Open Channels FM
Open Channels FM
From Blogs to Ecommerce Shops, Privacy Policies
Loading
/

In this episode hosts Emma and Adam look at the critical importance of website policies for ecommerce shops. Donata Stroink-Skilrud, President of Termageddon, is our guest and shares her expert insights on creating and maintaining crucial legal documents like privacy policies and terms of service.

The conversation covers the complexities of complying with evolving privacy laws, the importance of transparent policies as a competitive advantage, and the specifics of data collection and consent.

Since 2005, Automattic has built tools for the open web including WordPress.com, WooCommerce, and Jetpack that are used by millions of people to create, sell, and publish online. They believe in ownership, flexibility, and open source and we’re grateful for their support. Learn more at automattic.com.


Logo of Omnisend featuring a stylized 'i' icon and the brand name in lowercase letters.

Omnisend just dropped SMS pricing to $0.007, and their migration team moves your automations, templates and contacts in five days, free. That means you could be saving up to 35% in less than a week. We’re glad to have them supporting the show and the community we’re building around it. Use the code OpenChannels and get 30% off your first 3 months of any paid plan.

Takeaways

Critical Role of Website Policies – Website policies such as privacy policies and terms of service are essential for protecting both the business and its customers, especially in e-commerce.

Consequences of Non-Compliance – Failing to implement proper legal policies can lead to significant fines and lawsuits. California’s laws, for instance, are particularly strict and can apply even to businesses not based in the state.

Global Application of Privacy Laws – Privacy laws apply based on where your customers are located, not just where your business operates. Regulations like GDPR and U.S. state-specific laws can affect businesses anywhere in the world.

Steps to Minimize Legal Risks – Key steps include collecting only the data you need, limiting the use of tracking tools, ensuring proper consent mechanisms, and understanding which laws apply to your business.

Ongoing Policy Updates – Privacy policies need regular updates to reflect changes in business practices, new legislation, or guidance. Keeping them up-to-date is crucial for compliance.

Automating Compliance with Tools – Services like Termageddon automate the creation and updating of legal policies, making compliance easier for small businesses without the need for legal expertise.

Dangers of Free Generators and Copy-Pasting – Free or AI-generated privacy policies are often inaccurate and don’t account for specific legal needs. Copying from other sites can lead to legal risks and copyright issues.

E-commerce Terms of Service Essentials – For e-commerce businesses, terms of service are crucial for limiting liability, outlining refund/return policies, and complying with laws around subscriptions and international trade.

Consumer Expectations and Trust – Clear and transparent privacy practices can build consumer trust and offer a competitive edge, as customers are increasingly concerned about data protection.

Evolution of Privacy Laws – Privacy laws are constantly evolving to adapt to new technologies. Businesses must stay informed and expect more changes in the coming years, especially as state and global regulations develop further.

Links

Chapter Titles with Timestamps

  • 00:00 Introduction and Welcome
  • 01:09 Importance of Website Policies
  • 02:31 Guest Introduction: Donata Stroink-Skilrud
  • 03:16 Legal Must-Haves for WooCommerce Stores
  • 06:03 Understanding Privacy Laws
  • 12:12 Steps to Ensure Compliance
  • 16:20 Visibility and Consent Requirements
  • 20:55 Enforcement and Compliance
  • 24:59 Terms of Service for E-commerce
  • 27:16 Navigating Terms of Service for Your Business
  • 27:41 Setting Up Business in Different Regions
  • 28:15 Understanding GDPR and Data Tracking
  • 29:19 Essential Website Policies
  • 31:04 Cookie Consent and User Privacy
  • 32:14 Maintaining and Updating Policies
  • 34:03 Automating Privacy Compliance
  • 38:40 Challenges with Free Policy Generators
  • 42:38 When to Consider Professional Help
  • 45:31 Future of Privacy Laws
Episode Transcript

Emma:
So, hello Woo builders, and welcome back to another episode of Do the Woo Podcast, where we dive into all things WooCommerce, community, and the future of work. I’m Emma, and I’m joined today by my co-host, Adam. Hey, Adam, how’s it going?

