Small Fixes, Big Impact: Five Practical Ways to Strengthen Your Privacy Posture
Data privacy enforcement is accelerating, and companies of all sizes face increasing scrutiny of their data practices. But compliance doesn’t always require a complete overhaul. In fact, some of the most effective ways to avoid getting caught in a regulator’s crosshairs are also among the simplest measures a business can take to strengthen their privacy governance.
Put simply, regulators look for low-hanging fruit. Before diving into a company's internal data privacy practices, a regulator can spot-check a handful of publicly visible indicators—a stale privacy policy, the absence of a cookie banner, a missing opt-out link—and draw immediate conclusions about the company's overall compliance. These issues invite scrutiny, but they are also the easiest to fix, making them a sensible starting point for any company looking to shore up its privacy posture before a dispute arises.
Below are five practical steps any business can take to tighten up its privacy compliance and avoid becoming an easy target.
Keep Your Website Privacy Policy Updated
An outdated privacy policy is one of the fastest ways to attract regulatory attention. As the proliferation of comprehensive consumer privacy legislation continues, it becomes increasingly important for businesses to ensure alignment between their privacy practices and their privacy statements. Every state comprehensive consumer privacy law that has been enacted—24 to date—requires companies to post a website privacy policy detailing the nature and scope of the company’s data collection practices and to review such policies on at least an annual basis to ensure alignment between practices and statements.
This is sometimes codified as a requirement for companies to post the date on which the privacy policy was last reviewed or updated, making it easy for a regulator to visit a company’s website and determine whether the business has a privacy policy and whether such policy is current. Determining noncompliance due to an outdated or nonexistent privacy policy is as simple as a few clicks and scrolls.
Beyond the date itself, companies should ensure that their privacy policy accurately describes the nature and scope of the company's information collection, use, and storage practices. A number of regulators at state and federal levels have led enforcement actions against companies whose privacy statements do not reflect their actual practices, often on the basis of consumer protection laws such as Section 5 of the FTC Act and state analogs. A privacy policy drafted years ago may not account for new data categories the business has started collecting, new third-party vendors receiving personal information, or new state-law requirements that have taken effect since the policy was last reviewed, leaving the company vulnerable to regulatory actions.
An annual review, ideally conducted with the assistance of legal counsel, ensures that the policy remains both legally compliant and factually accurate.
Implement a Cookie Banner
While laws in the United States generally do not explicitly require companies to have a cookie banner, the presence of automatic data collection tools—particularly in the absence of an accompanying cookie banner providing notice and choice at the point of collection—is a growing source of litigation risk. In recent years, for example, a number of pro se litigants and plaintiff’s firms have initiated a wave of litigation under the California Invasion of Privacy Act (“CIPA”) targeting websites that deploy cookies and similar tracking technologies without first obtaining consent. At this point, thousands of companies nationwide have received a demand letter alleging CIPA non-compliance.
The fix is simple: install a cookie banner or cookie consent management platform on your website. For additional protection, companies can elect to toggle off automatic data collection tools unless and until a user affirmatively enables such tools. Companies should also audit their websites to identify all cookies currently in use and confirm whether the data collected by those tools is being transferred to or shared with third parties.
A website’s cookie banner should be prominently displayed, easy to understand, and readily accessible to users. It should include a link to the site’s privacy policy, cookie policy, and/or terms of use and clearly explain what tools are being used and the purpose for such use. Users should be provided with straightforward options to accept or reject cookies, as well as the ability to modify their preferences later. Failure to configure cookie settings in this way constitutes a dark pattern, which regulators have increasingly targeted for enforcement.
Honor Universal Opt-Out Mechanisms
Closely related to cookie compliance is the obligation to honor universal opt-out mechanisms (“UOOMs”), such as the Global Privacy Control (“GPC”). A UOOM allows a consumer to automatically convey a privacy preference (for example, an opt-out of the sale or sharing of personal information) across numerous websites and online services simultaneously. UOOMs eliminate the need for a consumer to submit a separate opt-out request to each individual platform, providing a centralized privacy preference framework.
Because these signals are transmitted directly through the consumer’s browser or device, a business’s website and any consent management platform should be configured to recognize and act on these requests automatically, without requiring the consumer to take any additional action.
