All guides
113 guides, organized by topic. Educational guides and tool comparisons, written from hands-on testing rather than vendor briefings.
Consent Mode and CIPA: How Proper Tag Sequencing Protects You
Google Consent Mode and correct tag sequencing in a tag manager are the technical mechanism behind actually blocking trackers pre-consent, not just disclosing them. Here's how to get it right.
Updated Aug 18, 2026Read guide →AnalysisSB 690 and the Future of CIPA: Will a Safe Harbor Ever Arrive?
California SB 690 represents legislative pushback against the CIPA website litigation wave, aiming to carve out a safe harbor for standard analytics and marketing tools. Here's what that would mean if enacted.
Updated Aug 18, 2026Read guide →GuideThe Plaintiff Firms Behind CIPA Lawsuits: How the Playbook Works
CIPA demand letters and lawsuits follow a recognizable, largely automated pattern. Understanding the mechanism behind it helps explain why letters arrive and what determines who gets one.
Updated Aug 18, 2026Read guide →GuideCIPA Beyond California: Which Other States Have Wiretapping Laws
CIPA is California-specific, but the underlying legal structure, all-party consent wiretapping statutes with a private right of action, exists in other states too. Here's the landscape.
Updated Aug 18, 2026Read guide →GuideDoes Your Business Insurance Cover CIPA Claims? The Exclusion Problem
General liability and cyber policies don't automatically cover CIPA claims, and many explicitly exclude statutory privacy violations. Here's what to actually check with your broker.
Updated Aug 18, 2026Read guide →GuideCIPA for Ecommerce Stores: Where Shopify and WooCommerce Sites Get Exposed
Ecommerce stores run a heavier tracker stack than most sites, retargeting pixels, cart-abandonment tools, live chat, session replay. Here's where Shopify and WooCommerce sites specifically get exposed.
Updated Aug 18, 2026Read guide →GuideDo Live Chat Widgets Violate CIPA? The Split Court Decisions
Courts have reached genuinely different conclusions on whether third-party live chat widgets violate CIPA. Here's what the split actually looks like and why it hasn't resolved.
Updated Aug 18, 2026Read guide →GuideCIPA and Session Replay Tools: Hotjar, Clarity, and FullStory
Session replay tools are the single most litigated tracker category in CIPA suits. Here's why, and what to actually check if you run Hotjar, Microsoft Clarity, or FullStory.
Updated Aug 18, 2026Read guide →GuideIs Google Analytics a CIPA Risk? What Site Owners Need to Know
Google Analytics is lower on the CIPA risk spectrum than session replay or chat widgets, but it's not automatically exempt. Here's what configuration details actually matter.
Updated Aug 18, 2026Read guide →GuideCIPA Section 631 vs 638.51: The Two Provisions Plaintiffs Use
Most CIPA website suits cite Penal Code §631, but a second theory under §638.51's pen-register language is increasingly common. Here's how the two provisions differ and why it matters.
Updated Aug 18, 2026Read guide →GuideHow to Reduce Your CIPA Risk: A Practical Checklist
A concrete, non-alarmist checklist for reducing your website's CIPA exposure, covering tracker audits, consent gating, documentation, and what to verify technically, not just legally.
Updated Aug 18, 2026Read guide →AnalysisCIPA Settlements in 2026: What Cases Are Actually Costing
The $5,000-per-violation figure is a statutory ceiling, not what cases settle for. Here's an honest look at the gap between theoretical exposure and what CIPA cases are actually costing defendants.
Updated Aug 18, 2026Read guide →GuideWhy Healthcare Websites Face the Highest CIPA Risk
Healthcare and health-adjacent websites face a sharper version of CIPA risk than most industries, for reasons that go beyond general privacy sensitivity. Here's the specific mechanism.
Updated Aug 18, 2026Read guide →GuideYou Received a CIPA Demand Letter. What Now?
A calm, practical walkthrough of what a CIPA demand letter is, why you got one before any lawsuit was filed, and the first steps to take in the days after it arrives.
Updated Aug 18, 2026Read guide →GuideWhich Website Trackers Trigger CIPA Lawsuits?
Not every tracking script carries the same CIPA risk. Here's how session replay, chat widgets, ad pixels, and analytics tools compare on the specific pattern plaintiffs' firms target.