Adam:
I’m doing great, Ms. Emma. It is nice to see your face, although no one else can. Bob and I still can’t get him to make this a video podcast, but it’s probably for the best. It’s so great to see you. I’m excited about today’s episode. We’re going to be discussing something that every online business owner should have on their radar: website policies and why they matter. We’ve got a special guest with us today to go through all the legal must-haves for WooCommerce stores, but we’ll introduce her soon. Let me ask you, Emma, before we introduce her, how often do people actually read those terms and conditions on websites? Is that something you do regularly?

Emma:
No, not nearly enough.

Adam:
Read all of them?

Emma:
But actually, recently, I have read too many of them. I think I’ve read every single one on every single website. So now I’m on that side of it, thinking, “I used to be one of those people like, oh well, maybe they should read them, maybe they shouldn’t.” But now I’m very much like people should have clear and up-to-date terms, privacies, and policies, and it’s super critical. I can see the benefit of protecting both your business and the customers. Yeah. So, today, we’re going to be diving into the world of website policies. These can range from terms and conditions to privacy policies. I feel like I’ve just said ‘policies’ a lot—that word. But learning why they are super important and more important now, more than ever, in the current digital landscape.

Adam:
Absolutely. And today, we’re thrilled to have Donata Stroink-Skillrud.

Donata:
Did I say that correctly?

Adam:
Did I get close? Yeah?

Donata:
Yeah, close enough.

Adam:
Close enough. Ah, you’re the president of Termageddon. This is an exciting time. We are super grateful to have you on to help us make sense of all of this. We know you’re going to give us all the legal advice, right? Wait, no, no. That was the opposite of what I was supposed to say. This is not legal advice, but you’re going to set us straight. You’re going to help us get this figured out, making sure that we are staying up to date with all of the changes in legislation, and that’s what we do here.

Donata:
Yeah, absolutely. Thank you for having me here.

Emma:
So maybe you can start off by telling us and the listeners a little bit about yourself and how you got into this field.

Donata:
Sure. So, I’m an attorney licensed in Illinois and a certified information privacy professional. I’m the president and legal engineer of Termageddon. We’ve generated tens of thousands of policies and kept them updated with changing legislation. I’m the American Bar Association’s ePrivacy Committee Chair, a member of the ABA Cybersecurity Legal Task Force, a fellow at the American Bar Foundation, and the ABA’s representative to the United Nations. The reason I got into this is that I was in private practice. I used to work at an agency, and after the agency was bought out, I went into private practice, and clients were asking me what they should do for a privacy policy or terms of service. This was before all of these new privacy laws—before everything got very complicated. I had to ask some very similar questions, like “What are you doing with this data? Do you share it, do you sell it?” Things like that.

Then I had 10 templates that I would Frankenstein together into one document, and the process was really terrible, and I absolutely hated it. I thought, “Hey, there’s got to be a way to automate this.” At the time, I was dating a person who’s now my husband, and we were talking about this at dinner. He worked at an agency, and he was like, “Yeah, clients ask me what to do for a privacy policy, and I’m like, I don’t know. I’m not a lawyer. Go ask somebody else.” Or they would take a template or ask him to copy and paste somebody else’s privacy policy, and he was like, “I’m not really comfortable with this.” So we kind of melded those problems together and came up with this solution—Termageddon.

Adam:
So what you’re saying is, you are exactly the right person for us to talk to about this topic.

Emma:
Yes.

Adam:
There’s nobody I can think of who understands this stuff better. Thank you so much for coming on today.

Emma:
Yeah, absolutely. I feel like you needed a mic drop after listing off your credentials. For those who can’t see our faces, Adam and I, our jaws dropped. We were like, “What? So amazing.”

Adam:
That is fantastic. Very, very cool. So, I think one of the things I am curious about is: what’s at stake here? If someone gets this wrong—you’re setting up a WooCommerce website, and you just don’t put anything in there, no legal documentation. “Yeah, I put up a website, I’ve got my stuff for sale.” What’s at stake?

