Guides

All guides

113 guides, organized by topic. Educational guides and tool comparisons, written from hands-on testing rather than vendor briefings.

CIPA
Guide

Consent Mode and CIPA: How Proper Tag Sequencing Protects You

Google Consent Mode and correct tag sequencing in a tag manager are the technical mechanism behind actually blocking trackers pre-consent, not just disclosing them. Here's how to get it right.

Updated Aug 18, 2026Read guide →
Analysis

SB 690 and the Future of CIPA: Will a Safe Harbor Ever Arrive?

California SB 690 represents legislative pushback against the CIPA website litigation wave, aiming to carve out a safe harbor for standard analytics and marketing tools. Here's what that would mean if enacted.

Updated Aug 18, 2026Read guide →
Guide

The Plaintiff Firms Behind CIPA Lawsuits: How the Playbook Works

CIPA demand letters and lawsuits follow a recognizable, largely automated pattern. Understanding the mechanism behind it helps explain why letters arrive and what determines who gets one.

Updated Aug 18, 2026Read guide →
Guide

CIPA Beyond California: Which Other States Have Wiretapping Laws

CIPA is California-specific, but the underlying legal structure, all-party consent wiretapping statutes with a private right of action, exists in other states too. Here's the landscape.

Updated Aug 18, 2026Read guide →
Guide

Does Your Business Insurance Cover CIPA Claims? The Exclusion Problem

General liability and cyber policies don't automatically cover CIPA claims, and many explicitly exclude statutory privacy violations. Here's what to actually check with your broker.

Updated Aug 18, 2026Read guide →
Guide

CIPA for Ecommerce Stores: Where Shopify and WooCommerce Sites Get Exposed

Ecommerce stores run a heavier tracker stack than most sites, retargeting pixels, cart-abandonment tools, live chat, session replay. Here's where Shopify and WooCommerce sites specifically get exposed.

Updated Aug 18, 2026Read guide →
Guide

Do Live Chat Widgets Violate CIPA? The Split Court Decisions

Courts have reached genuinely different conclusions on whether third-party live chat widgets violate CIPA. Here's what the split actually looks like and why it hasn't resolved.

Updated Aug 18, 2026Read guide →
Guide

CIPA and Session Replay Tools: Hotjar, Clarity, and FullStory

Session replay tools are the single most litigated tracker category in CIPA suits. Here's why, and what to actually check if you run Hotjar, Microsoft Clarity, or FullStory.

Updated Aug 18, 2026Read guide →
Guide

Is Google Analytics a CIPA Risk? What Site Owners Need to Know

Google Analytics is lower on the CIPA risk spectrum than session replay or chat widgets, but it's not automatically exempt. Here's what configuration details actually matter.

Updated Aug 18, 2026Read guide →
Guide

CIPA Section 631 vs 638.51: The Two Provisions Plaintiffs Use

Most CIPA website suits cite Penal Code §631, but a second theory under §638.51's pen-register language is increasingly common. Here's how the two provisions differ and why it matters.

Updated Aug 18, 2026Read guide →
Guide

How to Reduce Your CIPA Risk: A Practical Checklist

A concrete, non-alarmist checklist for reducing your website's CIPA exposure, covering tracker audits, consent gating, documentation, and what to verify technically, not just legally.

Updated Aug 18, 2026Read guide →
Analysis

CIPA Settlements in 2026: What Cases Are Actually Costing

The $5,000-per-violation figure is a statutory ceiling, not what cases settle for. Here's an honest look at the gap between theoretical exposure and what CIPA cases are actually costing defendants.

Updated Aug 18, 2026Read guide →
Guide

Why Healthcare Websites Face the Highest CIPA Risk

Healthcare and health-adjacent websites face a sharper version of CIPA risk than most industries, for reasons that go beyond general privacy sensitivity. Here's the specific mechanism.

Updated Aug 18, 2026Read guide →
Guide

You Received a CIPA Demand Letter. What Now?

A calm, practical walkthrough of what a CIPA demand letter is, why you got one before any lawsuit was filed, and the first steps to take in the days after it arrives.

