Your customers have a right to know how you are handling their personal data. Whether you are processing credit card payments, saving their shipping or contact information, or simply signing them up for a newsletter, customers should know what data your business collects and how it is used. A good privacy plicy does just this.
Are Privacy Policies Required by Law?
It depends. In general, the Federal Trade Commission recommends privacy policies for most websites that collect and share consumer data. But laws different from place to place and depending on what data you collect. In the United States, federal laws require privacy policies for businesses collecting sensitive data, such as personal information from children under 13, protected health information, or information collected to provide certain financial products or services (e.g., loans, investment advice, insurance) to consumers. But some states have their own requirements for privacy policies. Canada also has regulations about privacy online.
- Keep it real. Say what you do and do what you say. Your policy is a pledge to your customers about how your business will handle and protect their personal data. It should accurately reflect data practices unique to your business. You can check out policies of similar businesses for inspiration, but don’t cut and paste another company’s policy – one size does not fit all!
- Keep it current. Make sure your policy is updated if you change your business and privacy practices affecting. Communicate any substantial changes in data use or sharing to customers before they take effect
Issues to Address in your Policy
You are legally responsible for abiding by the privacy promises you make in your policy. If you have questions about your obligations, seek legal guidance before finalizing the policy to make sure it complies with federal and state laws that may apply to your business.
- What data is collected. Identify the types of data your site collects. In addition to names, home addresses, email addresses, phone numbers, credit card information, and IP addresses, you may be collecting information about your customers’ interests and purchase histories or demographic information such as their gender, age, income or marital status. Your analytics provider, your advertisers, your third party shopping cart or payment processor may all be collecting information on various parts of the site. These activities should be identified and consumers should be directed to any third party privacy policies that may apply.
- How data is being collected. Online forms used to enter email details for newsletters and credit card data for purchases may be obvious to the consumer. Data collection using cookies and other trackers placed on the visitor’s computer browser may go unnoticed. You should clearly explain your cookie practices to customers.
- What you are doing with the data. Tell your customers how you’re using their data and how, where and how long you will store it. If you share customer data with affiliates or service providers, sell data you collect to business partners, or allow marketers or others to collect data on your site, be sure to explain what information is being shared or sold and how it may be used.
- How customers can control their data. Provide a point of contact at your business – an email address or phone number – to help customers change passwords, unsubscribe from mailing lists, close accounts, or complain if there’s a problem. If marketers are using your site to collect browsing data for interest-based advertising, you should also provide customers with opt-out information for this activity.
- How you protect the data. You should be protecting customer data with strong data integrity and security measures. You can reference these measures in your published policy to provide assurance to your customers. But avoid going into detail — publicly revealing too much about your security practices could put your systems at risk.
For More Information
For more on how to make sure your business complies with privacy laws, including GDPR and COPPA, follow these tips. Check out the National Cyber Security Alliance’s tips for businesses. You can find more data security tips from the BBB at “Data Security – Made Simpler.” (bbb.org/data-security)
Hear BBB’s privacy and security professionals discuss data privacy issues on our “Better Business > Better Series” podcast series. Make sure to subscribe to the series on your mobile device or listen to it on the web.
Businesses should check out BBB’s Five Steps to Better Business Cybersecurity (BBB.org/cybersecurity). Ask the BBB in your area about programs for business leaders and employees (BBB.org/bbb-locator).