Donata:
So, I guess the first thing I would want to say is: are you collecting personal information, right? That’s when these privacy laws come into play. From a privacy perspective, let’s say you have a contact form, e-commerce forms, email newsletter subscriptions, or, let’s say, analytics or a Facebook pixel. That’s when privacy issues come into play. The first thing from a privacy perspective is fines. Those start at $2,500 per website visitor. So, let’s say I have a hundred website visitors from California, and I don’t get their consent for tracking or I don’t give them an appropriate privacy policy. That fine is $2,500 times 100. From a privacy perspective, you also have lawsuits.

Right now, the California Invasion of Privacy Act—a super old privacy law—has become very popular. Businesses have been getting sued for tracking people through the pixel without their consent in California, and those lawsuits are very expensive. Businesses are getting demand letters for $30,000 to $60,000 or anywhere in between for violations of that law. When it comes to the terms of service, I think a lot of people aren’t aware of certain laws. For example, there’s a California automated subscription law. So, if I have subscriptions that automatically renew but I don’t present the consumer with certain information in my terms of service, the things that they got through the subscription are actually considered a gift. So, let’s say I’m selling a subscription magazine. All the magazines that I’ve sent them are considered a gift, and now I have to refund them all their money.

Emma:
Oh no.

Donata:
Yeah. Or if you don’t limit your liability or damages, or if you offer warranties that you’re not actually offering, you may be required to offer refunds or compensation to the consumer. So, these things can get very, very expensive. On the other side of things, we’re seeing how privacy and providing transparent information to consumers can be a competitive advantage. More and more consumers are willing to leave websites, not provide them with their personal information, or not buy from them, or switch to a different provider if they feel like their privacy has been violated or they’re not getting transparent information. So, all of this stuff can be a competitive advantage to businesses as well.

Emma:
Got it. I feel like I’m just super scared now. I need to go to my personal site and put every single policy on there.

Donata:
Sorry, that’s not my intention to scare people. I’m just trying to provide general information that I think most businesses don’t think about. As a business, there are so many things you need to pay attention to. This is something that people tend to put off for as long as they can. Unfortunately, it’s just not the world we live in anymore.

Emma:
I was super excited to have you on because I was setting up a personal site, and I was trying to research which ones I need and which ones I don’t. Can I combine any of these things together? And there was actually not a lot of information about this. So, I was super excited to have you on so that I can, from a first-person experience, ask you some questions. But you did mention specifically California. So, do laws change state by state in the U.S., and are there different ones for every single country, or do you have to create new policies for international clients or customers?

Donata:
In the United States, we have a huge problem, which is what we call the state privacy law patchwork, and it’s the bane of every privacy lawyer’s existence. In the U.S., we don’t have a comprehensive federal privacy law. We have privacy laws for healthcare information, children’s information, and financial information, but nothing federally that covers information commonly collected through websites, like names, emails, phone numbers, or IP addresses. That’s where you’re seeing each state propose and pass its own privacy laws. For example, California currently has three laws that we need to pay attention to. States have different laws, and they may have multiple laws, and they do change and update those

laws as technology changes and as privacy infringements evolve. The issue with this is that the laws don’t just apply to businesses located in the state of California, for example. Let’s say I’m a business in Illinois, and I have a contact form where people from California can submit their name and email. I would be subject to the California Online Privacy and Protection Act of 2003 because I’m collecting the data of residents of California, even though I’m not located there. The same thing applies to other countries. GDPR can apply to businesses outside of the EU. The UK Data Protection Act can apply to businesses outside of the UK. That’s what makes this very complicated. It’s not just where your business is located; it’s where your customers are located, where you’re offering goods or services, who you’re tracking online, things like that. Most privacy laws don’t care about the size of your business. It doesn’t matter what revenue you have, how much data you’re collecting, how many employees you have—any of that. Some privacy laws even apply to nonprofits. Some laws do have exemptions, like they apply only to for-profit businesses, but other laws don’t. Some laws apply to larger businesses; some apply to smaller businesses as well. It’s kind of this crazy patchwork that is hard to navigate.

