Why do you need a privacy policy on your website?
A privacy policy is a legal requirement if you collect and process any personal data from customers or users of your website. It outlines the type of data collected, how you collect it, what it’s used for, where it’s stored, and how you keep it secure. There are also international laws you’ll need to comply with if you have users who reside in the EU or California, or who are under the age of 13.
Personal Data
Let’s start by defining personal data: any information that enables the identity of a person. Examples include name, address, email address, mobile number, and driver’s license.
Collecting and Using Personal Data
Your privacy policy needs to outline how you collect personal data from your users. You may do this in a variety of ways: through a newsletter subscription, selling products and services, running a social media page, or when customers interact with you by email, phone, or in person.
What are you using the personal information for? Perhaps you need payment details to process a sale, and name and address details to ship goods. Perhaps you want to send personalised offers or run promotional events, or track sales data and monitor site usage. Whatever your reasons for collecting and processing customer data, they need to be included in your privacy policy.
Sharing Personal Data
Do you share any of your users’ personal data with a third party? This could include advertising services, social media, analytics services such as Google Analytics, web hosting companies, or cloud storage providers.
If the answer is yes to any of these, your privacy policy needs to state who you’re sharing your users’ personal data with.
Security
The ways you try to secure your users’ personal data must also be included in your privacy policy. There’s no guarantee you’ll keep data 100% secure from hackers or unauthorised access, but you do need appropriate safeguards in place.
A common security measure is HTTPS (Hypertext Transfer Protocol Secure), an internet communication protocol that encrypts data between your customers’ computers and your website.
Storage
Your privacy policy should state where your data is stored, including the country or countries where your servers are located. If any of your servers are within the EU, your privacy policy needs to comply with GDPR regulations. You should also let users know how long you retain their personal data.
International Laws
If you have users who reside in the EU or California, or you store personal data on servers in the EU, you’re required to comply with specific privacy laws. Given the nature of the internet, and that you may not automatically know where your users are from, it’s best to ensure your privacy policy covers these laws regardless.
The three main international laws to comply with are GDPR, CalOPPA, and COPPA.
GDPR
The General Data Protection Regulation is a set of regulations designed to protect the rights and personal data of EU residents and citizens. It came into effect on 25th May 2018.
There are seven key principles for how personal data is to be protected:
- Lawfulness, fairness, and transparency: processing personal data must be lawful, fair, and transparent.
- Purpose limitation: personal data is only to be collected for explicit and legitimate purposes.
- Data minimisation: personal data must be relevant and limited to the purpose it’s processed for.
- Accuracy: personal data needs to be as accurate and relevant as possible.
- Storage limitation: personal data should be stored for the least amount of time possible.
- Integrity and confidentiality (security): personal data needs to be processed in a way that safeguards it.
- Accountability: you need to be able to demonstrate accountability for the previous six points.
There are also individual rights that need to be explained to your users and included in your policy:
- The right to be informed: provide users with information about how you use, secure, and share their personal data.
- The right of access: users must be able to access their personal data if they wish.
- The right to rectification: users can have incorrect data corrected as soon as possible.
- The right to erasure: also known as the right to be forgotten; users can have their data erased under certain circumstances.
- The right to restrict processing: individuals can have their personal data restricted under certain circumstances.
- The right to data portability: individuals can obtain, use, and move their personal data to another environment for reuse.
- The right to object: in certain circumstances, individuals can object to their personal data being processed.
- Rights related to automated decision making and profiling: there must be a lawful basis for using an individual’s personal data for profiling or automated decision making.
CalOPPA
Under the California Civil Code, residents of California can request information about the disclosure of their personal information to third parties for direct marketing purposes. Users of your site under the age of 18 have the right to have content or information they’ve posted publicly removed.
COPPA
The Children’s Online Privacy Protection Act is a US privacy law protecting the rights of children under 13. To comply, your website needs to make clear whether it collects personal information from children under 13.
Conclusion
A privacy policy is a must, and having a GDPR, CalOPPA, and COPPA compliant privacy policy will cover you if you have users and customers from the EU, California, or elsewhere in the US.
A privacy policy doesn’t need to be drafted by a lawyer, but it must include relevant, clear clauses covering the types of personal data you collect, users’ rights, your security measures, how you store and retain personal data, whether you share data with third parties, and more.
Generate your own GDPR, CalOPPA, and COPPA-compliant privacy policy using our free generator.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.