Updated Aug 18, 2026Read guide →GuideThe Millisecond Problem: Why Cookie Banners Aren't Enough for CIPA
A cookie banner that discloses tracking isn't the same as one that blocks it. CIPA claims turn on the exact moment a script starts talking to a third party, here's why that distinction matters.
Updated Aug 18, 2026Read guide →GuideDoes My Website Need to Worry About CIPA?
A practical framework for deciding whether your site's traffic and tracking stack put you in the range of CIPA lawsuit risk, and when it's genuinely a non-issue.
Updated Aug 18, 2026Read guide →ComparisonCIPA vs CCPA: Why Being CCPA-Compliant Doesn't Protect You
CCPA compliance and CIPA exposure are two different problems with two different legal mechanisms. Here's why passing one doesn't mean you've handled the other.
Updated Aug 18, 2026Read guide →GuideCIPA's $5,000 Per Violation: How the Math Actually Works
The $5,000-per-violation figure in CIPA lawsuits sounds small until you see how 'per violation' gets counted. Here's the actual math, and why the real number is almost always smaller.
Updated Aug 18, 2026Read guide →GuideWhat Is CIPA? The 1967 Wiretap Law Now Suing Websites
CIPA was written for phone taps, not pixels. Here's how a 1967 California wiretapping law became the legal theory behind thousands of website tracking lawsuits.
Updated Aug 18, 2026Read guide →Does GDPR Apply to B2B Data and Business Contacts?
A common assumption is that GDPR only covers consumer data. It doesn't, a work email address and job title are personal data too. Here's what actually changes, and doesn't, for B2B processing.
Updated Sep 2, 2026Read guide →GuideHow Long Can I Keep Personal Data Under GDPR?
GDPR doesn't set a fixed retention period, it requires you to justify one. Here's how the storage limitation principle actually works and how to set defensible retention periods.
Updated Sep 2, 2026Read guide →GuideWhat Is a Lawful Basis for Processing, and Which One Do I Need?
GDPR gives you six possible lawful bases for processing personal data, not just consent. Here's what all six actually are and how to figure out which one fits a given activity.
Updated Sep 2, 2026Read guide →GuideWhat Is the Difference Between a Data Controller and a Data Processor?
GDPR splits obligations between controllers and processors, and getting the label wrong for your business can mean missing entire categories of legal requirements. Here's how to tell which one you are.
Updated Sep 1, 2026Read guide →GuideDo I Need Consent for Every Cookie on My Website?
No, but the exemption is narrower than most sites assume. Here's exactly which cookies need consent, which don't, and where the line actually sits.
Updated Sep 1, 2026Read guide →AnalysisHow Much Can I Actually Be Fined Under GDPR?
The €20M / 4% figure is a ceiling, not a typical outcome. Here's what fine amounts actually look like in practice across company sizes, not just the headline maximums.
Updated Sep 1, 2026Read guide →GuideDo I Need a Data Protection Officer for My Small Business?
Most small businesses don't need a formal DPO under GDPR, but the exceptions catch more small teams than you'd expect. Here's how to think about it at small-business scale specifically.
Updated Aug 31, 2026Read guide →GuideWhat Counts as Personal Data Under GDPR?
GDPR's definition of personal data is broader than most businesses assume, it covers far more than names and emails. Here's what actually counts, including the identifiers most sites overlook.
Updated Aug 31, 2026Read guide →GuideDo I Need a Cookie Banner Under GDPR, or Is That a Myth?
Cookie banners have picked up a lot of folklore: some businesses think they're always required, others think they're theater nobody checks. Neither is quite right. Here's what's myth and what's real.
Updated Aug 30, 2026Read guide →GuideDoes GDPR Apply to My Business If I'm Not Based in the EU?
GDPR's territorial scope is based on your visitors and customers, not your company's address. Here's how to tell whether your non-EU business is actually in scope.
Updated Aug 30, 2026Read guide →AnalysisThe Biggest GDPR Fines Ever and What Caused Them
The largest GDPR fines on record share a common pattern: international data transfers and consent for advertising, more often than data breaches. Here's what actually caused the biggest ones.
Updated Aug 18, 2026Read guide →GuideGDPR for Shopify and WooCommerce Stores: A Setup Guide
Ecommerce stores collect more personal data than most sites, orders, payment details, marketing lists, and run heavier tracking stacks. Here's a practical GDPR setup guide for Shopify and WooCommerce.
