IoT Worlds
Blog

Adapt your website or app to the regulations

The law obliges each site/app that collects personal data to disclose relevant details to users via dedicated privacy and cookie notices.
Privacy policies must contain certain fundamental elements specific to your particular processing activities, including:
• the contact and identifying details of the data controller;
• which personal data is being processed;
• the purposes and methods of processing;
• the categories of sources from which consumers’ data is being collected;
• the legal bases of processing (e.g., consent);
• the third-parties that may also access the data — this includes any third-party tools
(e.g., Google Analytics);
• details relating to the transfer of data outside the European Union (where it applies);
• the rights of the user;
• description of notification process for changes or updates to the privacy policy;
• the effective date of the privacy policy.

The cookie policy specifically describes the different types of cookies installed through the site, any third-parties to which these cookies refer — including a link to the respective documents and opt-out forms — and the purposes of the processing.

Can’t we use a generic document?

It’s not possible to use generic documents as your policy must describe in detail the specific data processing carried out by your site/app, and must also include the particular details of any third-party technologies (e.g., facebook Like buttons or Google Maps) specifically used by you.

What if my site does not process any data?

It’s very difficult for your site not to process any data. A simple contact form or a traffic analysis system such as Google Analytics is enough to trigger the obligation to prepare and display a privacy and cookie policy.

In addition to providing an easily available and accurate cookie policy, in order to adapt a website to the cookie law, it is also necessary to show an informative cookie banner which links to a detailed cookie policy at the first visit of each user, giving the user the opportunity to either reject or grant consent to the installation of cookies. Most types of cookies, including those issued by tools such as social sharing buttons, should only be released after the user have provided a valid consent.
Furthermore, many third-party vendor networks may limit ad reach if you do not have a cookie management system that meets industry standards in place — potentially reducing your ability to generate ad revenue.

Cookies are small files used to store or track certain information while a user browses a site. Cookies are now essential to the proper functioning of a site. In addition, many third party technologies that we integrate into our sites, such as simple video widgets or analytics programs, also use cookies.

CCPA

CCPA requires that businesses inform California users about how and why their data is being used, their rights in regards to this and how they can exercise these rights — including the right to opt-out. In order to comply with these requirements, you need to include both the relevant disclosures within your privacy policy and display a notice of collection at the first user’s visit (where applicable).
The process which allows the user to opt-out should be facilitated via a “Do Not Sell My Personal Information” (DNSMPI) link which should be accessible from your notice of collection and elsewhere on your site (best practice would be to also include the link in the footer).

My business is not based in California, do I need to comply with CCPA?

The CCPA applies to most businesses that collect or could potentially collect Californian customers personal information, whether or not the business itself is geographically located in California. Since IP addresses are considered personal information, this likely applies to any website with at least 50,000 unique visits per year from California.

When a user directly enters personal data on a site/app, for example by filling in a contact form, service registration or newsletter subscription, it is necessary to collect consent that is freely given, specific and informed. Under the GDPR, it’s also necessary to keep unambiguous records that allow you to demonstrate that valid consent was collected.

You must obtain consent for each specific processing purpose — for example, a consent to send newsletters and another consent to send promotional material on behalf of third parties. Consent may be requested by setting up one or more checkboxes that are not pre-selected, not mandatory or coerced (freely given) and accompanied by relevant disclosures that make it clear to the user how his or her data will be used.

A range of information must be collected each time a user fills in a form on your site/app. This information includes a unique user identification code, the content of the privacy policy accepted, a copy of the form submitted by the user as well as a record of the opt-in mechanism used.

Unfortunately, it is not sufficient, as some information necessary to reconstruct the suitability of the procedure for collecting consent is missing, such as a copy of the form actually completed by the user and the version of the privacy documents available to the user at the time the consent was collected.

How IoT Worlds can help you using iubenda’s solutions

Thanks to our partnership with iubenda, we can help you configure everything you need to make your site/app compliant. iubenda is in fact the simplest, most complete and professional solution to comply with regulations.

With iubenda’s Privacy and Cookie Policy Generator we can prepare a fully customized, self-updating policy for your site/app. iubenda’s policies are generated starting from a database of clauses drafted and continuously reviewed by an international team of lawyers.

The iubenda Cookie Solution is a comprehensive solution to meet EU Cookie Law, CCPA and any other third-party requirements by facilitating the display of a GDPR-compliant cookie banner or a CCPA notice of collection at each user’s first visit, the preventive blocking of the profiling cookies and the collection of users’ consent to the installation of cookies. It also supports opt-out from sale for Californian users via a “Do Not Sell My Personal Information” link.

iubenda’s Consent Solution allows the collection and storage of an unambiguous proof of consent whenever a user fills out a form — such as a contact form or newsletter subscription — on your website or app.

Terms and Conditions Generator

With iubenda’s Terms and Conditions Generator we can prepare a fully customized, selfupdating T&C document for your site/app. iubenda’s Terms and Conditions are generated starting from a database of clauses drafted and continuously reviewed by an international team of lawyers.

Contact us to receive a tailored proposal!

Related Articles

WP Radio
WP Radio
OFFLINE LIVE