Adam:
Wow, it’s so interesting. There are so many different pitfalls, and I like how you said you’re not here to scare us. It’s about informing us of what we need to do to get this right. A couple of questions that I want to break down by priority: let’s say you’re building a website to sell something, like T-shirts. As you’re putting together that website—you’ve designed a beautiful site, you’ve got the store running—from these different types of legal aspects, could you walk us through a priority list of what to do first, second, and so on? Could you walk us through that in our T-shirt store example?

Donata:
Yeah, absolutely. The first thing you should do is determine what amount of data you actually need to collect. For example, let’s say I have a contact form that asks for name, email, and phone number, but I never intend to call this person—I’m only going to respond via email. I shouldn’t be collecting that phone number because I’m never going to call them anyway. So, reduce the amount of data you’re actually collecting. The second thing, or part of the first thing, is to think about all the third-party tracking tools you have on the site. Let’s say I decide to have Google Analytics. I’d encourage you to really take the time to understand whether you’re actually going to use the analytics data. Don’t just install tools because you may need them in the future. These tools can subject you to additional privacy laws and increase your risk.

Let’s say you want Google Analytics but never intend to look at the data—don’t have it. Or, if you need analytics for some reason, try to find a more privacy-focused tool that collects less data or tracks people less. The second thing you should think about is figuring out what privacy laws apply to you. Without knowing which privacy laws apply, you won’t know what standards you need to meet. For example, some laws require explicit consent to be provided before tracking, while other laws don’t. Understanding which laws apply to you will dictate what you need to do next. The third thing is obtaining consent, whether through a cookie consent banner or having checkboxes on your form, ensuring people agree to your policies. Then, think about the policies you’re going to have on your site, like a privacy policy, terms of service, or cookie policy, and how you’re going to keep them up to date. Those are probably the first steps I’d take. Obviously, there are more steps you’ll need to take, like figuring out what privacy rights you provide and to whom, and how to respond to privacy rights requests, but just to start, that’s where I’d begin.

Adam:
That’s our hierarchy of what’s most important. I’m taking notes. Everyone at home, take notes.

Emma:
I am too. I’m actively typing while you’re talking. Okay, so, is there an easy way to figure out what privacy laws apply to you? I liked your example of determining the amount of data you need to collect, like not asking for a phone number if you’re not going to call. But how do you figure out which privacy laws apply to you? What’s the workflow for that?

Donata:
There are a couple of ways to do that. The first way would be to hire a privacy attorney who can help walk you through those steps. That can get kind of expensive, but they would be able to give you an exact list of what you need to comply with. The second way would be to look up a list of laws and read them, and the laws will say who they apply to. We also have a blog post about this. If you go to termageddon.com and search “What laws require websites to have a privacy policy,” we have a blog that breaks down those requirements. We also include that in our privacy policy generator.

Adam:
Nice. As you’re building this fantastic T-shirt website and thinking about where these policies and terms—the legalese—should go, is there anything that regulates how visible they need to be? For example, where they need to be or when someone needs to consent to cookies. How does visibility and ease of access to these terms play into it?

Donata:
The main standard is that these policies need to be conspicuous on your website, meaning easily visible and not hidden. Usually, this is done through a link in the footer of the website. The policies can’t be combined together—multiple privacy laws prohibit the combining of privacy policies and terms of service. The privacy policy needs to say “Privacy.” If you just have a link that says “Legal,” that’s usually not compliant with most privacy laws. We usually recommend that the footer includes links for “Privacy Policy,” “Terms of Service,” “Cookie Policy,” or whatever else you have, and these are all separated. They also need to be in contrasting text compared to the color of the footer. For example, if your footer is dark gray and your policy links are a slightly lighter gray, that’s not going to be compliant. Make sure to keep accessibility standards in mind, and ensure those links are available on every page of the site, which is typically done in the footer. When you click on that link, it needs to open the actual document.

As someone who frequently looks at privacy policies on websites, I’ve often seen a link to a privacy policy that leads to a 404 error page—that’s not compliant. It needs to lead to an actual privacy policy. In terms of cookie consent banners, you want them to appear when someone visits the website, especially for the first time, if you’re tracking people. Make sure it’s easily visible, and it gives users an actual choice. It needs to have an accept and a decline button, and both need to be equally prominent. For example, if the accept button is green and the reject button is red, that’s going to be considered a dark pattern because it nudges people into accepting cookies. Or, let’s say the accept button is big, and the reject button is tiny—that’s not acceptable. It should clearly say “Accept” or “Reject,” and they need to be given equal prominence.