Updated Aug 18, 2026Read guide →GuideDo You Need a Privacy Policy Under GDPR? What to Include
GDPR requires transparency about data processing in practice, which almost always means a real privacy policy. Here's what has to be in it and where generic templates fall short.
Updated Aug 18, 2026Read guide →GuideGDPR for Email Marketing: Consent, Opt-Ins, and the PECR Overlap
Email marketing sits at the intersection of two different EU laws, GDPR and the ePrivacy Directive (PECR in the UK). Here's how they overlap and what that means for opt-ins in practice.
Updated Aug 18, 2026Read guide →GuideLegitimate Interest vs Consent: Why It Matters for Cookies
Legitimate interest and consent are both valid GDPR lawful bases, but they're not interchangeable for cookies. Here's when each actually applies, and where sites get it wrong.
Updated Aug 18, 2026Read guide →GuideRecords of Processing Activities (ROPA): What Article 30 Requires
Article 30 requires many organizations to maintain a written record of their data processing activities. Here's what has to be in it, who's exempt, and how to build one without overcomplicating it.
Updated Aug 18, 2026Read guide →GuideGDPR Breach Notification: The 72-Hour Rule Explained
GDPR gives you 72 hours to notify a supervisory authority after becoming aware of a personal data breach. Here's what starts the clock, what has to be in the notification, and when you also have to tell affected individuals.
Updated Aug 18, 2026Read guide →ComparisonGDPR vs CCPA vs the US State Laws: One Comparison Table
GDPR, CCPA/CPRA, and the growing set of US state privacy laws share a lot of DNA but differ in real, practical ways. Here's a single table comparing scope, rights, and enforcement.
Updated Aug 18, 2026Read guide →GuideDo You Need a Data Protection Officer (DPO)? A Simple Test
GDPR requires a Data Protection Officer in specific situations, not for every business. Here's the actual three-part test Article 37 sets out, and what to do if you're on the edge.
Updated Aug 18, 2026Read guide →GuideWhat Is a DSAR? Handling Data Subject Requests Under GDPR
A data subject access request lets anyone ask what personal data you hold on them. Here's what DSARs actually require, the 30-day clock, and how to handle one without dedicated tooling.
Updated Aug 18, 2026Read guide →GuideGDPR Fines Explained: How €20M and 4% of Revenue Really Work
The '€20 million or 4% of global revenue' GDPR fine figure is a maximum, calculated per tier, not a flat penalty. Here's how the math actually works and what determines which tier applies.
Updated Aug 18, 2026Read guide →GuideInternational Data Transfers After Schrems II: The SCC Problem
Schrems II invalidated Privacy Shield and put Standard Contractual Clauses under new scrutiny. Here's what the ruling actually requires for transferring EU personal data outside the EEA.
Updated Aug 18, 2026Read guide →GuideGDPR Cookie Consent: What a Compliant Banner Actually Requires
Most cookie banners disclose tracking without actually blocking it. Here's what GDPR consent actually requires, technically and legally, for a banner to be compliant.
Updated Aug 18, 2026Read guide →GuideGDPR and Google Analytics: Is GA4 Legal to Use in the EU?
Several EU regulators found Universal Analytics unlawful over US data transfers. Here's what changed with GA4 and the 2023 EU-US Data Privacy Framework, and what's still uncertain.
Updated Aug 18, 2026Read guide →GuideThe Small-Business GDPR Compliance Checklist
A structured, step-by-step GDPR compliance checklist covering data mapping, vendor agreements, breach response, and recordkeeping, the program-level steps beyond the cookie banner basics.
Updated Aug 18, 2026Read guide →GuideWhat Is a Data Processing Agreement (DPA) and When You Need One
A DPA is the contract GDPR requires between you and any vendor that processes personal data on your behalf. Here's when you need one, what it has to cover, and how to get one in place fast.
Updated Aug 18, 2026Read guide →GuideDoes GDPR Apply to My US-Based Website?
GDPR applies based on your visitors' location, not your business's. Here's how to actually determine whether a US-based site is in scope.
Updated Aug 18, 2026Read guide →GuideGDPR Consent vs Legitimate Interest: A Decision Guide
A practical decision framework for choosing between consent and legitimate interest as your GDPR lawful basis, for any kind of processing, not just cookies.