State legislatures have increasingly incorporated UOOM recognition into their comprehensive consumer privacy laws, and regulators have shown a willingness to enforce these requirements aggressively. In California, for instance, enforcement actions have resulted in significant penalties against companies that failed to properly process opt-out signals or otherwise honor consumers’ statutory privacy rights. Disney, for instance, agreed to pay $2.75 million to settle allegations that it failed to honor consumers’ opt-out requests by limiting Global Privacy Control (GPC) opt-outs to the specific device from which the request was made, rather than applying the opt out across a logged-in consumer’s account.
Given this enforcement trend, businesses should treat UOOM compliance as a practical priority rather than an afterthought. At a minimum, a company’s website and consent management platform should be configured to detect a recognized opt-out preference signal, such as the GPC, and automatically suppress the sale or sharing of that consumer’s personal information upon receipt of the signal. Companies should also disclose their UOOM recognition practices in their privacy policies to inform consumers of their options. Because this configuration typically only requires a one-time technical adjustment, UOOM recognition offers a low-cost, high-value way to reduce a company’s exposure to the type of enforcement risk that regulators are actively pursuing.
Ensure PCI-DSS Compliance
The Payment Card Industry Data Security Standard (“PCI-DSS”) is a mandatory global information security standard for all entities involved in cardholder data processing. Many companies assume that because they use a third-party payment card processor, they have no independent obligation to demonstrate compliance with PCI-DSS. That assumption is incorrect and can expose the company to unnecessary regulatory risk.
Under PCI-DSS, any company that accepts, transmits, stores, or otherwise processes credit card data is classified as a "merchant," and is subject to PCI-DSS obligations, regardless of transaction volume and whether the actual payment processing is outsourced to a third party.
Depending on factors such as the nature of the company’s processing activities and volume of processing, merchants are required to complete certain steps to demonstrate compliance with PCI-DSS standards, such as undergoing a self-assessment questionnaire (“SAQ”) or obtaining an attestation of compliance (“AOC”).
Through this process, a merchant or service provider either self-reports their adherence to certain security measures or undergoes an independent assessment of its compliance with PCI-DSS requirements. These assessments also help businesses proactively identify security gaps and vulnerabilities within their systems and processes, providing a clear roadmap for security remediation and compliance.
Put Data Processing Contracts in Place
Many states’ comprehensive privacy laws require a written contract to be in place whenever a business (acting as a “controller” of data) shares personal information with a third party (acting as a joint controller or “processor” of data). Examples of provisions that data processing agreements (“DPAs”) may be required to contain include:
- Language addressing the nature and purpose of the processing.
- Categories of personal information involved.
- Duration of processing.
- Rights and responsibilities of both parties.
- Data security requirements.
- Sub-processor restrictions.
While specific DPA requirements vary by state, the core obligation—having a written agreement in place—is a feature that is now virtually ubiquitous in all state consumer privacy legislation.
In practice, many companies share personal information with vendors without any contract specifically addressing the handling of that data. This gap is a compliance problem that is both common and easy to fix. Engaging legal counsel to draft and implement data processing addenda for existing vendor agreements is one of the most effective steps a company can take to reinforce its privacy compliance and protect its service provider relationships. As privacy enforcement continues to expand, ensuring that appropriate data processing agreements are in place should be viewed as a foundational component of any organization's privacy compliance program.
Conclusion
In a regulatory environment where enforcement is increasing and the number of state privacy laws continues to grow, addressing these issues represents low-hanging fruit for companies seeking to strengthen their privacy compliance programs. Taking these simple steps is a cost-effective way to reduce legal exposure, improve data governance, and demonstrate a meaningful commitment to privacy obligations.
Koley Jessen monitors developments in data privacy and can provide guidance as new information emerges. If you have questions about your compliance obligations or need assistance evaluating your privacy practices, please contact a member of Koley Jessen’s Data Privacy and Security Practice Area.
** Special thanks to summer associate Sarah Sedivy for her contributions to this article.
This content is made available for educational purposes only and to give you general information and a general understanding of the law, not to provide specific legal advice. By using this content, you understand there is no attorney-client relationship between you and the publisher. The content should not be used as a substitute for competent legal advice from a licensed professional attorney in your state.