Do's and Dont's of Website Privacy Policies

March 4, 2021
source: 
No items found.

DO'S AND DON’TS OF WEBSITE PRIVACY POLICIES

By Marc Reiner

As direct-to-consumer marketing and sales have exploded in recent years, there has also been an explosion of website privacy policies. It is unlikely that you could find a popular site that does not have a privacy policy on the web today. Yet as late as 1998, only 14 percent of websites made any disclosures as to their data gathering or use of that data even though over 90 percent of websites collected great amounts of personal information about their users.Whether or not such an approach was advisable, laws enacted in the dominant markets of the European Union – the General Data Protection Regulation (GDPR) – and California – the California Consumer Privacy Act (CCPA) – as well as laws regarding marketing to children – the Children’s Online Privacy Protection Act (COPPA) – have effectively mandated that companies disclose their privacy policies and take great care in drafting those policies. We have prepared many of these policies on behalf of our clients and want to share our observations on best practices for these detailed, and often inscrutable, policies.

  1. DON’T fail to have a privacy policy

Although privacy concerns might seem like a secondary issue that need not be focused on either at the launch of a business or later, they are not. As discussed above, there is significant regulatory pressure both in the U.S. and in the E.U. that requires that data collection, maintenance, and processing be treated in a particular manner. A clear, well-drafted privacy policy is essential in ensuring that regulatory requirements are being met.

  1. DO write the policy in plain English

This suggestion may be surprising coming from an attorney considering our profession invented “Legalese” and uses it far too often. But the proper goal of a privacy policy is for users to understand what they are agreeing to. Clarity is a primary objective of any privacy policy. Not only is this best practice, but the GDPR makes clear that privacy policies that do not use clear and plain language are not in compliance with that law.

  1. DON’T hide your privacy policy where it cannot be found

For a privacy policy to have the most effect, it must be easy to find. This ensures any presumption and argument that the website user either read it or deliberately chose not to do so. A common location for the privacy policy is in the website’s footer space. This selection is acceptable though best practice is to have your privacy policy be accessible from all pages of the website. In addition, is it is advisable to have a link to the privacy policy on any pop-ups that seek consent to that privacy policy.

  1. DO ensure that you comply with any and all applicable data protection laws

Although the previous guidelines are important, obviously complying with the applicable laws is of paramount importance. The GDPR effectively applies to any website that collects personal information from European residents. A privacy policy may choose to make clear that certain rights and remedies that are required under the GDPR apply to any individuals that reside in the E.U. Similarly, for businesses subject to the CCPA a separate section applying to California residents is applicable. Finally, COPPA applies for websites that are targeted to children under the age of 13 and has its own requirements for what such a website’s privacy policy must contain.

  1. DON’T forget to ask for consent

Not only is your company’s privacy policy most effective when users truly read and understand it, but they must also make an informed consent to it. Consent may not be assumed, although that used to be the practice. Now, the GDPR can require an affirmative action from the user, such as clicking on an “I Accept” button on a pop-up that discloses, and preferably links to, the privacy policy or at least clicking to close a notification pop-up.

  1. DO update your privacy policy as your data collection practices change

Many companies hire us to draft their privacy policy when they set up their website for the first time and then we do not hear from them again. To put it mildly, this is not best practice. Privacy policies should include a date for when it was last modified. If it has been over a year since the policy was last modified, then it should certainly be reviewed to see if it complies with current laws governing data protection and also whether it truly reflects the company’s current data practices.

  1. DON’T use the same privacy policy for vastly different users

Some business, such as those in the Software as a Service (SaaS) space, have several different types of users. These may be customers, developers, and partners. Each of these different types involves a different type of use of data. The privacy policy should reflect these differences. Instead of having just one privacy policy, an alternative is to have a different policy applicable to each of the key categories of users.

  1. DO make sure your team knows what is in your privacy policy

A privacy policy is only effective to the extent that it reflects your company’s actual privacy practices. It is important that your team knows of your policy and ensures that it is followed as written. The privacy policy is more than just a document of best practices. It should track closely with your company’s actions.

  1. DON’T ignore how your vendors and partners use customer data

Under CCPA and GDPR, a business may be held financially liable for failure to perform due diligence on third parties that process customer data. Marriott Hotel Group was fined $123 million by UK authorities as the result of laxity in this area. Companies should be cautious when reviewing data processing agreements with its vendors and partners to make sure that those companies’ data policies are consistent with their own such policies.

