Website Policy Blueprint US · EU · Colombia · v2.0

Deep research and implementation guide

Website policies required across the US, EU and Colombia

There is no universal list of policies that every website must publish. The correct policy package is determined by jurisdiction, controller status, commercial activity, user accounts, tracking technologies, data sensitivity, audience, and platform features.

Recommended posture: global compliance floor Public login prototypes Supabase Auth Cloudflare Workers Research date: July 22, 2026 Not legal advice

Primary recommendation

Build one durable global policy floor, then add narrow jurisdiction and feature modules.

Use GDPR-level transparency, California-compatible collection notices and rights, Colombia-compliant authorization evidence, no nonessential tracking by default, and working account export and deletion. Add specialized policies only when a feature activates them.

Scope and legal model

“Required” has three meanings

A document may be expressly required by statute, operationally required to satisfy a legal duty, or strongly advisable to establish an enforceable relationship and reduce ambiguity.

Expressly required

A law directly requires a notice, policy, disclosure, link, or procedure.

  • GDPR collection notice
  • California CalOPPA policy
  • Colombia treatment policy and notice
  • COPPA child privacy policy

Operationally required

The law requires conduct that needs a public interface or internal procedure.

  • Consumer-rights request workflow
  • Cookie preference control
  • Account deletion and export
  • Content takedown and appeal channels

Contractually advisable

Not always mandated by a named statute, but needed to define service rules and obtain defensible assent.

  • Terms of Use
  • Acceptable Use Policy
  • Prototype and availability terms
  • Security reporting policy

Boundary

This guide focuses on general public websites and login-enabled prototypes. Financial services, healthcare, education, employment, telecommunications, gambling, regulated professional services, and government systems require additional sector and local-law analysis.

Policy architecture

Recommended website policy stack

The stack separates disclosures, contractual terms, rights procedures, and internal controls. Combining them into one page can obscure consent and make versioning difficult.

Document or control Default posture Purpose Primary triggers
Privacy Notice Baseline Explains controller identity, data categories, sources, purposes, legal bases, recipients, transfers, retention, rights, security, and contacts. User accounts, forms, analytics, logs, support, or any personal data collection.
Notice at collection Baseline Provides concise, just-in-time information before the user enters an email or other personal information. California CCPA when covered; GDPR transparency; good global practice.
Cookie and device-storage notice Baseline disclosure Describes cookies, local storage, session tokens, guest data, preference storage, vendors, and durations. Any browser or device storage. Consent layer depends on purpose and jurisdiction.
Cookie preference center Triggered Blocks nonessential technologies until valid consent and supports withdrawal. EU nonessential storage; behavioral analytics; advertising; session replay; embeds.
Terms of Use Baseline for accounts Defines eligibility, account rules, service scope, user content, IP, suspension, termination, disclaimers, liability, and change procedures. Login, saved data, interactive services, beta access, API access, or user content.
Acceptable Use Policy Baseline for accounts Defines prohibited conduct, security abuse, automation, malware, impersonation, illegal content, enforcement, and appeal. Accounts, APIs, uploads, shared resources, or platform interactions.
Colombia Personal Data Processing Policy
Política de Tratamiento de Datos Personales
Jurisdictional Publishes controller duties, purposes, rights, channels, procedures, effective date, and database duration. Colombian controller or processing governed by Colombian law.
Colombia Privacy Notice and authorization
Aviso de Privacidad y autorización
Jurisdictional Gives collection-time notice and records prior, express, informed authorization where no exception applies. Collection of personal data subject to Law 1581.
Legal / company notice Jurisdictional Identifies legal entity, address, email, registration, VAT, professional or supervisory details. EU business websites; Colombia e-commerce; regulated activities.
Accessibility statement Recommended floor States target standard, status, known limitations, testing date, feedback channel, and remediation process. EU e-commerce and covered services; U.S. public accommodations; public-sector rules.
Retention schedule Internal control Defines category-level retention and disposal. The public notice summarizes it. Any personal data system.
Data rights procedure Internal + public channel Identity verification, access, correction, deletion, portability, opt-outs, appeals, and statutory deadlines. GDPR, Colombia, California, and other state privacy laws.
Incident response and breach notice plan Internal control Maps detection, containment, investigation, legal analysis, notification, evidence preservation, and communications. Any personal data system; all U.S. states have breach-notification laws.

