By Helen Sedwick (@HelenSedwick)
Today’s writers wear many hats. We are Tweeters, Pinteresters, YouTube-ists and most of all, bloggers. Maybe we have heard about privacy policies, but we don’t know whether we need one. After all, we are not challenging Wall Street, City Hall, or Big Data. Most of us are not selling advertising space alongside our posts. We are blogging simply to inform readers about our work and sell a few books. Most writers do not want to wear a lawyer’s hat, too.
However, if you:
- collect names and addresses to send newsletters,
- require readers to register and log-in in order to comment,
- obtain contact information as part of a giveaway,
- post photos of and reviews by your readers,
- collect any personally identifiable information, or
- track visitors to see where else they venture on the internet,
What is personally identifiable information?
Names, addresses, email addresses, phone numbers, user names, passwords, marital status, children’s names, occupation, credit and financial information, medical history, travel itineraries, photographs, Social Security Numbers, or any information in “personally identifiable form.”
What about web stats and analytics?
- Describe the types of information collected, such as names, addresses, and credit-card numbers. Provide the user a way to correct errors. This may be as simple as sending you an email.
- Explain how the information will be used and the categories of people with whom the information might be shared. For instance, do you share it with potential publishers, agents, publicists, or marketing companies?
- Describe how you maintain security.
- Include an opt-out option.
- Put a date of the policy.
- Explain how readers will be notified of changes in the policy.
- If you will be collecting personal information about children under the age of 13, then comply with the Children’s Online Privacy Protection Act (COPPA).
- If you or your advertisers will be tracking visitors after they leave your site, then disclose how you respond to Do-Not-Track requests.
Is your site subject to COPPA?
If you operate a website, online service, or app directed toward children under 13 and collect personal information from those children, then you must comply with a long list of requirements under the Children’s Online Privacy Protection Act (COPPA) . COPPA also applies if you operate a general audience website and have actual knowledge you are collecting, using, or disclosing personal information from children under 13.
For example, if you operate a website where children share questions and discussions about your book, or they may upload photos and drawings using their real or user names, hometowns, etc., then you must comply with COPPA.
- Obtain verifiable parental consent.
- Give parents the choice of prohibiting disclosure to third parties.
- Provide parents a way to review, correct, and delete information.
- Take reasonable steps to maintain confidentiality and security.
- Retain personally identifiable information only as long as necessary.
How do you handle Do-Not-Track requests?
California law requires anyone who operates a website that may be viewed by someone in California (okay, virtually everyone) to disclose how they respond to Do-Not-Track requests.
Few casual bloggers must deal with this issue because we do not track users browsing habits after they leave our sites. But if you track visitors, or if you host click-through advertisements and your advertisers track visitors, then you must disclose that information and explain how you respond to Do-Not-Track requests.
Tracking is not prohibited. The law requires disclosure only.
The law and technology in the area are new, so I expect we will see many changes on how visitors opt in and out of Do-Not-Track lists and how websites handle such elections.
- I do not sell books through my site, or post third-party advertising, or track users.
- I collect names and email addresses when readers submit a comment or subscribe to my blog or newsletter through MailChimp.
- WordPress and Google Analytics collect general user data.
- My site is not geared toward children under 13, and I am not aware that I have collected any personal information from any children.
About the Author
Writer and lawyer Helen Sedwick has thirty years of experience representing businesses and entrepreneurs as diverse as wineries, graphic designers, green toy makers, software engineers, investors, restaurateurs, and writers. Her newest release Self-Publisher’s Legal Handbook: The Step-by-Step Guide to the Legal Issues of Self-Publishing is assisting indie author in navigating the legal minefield of self-publishing and blogging. Her historical novel Coyote Winds earned five-star reviews from ForeWord Reviews and Compulsion Reads and is an IndieBRAG Medallion Honoree. For more information about protecting your rights and your wallet, email her at Helen@helensedwick.com or visit http://helensedwick.com/.
Disclaimer: Helen Sedwick is an attorney licensed to practice in California only. This information is general in nature and should not be used as a substitute for the advice of an attorney authorized to practice in your jurisdiction.
Photo courtesy of Stuart Miles | Freedigitalphotos.net. Amazon links contain my affiliate code.