{"id":387,"date":"2016-12-13T12:09:22","date_gmt":"2016-12-13T18:09:22","guid":{"rendered":"http:\/\/ericlambert.net\/blog\/?p=387"},"modified":"2016-12-13T12:09:22","modified_gmt":"2016-12-13T18:09:22","slug":"website-app-legal-disclosures-saying-enough-much","status":"publish","type":"post","link":"https:\/\/ericlambert.net\/blog\/2016\/12\/13\/website-app-legal-disclosures-saying-enough-much\/","title":{"rendered":"Are Your Website and App Legal Disclosures Saying Enough (Or Too Much)?"},"content":{"rendered":"<p>Almost every business has\u00a0an online presence of some form.\u00a0Many have a website which serves as anything from an\u00a0online company brochure to a fully-featured online store or customer\/vendor\/user portal. Some have apps available through Google Play Store, the Apple App Store, or other app stores.\u00a0A number of companies\u00a0spend significant sums on their websites and apps to design robust\u00a0features and content delivered through\u00a0a compelling\u00a0user experience.\u00a0But if there&#8217;s one place website and app operators\u00a0miss the mark, it&#8217;s ensuring the right legal disclosures are in place, and that the ones that are in place are saying the right things.<\/p>\n<p>When most people think of a website or app disclosure, they think of a privacy policy and terms of use.\u00a0These are definitely important.\u00a0However, There are a number of other disclosures required or recommended under federal and state law that companies should consider\u00a0to manage risk and avoid potentially distracting and costly litigation.\u00a0\u00a0At the same time, saying <em>too much<\/em> in disclosures such as your privacy policy can expose your company to unnecessary risk.<\/p>\n<p>There are four\u00a0core\u00a0rules\u00a0that should apply to all website disclosures:<\/p>\n<ol>\n<li><strong>Write them in plain English.<\/strong><\/li>\n<li><strong>Avoid using\u00a0undefined technical jargon and using marketing bluster.<\/strong><\/li>\n<li><strong>Make them easy to understand and use.<\/strong><\/li>\n<li><strong>Make them 100% accurate and truthful.<\/strong><\/li>\n<\/ol>\n<p>Consider having your company&#8217;s\u00a0User Experience group\u00a0review your disclosures and policies\u00a0to ensure they are\u00a0as easy to read and navigate\u00a0as possible. Consider using design elements such as progressive reduction and progressive disclosure (you can see my <a href=\"http:\/\/ericlambert.net\/blog\/progressive-reduction-progressive-disclosure-legal-disclosures-incompatible\/\" target=\"_blank\" rel=\"noopener nofollow\">earlier blog post on this topic\u00a0by clicking here<\/a>.)\u00a0The goal is to ensure\u00a0consumers easily understand your disclosures.\u00a0If you ever have an issue with a term or provision in your disclosures, being able to argue that\u00a0the content and design were\u00a0optimized for easy reading and navigation\u00a0can pay dividends.<\/p>\n<p>Here are some website and app disclosures to consider:<\/p>\n<ul>\n<li><strong>The Privacy Policy.\u00a0<\/strong>States such as California have\u00a0laws requiring companies to have online privacy policy.\u00a0Since almost every\u00a0website is\u00a0accessed by users in California,\u00a0it&#8217;s safe to say <strong>you are legally required by state law to have a privacy policy<\/strong>. Companies in certain industries or sectors such as in the healthcare sector (HIPAA) and financial sector (Gramm-Leach-Bliley) have specific requirements for their privacy policies.\u00a0A privacy policy is\u00a0also required by law in some states on an information category basis, such as Connecticut&#8217;s requirement that anyone collecting Social Security Numbers have a publicly displayed privacy policy with certain required disclosures.\u00a0Certain laws also\u00a0mandate that you cover certain topics in your privacy policy (e.g., California&#8217;s requirement to disclose how\u00a0you handle &#8220;do-not-track&#8221; headers, and California&#8217;s requirement to provide information on how minors who are your registered website users can request that you remove their personal information).\u00a0Don&#8217;t forget that your privacy policy needs to\u00a0apply to, and be displayed on, your company&#8217;s apps as well.\n<p>A company&#8217;s privacy policy obligations can be summarized simply: <strong>say what you do, and do what you say.<\/strong>\u00a0&#8220;<em>Say what you do<\/em>&#8221; means ensure your privacy policy fully describes how you collect, use, and share information (both personally identifiable information, such as your name and address,\u00a0and non-personally identifiable information such as behavioral data) collected from or about your customers.\u00a0&#8220;<em>Do what you say<\/em>&#8221; means ensuring your day-to-day business activities with respect to information collected from consumers falls within the boundaries of what you say you do in your privacy policy.\u00a0Two important rules to follow\u00a0are, <strong>(1) if you want to change how you collect, use or share information from consumers, make sure your privacy policy allows it first, and give prior\u00a0notice to website users that your privacy policy is changing<\/strong>; and <strong>(2) if you want to change how you use information you&#8217;ve already collected from consumers, you&#8217;ll need permission from the consumers first<\/strong>.\u00a0Always include an effective date on your privacy policy (again, a state law requirement).<\/p>\n<p>Look for a more detailed post on\u00a0privacy policies coming soon.<\/li>\n<li><strong>Terms of Use\/Terms of Service.