United States

Federal baseline: sectoral law plus FTC enforcement

The U.S. still lacks one generally applicable federal private-sector privacy law. Website obligations arise from FTC consumer-protection authority, sector laws, activity-specific rules, state law, and the promises the operator publishes.

No 1×
No single general federal privacy-policy statute for all private websites
50+
Every state and major U.S. territory has breach-notification requirements
13−
COPPA applies to covered collection from children under 13
48h
TIDA removal deadline after a valid request for covered intimate imagery

General commercial website

  • Publish truthful and complete privacy representations.
  • Use security appropriate to the nature of the data.
  • Do not collect materially more data than the service needs.
  • Match public statements to actual vendors, logs, retention, and deletion behavior.
  • Provide accessible Terms and privacy links before account creation.

The FTC treats misleading privacy statements and materially inadequate data-security practices as potential unfair or deceptive practices.1

What federal law does not do

  • It does not make a copied policy safe merely because the text is comprehensive.
  • It does not convert “by using this site” into valid consent for every purpose.
  • It does not eliminate state-law duties.
  • It does not permit a beta disclaimer to waive non-waivable consumer rights.
Federal trigger: children and COPPA

COPPA applies to commercial sites and online services directed to children under 13 and to general-audience services with actual knowledge that they collect personal information from a child under 13. Covered operators need a clear child-specific privacy policy, direct parental notice, verifiable parental consent, parent access and deletion, minimization, security, and purpose-limited retention.2

Prototype control: use an 18+ eligibility rule unless the product intentionally designs age assurance, parental consent, child rights, and minor-safe defaults.

Federal trigger: subscriptions, free trials and auto-renewal

Online negative-option programs remain subject to the Restore Online Shoppers’ Confidence Act and FTC Act enforcement. Before charging, disclose all material terms clearly, obtain express informed consent, and provide a simple cancellation mechanism.3

Required policy modules: subscription terms, billing cadence, trial conversion, renewal, cancellation, refund policy, price changes, and confirmation records. State auto-renewal laws may add stricter requirements.

Federal trigger: commercial email

CAN-SPAM applies to commercial email, including business-to-business messages. Operational email and marketing email should be classified separately. Marketing messages need accurate headers, nondeceptive subject lines, identification as advertising where applicable, a valid postal address, and a working opt-out process.4

Federal trigger: user uploads and hosted content

A service seeking DMCA section 512(c) safe-harbor protection for user-stored material must designate an agent with the Copyright Office and publish the agent’s contact information. It also needs an operational notice-and-takedown process and other safe-harbor controls, including a repeat-infringer policy.5

Since May 19, 2026, covered platforms must also provide a clear process to request removal of nonconsensual intimate images and remove validly identified content and known identical copies within 48 hours under the TAKE IT DOWN Act.6

Federal and litigation trigger: accessibility

DOJ states that the ADA applies to goods and services offered online by businesses open to the public. Private businesses do not yet have a single detailed federal web technical standard under Title III, but they must provide equal access and effective communication. WCAG is the practical engineering baseline.7

The specific Title II rule for state and local governments uses WCAG 2.1 AA. In April 2026, DOJ extended compliance dates to April 26, 2027 for entities serving 50,000 or more people and April 26, 2028 for smaller public entities and special districts.8

California and U.S. states

The state layer is now the operative privacy baseline

By July 2026, 20 states had comprehensive or broad consumer privacy laws in effect. Four additional states enacted new laws in 2026 with future effective dates. Thresholds and exemptions vary substantially.

Current landscape

Active broad laws: California, Colorado, Connecticut, Delaware, Florida, Iowa, Indiana, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia. Alabama, Louisiana, Oklahoma, and Vermont enacted additional laws in 2026. Florida’s law is materially narrower than the common state model.9

California: two different policy regimes

CalOPPA

CalOPPA applies to an operator of a commercial website or online service collecting personally identifiable information—including an email address—from California consumers. It is not limited to businesses meeting CCPA thresholds.

  • Conspicuously post the policy.
  • List collected PII categories.
  • List categories of third parties receiving PII.
  • Describe any user review/change process.
  • Explain material-change notices.
  • State the effective date.
  • Explain Do Not Track or similar mechanisms.
  • Disclose cross-site collection by other parties.