Updated Aug 18, 2026Read guide →
Guide

Which Website Trackers Trigger CIPA Lawsuits?

Not every tracking script carries the same CIPA risk. Here's how session replay, chat widgets, ad pixels, and analytics tools compare on the specific pattern plaintiffs' firms target.

Updated Aug 18, 2026Read guide →
Guide

The Millisecond Problem: Why Cookie Banners Aren't Enough for CIPA

A cookie banner that discloses tracking isn't the same as one that blocks it. CIPA claims turn on the exact moment a script starts talking to a third party, here's why that distinction matters.

Updated Aug 18, 2026Read guide →
Guide

Does My Website Need to Worry About CIPA?

A practical framework for deciding whether your site's traffic and tracking stack put you in the range of CIPA lawsuit risk, and when it's genuinely a non-issue.

Updated Aug 18, 2026Read guide →
Comparison

CIPA vs CCPA: Why Being CCPA-Compliant Doesn't Protect You

CCPA compliance and CIPA exposure are two different problems with two different legal mechanisms. Here's why passing one doesn't mean you've handled the other.

Updated Aug 18, 2026Read guide →
Guide

CIPA's $5,000 Per Violation: How the Math Actually Works

The $5,000-per-violation figure in CIPA lawsuits sounds small until you see how 'per violation' gets counted. Here's the actual math, and why the real number is almost always smaller.

Updated Aug 18, 2026Read guide →
Guide

What Is CIPA? The 1967 Wiretap Law Now Suing Websites

CIPA was written for phone taps, not pixels. Here's how a 1967 California wiretapping law became the legal theory behind thousands of website tracking lawsuits.

Updated Aug 18, 2026Read guide →
GDPR & CCPA
Guide

Does GDPR Apply to B2B Data and Business Contacts?

A common assumption is that GDPR only covers consumer data. It doesn't, a work email address and job title are personal data too. Here's what actually changes, and doesn't, for B2B processing.

Updated Sep 2, 2026Read guide →
Guide

How Long Can I Keep Personal Data Under GDPR?

GDPR doesn't set a fixed retention period, it requires you to justify one. Here's how the storage limitation principle actually works and how to set defensible retention periods.

Updated Sep 2, 2026Read guide →
Guide

What Is a Lawful Basis for Processing, and Which One Do I Need?

GDPR gives you six possible lawful bases for processing personal data, not just consent. Here's what all six actually are and how to figure out which one fits a given activity.

Updated Sep 2, 2026Read guide →
Guide

What Is the Difference Between a Data Controller and a Data Processor?

GDPR splits obligations between controllers and processors, and getting the label wrong for your business can mean missing entire categories of legal requirements. Here's how to tell which one you are.

Updated Sep 1, 2026Read guide →
Guide

Do I Need Consent for Every Cookie on My Website?

No, but the exemption is narrower than most sites assume. Here's exactly which cookies need consent, which don't, and where the line actually sits.

Updated Sep 1, 2026Read guide →
Analysis

How Much Can I Actually Be Fined Under GDPR?

The €20M / 4% figure is a ceiling, not a typical outcome. Here's what fine amounts actually look like in practice across company sizes, not just the headline maximums.

Updated Sep 1, 2026Read guide →
Guide

Do I Need a Data Protection Officer for My Small Business?

Most small businesses don't need a formal DPO under GDPR, but the exceptions catch more small teams than you'd expect. Here's how to think about it at small-business scale specifically.

Updated Aug 31, 2026Read guide →
Guide

What Counts as Personal Data Under GDPR?

GDPR's definition of personal data is broader than most businesses assume, it covers far more than names and emails. Here's what actually counts, including the identifiers most sites overlook.

Updated Aug 31, 2026Read guide →
Guide

Do I Need a Cookie Banner Under GDPR, or Is That a Myth?

Cookie banners have picked up a lot of folklore: some businesses think they're always required, others think they're theater nobody checks. Neither is quite right. Here's what's myth and what's real.

Updated Aug 30, 2026Read guide →
Guide

Does GDPR Apply to My Business If I'm Not Based in the EU?

GDPR's territorial scope is based on your visitors and customers, not your company's address. Here's how to tell whether your non-EU business is actually in scope.