  1. DO designate a Data Protection Officer (DPO)

With something as important and legally fraught as data protection, it is important to centralize responsibility. Naming a DPO can ensure that a complicated and regulated area is given the attention that is warranted.* * * * *Drafting a privacy policy is an important and often difficult task. It requires navigating the legal requirements for these policies while still keeping in mind that the readers of the policies are generally not trained lawyers. If you need assistance in this area or have any questions, please feel free to reach out to Marc Reiner at HBA mreiner@hballp.com.Marc Reiner’s current practice includes General Commercial Litigation; the registration of trademarks; litigation and counseling in the areas of trademarks, copyrights, false advertising, cybersquatting, and violations of the rights of privacy and publicity.

Do's and Dont's of Website Privacy Policies

March 4, 2021

DO'S AND DON’TS OF WEBSITE PRIVACY POLICIES

By Marc Reiner

As direct-to-consumer marketing and sales have exploded in recent years, there has also been an explosion of website privacy policies. It is unlikely that you could find a popular site that does not have a privacy policy on the web today. Yet as late as 1998, only 14 percent of websites made any disclosures as to their data gathering or use of that data even though over 90 percent of websites collected great amounts of personal information about their users.Whether or not such an approach was advisable, laws enacted in the dominant markets of the European Union – the General Data Protection Regulation (GDPR) – and California – the California Consumer Privacy Act (CCPA) – as well as laws regarding marketing to children – the Children’s Online Privacy Protection Act (COPPA) – have effectively mandated that companies disclose their privacy policies and take great care in drafting those policies. We have prepared many of these policies on behalf of our clients and want to share our observations on best practices for these detailed, and often inscrutable, policies.

  1. DON’T fail to have a privacy policy

Although privacy concerns might seem like a secondary issue that need not be focused on either at the launch of a business or later, they are not. As discussed above, there is significant regulatory pressure both in the U.S. and in the E.U. that requires that data collection, maintenance, and processing be treated in a particular manner. A clear, well-drafted privacy policy is essential in ensuring that regulatory requirements are being met.

  1. DO write the policy in plain English

This suggestion may be surprising coming from an attorney considering our profession invented “Legalese” and uses it far too often. But the proper goal of a privacy policy is for users to understand what they are agreeing to. Clarity is a primary objective of any privacy policy. Not only is this best practice, but the GDPR makes clear that privacy policies that do not use clear and plain language are not in compliance with that law.

  1. DON’T hide your privacy policy where it cannot be found

For a privacy policy to have the most effect, it must be easy to find. This ensures any presumption and argument that the website user either read it or deliberately chose not to do so. A common location for the privacy policy is in the website’s footer space. This selection is acceptable though best practice is to have your privacy policy be accessible from all pages of the website. In addition, is it is advisable to have a link to the privacy policy on any pop-ups that seek consent to that privacy policy.

  1. DO ensure that you comply with any and all applicable data protection laws

Although the previous guidelines are important, obviously complying with the applicable laws is of paramount importance. The GDPR effectively applies to any website that collects personal information from European residents. A privacy policy may choose to make clear that certain rights and remedies that are required under the GDPR apply to any individuals that reside in the E.U. Similarly, for businesses subject to the CCPA a separate section applying to California residents is applicable. Finally, COPPA applies for websites that are targeted to children under the age of 13 and has its own requirements for what such a website’s privacy policy must contain.

  1. DON’T forget to ask for consent

Not only is your company’s privacy policy most effective when users truly read and understand it, but they must also make an informed consent to it. Consent may not be assumed, although that used to be the practice. Now, the GDPR can require an affirmative action from the user, such as clicking on an “I Accept” button on a pop-up that discloses, and preferably links to, the privacy policy or at least clicking to close a notification pop-up.

  1. DO update your privacy policy as your data collection practices change

Many companies hire us to draft their privacy policy when they set up their website for the first time and then we do not hear from them again. To put it mildly, this is not best practice. Privacy policies should include a date for when it was last modified. If it has been over a year since the policy was last modified, then it should certainly be reviewed to see if it complies with current laws governing data protection and also whether it truly reflects the company’s current data practices.

  1. DON’T use the same privacy policy for vastly different users

Some business, such as those in the Software as a Service (SaaS) space, have several different types of users. These may be customers, developers, and partners. Each of these different types involves a different type of use of data. The privacy policy should reflect these differences. Instead of having just one privacy policy, an alternative is to have a different policy applicable to each of the key categories of users.