10

CCPA / CPRA

CCPA applies only when a statutory “business” threshold or relationship is met. The current revenue threshold is $26.625 million, effective January 1, 2025; other thresholds concern 100,000 consumers or households and revenue from selling or sharing personal information.

  • Notice at or before collection.
  • Categories, purposes, sale/share status, and retention.
  • Access, correction, deletion, and portability methods.
  • Sale/share opt-out and Global Privacy Control where applicable.
  • Sensitive-information limitation where applicable.
  • Prior-12-month disclosures and annual policy review.
  • Service-provider and contractor terms.
  • Reasonable security and proportional processing.

11 12

Important distinction

A small prototype may be below CCPA thresholds and still be subject to CalOPPA. Do not use “we are not a CCPA business” as a reason to omit the general privacy policy.

Harmonized state-law notice

A single U.S. state addendum can usually support the common state model. It should explain:

Disclosures

  • Personal-data categories
  • Purposes
  • Categories shared or sold
  • Third-party categories
  • Retention or criteria
  • Contact methods

Rights

  • Access or confirmation
  • Correction
  • Deletion
  • Portable copy
  • Sale and targeted-ad opt-out
  • Profiling opt-out
  • Appeal where required

Operational controls

  • Sensitive-data consent
  • Universal opt-out signals
  • Data protection assessments
  • Processor contracts
  • Data minimization
  • Reasonable security

State-specific overlays that a general privacy law matrix misses

State / regime Trigger Website policy or control
Washington — My Health My Data Consumer health data outside traditional HIPAA relationships, including inferred health information. Separate and prominently linked consumer health data privacy policy, authorization for certain sharing, deletion workflows, and geofencing restrictions.
Illinois — BIPA Collection or possession of biometric identifiers or biometric information. Public retention/destruction policy, written notice, purpose and duration disclosure, written release, security, and no prohibited profit from biometrics.
Nevada online privacy law Covered operators collecting specified information from Nevada consumers, even outside the comprehensive-law list. Privacy notice and designated request address; opt-out of covered sales.
California minors Sale or sharing of personal information of known users under 16; registered minors posting content. Opt-in rules for sale/share and, where applicable, content-removal mechanisms.
State auto-renewal laws Subscriptions, free trials, recurring billing, or automatic renewal. Clear renewal terms, affirmative consent, acknowledgments, reminders in some states, and easy online cancellation.
All states — breach laws Unauthorized acquisition or access to defined personal information. Internal incident plan and jurisdiction-specific notice templates; some states require regulator or credit-agency notice.

European Union

Privacy is only one part of the EU website policy system

EU-targeted sites may need privacy, cookies, legal identity, consumer-contract, accessibility, intermediary-service, and AI disclosures. Member-state implementation can add local requirements.

01

Identify role

Controller, processor, trader, hosting provider, online platform, marketplace, or AI provider/deployer.

02

Map purposes

Data, lawful basis, cookies, service contract, advertising, profiling, and international transfers.

03

Publish layers

Privacy notice, storage choices, legal notice, terms, consumer information, and specialized disclosures.

04

Operate rights

Access, deletion, portability, objection, withdrawal, complaints, moderation appeals, and accessibility feedback.

GDPR privacy notice

At collection, Article 13 generally requires controller and representative identity, DPO contact where applicable, purposes and legal bases, legitimate interests where used, recipients, international-transfer information, retention, rights, complaint rights, whether provision is required, and automated-decision information. Article 14 adds source and category information when data is obtained elsewhere.13

  • Use layered and plain language.
  • Separate contract necessity from optional consent.
  • Record lawful basis per purpose.
  • Describe U.S. or other third-country hosting and transfer safeguards.
  • Do not use consent where the user has no real choice.
Cookies, local storage and device access

The ePrivacy Directive requires clear information and consent for storing or accessing information on a user’s terminal equipment unless the operation is strictly necessary to provide a service explicitly requested by the user. The rule reaches cookies, local storage, identifiers, pixels, SDK storage, and similar mechanisms through member-state law.14

Practical control: authentication and security storage can often fit the necessary exemption. Analytics, advertising, session replay, cross-site tracking, and most third-party embeds should remain blocked until valid consent.