Updated Aug 30, 2026Read guide →
Analysis

The Biggest GDPR Fines Ever and What Caused Them

The largest GDPR fines on record share a common pattern: international data transfers and consent for advertising, more often than data breaches. Here's what actually caused the biggest ones.

Updated Aug 18, 2026Read guide →
Guide

GDPR for Shopify and WooCommerce Stores: A Setup Guide

Ecommerce stores collect more personal data than most sites, orders, payment details, marketing lists, and run heavier tracking stacks. Here's a practical GDPR setup guide for Shopify and WooCommerce.

Updated Aug 18, 2026Read guide →
Guide

Do You Need a Privacy Policy Under GDPR? What to Include

GDPR requires transparency about data processing in practice, which almost always means a real privacy policy. Here's what has to be in it and where generic templates fall short.

Updated Aug 18, 2026Read guide →
Guide

GDPR for Email Marketing: Consent, Opt-Ins, and the PECR Overlap

Email marketing sits at the intersection of two different EU laws, GDPR and the ePrivacy Directive (PECR in the UK). Here's how they overlap and what that means for opt-ins in practice.

Updated Aug 18, 2026Read guide →
Guide

Legitimate Interest vs Consent: Why It Matters for Cookies

Legitimate interest and consent are both valid GDPR lawful bases, but they're not interchangeable for cookies. Here's when each actually applies, and where sites get it wrong.

Updated Aug 18, 2026Read guide →
Guide

Records of Processing Activities (ROPA): What Article 30 Requires

Article 30 requires many organizations to maintain a written record of their data processing activities. Here's what has to be in it, who's exempt, and how to build one without overcomplicating it.

Updated Aug 18, 2026Read guide →
Guide

GDPR Breach Notification: The 72-Hour Rule Explained

GDPR gives you 72 hours to notify a supervisory authority after becoming aware of a personal data breach. Here's what starts the clock, what has to be in the notification, and when you also have to tell affected individuals.

Updated Aug 18, 2026Read guide →
Comparison

GDPR vs CCPA vs the US State Laws: One Comparison Table

GDPR, CCPA/CPRA, and the growing set of US state privacy laws share a lot of DNA but differ in real, practical ways. Here's a single table comparing scope, rights, and enforcement.

Updated Aug 18, 2026Read guide →
Guide

Do You Need a Data Protection Officer (DPO)? A Simple Test

GDPR requires a Data Protection Officer in specific situations, not for every business. Here's the actual three-part test Article 37 sets out, and what to do if you're on the edge.

Updated Aug 18, 2026Read guide →
Guide

What Is a DSAR? Handling Data Subject Requests Under GDPR

A data subject access request lets anyone ask what personal data you hold on them. Here's what DSARs actually require, the 30-day clock, and how to handle one without dedicated tooling.

Updated Aug 18, 2026Read guide →
Guide

GDPR Fines Explained: How €20M and 4% of Revenue Really Work

The '€20 million or 4% of global revenue' GDPR fine figure is a maximum, calculated per tier, not a flat penalty. Here's how the math actually works and what determines which tier applies.

Updated Aug 18, 2026Read guide →
Guide

International Data Transfers After Schrems II: The SCC Problem

Schrems II invalidated Privacy Shield and put Standard Contractual Clauses under new scrutiny. Here's what the ruling actually requires for transferring EU personal data outside the EEA.

Updated Aug 18, 2026Read guide →
Guide

GDPR Cookie Consent: What a Compliant Banner Actually Requires

Most cookie banners disclose tracking without actually blocking it. Here's what GDPR consent actually requires, technically and legally, for a banner to be compliant.

Updated Aug 18, 2026Read guide →
Guide

GDPR and Google Analytics: Is GA4 Legal to Use in the EU?

Several EU regulators found Universal Analytics unlawful over US data transfers. Here's what changed with GA4 and the 2023 EU-US Data Privacy Framework, and what's still uncertain.

Updated Aug 18, 2026Read guide →
Guide

The Small-Business GDPR Compliance Checklist

A structured, step-by-step GDPR compliance checklist covering data mapping, vendor agreements, breach response, and recordkeeping, the program-level steps beyond the cookie banner basics.

