Protecting user privacy is paramount in digital initiatives. Understanding regulatory requirements such as HIPAA, GDPR, CCPA and other US state privacy laws, and cookie policies is crucial for reducing risk. The information here is general guidance, not legal advice; please consult your own legal counsel for your specific situation.
Our recommended tool: Termageddon
For privacy policies and consent, we recommend Termageddon. It is an attorney-founded service that generates your privacy policy, cookie policy, and disclosures and keeps them updated as laws change, paired with a consent tool that manages the cookie banner and consent logging. Together, these cover both the policy side and the enforcement side of privacy compliance.
Clients purchase Termageddon directly (~$119 per year per site), and GLIDE helps connect and configure it as part of your project or support plan. Use promo code GLIDE at checkout for 10% off your first payment.
Termageddon is our default recommendation, but it is not the only option. The alternatives below (policy generators, consent tools, and WordPress plugins) remain fully supported, so you can choose what fits your site and stack.
HIPAA (Health Insurance Portability and Accountability Act): HIPAA compliance is mandated for healthcare providers, health plans, and healthcare clearinghouses (covered entities) that handle protected health information (PHI). Business associates of covered entities, such as software vendors and service providers, must also comply with certain HIPAA requirements. More often than not, we recommend that any PHI collected on your website is encrypted or securely transferred to a HIPAA-compliant database such as an Electronic Health Record (EHR) or Electronic Medical Record (EMR) system, and not stored on your website or in an email inbox. We also recommend keeping standard third-party tracking pixels off pages and forms that capture health information, and routing intake forms through a tool that will sign a Business Associate Agreement (BAA). We follow HIPAA-aware development practices and work alongside your compliance team; we do not certify HIPAA compliance.
Relevant Use Cases:
Healthcare Websites: Websites belonging to hospitals, clinics, doctors' offices, and other healthcare entities that collect, store, or transmit patient information must comply with HIPAA regulations. This includes ensuring the confidentiality, integrity, and availability of PHI, implementing appropriate security measures, and obtaining patient consent for data handling practices.
Healthcare Apps: Mobile applications designed for healthcare purposes, such as telemedicine platforms or health tracking apps, fall under HIPAA regulations if they handle PHI. These apps must implement robust security measures, secure data transmission, and provide mechanisms for user consent and data access control.
GDPR (General Data Protection Regulation): GDPR compliance is mandatory for organizations that process personal data of individuals residing in the European Union (EU), regardless of the organization's location. This includes businesses, nonprofits, and government agencies that offer goods or services to EU residents or monitor their behavior. If you utilize a CRM or email marketing tool, there will likely be GDPR features to ensure they are working along with your website when collecting data.
Termageddon covers GDPR policy and consent. If you prefer a WordPress plugin instead, these options can help:
GDPR Cookie Consent: Displays a customizable cookie consent banner, letting users consent to cookies and manage their preferences.
WP GDPR Compliance: Adds consent checkboxes to forms (contact, newsletter, and more) and helps handle data access and erasure requests.
Cookie Notice for GDPR & CCPA: Displays a cookie notice, requests consent, and offers granular control over cookie settings.
GDPR Compliance for Mailchimp: For sites using Mailchimp, helps obtain consent, manage subscriber preferences, and handle data subject requests.
GDPR Personal Data Reports: Generates and exports personal data reports for users on request, streamlining data subject access requests.
WP GDPR Fix: Adds privacy features such as consent checkboxes to comment, registration, and WooCommerce checkout forms, plus data access and deletion handling.
WP Security Audit Log: Keeps a detailed log of user activity, including changes to personal data, which helps with monitoring and breach detection.
CCPA (California Consumer Privacy Act) and US state privacy laws: CCPA compliance is mandatory for businesses that meet certain criteria and operate in or serve residents of California. Covered businesses must comply if they meet one or more of these thresholds: annual gross revenues exceeding $25 million; annually buy, receive, sell, or share the personal information of 50,000 or more California consumers, households, or devices; or derive 50% or more of annual revenue from selling consumers' personal information. Beyond California, a growing number of US states now have their own comprehensive privacy laws in effect, and many require honoring the Global Privacy Control signal, so these obligations may apply if you serve residents of those states.
Relevant Use Cases:
Online Retailers: E-commerce websites that sell products or services to California residents and meet the CCPA criteria must comply. This includes giving consumers the right to opt out of the sale of their personal information, disclosing data collection practices, and ensuring data security.
Data Brokers: Companies that buy, receive, or sell the personal information of California consumers in large volumes fall under CCPA. They must provide transparency and control over personal information and refrain from selling data without explicit consent.
Cookies: Cookie regulations vary by jurisdiction, but many countries require websites to obtain user consent before setting non-essential cookies or tracking technologies. Cookie and consent laws continue to evolve, and we aim to keep clients informed. The most common issue we see is cookies and tags firing before a visitor has given consent.
Relevant Use Case:
E-commerce Websites: Online retailers use cookies to remember preferences, track cart items, and analyze behavior to personalize the shopping experience. These sites must obtain user consent for non-essential cookies and provide options to manage cookie preferences.
Termageddon's consent tool handles cookie consent and logging. If you prefer a standalone consent tool or plugin, these options can help:
Cookie Notice & Compliance for GDPR / CCPA: A customizable consent banner with options to configure appearance, behavior, and cookie settings.
GDPR Cookie Consent Banner: Create and customize consent banners, with categorization and granular control over cookie preferences.
Cookie Consent: A lightweight, customizable consent notice that lets users accept or reject cookies.
Cookie Law Info: A customizable consent banner with cookie categorization and detailed cookie information for users.
CookieYes: A widely used consent management tool that scans and categorizes cookies and manages consent across GDPR and CCPA.
Cookiebot: A comprehensive consent solution that automatically scans and categorizes cookies, with customizable banners, detailed policies, and robust consent management.
Publishing your privacy measures
As the website's designer and developer, GLIDE provides a toolkit page to help you publish your privacy measures, including:
Privacy Policy: outlining how data is collected, used, and protected.
Terms of Service: where applicable, governing how visitors interact with your site.
If you do not already have this documentation, we recommend Termageddon, or a generator like termly.io, along with your own legal counsel for a customized solution. Sprinto also offers certification services for HIPAA, CCPA, GDPR, and other privacy frameworks for organizations that need a formal program.