Adam:
Got it. That makes sense.

Emma:
That’s so interesting. Yeah, it does make sense, but you’d never think about all these subtle things. What about when they have multiple options, like “Customize,” “Customize essentials only?” Is that a gray area, or is that okay?

Donata:
In terms of the cookie consent banner, you do need to have an accept and a reject button. But if you have options like “Accept necessary only,” that’s fine, because necessary cookies can be enabled without user consent—they’re necessary for the website to function. You could also have toggles that allow users to choose functional cookies but not marketing cookies, or vice versa. But it’s important that these cookies are classified correctly. An essential cookie is one that’s necessary for the operation of the website. What a lot of business owners do is say, “Well, Google Analytics is essential to my business because it’s essential that I get analytics.” You laugh, but that’s how people think. Google Analytics is not an essential cookie; it’s a marketing cookie. So is the Facebook pixel. These are not essential cookies. Make sure they’re classified correctly, and provide users with information on what these cookies actually are. Have a cookie policy that explains, “These are the marketing cookies we have, these are the essential ones, and these are the functional ones,” so people can make an informed choice.

Emma:
What if you don’t provide it? It’s not essential to me! No, I’m just kidding. But is there a timeframe by which it has to be live? Does it need to be ready the second your site or T-shirt business is live? What if your policies are incorrect and need an update? Is there a privacy policy police?

Donata:
Privacy laws start applying as soon as personal information is being collected. So, if you launch the website with forms, analytics, and advertising, you need to have this privacy stuff in place before the launch. Now, I live in the real world, and I understand that most businesses may not have this in place the moment they launch, or they may not have the resources. It’s up to you to determine your level of risk. If you launch today, there might not be anybody visiting your website or submitting their personal information. You can choose to roll the dice, but if something happens, it’s on

you. However, there are affordable ways to get this done, especially for small businesses. But privacy laws start applying as soon as personal information is collected, so if you don’t have this in place, I’d recommend getting it done as soon as possible, given the number of lawsuits and fines being issued right now. You don’t want to delay it. Now, in terms of violations—is there a privacy policy police? It depends. State attorney generals enforce privacy laws in the United States, along with the Federal Trade Commission. In the EU, you have data protection authorities, and in the UK, you have the Information Commissioner’s Office. Some states in the U.S. are forming specific entities within the attorney general’s office just to enforce privacy laws. When they first pass laws, you may have a grace period of six months where they’ll send you a letter saying, “Hey, fix your stuff.” But after that, the grace period ends, and they’ll go after you. When enforcement actions start, you might be able to work with them and say, “Hey, I’ve fixed everything, please don’t fine me.” Sometimes that works, sometimes it doesn’t.

Adam:
This is scary encouragement. All right, so we’ve talked about privacy, especially when you start collecting data. As I’m thinking about this: when you’re selling something, is there additional legal information you need to have on your site to cover yourself regarding trade and commerce?

Donata:
Yes. This is where you’d want to think about the terms of service. Terms of service are the rules for using your website. There are two aspects: the commerce aspect and the aspect for websites that may not even have e-commerce. Terms of service are recommended for any business because they help protect your business, limit your liability, limit damages, protect your intellectual property, and more. For example, let’s say I have a website that doesn’t do e-commerce but allows comments. I can let people know what types of comments are not allowed or will be taken down. When it comes to e-commerce, you want to think about subscriptions and those subscription laws we talked about earlier. You also want to consider international terms. For example, certain international terms will apply by default unless you specifically disclaim them—like the UN Convention on Contracts, Incoterms, or the Uniform Commercial Code (UCC).