Updated Aug 18, 2026Read guide →
Guide

What Is a Data Processing Agreement (DPA) and When You Need One

A DPA is the contract GDPR requires between you and any vendor that processes personal data on your behalf. Here's when you need one, what it has to cover, and how to get one in place fast.

Updated Aug 18, 2026Read guide →
Guide

Does GDPR Apply to My US-Based Website?

GDPR applies based on your visitors' location, not your business's. Here's how to actually determine whether a US-based site is in scope.

Updated Aug 18, 2026Read guide →
Guide

GDPR Consent vs Legitimate Interest: A Decision Guide

A practical decision framework for choosing between consent and legitimate interest as your GDPR lawful basis, for any kind of processing, not just cookies.

Updated Aug 18, 2026Read guide →
Guide

The 7 GDPR Principles Every Business Should Know

GDPR's specific rules all trace back to seven core principles in Article 5. Understanding them makes every other requirement, consent, retention, security, easier to reason about.

Updated Aug 18, 2026Read guide →
Guide

What Is GDPR? A Plain-English Guide for Small Businesses

GDPR explained without the legalese: what it actually requires, who it applies to, and what a small business needs to get right first.

Updated Aug 18, 2026Read guide →
Comparison

Best Cookiebot Alternatives in 2026

We tested the leading Cookiebot alternatives on setup time, script-blocking accuracy, pricing, and support. Here's how they compare.

Updated Aug 1, 2026Read guide →
Guide

Does My Business Need a Cookie Banner?

A plain-language breakdown of when cookie consent banners are legally required, based on where your visitors are and what your site actually does.

Updated Jul 22, 2026Read guide →
Guide

The Small-Business GDPR Checklist

A practical, no-jargon checklist for small businesses that need to get GDPR basics right without hiring a compliance team.

Updated Jun 30, 2026Read guide →
COPPA
Guide

COPPA Compliance Checklist for EdTech and Gaming Sites

EdTech and gaming platforms carry the highest COPPA exposure of any category, both by design and by actual audience. Here's a practical checklist for where to focus first.

Updated Aug 23, 2026Read guide →
Guide

COPPA Penalties: How the FTC Actually Calculates Per-Violation Fines

COPPA fines aren't a single flat number, they're calculated per violation, and the FTC's definition of a 'violation' is broader than most businesses expect. Here's how the math actually works.

Updated Aug 22, 2026Read guide →
Guide

What COPPA Requires in Your Privacy Policy (and What Most Sites Get Wrong)

COPPA doesn't just require a privacy policy, it requires specific disclosures a general privacy policy usually doesn't include. Here's exactly what has to be there.

Updated Aug 21, 2026Read guide →
Guide

Mixed-Audience Websites: COPPA's Hardest Compliance Question

Most sites aren't purely for kids or purely for adults, they're somewhere in between. COPPA has a specific carve-out for this, the mixed-audience approach, but it only works if you implement it correctly.

Updated Aug 20, 2026Read guide →
Guide

COPPA vs. GDPR-K and the UK Children's Code: Comparing Global Kids' Privacy Rules

If your site has visitors in the US, EU, and UK, you're dealing with three different children's privacy frameworks at once, and they don't require the same things. Here's how they actually differ.

Updated Aug 19, 2026Read guide →
Guide

The COPPA Safe Harbor Program: Is Self-Certification Worth It?

COPPA lets businesses join an FTC-approved safe harbor program instead of being directly investigated by the FTC. Here's what that trade actually involves and who it makes sense for.

Updated Aug 18, 2026Read guide →
Guide

COPPA and Third-Party Trackers: Why Your Ad Pixels Are the Real Exposure

Most COPPA conversations focus on signup forms, but the more common violation is a persistent advertising or analytics identifier collected from a child without consent. Here's why trackers are the real risk.

Updated Aug 17, 2026Read guide →
Guide

Verifiable Parental Consent: Which COPPA-Approved Methods Actually Work

COPPA requires more than a checkbox for parental consent, it requires a method the FTC considers 'verifiable.' Here's what's actually on the approved list and how each one works in practice.

