Online privacy laws regulate and standardise the storing and using of personally identifiable information of individuals. This information is usually collected by entities like governments, big businesses, organisations, or other individuals operating as contractors or sole traders.
Let’s take a look at some of the major privacy laws around the globe, and why it’s worth being mindful of them while drafting your privacy policy statement.
Three privacy laws we’re reviewing
- GDPR
- CalOPPA
- CCPA
GDPR (General Data Protection Regulation)
The General Data Protection Regulation is a European Union (EU) privacy law on data protection and privacy for all individual citizens of the EU and the European Economic Area (EEA). This privacy law aims to protect the privacy and use of an EEA resident’s personal data in an increasingly digital world.
The GDPR states that companies and websites need to comply with the following in relation to their users’ personal information:
- The right to information
- The right to access
- The right to rectification
- The right to erasure
- The right to restrict processing
- The right to data portability
- Rights related to automated decision making, including profiling
For further information, see the official GDPR FAQs.
CalOPPA (California Online Privacy Protection Act)
The California Civil Code permits residents of California to request information regarding the disclosure of their personal information to third parties for direct marketing purposes. It also permits requests from residents who are users of your site, under the age of 18, to have content or information they have posted publicly removed.
For further information, see the California Attorney General’s privacy law resources.
CCPA (California Consumer Privacy Act)
CCPA applies to your business if one or more of the following apply:
- Has annual gross revenues in excess of $25 million
- Buys, receives, or sells the personal information of 50,000 or more consumers or households
- Derives more than half of its annual revenue from selling consumers’ personal information
This privacy law strengthens the privacy of California residents by giving them the right to:
- Know what personal data is being collected about them
- Know whether their personal data is sold or disclosed, and to whom
- Say no to the sale of personal data
- Access their personal data
- Request that a business delete any personal information collected about them
- Not be discriminated against for exercising their privacy rights
For more information, see the official CCPA fact sheet.
How to be compliant with privacy laws
A great way to keep your business compliant with global privacy laws is to have a privacy policy statement on your website. Your privacy policy should declare your business’s approach to the data it collects from users.
A privacy policy is a legal document which outlines the data you collect from your users, what this data is used for, where it is stored, and what third parties (if any) it is shared with.
More specifically, it should include:
- The personally identifying information (PII) you collect
- The non-personally identifying information you collect
- Where you share the PII, if at all
- What information you gather through the use of cookies
- What type of cookies you use, and options for users to opt out of cookie tracking
- Contact information so you can answer any queries, and your users can request their information if desired
Personal information that may be collected includes:
- Full name
- Residential and mailing address
- Date of birth
- Phone number
- Email address
- Passport number
- Driver’s license
- Bank account details
Write in as basic language as possible, so it can be easily understood by your users.
Why you should have a privacy policy
Your website needs a privacy policy as required by law. When you collect personal information from your users, in any manner, through your website, you must have a privacy policy agreement.
Each country has its own laws regarding privacy policies, but with the far reach of the internet, it’s very likely some of your customers or users will be from countries outside your own. For this reason, a privacy policy needs to contain information relevant to the GDPR and CalOPPA as well.
A well-written privacy policy is important for your website. Be prepared to stand by your agreement, and have measures in place to protect your users’ confidential information.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.