These can apply regardless of what you actually say to the customer unless you specifically disclaim them. These terms are not always advantageous for businesses. So, if I’m selling internationally and don’t offer refunds but don’t specifically disclaim Incoterms, those terms will apply by default. I may be required to provide a refund to a customer, even though I don’t normally offer refunds. Those are the small things you’d want to think about within the terms of service, as well as informing customers about things like refunds and returns. As a consumer, if I’m buying shoes online, I know I’m going to return 50% of the shoes because they won’t fit right. So, I’ll only shop from companies that offer refunds and returns. If the website has terms of service that say they offer refunds and returns, great, I’ll continue. If they don’t have terms of service or don’t provide that information, I’m going to go somewhere else. I’m not going to spend time calling or emailing them to figure that out. These terms can actually help customers along the purchasing path as well.

Emma:
That’s interesting. Do you feel like it’s easier to have your business registered in the EU, the U.S., or Canada, considering all the laws and regulations involved in setting up these terms and conditions?

Donata:
I don’t think it really matters where your business is set up. For example, let’s say I’m located in Taiwan. These terms may still apply to me if I’m selling in the EU, the U.S., the UK, or Canada. So, it’s not necessarily about where your business is set up because the laws don’t care where your business is located. It’s more about who you’re selling to, where you’re shipping, and things like that. There are certain things that are set up in the EU. GDPR will apply if you’re offering goods or services there, or if you’re tracking people online. For example, if I have a T-shirt store and I’m not shipping to the EU, I don’t have pricing in euros, and I don’t have an address in the EU, GDPR may not apply to me. But if I have analytics and people from the EU visit my website and are tracked, GDPR would apply. You have to be careful about things like analytics because, if you don’t need it, don’t have it on your site—it can subject you to multiple laws. It’s not about where your business is set up; it’s about who you’re selling to and whose data you’re collecting.

Emma:
I think the first thing I’m going to do after this is remove Google Analytics from my site. Who am I kidding? I don’t need SEO. It’s fine.

Adam:
It’s not that important.

Emma:
It’s okay. I most definitely do not have all of this covered.

Adam:
I was a little curious, and I went to the Termageddon website. I saw at the bottom of your website, you have the Termageddon LLC copyright, and links to your privacy policy, terms and conditions, disclaimer, affiliate terms and conditions, and a cookie policy. That’s a lot. Would you recommend that most websites should have all of those things in their footer?

Donata:
We’re a little bit different in that we have affiliates, like web designers who resell or refer clients to us, so if you’re not doing that, you wouldn’t need affiliate terms and conditions. We also have a disclaimer saying we’re not offering legal advice because we want to make sure people know that. Unless you’re providing information that could be seen as legal advice, or if you’re participating in affiliate programs, offering health or fitness tips, or displaying third-party ads, you probably don’t need a disclaimer. So, we’re unique in that sense, but for regular businesses, if you’re collecting personal information, you’ll want a privacy policy. If you have cookies, you’ll want a cookie policy. And if you want to limit your liability and damages, or if you have e-commerce, you’ll want terms of service. Those are the main things we recommend. Disclaimers are only needed if you have certain features on your website, and affiliate terms and conditions only apply if you have an affiliate program.

Adam:
Got it. One thing I noticed is that there’s a little fingerprint logo on your site, and you can click on it anytime to see the privacy settings. Is that something that Termageddon does, or what’s that about?

Donata:
Yeah, that tells me you’ve been on our website before. When you first visit, it shows a cookie consent banner, where you can either accept or decline cookies. Once you make your choice, you have the right to change your settings at any time. The fingerprint icon allows you to pull up the cookie consent banner again and change your settings. So, if you accepted cookies before but now want to decline them, you can click the fingerprint and withdraw your consent. That feature is provided by us through an integration with a German company called Usercentrics because they don’t transfer data to the U.S. It’s a whole mess, but I won’t get into that. You can create something similar through your Termageddon account as well.

Emma:
Okay, would you say these terms and conditions are a one-and-done thing, or is there some housekeeping to keep up with?