  1. DO make sure your team knows what is in your privacy policy

A privacy policy is only effective to the extent that it reflects your company’s actual privacy practices. It is important that your team knows of your policy and ensures that it is followed as written. The privacy policy is more than just a document of best practices. It should track closely with your company’s actions.

  1. DON’T ignore how your vendors and partners use customer data

Under CCPA and GDPR, a business may be held financially liable for failure to perform due diligence on third parties that process customer data. Marriott Hotel Group was fined $123 million by UK authorities as the result of laxity in this area. Companies should be cautious when reviewing data processing agreements with its vendors and partners to make sure that those companies’ data policies are consistent with their own such policies.

  1. DO designate a Data Protection Officer (DPO)

With something as important and legally fraught as data protection, it is important to centralize responsibility. Naming a DPO can ensure that a complicated and regulated area is given the attention that is warranted.* * * * *Drafting a privacy policy is an important and often difficult task. It requires navigating the legal requirements for these policies while still keeping in mind that the readers of the policies are generally not trained lawyers. If you need assistance in this area or have any questions, please feel free to reach out to Marc Reiner at HBA mreiner@hballp.com.Marc Reiner’s current practice includes General Commercial Litigation; the registration of trademarks; litigation and counseling in the areas of trademarks, copyrights, false advertising, cybersquatting, and violations of the rights of privacy and publicity.

No items found.
Stay updated

MEDIA

News

New York’s Noncompete Ban – what next?

July 25, 2023
source: 
Alan Baldachin
Julia Jansen
Andrew Peken
Publications

New York Website Accessibility Litigation Expands to State Court

April 26, 2023
source: 
No items found.
Publications

New California Plastic Law Forces the Industry to Rethink Packaging

August 18, 2022
source: 
No items found.
NY TIMES
News

MEET MR’S NEW CONTRIBUTOR DOUGLAS HAND

January 11, 2024
source: 
No items found.
News

Douglas Hand on the Yeezy and Adidas Fallout

September 9, 2022
source: 
Douglas Hand
Adam Michaels
Podcasts

The Laws of Style Hosted by Douglas Hand - Rinat Brodach

August 25, 2022
source: 
Douglas Hand
Publications

The Impact of Russian Sanctions on Multi-National Brands

March 24, 2022
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand - Gigi Burris

July 29, 2022
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Michael Bastian

May 11, 2022
source: 
Douglas Hand
News

Douglas Hand on What Russian Sanctions Mean for Fashion

March 29, 2022
source: 
No items found.
Publications

Protecting Trademarks in the Metaverse – What Can Be Done?

January 14, 2022
source: 
No items found.
Publications

SHOP Till You Drop by Paul K. Smith

October 29, 2021
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand - Tiffany Stevens

February 24, 2022
source: 
Douglas Hand
News

Fashion Law at a Glance with Professor Douglas Hand

December 8, 2021
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand - Bridget Foley

February 9, 2022
source: 
Douglas Hand
Publications

IS WEIGHTS AND MEASURES KNOCKING AT YOUR DOOR?

November 30, 2021
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand - Todd Snyder

August 4, 2021
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Karin Dillie

November 22, 2021
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Ippolita Rostagno

July 16, 2021
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Sam Ku

November 9, 2021
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Sarah Flint

August 19, 2021
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Kristy Caylor

October 29, 2021
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Ron Thurston

September 27, 2021
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Billy Reid

September 1, 2021
source: 
Douglas Hand
News

Douglas Hand on Legal Considerations When Launching a Fashion Brand

June 30, 2021
source: 
Douglas Hand
News

Douglas Hand as a Board Member of the FIT Foundation

June 30, 2021
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Aaron Luo

May 25, 2021
source: 
Douglas Hand
Podcasts

The Laws of Style Hosted by Douglas Hand - Euan Rellie

June 18, 2021
source: 
Douglas Hand
Adam Michaels
Alan Baldachin
Andrew Peken
News

Douglas Hand on What Fashion Can Get Out of Gaming

April 30, 2021
source: 
Douglas Hand
Publications

Use of Another Brand’s Merchandise in Promotional Materials

March 12, 2021
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand - Vanessa Barboni Hallik

April 30, 2021
source: 
Douglas Hand
News

Douglas Hand on Nike's Suit Against MSCHF Over the "Satan Shoes"