Updated Aug 18, 2026Read guide →GuideThe 7 GDPR Principles Every Business Should Know
GDPR's specific rules all trace back to seven core principles in Article 5. Understanding them makes every other requirement, consent, retention, security, easier to reason about.
Updated Aug 18, 2026Read guide →GuideWhat Is GDPR? A Plain-English Guide for Small Businesses
GDPR explained without the legalese: what it actually requires, who it applies to, and what a small business needs to get right first.
Updated Aug 18, 2026Read guide →ComparisonBest Cookiebot Alternatives in 2026
We tested the leading Cookiebot alternatives on setup time, script-blocking accuracy, pricing, and support. Here's how they compare.
Updated Aug 1, 2026Read guide →GuideDoes My Business Need a Cookie Banner?
A plain-language breakdown of when cookie consent banners are legally required, based on where your visitors are and what your site actually does.
Updated Jul 22, 2026Read guide →GuideThe Small-Business GDPR Checklist
A practical, no-jargon checklist for small businesses that need to get GDPR basics right without hiring a compliance team.
Updated Jun 30, 2026Read guide →COPPA Compliance Checklist for EdTech and Gaming Sites
EdTech and gaming platforms carry the highest COPPA exposure of any category, both by design and by actual audience. Here's a practical checklist for where to focus first.
Updated Aug 23, 2026Read guide →GuideCOPPA Penalties: How the FTC Actually Calculates Per-Violation Fines
COPPA fines aren't a single flat number, they're calculated per violation, and the FTC's definition of a 'violation' is broader than most businesses expect. Here's how the math actually works.
Updated Aug 22, 2026Read guide →GuideWhat COPPA Requires in Your Privacy Policy (and What Most Sites Get Wrong)
COPPA doesn't just require a privacy policy, it requires specific disclosures a general privacy policy usually doesn't include. Here's exactly what has to be there.
Updated Aug 21, 2026Read guide →GuideMixed-Audience Websites: COPPA's Hardest Compliance Question
Most sites aren't purely for kids or purely for adults, they're somewhere in between. COPPA has a specific carve-out for this, the mixed-audience approach, but it only works if you implement it correctly.
Updated Aug 20, 2026Read guide →GuideCOPPA vs. GDPR-K and the UK Children's Code: Comparing Global Kids' Privacy Rules
If your site has visitors in the US, EU, and UK, you're dealing with three different children's privacy frameworks at once, and they don't require the same things. Here's how they actually differ.
Updated Aug 19, 2026Read guide →GuideThe COPPA Safe Harbor Program: Is Self-Certification Worth It?
COPPA lets businesses join an FTC-approved safe harbor program instead of being directly investigated by the FTC. Here's what that trade actually involves and who it makes sense for.
Updated Aug 18, 2026Read guide →GuideCOPPA and Third-Party Trackers: Why Your Ad Pixels Are the Real Exposure
Most COPPA conversations focus on signup forms, but the more common violation is a persistent advertising or analytics identifier collected from a child without consent. Here's why trackers are the real risk.
Updated Aug 17, 2026Read guide →GuideVerifiable Parental Consent: Which COPPA-Approved Methods Actually Work
COPPA requires more than a checkbox for parental consent, it requires a method the FTC considers 'verifiable.' Here's what's actually on the approved list and how each one works in practice.
Updated Aug 16, 2026Read guide →GuideIs Your Website 'Directed to Children' Under COPPA? The FTC's Actual Test
COPPA's 'directed to children' standard isn't a single yes/no question, the FTC weighs a specific list of factors. Here's what actually determines which side of the line your site falls on.
Updated Aug 15, 2026Read guide →GuideWhat Is COPPA? The Federal Children's Privacy Law Explained
COPPA has governed how US websites handle children's data since 1998, and its requirements are stricter and more specific than most general privacy law. Here's what it actually covers.
Updated Aug 14, 2026Read guide →DPA Negotiation Mistakes That Create Real Liability
Most DPA problems aren't dramatic, they're small, repeated mistakes made under deadline pressure during vendor procurement. Here are the ones we see most often.
Updated Aug 22, 2026Read guide →GuideAudit Rights in a DPA: What to Negotiate and How to Use Them
An audit rights clause is only useful if it's specific enough to actually invoke. Here's what to negotiate for, and what a reasonable audit request actually looks like in practice.
