Is Your Website Data Privacy Compliant for 2024?
With new consumer data privacy protection laws being enacted by state legislatures, being “Data Privacy Compliant” is a critical factor for your firm’s digital footprint in 2024.
Mention the list of cookies collected by your website from the users/customers.
cpr email marketing
cpr email marketing
cpr email marketing
Is Your Website Data Privacy Compliant For 2024?
StaffJanuary 2024
Originating in the EU, Data Privacy Compliance is now the buzz all across the US as firms race to manage the risks, fines and penalties associated with non-compliance. Your business needs to stay ahead of the curve by providing a safe environment for your customers to engage with you in the digital arena.
Websites, apps and social media platforms collect and store personal data that they receive from users in order to offer and improve upon the services they offer. As businesses engage clients more and more in the digital arena, the importance of data privacy has grown fourfold. Data privacy is not only about the protection of a user's personal data in the digital realm, but also the empowerment of users who share their data in the digital space to determine who can access their personal information and to what extent.
Data Privacy awareness in the world can easily be described as before the US Presidential election of 2016 and after. After the elections, a story broke out about how the data of millions of Facebook users was gathered by the company without their consent, through a third-party company known as Cambridge Analytica. The data gathered was to be used for political advertising. The company did this by asking a series of questions to create a psychological profile of individual users, the data was then collated and used for targeting voters during the elections. It turns out that….
Data of about 87 million Facebook users was collected (and shared without their consent).
This brought to light a serious laxity in privacy laws and also showcased how little control users have over what and how much of their personal information can be shared by apps, websites, e-commerce companies and social media platforms.
The direct result of the Cambridge Analytica fiasco was that governments were jolted into action, and we now have stringent laws in place that protect users and consumers alike from such data-sharing activities (without their prior consent). In 2018 The European Union’s General Data Protection Regulation (GDPR) came into effect. It regulates how the data of the subjects of the European Union can be collected, stored, and processed, and gives the citizens rights to control their personal data. It also includes a right to be forgotten.
Note: Firms in the US that provide services or serve clients in the EU have had to update their digital footprint to follow the regulations set down by GDPR. Over the past few years, CPR has assisted the majority of clients that do business across the pond to achieve this compliance.
Here in the USA, the majority of states are in the process of creating and enforcing data privacy laws, with several already enacting laws, to protect the rights of users and their personal information in the digital space. The responsibility lies on the business entity to ensure that its digital platforms are adhering to these requirements. The strictest and perhaps the most famous of these laws was passed in 2018, known as the CCPA (CALIFORNIA CONSUMER PRIVACY ACT). The act was updated in 2020 and took effect in 2023.
Business leaders need to realize that it's already been more than five years since this all started, and non-compliance could lead to serious consequences (fines and penalties). Some of the rights that CCPA allows a user/consumer are:
- The right to know what personal information a business (apps, websites, social media, etc.) collects and to whom it is sold.
- The right to delete personal information collected by the business.
- The right to opt out of the sale of personal information.
- The right to non-discriminatory treatment for exercising privacy rights.
- The right to limit the use and disclosure of sensitive data.
- The right to correct inaccurate data that a business collected about them.
There are currently (as of November 2023) 12 US states that have data privacy laws in place, these are: California, Virginia, Connecticut, Colorado, Utah, Iowa, Indiana, Tennessee, Oregon, Montana, Texas, and Delaware. The rest are not far behind…!
Most if not all websites today ask you if you want to accept cookies. This choice offering is a direct result of the enactment of data compliance laws. It is simply the beginning of the puzzle, as there are many other parameters that companies need to address with their in-house webmasters or an outsourced digital solutions partner. As your Digital Partner, Consult PR, Inc., AKA The Digital WOW follows, promotes and recommends best practices regarding Data Privacy Compliance. Although there is a huge list, here are some of the practices that we at The Digital WOW offer:
- Mention the list of cookies collected by your website from the users/customers.
- Cookies notification on the website (offering a user to read and agree with the privacy policy).
- A form allowing a user to delete their information/data.
- Right to be forgotten: Users/customers can have their details removed from a website and the database if they request it.
- Updating the Privacy Policy of the website to have more details on how a user's data is used and 3rd party Privacy Policy list of the ones taking the info.
- …as well as several proprietary techniques
With so much emphasis being placed on Data Privacy Compliance, make sure you give it your full attention in 2024. No two websites are the same. To find out what you need to do for your website to become Data Privacy Compliant, please reach out to us.