Updated Aug 16, 2026Read guide →
Guide

Is Your Website 'Directed to Children' Under COPPA? The FTC's Actual Test

COPPA's 'directed to children' standard isn't a single yes/no question, the FTC weighs a specific list of factors. Here's what actually determines which side of the line your site falls on.

Updated Aug 15, 2026Read guide →
Guide

What Is COPPA? The Federal Children's Privacy Law Explained

COPPA has governed how US websites handle children's data since 1998, and its requirements are stricter and more specific than most general privacy law. Here's what it actually covers.

Updated Aug 14, 2026Read guide →
DPA
Guide

DPA Negotiation Mistakes That Create Real Liability

Most DPA problems aren't dramatic, they're small, repeated mistakes made under deadline pressure during vendor procurement. Here are the ones we see most often.

Updated Aug 22, 2026Read guide →
Guide

Audit Rights in a DPA: What to Negotiate and How to Use Them

An audit rights clause is only useful if it's specific enough to actually invoke. Here's what to negotiate for, and what a reasonable audit request actually looks like in practice.

Updated Aug 21, 2026Read guide →
Guide

US State Privacy Laws and Service Provider Agreements: How They Compare to a GDPR DPA

CCPA/CPRA and other US state privacy laws require their own vendor contract terms, similar in spirit to a GDPR DPA but not identical. Here's what's different and where one contract can cover both.

Updated Aug 20, 2026Read guide →
Guide

Building a DPA to Send Your Own Customers: A Guide for SaaS Vendors

If your product processes personal data on behalf of business customers, you're the processor now, and they'll expect a DPA from you. Here's what to put in it.

Updated Aug 19, 2026Read guide →
Guide

Breach Notification Clauses in a DPA: What Timeline to Require

When a vendor is breached, your own 72-hour GDPR clock is already running before you even hear about it, unless the DPA requires fast notice. Here's what timeline to actually require.

Updated Aug 18, 2026Read guide →
Guide

Reviewing a Vendor's DPA: Red Flags Before You Sign

Most vendor DPAs get accepted without a real read-through. Here are the specific red flags worth actually stopping on before you click accept.

Updated Aug 17, 2026Read guide →
Guide

DPAs and Standard Contractual Clauses: How They Work Together for International Transfers

A DPA and Standard Contractual Clauses solve different problems and are both often needed for the same vendor relationship. Here's how they fit together when personal data leaves the EU.

Updated Aug 16, 2026Read guide →
Guide

Sub-Processor Clauses in a DPA: What to Require From Vendors

Your vendor's own vendors are handling your data too. Here's what a DPA's sub-processor clause should actually require, and the difference between general and specific authorization.

Updated Aug 15, 2026Read guide →
Guide

What a Compliant DPA Must Include: An Article 28 Checklist

GDPR Article 28 lists specific provisions a Data Processing Agreement has to contain. Here's a practical checklist to run any vendor's DPA against before you sign it.

Updated Aug 14, 2026Read guide →
Guide

DPA vs. BAA vs. Data Processing Addendum: Which Contract Do You Actually Need

DPA, BAA, and data processing addendum get used interchangeably, but they cover different legal ground. Here's how to tell which one a given vendor relationship actually requires.

Updated Aug 13, 2026Read guide →
DSAR
Guide

Building a DSAR Log: Audit Trail and Documentation Best Practices

A DSAR log is the difference between being able to demonstrate compliance and just asserting it. Here's what to track, how long to keep it, and how to structure it so it holds up under scrutiny.

Updated Aug 21, 2026Read guide →
Guide

Handling a DSAR When Your Data Lives With Subprocessors

Most businesses don't hold all of a person's data themselves, it's spread across analytics tools, payment processors, and other vendors. Here's how to pull a complete DSAR response together across subprocessors.

Updated Aug 20, 2026Read guide →
Guide

DSAR Exemptions: What You Can Legally Refuse to Disclose

The right to access personal data isn't unlimited. Here's the narrow, specific set of exemptions that let you withhold or redact information in a DSAR response, and where the limits of those exemptions actually sit.

