Privacy 16 April 2019

Best Practices: Privacy

Basic Notice/Disclosure

  • Make sure the privacy statement has a link and is easily discoverable from the home page.
  • Place the revision date of the statement at the top of the page.
  • Provide access to archived versions of the statement, allowing users to see what has changed.
  • Use a simple layered and/or short notice designed to help consumers understand the statement.
  • Use icons to help consumers navigate privacy statements in conjunction with layered/short notices.
  • Write statements for the site’s target audience and demographics. Consider providing multi-lingual versions supporting non-English-speaking site visitors.

Key Compliance Policies

  • Compliance with Children’s Online Privacy Protection Act (COPPA) or related regulations.
  • Disclose whether the site honors Do Not Track (DNT) browser settings and preferably honor users’ DNT browser settings.
  • Provide a summary of the data retention policy, including a specific timeframe and for what reason data is retained.

Protect Privacy and Define Protected Sharing

  • Do not share personal data with any third party except to deliver service to the user. Provide a clear statement including details regarding if, what and for what purposes data is shared.
  • Require vendor compliance by contract and notify consumers that service providers are prohibited from the use or sharing of their data for any purpose other than providing services on behalf of the site.
  • Provide disclosure of cross-device tracking.
  • Utilize tag management systems or privacy solutions to manage third-party trackers.
  • Disclose whether data will be shared to meet legal obligations and make best efforts to notify consumers if their data is requested by third parties due to legal requirements.

, Global,

Related Resources

Supporting a Secure and Trustworthy Internet 4 December 2025

Policy Brief: Age Restrictions and Online Safety

While often well-intentioned, policies requiring age checks create risks for people’s privacy, security, and access to an open Internet. 

Supporting a Secure and Trustworthy Internet 10 April 2025

Internet Society’s Comments on India’s Digital Personal Data Protection (DPDP) Rules 2025

Internet Society's comments and recommendations on India's Digital Personal Data Protection (DPDP) Rules 2025.

Supporting a Secure and Trustworthy Internet 22 May 2024

How Bill S-210 Puts Canadians’ Security and Privacy at Risk by Harming the Internet

Canadian Bill S-210 includes requirements that could disrupt essential functions of the Internet and ultimately harm Canadians’ security and...