April 8, 2021
source: 
No items found.
News

Douglas Hand on Dolce & Gabbana's Defamation Suit Against Diet Prada

March 5, 2021
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 30- Josh Peskowitz

March 5, 2021
source: 
Douglas Hand
News

Douglas Hand on the Use of Antique Quilt Patterns: Bode vs. Stan

February 23, 2021
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 29- Jim Moore

February 16, 2021
source: 
Douglas Hand
News

What the Tiffany/LVMH Case May Tell Us About Future Fashion Mergers

October 28, 2020
source: 
No items found.
Publications

New “Open Storefronts” Program Allows Retailers to Operate Outside

October 28, 2020
source: 
No items found.
News

Douglas Hand on the Tiffany x LVMH Deal

January 8, 2021
source: 
Douglas Hand
David Schumeister
Mark Pieri
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 28- Gary Wassner

November 18, 2020
source: 
Douglas Hand

New Accredited Investor Definition Expands Investment Opportunities

September 25, 2020
source: 
No items found.
News

Douglas Hand on the Supreme/VF Deal

November 12, 2020
source: 
No items found.
Publications

Proposition 24 – the California Privacy Rights and Enforcement Act

October 5, 2020
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 27- Eric Jennings

October 26, 2020
source: 
Douglas Hand
News

Douglas Hand on the Future of the Modelling Industry

August 12, 2020
source: 
Douglas Hand
Publications

Being a Summer Associate during COVID-19

July 22, 2020
source: 
No items found.
Publications

Social Media Influencers: Legal Considerations for Brands

June 19, 2020
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 26- Jason Scott

August 14, 2020
source: 
Douglas Hand
Publications

The PPPFA Makes It Easier To Receive Forgiveness of PPP Loans

June 15, 2020
source: 
No items found.
Publications

Climate Change in Retail Leasing

July 3, 2020
source: 
No items found.
Publications

Preparing for Retail’s Re-Opening Post-Quarantine

May 15, 2020
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 25- Greg Lauren

June 15, 2020
source: 
Douglas Hand
News

Fashion Frameworks' Webinar: Fashion Law Amidst The COVID-19 Pandemic

May 20, 2020
source: 
No items found.
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 24- David Hart

May 16, 2020
source: 
No items found.
Publications

Neiman Marcus’ Impending Bankruptcy

April 29, 2020
source: 
No items found.
Publications

The Coming FTC Crackdown on Misleading Influencer Marketing

April 28, 2020
source: 
No items found.
Publications

The Paycheck Protection Program offers relief to small Businesses

April 2, 2020
source: 
No items found.
News

Douglas Hand on 5 M&A Fashion Predictions

April 20, 2020
source: 
No items found.
News

Marc Reiner on High Court's Trademark Ruling sparking Litigation Wave

April 26, 2020
source: 
No items found.
Publications

Covid-19 Client Advisory

March 25, 2020
source: 
No items found.
Publications

A Summary of the CARES Act and What it Could Mean for Your Business

March 27, 2020
source: 
No items found.
News

Douglas Hand on crisis management, legal issues, and opportunities for brands and retailers in WWD

March 24, 2020
source: 
Douglas Hand
Publications

Stay Secure While Working Remotely

March 21, 2020
source: 
Marc Reiner
Publications

Newly Introduced SHOP SAFE Act of 2020 Takes on Counterfeiting in Electronic Commerce But Does Not Go Far Enough

March 13, 2020
source: 
No items found.
Publications

Coronavirus Fashion Trends

March 18, 2020
source: 
No items found.
Podcasts

The Medium Rules: Aggregating and Innovating in Publishing with James Heckman, CEO of Maven

March 18, 2020
source: 
Alan Baldachin
News

Douglas Hand on Coronavirus, Cancellations & Contracts in WWD

March 10, 2020
source: 
Douglas Hand
Publications

Lessons Learned From Barneys’ Bankruptcy by Sarah Bagley and Michael Norton

March 5, 2020
source: 
Michael Norton
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 23 - Alec Baldwin

March 4, 2020
source: 
Douglas Hand
Publications

HBA's Top Tech Trends For 2020

January 14, 2020
source: 
No items found.
Publications

The Medium Rules: Network Effects with Tim Gunderson of Carta

December 26, 2019
source: 
Alan Baldachin
Podcasts

The Medium Rules: Trump Impeachment Trial with Attorneys from HBA

January 22, 2020
source: 
Alan Baldachin
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 22 - Megan Maguire Steele