<\/strong>\u00a0Your terms of use (sometimes also referred to as &#8220;terms of service&#8221;) should describe the rights and obligations applicable to both your company&#8217;s website\/app\/online service users and to your company itself with respect to the operation and\/or use of an online\u00a0website, app, and\/or online service.\u00a0It should cover topics such as ownership of the website and company-provided content on it (including your copyrights, trademarks and licensed trademarks), and associated restrictions (e.g., no screen scraping website content); disclaimers of third party content, such as third party ad networks on your site, and language to prevent\u00a0use of your\u00a0company&#8217;s trademarks other content to\u00a0create the\u00a0appearance of sponsorship by or affiliation with a third party;\u00a0whether or not you collect information from children under 13 (if you do, ensure you are complying with the Children&#8217;s Online Privacy Protection Act or &#8220;COPPA&#8221;); an obligation to report lost or stolen passwords and change passwords regularly;\u00a0what you can do with user-generated content uploaded or shared to the website (e.g., a broad right and license to use it), and related terms (e.g., it&#8217;s provided royalty-free and with no license costs, that it doesn&#8217;t infringe anyone else&#8217;s rights, etc.); a feedback provision if users may\u00a0provide feedback or comments; links to third party content; and important legal terms such as jurisdiction, choice of law, indemnification, and the like.\u00a0Many website operators include an acceptable use policy as part of their Terms of Use\/Terms of Service; some have a separate policy on their website.<\/li>\n<li><strong>DMCA Notice.<\/strong>\u00a0If your website collects, displays, or otherwise uses or shares\u00a0user-generated content, consider a copyright notice (also called a &#8220;DMCA notice&#8221;).\u00a0The Digital Millennium Copyright Act creates a &#8220;safe harbor&#8221; from copyright infringement for websites operators who honor takedown requests and display on their website information for their designated &#8220;copyright agent&#8221; to which takedown requests can be sent.\u00a0There&#8217;s more to the statute than that, so if you need a DMCA notice please review one of the multitude of articles out then on crafting a proper DMCA notice.\u00a0Don&#8217;t forget that you need to register your designated copyright agent with the US Copyright Office by filing a &#8220;Designation of Copyright Agent&#8221; form.<\/li>\n<li><strong>California &#8220;Shine the Light&#8221; Notice.<\/strong>\u00a0In 2005, California enacted the &#8220;Shine the Light&#8221; law as part of its Consumer Records Act.\u00a0The law requires businesses to provide disclosures to California consumers of the types of\u00a0customer information they share with third parties for the third party&#8217;s direct marketing purposes during the immediately preceding calendar year.\u00a0If your business shares collected personal information with third parties for the third party&#8217;s direct marketing purposes and does business in California, with a few exceptions this law applies to you.\u00a0Businesses are required to\u00a0let customers know how to submit requests for this information.\u00a0While there are a few options, the simplest for most businesses is to include a link on the company&#8217;s homepage to &#8220;<strong>Your California Privacy Rights<\/strong>&#8221; or &#8220;<strong>Your Privacy Rights<\/strong>&#8221; to a page describing customer&#8217;s rights under the &#8220;Shine the Light&#8221; law and the email\/physical address to which requests should be sent.\u00a0There has been an uptick in class action litigation recently against companies\u00a0which do not have a &#8220;Shine the Light&#8221; disclosure on their website.<\/li>\n<li><strong>Terms of Sale.<\/strong>\u00a0If you sell products through your website, consider using a Terms of Sale to govern the sales transaction.\u00a0Terms of Sale typically include provisions such as placing an order; when it is accepted by the company; delivery and fulfillment terms; the return\/cancellation policy; information on prices (e.g., subject to change without notice, not\u00a0required to honor incorrect pricing); license rights to software; etc.<\/li>\n<li><strong>Warranties.<\/strong>\u00a0One policy you may want to consider adding to your website are product warranties.\u00a0Last year Congress passed, and President Obama signed, the E-Warranty Act of 2015.\u00a0This law amended the 1975 Magnuson-Moss Warranty Act to allow companies to put their warranties online instead of including them on or in product packaging.\u00a0The product documentation or packaging would need to include a link to the online warranty, instead of the warranty terms themselves.\u00a0Companies that\u00a0sell products that come with warranties\u00a0should consider reviewing and taking advantage of the E-Warranty Act.<\/li>\n<li><strong>Supply Chains Notice.\u00a0<\/strong>In 2010, California enacted the Transparency in Supply Chains Act.\u00a0The law requires large retailers doing business in California (over $100 million in annual revenue identifying itself as a retail seller or manufacturer on their CA tax return)\u00a0to post disclosures on their websites on their &#8220;efforts to eradicate slavery and human trafficking from their [direct] supply chain for tangible goods offered for sale&#8221;\u00a0in\u00a0five specific areas: verification, audits, certification, internal accountability, and training. It requires the disclosures be accessible through the company&#8217;s homepage via a &#8220;conspicuous and easily understood&#8221; link.