Business identity and legal notice

A business website should make its trading identity, geographic and email address, telephone contact, legal form and register details, VAT number where applicable, and regulated-profession or supervisory information easily accessible. These duties derive from the E-Commerce Directive and national implementations.15

Terms, digital services and e-commerce

Before a distance contract, consumers must receive clear information about product or service characteristics, total price, payment and performance, trader identity, contract duration, termination, complaint channels, and withdrawal rights. Online purchases generally carry a 14-day withdrawal period, subject to exceptions. Terms must be fair and understandable.16

The Digital Content and Services Directive can apply even when the consumer provides personal data instead of money, unless the data is processed only to provide the service or satisfy legal requirements. It creates conformity and remedy obligations for digital services.17

Remove obsolete text

Do not add the old EU Online Dispute Resolution platform link. Regulation (EU) 2024/3228 discontinued the platform and repealed the regime effective July 20, 2025.18

Digital Services Act: hosting and platform terms

When a service qualifies as an intermediary, hosting provider, or online platform, the DSA can require terms describing content restrictions, moderation policies, algorithms and human review, complaint handling, and account restrictions in clear language. Additional notice-and-action, statement-of-reasons, internal complaint, transparency-report, marketplace, advertising, recommender, and minor-protection duties depend on service type and size.19

European Accessibility Act

Since June 28, 2025, the EAA applies to specified products and services, including e-commerce services, consumer banking, e-books, electronic communications, and certain transport services. Microenterprises providing services have a limited exemption under the Directive, but national implementation must be checked.20

Policy control: publish accessible service information describing how the service meets applicable accessibility requirements, known limitations, compatibility, testing, and a feedback channel. Target WCAG 2.2 AA even where the binding national standard references EN 301 549 or WCAG 2.1.

EU AI Act disclosures

Article 50 requires users to be informed when they interact directly with an AI system unless that fact is obvious in context. It also creates machine-readable marking and disclosure duties for certain synthetic content and deepfakes. The exact obligation depends on whether the operator is a provider or deployer and on the use case.21

Colombia

Policy, notice and authorization are separate controls

Law 1581 is technology-neutral and applies to personal data in databases or files subject to Colombian law. A prototype with email login normally creates regulated processing.

1. Política

Política de Tratamiento de Datos Personales

The full public governance document. It describes controller identity, processing, purposes, rights, responsible area, consultation and claim procedures, effective date, and database duration.

2. Aviso

Aviso de Privacidad

A concise notice at collection. It identifies the treatment purposes, user rights, and how to access the full policy.

3. Autorización

Autorización previa, expresa e informada

The user’s provable authorization where an exception does not apply. It must be obtained by a means that can be consulted later.

Do not collapse these

Accepting Terms of Use does not automatically prove valid Colombian data-processing authorization. Silence and a preselected checkbox are not a reliable authorization model. Preserve the exact purpose text, policy version, timestamp, locale, and acceptance event.

Required policy content and operating duties

  • Controller legal identity and contact information.
  • Specific and legitimate treatment purposes.
  • Data-subject rights to know, update, rectify, request proof, learn uses, complain, revoke, and request deletion where applicable.
  • Responsible area or person.
  • Consultation and claim channels and procedures.
  • Policy effective date and database-duration period.
  • Security, restricted access, confidentiality, and vendor controls.
  • Consultations generally answered within 10 business days, with a limited five-day extension.
  • Claims generally answered within 15 business days, with a limited eight-day extension.
  • Authorization evidence remains retrievable.
  • Material policy changes are communicated.
  • Children’s and sensitive data receive enhanced treatment.
  • International transmission and transfer roles are identified.
  • Internal policies and procedures support actual compliance.

These obligations follow Law 1581 and its implementing rules in Decree 1074, as summarized by the SIC.22 23

Spanish collection-time authorization pattern

Autorizo a [nombre legal del Responsable] para recolectar, almacenar, usar, transmitir y suprimir mi correo electrónico, identificadores de cuenta, registros de autenticación y seguridad, y contenido creado por mí, con el fin de crear y proteger mi cuenta, sincronizar mis datos, prestar soporte, atender solicitudes de derechos y cumplir obligaciones legales, de acuerdo con la Política de Tratamiento de Datos Personales.

