- Email address
- First and last name
- Billing and shipping address
- Credit card information
In 1968, Council of Europe did studies on the threat of the Internet expansion as they were concerned with the effects of technology on human rights. This lead to the development of policies that were to be developed to protect personal data.
This agreement can also be known under these names:
- Privacy Statement
- Privacy Notice
- Privacy Information
- Privacy Page
The requirements for Privacy Policies may differ from one country to another depending on the legislation. However, most privacy laws identify the following critical points that a business must comply with when dealing with personal data:
- Notice - Data collectors must clearly disclose what they are doing with the personal information from users before collecting it.
- Choice - The companies collecting the data must respect the choices of users on what information they choose to provide.
- Access - Users should be able to view, update or request the removal of personal data collected by the company.
- Security - Companies are entirely responsible for the accuracy and security (keeping it properly away from unauthorized eyes and hands) of the collected personal information.
- WordPress blogs, or any other platforms: Joomla!, Drupal etc.
- Ecommerce stores
- Desktop apps
- Digital products
In the U.S., privacy legislation varies from one state to another. Certain federal laws govern users' data in some circumstances.
Here are some examples of privacy laws in the U.S.:
- The Gramm-Leach-Bliley Act - This act obliges organizations to offer clear and accurate statements about their information collecting practices and it also limits usage and sharing of financial data.
- Children's Online Privacy Protection Act (COPPA) - This act is especially for businesses that collect information about children under 13 years of age.
- Health Insurance Portability and Accountability Act (HIPAA) - This act applies to online health services as well.
- California Online Privacy Protection Act (CalOPPA) - This privacy law affects anyone collecting personal information from residents of California.
- Student Online Personal Information Protection Act (SOPIPA) - This act applies if you collect personal data from students.
- Content Eraser law - This law applies if you collect data from minors (under the age of 18).
Note that there are a number of other privacy laws in the United States, so become familiar with the laws in your particular state and the state/s in which you do business.
Users need to know exactly what kinds of personal data you collect from them.
- To help develop new services or improve your existing services
- To send users emails about special offers, new services or other information they may be interested in
- To personalize their sessions on your website in order to better fit their interests, such as offering them relevant, individually tailored content
- The Information Collection and Use section is the most important section of the entire agreement where you need to inform users what kind of personal information you collect and how you are using that information.
The intro also specifies four main reasons why the company collects personal information:
- A Log Data disclosure section should inform users that certain data are collected automatically from the web browser users are using and through the web server you're using: IP addresses, browser types (Firefox, Chrome etc.), browser versions and various pages that users are visiting.
- A Cookies disclosure should inform users that you may store cookies on their computers when they visit your website. This applies even if you use Google Analytics (which would store cookies) or any other third party that would store cookies.
- A Links to Other Sites section should disclose that your website may link to other websites outside your control or ownership, i.e. linking to a news website, and that users are advised to read the Privacy Policies of each website they visit.
- A Do Not Track clause.
- A Security disclosure in the policy can give users assurance that their personal data is well protected, but you may also want to note that no method is 100% secure.
- What kind of personal information do you collect?
- What kind of personal information is collected automatically, e.g. via the web server (Apache, nginx etc.)?
- What kind of third parties are collecting personal information from your users?
- How are you using that personal information?
- Do you send promotional emails (newsletters)? If yes, can users opt-out? If so, how?
Disclose if any third parties are involved in collecting personal information in your name, i.e. you use MailChimp to collect email addresses to send weekly updates to your members.
Always use the clickwrap method to get your users to agree to your terms.