<\/li>\n<li><strong>Be careful your disclosures aren&#8217;t saying too much.<\/strong>\u00a0While having the right disclosures for your websites and apps is important, avoid saying too much.\u00a0Remember, when it comes to disclosures, what you say can hurt you.\u00a0Website disclosures are not the place for marketing puffery.\u00a0If you make a statement such as &#8220;100% guaranteed,&#8221; &#8220;we encrypt all data,&#8221; or &#8220;we use best-in-the-industry [whatever],&#8221; and it turns out to be false or inaccurate, you can expect state AGs and the FTC (and class action counsel) may come knocking. Generally,\u00a0one of the roles of the\u00a0Federal Trade Commission is to ensure that companies are\u00a0not engaging in unfair or deceptive trade practices.\u00a0This extends to ensuring that companies are making accurate and truthful disclosures on their websites. Some states, such as Pennsylvania, have expressly included false and misleading privacy policy statements as a\u00a0deceptive or fraudulent business practice.<\/li>\n<li>At the extreme end of this, consider what has been happening in New Jersey.\u00a0Class action counsel\u00a0have been using an extremely broad interpretation of NJ&#8217;s largely-ignored-until-recently Truth in Consumer Contract, Warranty and Notice Act to go after companies operating business-to-consumer (B2C) websites.\u00a0The law prohibits sellers from\u00a0providing notices, terms, or contracts with provisions that violate &#8220;any clearly established legal right of a consumer or responsibility of a seller&#8221; under federal or state law (whether or not the consumer is happy with the purchase).\u00a0Class action counsel are bringing suit under this statute stating\u00a0that just displaying a website notice with a general limitation of liability, broad disclaimers of\u00a0warranty, statements that certain terms such as warranty disclaimers may not apply to particular consumers without specifying whether NJ consumers are affected, or other limitations on a consumer&#8217;s rights is a violation of the statute.\u00a0Most of these cases are settling before trial, but like other nuisance lawsuits\u00a0they can end up costing your business considerable time and lost productivity if you end up facing one.<\/li>\n<\/ul>\n<p>Most companies place their website disclosures at the bottom of the page in a footer.\u00a0Do not bury them or make them hard to find.\u00a0\u00a0Your policies should be accessible through no more than 2-3 clicks via a logical navigation path.\u00a0While putting your disclosures in the footer\u00a0makes sense and is very common, consumers may argue that they simply never saw the disclosures because they never scrolled down to the bottom.\u00a0Consider also making\u00a0website disclosures &#8220;<strong>contextual<\/strong>,&#8221; i.e., place policy and disclosure\u00a0links in close proximity to the related usage.\u00a0For example,\u00a0on pages where you are actively collecting information, consider putting a link to the privacy policy right next to the &#8220;submit&#8221; button, or before a consumer places an order on your e-commerce website, add language\u00a0verifying they have read and agree to your terms of sale and privacy policy.\u00a0Consider\u00a0providing a welcome message, with notice of your\u00a0privacy policy and terms of use, to\u00a0consumers visiting your website as a disappearing pop-up, e.g., one that\u00a0appears for 3-4 seconds at the top of the webpage then fades out, similar to &#8220;cookie disclosures&#8221; on many EU-based websites.<\/p>\n<p>Finally, consider working with IT to create simple shortcuts for your most common policies (e.g., &#8220;privacy.company.com&#8221; or &#8220;www.company.com\/privacy&#8221; for your privacy policy) so you have a short and simple URL you can\u00a0use where you need to direct consumers to your online disclosures.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Almost every business has\u00a0an online presence of some form.\u00a0Many have a website which serves as anything from an\u00a0online company brochure to a fully-featured online store or customer\/vendor\/user portal. Some have apps available through Google Play Store, the Apple App Store, &hellip; <a href=\"https:\/\/ericlambert.net\/blog\/2016\/12\/13\/website-app-legal-disclosures-saying-enough-much\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2,4],"tags":[74,79,142,167,179,180],"class_list":["post-387","post","type-post","status-publish","format-standard","hentry","category-compliance","category-legal","tag-disclosures","tag-dmca","tag-privacy-policy","tag-shine-the-light","tag-terms-of-sale","tag-terms-of-use"],"_links":{"self":[{"href":"https:\/\/ericlambert.net\/blog\/wp-json\/wp\/v2\/posts\/387","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ericlambert.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ericlambert.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ericlambert.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ericlambert.net\/blog\/wp-json\/wp\/v2\/comments?post=387"}],"version-history":[{"count":0,"href":"https:\/\/ericlambert.net\/blog\/wp-json\/wp\/v2\/posts\/387\/revisions"}],"wp:attachment":[{"href":"https:\/\/ericlambert.net\/blog\/wp-json\/wp\/v2\/media?parent=387"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ericlambert.net\/blog\/wp-json\/wp\/v2\/categories?post=387"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ericlambert.net\/blog\/wp-json\/wp\/v2\/tags?post=387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}