The final text must identify the real controller, actual purposes, actual vendors, and actual processing. Colombian collection notices and authorizations should use clear, simple Spanish in the Colombian context.24

Colombia e-commerce overlay

Providers located in Colombia offering products or services electronically must provide accurate and accessible identity and contact information, product or service details, total price and additional charges, general contract conditions, transaction review and acceptance evidence, secure transaction mechanisms, complaint channels with traceability, and consumer-remedy information. A visible link to the SIC consumer-protection site is required under the amended Article 50 framework.25

  • Terms of sale or service
  • Price and charge disclosure
  • Refund, withdrawal and reversal policy
  • Delivery or performance terms
  • Warranty information
  • PQR contact and traceability
  • Proof of user acceptance
  • Visible SIC link
Cookies in Colombia

Colombia does not use an EU-style standalone cookie statute as the primary model. Cookies and similar identifiers fall into Law 1581 when they constitute or support personal-data processing. The privacy notice and authorization model should therefore describe relevant identifiers, purposes, vendors, retention, and user choices.

Feature trigger matrix

Policies activated by product capabilities

The safest architecture treats each feature as a compliance dependency. A feature cannot ship until its public disclosures and operational controls are present.

Feature Policy module Controls that must exist Primary regimes
User login Privacy, Terms, AUP, collection notice, storage disclosure Versioned assent, authorization where needed, session controls, export, deletion, RLS All regions
Analytics or advertising Cookie policy, preference center, U.S. state addendum Prior blocking in EU, withdrawal, sale/share and targeted-ad opt-outs, GPC EU, California, many U.S. states
Paid product Terms of sale, refund, cancellation, warranty, tax and pricing disclosures Order confirmation, total price, complaint channel, performance and delivery terms EU consumer law, Colombia Law 1480, U.S. state law
Recurring subscription Subscription and auto-renewal terms Express consent, renewal disclosure, simple cancellation, confirmations and reminders where required ROSCA, FTC Act, state auto-renewal, EU consumer law
User uploads or posts UGC terms, content standards, moderation policy, DMCA policy Takedown, counter-notice, repeat infringers, reporting, appeal, DSA duties where applicable DMCA, DSA, TIDA
Health or wellness data Consumer health data privacy policy Separate consent, deletion, sharing authorization, breach analysis, no health-ad targeting FTC HBNR, Washington and other state health laws, GDPR Art. 9
Biometrics Biometric privacy and retention policy Written notice/release, purpose and duration, security, destruction schedule, vendor limits Illinois BIPA and other state biometric laws; GDPR
Children or teens Child/minor privacy policy and parental notice Age design, parental consent, minor rights, minimization, safe defaults, deletion COPPA, state minor laws, GDPR Art. 8, Colombia Law 1581
AI chatbot or generation AI disclosure and acceptable-use terms AI interaction notice, limitations, data-use disclosure, content marking where applicable EU AI Act, state AI laws, FTC Act
Marketplace Marketplace terms, seller policy, product-safety and trader disclosures Trader traceability, complaint handling, product safety, moderation and ranking transparency EU DSA/GPSR, INFORM Consumers Act, Colombia consumer law
Security research Vulnerability disclosure policy Authorized testing boundaries, reporting channel, safe harbor language, remediation workflow Recommended operational control

Login-enabled prototypes

Minimum public policy and product controls

Login creates account, authentication, session, device, network, security, and user-content records. The privacy model must cover all of them.

Data inventory

  • Email address and user UUID
  • Authentication provider and verification events
  • Login, logout, refresh and failure records
  • IP address and user agent where logged
  • Access, refresh and session identifiers
  • Browser-local authentication storage
  • Guest-mode local data
  • User-created records and timestamps
  • Support and consent records

Recommended low-risk posture

  • 18+ accounts
  • No advertising or cross-site tracking
  • No sensitive-data fields
  • No public profiles or shared content
  • No AI training on user content
  • No files until storage controls are designed
  • Short operational log retention
  • Self-service export and deletion

Registration surfaces

01

Email entry

Show concise collection notice before submission. Link full privacy and treatment policies.

02

Terms assent

Use affirmative clickwrap. State that the user agrees to Terms and acknowledges the Privacy Notice.

03

Authorization

Use separate Colombian authorization or other optional consent where required. Do not precheck.

04

Evidence

Persist document version, hash, purpose version, timestamp, locale, surface and user identifier.

Acceptance ledger

user_id
document_type
document_version
document_hash
purpose_version
accepted_at
locale
acceptance_surface
application_version
withdrawn_at

Insufficient evidence

accepted_terms = true cannot prove which text, version, purposes, locale, or disclosure the user received.

