do, and there is a fee of £35 ($60 approx). The problem is not making the database - the problem occurs when you don't register it. Perhaps I should have been clearer.....
To be honest, I guess, in reality, most small biz owners don't bother - especially as the risks of being caught out are so low.
I suppose the thing I wanted to highlight is the possiblity of similar controls in the US - but it does not sound like you have anything similar there............
Ray