Website Compliance – How to comply with requirements imposed by law
Website Compliance
Website Compliance: How to Comply with Requirements Imposed by Law
Find out how we can help you adapt your site or app to the regulations.
Disclaimer: We are technical advisors, not lawyers or legal advisors. The information on this site is provided for informational purposes only and should not be construed as legal advice on any subject matter. You should not act or refrain from acting on the basis of any content on this site without seeking legal or other professional advice.
A Simple, Safe Solution to Compliance
Websites and apps must always comply with certain requirements imposed by law. Failure to comply can result in serious penalties, including substantial fines, audits, and potential litigation.
For this reason, we’ve chosen to rely on iubenda, a company built on both legal and technical expertise that specializes in this area. Together with iubenda, of which we are Certified Partners, we’ve developed a proposal to offer all our customers a simple and safe solution to their compliance needs. Want to get started? Contact us today!
Contact Us to Get Started Learn About iubenda (Save 10%)
The Requirements
Overview of the Main Legal Requirements for Website and App Owners
Privacy and Cookie Policy
The law obliges each site or app that collects personal data to disclose relevant details to users through dedicated privacy and cookie notices. Privacy policies must contain certain fundamental elements specific to your particular processing activities, including:
- the contact and identifying details of the data controller;
- which personal data is being processed;
- the purposes and methods of processing;
- the categories of sources from which consumers’ data is collected;
- the legal bases of processing (e.g., consent);
- the third parties that may also access the data, including any third-party tools (e.g., Google Analytics);
- details relating to the transfer of data outside the European Union (where it applies);
- the rights of the user;
- a description of the notification process for changes or updates to the privacy policy;
- the effective date of the privacy policy.
The cookie policy specifically describes the different types of cookies installed through the site, any third parties those cookies refer to (including links to their documents and opt-out forms), and the purposes of the processing.
Can’t we use a generic document?
No. Your policy must describe in detail the specific data processing carried out by your site or app, and must also include the particular details of any third-party technologies (e.g., Facebook Like buttons or Google Maps) you use.
What if my site does not process any data?
It’s very difficult for a site not to process any data. A simple contact form or a traffic analysis system such as Google Analytics is enough to trigger the obligation to prepare and display a privacy and cookie policy.
What is a cookie?
Cookies are small files used to store or track certain information while a user browses a site. Cookies are now essential to the proper functioning of a site. Many third-party technologies integrated into sites, such as simple video widgets or analytics programs, also use cookies.
CCPA
The CCPA requires businesses to inform California users about how and why their data is being used, their rights in regard to this, and how they can exercise those rights, including the right to opt out. To comply, you need to include the relevant disclosures in your privacy policy and display a notice of collection on the user’s first visit (where applicable).
The opt-out process should be facilitated through a “Do Not Sell My Personal Information” (DNSMPI) link, accessible from your notice of collection and elsewhere on your site. Best practice is to also include the link in the footer.
My business is not based in California. Do I need to comply with the CCPA?
The CCPA applies to most businesses that collect or could potentially collect California customers’ personal information, whether or not the business itself is located in California. Since IP addresses are considered personal information, this likely applies to any website with at least 50,000 unique visits per year from California.
EU Cookie Law
In addition to providing an easily available and accurate cookie policy, adapting a website to the cookie law also requires showing an informative cookie banner that links to a detailed cookie policy on each user’s first visit, giving the user the opportunity to reject or grant consent to the installation of cookies. Most types of cookies, including those issued by tools such as social sharing buttons, should only be released after the user has given valid consent.
Furthermore, many third-party vendor networks may limit ad reach if you don’t have a cookie management system that meets industry standards, potentially reducing your ability to generate ad revenue.
Consent According to GDPR and LGPD (EU and Brazil)
When a user directly enters personal data on a site or app, for example by filling in a contact form, service registration, or newsletter subscription, you need to collect consent that is freely given, specific, and informed. Under the GDPR, you also need to keep unambiguous records that demonstrate valid consent was collected.
Similar to the GDPR, the Brazilian LGPD also requires the data controller to provide unambiguous proof of consent, showing that the user’s consent was collected by a valid means.
What is free, specific, and informed consent?
You must obtain consent for each specific processing purpose, for example one consent to send newsletters and another to send promotional material on behalf of third parties. Consent may be requested with one or more checkboxes that are not pre-selected, not mandatory or coerced (freely given), and accompanied by disclosures that make it clear how the user’s data will be used.
How can proof of valid consent be demonstrated unambiguously?
A range of information must be collected each time a user fills in a form on your site or app, including a unique user identification code, the content of the privacy policy accepted, a copy of the form submitted, and a record of the opt-in mechanism used.
Isn’t the email I receive from the form enough proof of consent?
Unfortunately, no. Some information needed to reconstruct the consent collection process is missing, such as a copy of the form the user actually completed and the version of the privacy documents available to the user at the time.
Do I have to comply with the LGPD if my organization isn’t based in Brazil?
The LGPD’s territorial scope extends outside Brazil, so you may have to comply even if you aren’t based there. You fall under the LGPD if you process data from individuals located in Brazil, regardless of their nationality (even if they were in Brazil only at the time of data collection).
Terms and Conditions
In certain circumstances, it can be necessary to protect your online business from potential liabilities with a Terms and Conditions document. Though not always legally required, Terms and Conditions set the way your product, service, or content may be used, in a legally binding way. They typically contain copyright clauses, disclaimers, and terms of sale, allow you to set governing law, list mandatory consumer protection clauses, and more. Terms and Conditions should at least include:
- the identification of the business;
- a description of the service your site or app provides;
- information on risk allocation, liability, and disclaimers;
- warranty and guarantee information;
- the existence of a withdrawal right;
- safety information, including instructions for proper use (e.g., terms of delivery);
- rights of use;
- conditions of use or purchase (e.g., age requirements or location-based restrictions);
- refund, exchange, or termination policies and related information;
- information on methods of payment.
When is it mandatory to have Terms and Conditions?
Everyone from bloggers to e-commerce, SaaS, and enterprise businesses can benefit from Terms of Use. In some cases they’re mandatory, such as e-commerce, where payment data is processed.
Can I copy a Terms and Conditions document from another site?
Because it’s a legally binding agreement, it must meet legal requirements, match your specific business processes and model, and stay up to date with the laws it references. Copying Terms and Conditions from other sites is very risky and could result in the document being void or unenforceable.
How We Can Help
How We Can Help You
Thanks to our partnership with iubenda, we can help you configure everything you need to make your site or app compliant. iubenda is the simplest, most complete, and most professional solution for complying with regulations.
- Privacy and Cookie Policy GeneratorWith iubenda’s Privacy and Cookie Policy Generator, we can prepare a fully customized, self-updating policy for your site or app. iubenda’s policies are generated from a database of clauses drafted and continuously reviewed by an international team of lawyers.
- Cookie SolutionA comprehensive solution for the EU Cookie Law, CCPA, and other third-party requirements: it displays a GDPR-compliant cookie banner or CCPA notice of collection on each user’s first visit, blocks profiling cookies until consent, and collects consent. It also supports opt-out from sale for California users through a “Do Not Sell My Personal Information” link.
- Consent SolutionCollects and stores unambiguous proof of consent whenever a user fills out a form, such as a contact form or newsletter signup, as required by the GDPR and the Brazilian LGPD. It can also document opt-out requests from California consumers, as required by the CCPA.
- Terms and Conditions SolutionWith iubenda’s Terms and Conditions Generator, we can prepare a fully customized, self-updating T&C document for your site or app, generated from a database of clauses drafted and continuously reviewed by an international team of lawyers.