Updated Aug 21, 2026Read guide →GuideUS State Privacy Laws and Service Provider Agreements: How They Compare to a GDPR DPA
CCPA/CPRA and other US state privacy laws require their own vendor contract terms, similar in spirit to a GDPR DPA but not identical. Here's what's different and where one contract can cover both.
Updated Aug 20, 2026Read guide →GuideBuilding a DPA to Send Your Own Customers: A Guide for SaaS Vendors
If your product processes personal data on behalf of business customers, you're the processor now, and they'll expect a DPA from you. Here's what to put in it.
Updated Aug 19, 2026Read guide →GuideBreach Notification Clauses in a DPA: What Timeline to Require
When a vendor is breached, your own 72-hour GDPR clock is already running before you even hear about it, unless the DPA requires fast notice. Here's what timeline to actually require.
Updated Aug 18, 2026Read guide →GuideReviewing a Vendor's DPA: Red Flags Before You Sign
Most vendor DPAs get accepted without a real read-through. Here are the specific red flags worth actually stopping on before you click accept.
Updated Aug 17, 2026Read guide →GuideDPAs and Standard Contractual Clauses: How They Work Together for International Transfers
A DPA and Standard Contractual Clauses solve different problems and are both often needed for the same vendor relationship. Here's how they fit together when personal data leaves the EU.
Updated Aug 16, 2026Read guide →GuideSub-Processor Clauses in a DPA: What to Require From Vendors
Your vendor's own vendors are handling your data too. Here's what a DPA's sub-processor clause should actually require, and the difference between general and specific authorization.
Updated Aug 15, 2026Read guide →GuideWhat a Compliant DPA Must Include: An Article 28 Checklist
GDPR Article 28 lists specific provisions a Data Processing Agreement has to contain. Here's a practical checklist to run any vendor's DPA against before you sign it.
Updated Aug 14, 2026Read guide →GuideDPA vs. BAA vs. Data Processing Addendum: Which Contract Do You Actually Need
DPA, BAA, and data processing addendum get used interchangeably, but they cover different legal ground. Here's how to tell which one a given vendor relationship actually requires.
Updated Aug 13, 2026Read guide →Building a DSAR Log: Audit Trail and Documentation Best Practices
A DSAR log is the difference between being able to demonstrate compliance and just asserting it. Here's what to track, how long to keep it, and how to structure it so it holds up under scrutiny.
Updated Aug 21, 2026Read guide →GuideHandling a DSAR When Your Data Lives With Subprocessors
Most businesses don't hold all of a person's data themselves, it's spread across analytics tools, payment processors, and other vendors. Here's how to pull a complete DSAR response together across subprocessors.
Updated Aug 20, 2026Read guide →GuideDSAR Exemptions: What You Can Legally Refuse to Disclose
The right to access personal data isn't unlimited. Here's the narrow, specific set of exemptions that let you withhold or redact information in a DSAR response, and where the limits of those exemptions actually sit.
Updated Aug 19, 2026Read guide →GuideWhen to Automate DSAR Fulfillment (and When a Spreadsheet Is Fine)
Dedicated DSAR tooling isn't necessary for every business. Here's how to tell whether your request volume and data footprint justify automating fulfillment, or whether a manual process still works.
Updated Aug 18, 2026Read guide →GuideDSARs From Employees vs. Customers: Why HR Requests Are Different
A data subject request from a current or former employee raises different practical and legal wrinkles than one from a customer. Here's what changes when the requester is on your payroll.
Updated Aug 17, 2026Read guide →GuideWhat Happens If You Miss the DSAR Deadline
A missed data subject request deadline isn't automatically a fine, but it does change your position significantly. Here's what actually happens, and what to do if you're about to run out the clock.
Updated Aug 16, 2026Read guide →GuideCan You Charge a Fee for a DSAR? What GDPR and CCPA Allow
Both GDPR and CCPA default to free data subject requests. Here's the narrow set of circumstances where a fee or refusal is actually justified, and how to document it if you go that route.
Updated Aug 15, 2026Read guide →GuideVerifying Identity for a DSAR Without Overcollecting Data
You have to confirm a requester is who they claim to be before handing over personal data, but asking for too much identification is its own privacy problem. Here's how to calibrate verification.