Donata:
Unfortunately, they’re not one-and-done. There are two ways these policies change. The first change happens when you change your business practices. For example, if I initially only collected names and emails but now want to collect physical addresses to send gifts to clients, I’d need to update my policy to reflect that. Or, if I didn’t share data before but now I do, or if I didn’t offer refunds but now I do, I’d need to update my policies. The second change comes from legislation. We have new privacy laws being passed all the time. Next year, for example, eight new laws will go into effect that would affect privacy policy disclosures. When those changes happen, you need to update your policies. Lastly, we have rules, guidance, and enforcement actions that interpret privacy law requirements. Sometimes privacy laws are passed quickly, and rules and guidance are issued later to clarify how to comply. For example, a law might say you need five privacy policy disclosures, but the guidance may say you need ten. Those rules and guidance can lead to updates as well.

Emma:
With all of these regulations to follow, what are some ways a small business, like this T-shirt or broccoli business, can automate this process? Can they use Termageddon without having a full legal team, or do they need to put a reminder to check in every year?

Donata:
That’s literally what we do—keeping things up to date is my full-time job. There are a few ways to handle this. You can hire a privacy lawyer to do it for you, but that can get expensive. Alternatively, you can sign up for a service like Termageddon, which tracks and updates everything for you. We send you an email before new laws go into effect, and you may need to answer some new questions, but once you do, we automatically update your policies to comply with the new legislation. If you want to learn more, we have privacy bill trackers on our blog, listing all the proposed privacy bills in the U.S. and worldwide. We also have posts on what’s coming up in the next few

years and compliance guides for each law. So, if Delaware passes a new privacy law and you don’t want to read it, we have a guide summarizing the main points and what you need to do to comply.

Emma:
Kudos to that guy.

Adam:
My favorite page on your website is the “terma jargon” page. It’s brilliant. All these terms being thrown around are things we don’t deal with every day, and I think, “I know what that means…I think.” I like how you lay out this complex topic. It feels like dealing with all these legal issues for a website is a really hot situation, and Termageddon gives you the oven mitts to handle it. You’re still dealing with a hot situation, but the oven mitts keep you safe and prevent you from getting burned. Is that a good way to think of what you’re doing?

Donata:
I like the idea of an oven mitt! I tend to think of it as a rat’s nest.

Adam:
But I don’t want to get burned!

Donata:
Yeah, it’s very confusing. Even privacy lawyers find it hard to keep up. We see attorneys having a hard time navigating this, and it’s their full-time job! What we try to do is simplify it. We ask a series of questions. The first set helps us figure out which laws apply to you and what disclosures your policies need. The second set of questions helps create the disclosures. For example, we’ll ask if you sell data or share it. A lot of businesses think they don’t share data, but if you have an email marketing list on Mailchimp, you’re sharing data with Mailchimp. We have videos and help articles for each question to explain them. We also offer calls with customers to help them get set up. We try to make this terrible situation a little bit better for everyone. With a name like Termageddon, you have to make it fun!

Emma:
Yeah, definitely.

Donata:
Absolutely.

Emma:
How did you guys come up with that name, by the way? It’s such a good name.

Donata:
We were on a car ride with my husband’s cousin after Thanksgiving, and we said, “Okay, we have this business idea—can you help us come up with a name?” We initially thought of “Terminator,” but that domain was taken. So, we landed on Termageddon. We wanted to make it fun because otherwise, this topic would be miserable for everyone.

Emma:
Solid. I love it.

Adam:
I love it.

Emma:
Would you trust any of the free policy or privacy law generators or AI?

Adam:
Just grab it from Google?

Emma:
Yeah, or copy and paste from somebody else’s website? I’ll just take theirs.

Donata:
I’ve tried all of those, actually, just for fun because that’s what I do for fun. First, let’s talk about AI. It’s tempting to go to ChatGPT and ask it to create a privacy policy, but I did that test, and here’s what happened. The first attempt, I gave it my URL, and it generated random information, not based on the laws that apply to me. It said I was sharing data with fraud prevention vendors, even though I wasn’t. The key to having a good privacy policy is knowing which privacy laws apply to you. Without that knowledge, it’s not compliant. After hours of tweaking, I was able to get it to generate a compliant policy, but only because I told it all the disclosures I needed and which laws applied. Most people won’t know those things. AI also doesn’t update policies. In terms of free generators, most aren’t actually free. They’ll ask if you need GDPR disclosures, and when you say yes, boom—$20. Then, “Are you creating this for a business?” and it’s another $50. You end up paying $400–$500 for something you thought was free. Those policies are usually static templates that fill in basic info like your business name and address. They’re not based on privacy laws or your business practices. Lastly, copying and pasting from another website is a bad idea because it’s copyright infringement, and you don’t know if that site complies with the same laws you need to. You’d also have to monitor that site to see if they update it. It’s so time-consuming. You’re better off getting the right policy from the start.