Guest mode

Guest data is stored only in this browser. Clearing site data, using a different browser, or changing devices may permanently remove it. Creating an account will upload the selected guest items to cloud storage so they can be synchronized.

Do not silently migrate local data to an account. Show the item count, categories, destination, local-copy behavior, cancel option, and privacy link before upload.

Implementation architecture

The policy layer must be backed by enforceable controls

Policies are executable requirements. Each claim must map to a system control, owner, test, evidence source, retention rule, and change process.

Supabase

  • RLS on every exposed table
  • Ownership predicates using auth.uid()
  • Both USING and WITH CHECK for updates
  • No service role or secret key in clients
  • No authorization from user-editable metadata
  • Session-aware account deletion
  • Storage objects deleted before Auth user where needed

Cloudflare

  • No authorization headers or tokens in logs
  • No full request bodies by default
  • Redact email and user content
  • Document actual Workers log retention
  • Rate-limit authentication endpoints
  • Use secret bindings for private credentials
  • Define incident escalation and evidence retention

Application

  • Current-session and global sign-out
  • Reauthentication for destructive actions
  • Export in JSON or CSV
  • Account deletion status and confirmation
  • Privacy preference center
  • Policy version archive
  • Rights request tracking

Claim-to-control traceability

Public claim Required control Evidence Failure mode
“Users can delete their accounts.” Reauthenticated deletion orchestration across app rows, storage, sessions and Auth. Automated integration test and deletion audit record. Auth user deleted while storage remains or active tokens remain usable.
“We retain security logs for 30 days.” Configured log sink TTL and no unmanaged exports. Provider configuration and sampled deletion verification. External sink keeps logs indefinitely.
“We do not sell or share personal data.” No ad-tech, list rental, cross-context behavioral advertising, or incompatible third-party use. Vendor and network inventory. Analytics SDK or embedded content performs undisclosed sharing.
“Only you can access your data.” RLS ownership policies, server authorization and cross-user tests. User A/User B isolation suite. TO authenticated policy without row ownership predicate.
“Nonessential cookies are optional.” Prior blocking, equal accept/reject choice and withdrawal. Clean-browser network test before and after consent. Trackers load before banner choice.

Release governance

Public-login release gate

Treat these as release conditions, not post-launch documentation tasks.

P0

Required before public login

  • Real legal controller and monitored contact channels
  • Privacy Notice and collection notice
  • Terms and AUP with affirmative assent
  • Colombia policy, notice and authorization where applicable
  • Cookie/storage inventory and no unapproved nonessential tracking
  • RLS and cross-user isolation tests
  • Account export, current/global logout and complete deletion
  • Versioned acceptance and authorization evidence
  • Vendor and international-transfer inventory
  • Retention schedule and incident-response procedure
  • Accessibility target and feedback channel
  • Age eligibility and underage-account procedure
P1

Required before broader adoption or higher-risk features

  • Automated rights-request workflow and appeals
  • Formal DPIA or state data-protection assessment where triggered
  • Session inventory and high-risk operation reauthentication
  • Vendor/subprocessor change monitoring
  • Backup-deletion verification
  • Consent migration and material-change reacceptance
  • External security testing and incident exercise
  • Jurisdictional e-commerce, subscription, health, biometric, minor, AI or UGC modules

Statements that should fail review

  • “We collect no personal information.”
  • “Your data never leaves your device.”
  • “We never share data with third parties.”
  • “Your data is 100% secure.”
  • “By using the site, you consent to everything.”
  • “Data is immediately deleted from every system.”
  • “Supabase compliance makes our app compliant.”
  • “The prototype is exempt because it is free.”
  • “Accepting Terms authorizes every processing purpose.”
  • “We may use data for any business purpose.”

Evidence and provenance

Primary sources and current trackers

Sources were prioritized toward statutes, regulators, and official government guidance. The state-law count uses a current professional tracker and official 2026 enactment records.

02
FTC — COPPA FAQs

Child privacy policy, parental notice, consent, rights, minimization, security and retention.

13
EUR-Lex — GDPR

Article 13 and 14 privacy-notice requirements and broader controller duties.

28
CPPA — CCPA FAQs

Rights methods, Global Privacy Control, privacy links and phased ADMT rules.

Methodology

The research separated statutory publication duties from operational duties and advisable contract documents. It prioritized primary legal and regulator sources, checked changes through July 22, 2026, and treated state-law applicability as threshold-dependent rather than universal.