Updated Aug 19, 2026Read guide →
Guide

When to Automate DSAR Fulfillment (and When a Spreadsheet Is Fine)

Dedicated DSAR tooling isn't necessary for every business. Here's how to tell whether your request volume and data footprint justify automating fulfillment, or whether a manual process still works.

Updated Aug 18, 2026Read guide →
Guide

DSARs From Employees vs. Customers: Why HR Requests Are Different

A data subject request from a current or former employee raises different practical and legal wrinkles than one from a customer. Here's what changes when the requester is on your payroll.

Updated Aug 17, 2026Read guide →
Guide

What Happens If You Miss the DSAR Deadline

A missed data subject request deadline isn't automatically a fine, but it does change your position significantly. Here's what actually happens, and what to do if you're about to run out the clock.

Updated Aug 16, 2026Read guide →
Guide

Can You Charge a Fee for a DSAR? What GDPR and CCPA Allow

Both GDPR and CCPA default to free data subject requests. Here's the narrow set of circumstances where a fee or refusal is actually justified, and how to document it if you go that route.

Updated Aug 15, 2026Read guide →
Guide

Verifying Identity for a DSAR Without Overcollecting Data

You have to confirm a requester is who they claim to be before handing over personal data, but asking for too much identification is its own privacy problem. Here's how to calibrate verification.

Updated Aug 14, 2026Read guide →
Guide

DSAR Deadlines and Scope: CCPA/CPRA vs. GDPR Compared

GDPR and CCPA both give people the right to request their data, but the deadlines, scope, and fee rules differ enough that treating them as identical creates real compliance gaps.

Updated Aug 13, 2026Read guide →
Guide

How to Respond to a DSAR: Templates and a Sample Response Letter

A structured way to acknowledge, verify, and respond to a data subject access request, plus a sample response letter you can adapt for your own process.

Updated Aug 12, 2026Read guide →
FSCA
Guide

Is Florida Becoming the Next California for Wiretapping Lawsuits?

California's CIPA litigation wave took years to build. Here's why Florida's FSCA has the same underlying ingredients, and what that trajectory means for businesses serving Florida traffic.

Updated Aug 24, 2026Read guide →
Guide

FSCA and E-Commerce: Where Florida Shopify/WooCommerce Stores Get Exposed

E-commerce stores run more third-party tracking than almost any other site category, and Florida's FSCA reaches the same tools CIPA does. Here's where online stores are actually exposed.

Updated Aug 23, 2026Read guide →
Guide

Reducing Your FSCA Risk: A Practical Website Checklist

Most FSCA exposure comes down to a small, identifiable set of technical gaps. Here's a practical checklist for auditing and fixing them before they become a claim.

Updated Aug 22, 2026Read guide →
Guide

FSCA Damages: How Statutory Penalties Are Calculated

The FSCA doesn't require a plaintiff to prove financial harm to recover damages, statutory damages are available per violation. Here's how that structure actually drives exposure.

Updated Aug 21, 2026Read guide →
Guide

Who Can Sue Under the FSCA? Private Right of Action Explained

The FSCA doesn't rely on regulators to enforce it, individual website visitors can bring claims directly. Here's what that private right of action actually means for a business's exposure.

Updated Aug 20, 2026Read guide →
Guide

FSCA's Two-Party Consent Rule: What It Means for Chat Widgets and Pixels

Live chat and ad pixels are two of the most common tools on small business websites, and both sit inside the FSCA's two-party consent theory. Here's what changes about how they should be implemented.

Updated Aug 19, 2026Read guide →
Guide

Session Replay Tools and FSCA: The Same Risk as Hotjar Under CIPA

Session replay and heatmap tools are the single most litigated category under CIPA's wiretapping theory, and the same exposure applies directly under Florida's FSCA. Here's why.

Updated Aug 18, 2026Read guide →
Guide

Does the Florida FSCA Apply to Website Tracking and Analytics?

The FSCA was written for phone taps, not pixels, but the legal theory being used against websites turns on whether a script's data capture counts as an 'interception.' Here's how that argument works.