Adam:
At what point is a website so simple that you don’t need Termageddon? Is there a point where it’s like, “Okay, this is who we’re a good fit for”?

Donata:
There are some instances where you might not need to worry. For example, if you have a personal website with no visitors, where you just list family birthdays—that’s not something you need to worry about. Or if you have an internal website for employees to order swag, that’s not accessible to the public. But the moment you start collecting personal information from the public—like through contact forms, analytics, or email signups—you need to start thinking about privacy compliance. Whether you hire a lawyer, use a service like Termageddon, or try to write something yourself depends on your level of risk tolerance. Even small businesses are being sued. I recently read about a one-person company in California that sells patches to military members. It’s a tiny business, but they were sued under the California Invasion of Privacy Act. Unfortunately, some lawyers are targeting small businesses by visiting their websites and suing them for tracking visitors without consent. So, even small websites need to think about this as soon as they collect data.

Adam:
Got it. So essentially, if you’re collecting data from people, if you want someone to interact with your website, you need to get this figured out.

Donata:
Yep.

Emma:
Exactly.

Adam:
All right.

Emma:
Do you see privacy laws evolving much in the next few years? Do you think one day we’ll have a universal privacy policy?

Donata:
Privacy laws do evolve a lot. Many older laws are getting amended. For example, Australia’s Privacy Act of 1988 has been amended several times, and it’s going through another amendment process now because of changes in technology. In the U.S., we’re seeing a trend where consumers are being given the right to opt-out of the sale of their personal information, which is becoming more common. As privacy concerns evolve, so do laws. For example, the California Privacy Rights Act amended the California Consumer Privacy Act to allow consumers to opt out of the sharing of their information for targeted advertising. Privacy concerns change as technology changes. We also see older laws being adapted to newer technologies. As for a global standard, I think that’s going to be a tough sell. In the U.S., they’ve been trying to pass a comprehensive federal privacy law for five years, and it’s going nowhere. If we can’t agree within the U.S., imagine trying to agree on a global standard. However, we do see countries adapting GDPR, but they change it to fit their cultural perceptions of privacy. So, while some countries are working towards a similar standard, it’s not the same.

Adam:
Got it. So, we’re not solving this all tomorrow—it’s ongoing.

Donata:
I wish, but no.

Adam:
But thank you so much for sharing all this information. I feel like I understand this a lot better now. For people who are thinking, “Oh shoot, I need to get in touch with Termageddon,” how do people get in touch with you?

Donata:
You can find us at termageddon.com—T-E-R-M-A-G-E-D-D-O-N.com. We’re also on social media under the same name, and you can email me at donata@termageddon.com.

Adam:
Awesome. Donata, do you guys go to WordCamps and things like that, so people can catch you in person?

Donata:
Yeah, we were just at WordCamp US in Portland, and we have a few more upcoming WordCamps. If you’re there, definitely come see us.

Emma:
I definitely went from terrified to super excited to talk to you. At the beginning, I was like, “Oh my God, I screwed up already,” but now I’m like, “Nope, Termageddon just has a new client because this is too much for me to handle!” But I’m a lot less scared now, so it worked with me.

Donata:
I’m happy to hear that.

Emma:
Awesome.

Adam:
Alright, well thank you so much for joining us, and for you, dear listener, thank you for joining us for another episode of Woo Biz Chat on Do the Woo. Be sure to check out some of our past episodes, subscribe, and all that good stuff. Bob is always talking on social media, so interact there. If you have questions, find us on LinkedIn, Slack, or wherever, and send us a message. We’d love to include you in these conversations. Until next time, thank you so much. Have a great day, everyone.

Sponsors
Open Web Conversations