Updated Aug 14, 2026Read guide →GuideDSAR Deadlines and Scope: CCPA/CPRA vs. GDPR Compared
GDPR and CCPA both give people the right to request their data, but the deadlines, scope, and fee rules differ enough that treating them as identical creates real compliance gaps.
Updated Aug 13, 2026Read guide →GuideHow to Respond to a DSAR: Templates and a Sample Response Letter
A structured way to acknowledge, verify, and respond to a data subject access request, plus a sample response letter you can adapt for your own process.
Updated Aug 12, 2026Read guide →Is Florida Becoming the Next California for Wiretapping Lawsuits?
California's CIPA litigation wave took years to build. Here's why Florida's FSCA has the same underlying ingredients, and what that trajectory means for businesses serving Florida traffic.
Updated Aug 24, 2026Read guide →GuideFSCA and E-Commerce: Where Florida Shopify/WooCommerce Stores Get Exposed
E-commerce stores run more third-party tracking than almost any other site category, and Florida's FSCA reaches the same tools CIPA does. Here's where online stores are actually exposed.
Updated Aug 23, 2026Read guide →GuideReducing Your FSCA Risk: A Practical Website Checklist
Most FSCA exposure comes down to a small, identifiable set of technical gaps. Here's a practical checklist for auditing and fixing them before they become a claim.
Updated Aug 22, 2026Read guide →GuideFSCA Damages: How Statutory Penalties Are Calculated
The FSCA doesn't require a plaintiff to prove financial harm to recover damages, statutory damages are available per violation. Here's how that structure actually drives exposure.
Updated Aug 21, 2026Read guide →GuideWho Can Sue Under the FSCA? Private Right of Action Explained
The FSCA doesn't rely on regulators to enforce it, individual website visitors can bring claims directly. Here's what that private right of action actually means for a business's exposure.
Updated Aug 20, 2026Read guide →GuideFSCA's Two-Party Consent Rule: What It Means for Chat Widgets and Pixels
Live chat and ad pixels are two of the most common tools on small business websites, and both sit inside the FSCA's two-party consent theory. Here's what changes about how they should be implemented.
Updated Aug 19, 2026Read guide →GuideSession Replay Tools and FSCA: The Same Risk as Hotjar Under CIPA
Session replay and heatmap tools are the single most litigated category under CIPA's wiretapping theory, and the same exposure applies directly under Florida's FSCA. Here's why.
Updated Aug 18, 2026Read guide →GuideDoes the Florida FSCA Apply to Website Tracking and Analytics?
The FSCA was written for phone taps, not pixels, but the legal theory being used against websites turns on whether a script's data capture counts as an 'interception.' Here's how that argument works.
Updated Aug 17, 2026Read guide →GuideFSCA vs. CIPA: How Florida's Wiretapping Law Compares to California's
Florida and California both have two-party-consent wiretapping laws now being applied to website tracking, but they're not the same statute. Here's where the FSCA and CIPA actually diverge.
Updated Aug 16, 2026Read guide →GuideWhat Is the Florida Security of Communications Act (FSCA)?
Florida has its own two-party-consent wiretapping law, and like California's CIPA, it's increasingly being applied to website tracking technology. Here's what the FSCA actually says.
Updated Aug 15, 2026Read guide →Is There a Federal Privacy Law Coming, and How Should GA4 Users Prepare?
Congress has come close to a comprehensive federal privacy law more than once without passing one. Here's the current state of that effort and how to configure GA4 so you're not caught flat-footed either way.
Updated Aug 29, 2026Read guide →GuideSensitive Data and GA4: Avoiding Violations Under US State Laws
US state privacy laws single out sensitive personal information for stricter treatment, usually requiring opt-in consent rather than just an opt-out right. Here's what that means for common GA4 configurations.
Updated Aug 29, 2026Read guide →GuideGA4 Compliance Under the Texas Data Privacy and Security Act
Texas's TDPSA applies to more businesses than most state privacy laws because it drops the usual revenue and volume thresholds. Here's what that means for your GA4 setup.
Updated Aug 28, 2026Read guide →GuideGlobal Privacy Control (GPC) and GA4: Are You Actually Honoring It?
GPC is a browser signal with real legal force in several states, but most GA4 setups don't detect it at all. Here's what it is and how to actually wire it into your tag configuration.