January 16, 2020
source: 
Douglas Hand
News

Two Years in as a Podcast Host - What I've Learned

December 26, 2019
source: 
Alan Baldachin
Podcasts

The Laws of Style Hosted by Douglas Hand Episode 21 - Fern Mallis

December 26, 2019
source: 
Douglas Hand
Podcasts

The Laws of Style hosted by Douglas Hand Episode 20 - John Mezzo

November 11, 2019
source: 
Douglas Hand
News

RE: Barneys NY - “It’s Not Over Until It’s Over” Says Douglas Hand in WWD

October 28, 2019
source: 
Douglas Hand
News

Douglas Hand on What’s Next for Dr. Marten in this Footwear News Article

November 4, 2019
source: 
Douglas Hand
Podcasts

The Medium Rules: Media Strategies for Political Advocacy in the 2020 Election Cycle w/ Swing Left

October 31, 2019
source: 
Alan Baldachin
News

Douglas Hand Reflects on Madewell's IPO in Vogue Business Article

October 14, 2019
source: 
Douglas Hand
Podcasts

The Laws of Style hosted by Douglas Hand Episode 19 - Ryan Babenzian

October 18, 2019
source: 
Douglas Hand
Publications

M&A AND FASHION: IF THE DEAL FITS. . . BUY IT!

September 30, 2019
source: 
No items found.
News

Adam Michaels Authors Law360 Article "A New Way to Fight ADA Web Accessibility Claims..."

August 13, 2019
source: 
No items found.
News

Douglas Hand Quoted in WWD as Barneys Moves Closer to a Deal

October 4, 2019
source: 
Douglas Hand
News

Partner Adam Michaels Weighs in on Avenatti Extortion Scandal in WWD

March 26, 2019
source: 
No items found.
Podcasts

The Laws of Style hosted by Douglas Hand Episode 18 - Candice Cuoco

September 18, 2019
source: 
Douglas Hand
Podcasts

The Medium Rules: AppNexus, AT&T and the Future of Media w/Michael Rubenstein

September 18, 2019
source: 
Alan Baldachin
News

Douglas Hand Talks Retailer Website Accessibility Suits in WWD

July 17, 2019
source: 
Douglas Hand
Publications

Stories From the Crypt: Some ICO Lessons From Dot-Com 1.0 — A Venture Lawyer’s Perspective

May 2, 2018
source: 
No items found.
News

Alan Baldachin Featured in Crains NY on "How to Make Money in Tech"

August 19, 2019
source: 
Alan Baldachin
Publications

6 Priorities for Israeli Founders Seeking Early-Stage Capital in the US

August 9, 2019
source: 
No items found.
News

Douglas Hand on What’s Next for Barneys After Bankruptcy in WWD

August 7, 2019
source: 
Douglas Hand
News

HBA's Douglas Hand Offers Advice to Brands in this WWD Article

August 2, 2019
source: 
Douglas Hand
Podcasts

The Medium Rules: The Rise of Food Media, with Gail Simmons

June 13, 2019
source: 
Alan Baldachin
Podcasts

The Laws of Style hosted by Douglas Hand Episode 16 - Barbara Kolsun

July 2, 2019
source: 
Douglas Hand
Podcasts

The Laws of Style hosted by Douglas Hand Episode 17 - Dimitry Toukhcher

July 12, 2019
source: 
Douglas Hand
Podcasts

The Medium Rules: Podtech Analytics & Attribution w/ Sean Creeley & Andy Pellett of Podsights

August 6, 2019
source: 
Alan Baldachin
Publications

New NYC Retail Requirements for Portable Wheelchair Ramps

November 12, 2019
source: 
No items found.
Podcasts

The Laws Of Style Hosted By Douglas Hand Episode 15 - Nick Wooster

June 5, 2019
source: 
Douglas Hand
Publications

The Uncertain Legal Future of Embedded Photographs in Tweets by Julia Paranyuk

June 20, 2019
source: 
No items found.
HBA news

The Laws of Style Hosted by Douglas Hand – Rinat Brodach

July 3, 2022
source: douglas hand
HBA news

The Laws of Style Hosted by Douglas Hand – Rinat Brodach

July 3, 2022
source: douglas hand
HBA news

The Laws of Style Hosted by Douglas Hand – Rinat Brodach

July 3, 2022
source: douglas hand
HBA news

The Laws of Style Hosted by Douglas Hand – Rinat Brodach

July 3, 2022
source: douglas hand