Updated Aug 28, 2026Read guide →GuideColorado Privacy Act Requirements for Google Analytics Users
Colorado's Privacy Act was the first US state law to mandate universal opt-out mechanism recognition. Here's what that means specifically for a GA4 implementation.
Updated Aug 27, 2026Read guide →GuideDo Not Sell or Share: Configuring GA4 to Honor Opt Out Signals
A Do Not Sell or Share link is only compliant if it actually changes what GA4 sends. Here's how to wire the two together instead of shipping a link that does nothing.
Updated Aug 27, 2026Read guide →ComparisonState by State: Which US Privacy Laws Impact Your GA4 Setup
Nearly 20 US states now have comprehensive privacy laws, and most of them treat analytics-driven advertising as a regulated data practice. Here's a state-by-state view of what that means for GA4.
Updated Aug 26, 2026Read guide →GuideThe Virginia CDPA and GA4: A Compliance Overview
Virginia's Consumer Data Protection Act uses an opt-out model built around 'targeted advertising' rather than 'sale.' Here's what that means for a standard GA4 setup.
Updated Aug 26, 2026Read guide →ComparisonCPRA vs CCPA: How the Changes Affect Your GA4 Configuration
The CPRA didn't replace the CCPA, it amended and expanded it. Here's what actually changed and what it means for how you've configured Google Analytics 4.
Updated Aug 25, 2026Read guide →GuideGA4 and the CCPA: What California Businesses Must Know
If you run Google Analytics 4 and have California visitors, the CCPA almost certainly applies to your setup. Here's what that actually requires, in plain terms.
Updated Aug 25, 2026Read guide →PECR and SMS, Live Chat, and Push Notifications: The Rules Beyond Email
PECR's marketing rules cover more than email, texts, automated calls, and increasingly push notifications and chat widgets all carry their own version of the same consent requirement.
Updated Sep 6, 2026Read guide →GuideAnalytics Cookies Under PECR: Are They Strictly Necessary or Not?
Analytics cookies feel essential to running a business, but PECR's 'strictly necessary' test asks a narrower question than that. Here's how the ICO actually draws the line.
Updated Sep 5, 2026Read guide →GuideDoes PECR Apply to Businesses Outside the UK?
PECR is UK law, but that doesn't mean only UK-incorporated businesses need to worry about it. Here's how PECR's reach actually works for a non-UK business with UK visitors or customers.
Updated Sep 5, 2026Read guide →AnalysisPECR Fines and Enforcement: What the ICO Actually Cracks Down On
PECR enforcement has a very different pattern from GDPR enforcement, dominated for years by nuisance calls and texts, with cookie enforcement rising more recently. Here's what the ICO actually prioritizes.
Updated Sep 5, 2026Read guide →GuidePECR and Cookie Consent: What Your Banner Actually Needs to Do
The ICO's expectations for a compliant cookie banner are more specific than most implementations account for. Here's exactly what a PECR-compliant banner needs to do, technically.
Updated Sep 4, 2026Read guide →GuidePECR and Email Marketing: When You Can and Cannot Send
A scenario-by-scenario guide to when PECR actually lets you send a marketing email, cold prospects, existing customers, purchased lists, referrals, and where the line sits for each.
Updated Sep 4, 2026Read guide →GuideThe Soft Opt In Explained: PECR's Exception for Existing Customers
The soft opt-in lets you email existing customers about similar products without fresh consent, but only if you satisfy all four conditions. Here's exactly what each one requires.
Updated Sep 4, 2026Read guide →GuideDo PECR Rules Apply to My Website's Cookies?
If your site has any UK visitors and sets non-essential cookies, PECR almost certainly applies. Here's how the cookie rule actually works and where the exemptions genuinely sit.
Updated Sep 3, 2026Read guide →ComparisonPECR vs GDPR: Where the Two Rules Overlap and Where They Differ
PECR and GDPR cover a lot of the same ground but aren't the same law, and they don't always agree on the details. Here's a side-by-side comparison of where each one actually governs what.
Updated Sep 3, 2026Read guide →GuideWhat Is PECR and How Does It Work Alongside GDPR?
PECR is the UK law that governs cookies, marketing emails, and electronic communications, sitting alongside GDPR rather than being replaced by it. Here's what PECR actually is.
Updated Sep 3, 2026Read guide →