Updated Aug 17, 2026Read guide →
Guide

FSCA vs. CIPA: How Florida's Wiretapping Law Compares to California's

Florida and California both have two-party-consent wiretapping laws now being applied to website tracking, but they're not the same statute. Here's where the FSCA and CIPA actually diverge.

Updated Aug 16, 2026Read guide →
Guide

What Is the Florida Security of Communications Act (FSCA)?

Florida has its own two-party-consent wiretapping law, and like California's CIPA, it's increasingly being applied to website tracking technology. Here's what the FSCA actually says.

Updated Aug 15, 2026Read guide →
GA4 & US Privacy Law
Analysis

Is There a Federal Privacy Law Coming, and How Should GA4 Users Prepare?

Congress has come close to a comprehensive federal privacy law more than once without passing one. Here's the current state of that effort and how to configure GA4 so you're not caught flat-footed either way.

Updated Aug 29, 2026Read guide →
Guide

Sensitive Data and GA4: Avoiding Violations Under US State Laws

US state privacy laws single out sensitive personal information for stricter treatment, usually requiring opt-in consent rather than just an opt-out right. Here's what that means for common GA4 configurations.

Updated Aug 29, 2026Read guide →
Guide

GA4 Compliance Under the Texas Data Privacy and Security Act

Texas's TDPSA applies to more businesses than most state privacy laws because it drops the usual revenue and volume thresholds. Here's what that means for your GA4 setup.

Updated Aug 28, 2026Read guide →
Guide

Global Privacy Control (GPC) and GA4: Are You Actually Honoring It?

GPC is a browser signal with real legal force in several states, but most GA4 setups don't detect it at all. Here's what it is and how to actually wire it into your tag configuration.

Updated Aug 28, 2026Read guide →
Guide

Colorado Privacy Act Requirements for Google Analytics Users

Colorado's Privacy Act was the first US state law to mandate universal opt-out mechanism recognition. Here's what that means specifically for a GA4 implementation.

Updated Aug 27, 2026Read guide →
Guide

Do Not Sell or Share: Configuring GA4 to Honor Opt Out Signals

A Do Not Sell or Share link is only compliant if it actually changes what GA4 sends. Here's how to wire the two together instead of shipping a link that does nothing.

Updated Aug 27, 2026Read guide →
Comparison

State by State: Which US Privacy Laws Impact Your GA4 Setup

Nearly 20 US states now have comprehensive privacy laws, and most of them treat analytics-driven advertising as a regulated data practice. Here's a state-by-state view of what that means for GA4.

Updated Aug 26, 2026Read guide →
Guide

The Virginia CDPA and GA4: A Compliance Overview

Virginia's Consumer Data Protection Act uses an opt-out model built around 'targeted advertising' rather than 'sale.' Here's what that means for a standard GA4 setup.

Updated Aug 26, 2026Read guide →
Comparison

CPRA vs CCPA: How the Changes Affect Your GA4 Configuration

The CPRA didn't replace the CCPA, it amended and expanded it. Here's what actually changed and what it means for how you've configured Google Analytics 4.

Updated Aug 25, 2026Read guide →
Guide

GA4 and the CCPA: What California Businesses Must Know

If you run Google Analytics 4 and have California visitors, the CCPA almost certainly applies to your setup. Here's what that actually requires, in plain terms.

Updated Aug 25, 2026Read guide →
PECR
Guide

PECR and SMS, Live Chat, and Push Notifications: The Rules Beyond Email

PECR's marketing rules cover more than email, texts, automated calls, and increasingly push notifications and chat widgets all carry their own version of the same consent requirement.

Updated Sep 6, 2026Read guide →
Guide

Analytics Cookies Under PECR: Are They Strictly Necessary or Not?

Analytics cookies feel essential to running a business, but PECR's 'strictly necessary' test asks a narrower question than that. Here's how the ICO actually draws the line.

Updated Sep 5, 2026Read guide →
Guide

Does PECR Apply to Businesses Outside the UK?

PECR is UK law, but that doesn't mean only UK-incorporated businesses need to worry about it. Here's how PECR's reach actually works for a non-UK business with UK visitors or customers.

Updated Sep 5, 2026Read guide →
Analysis

PECR Fines and Enforcement: What the ICO Actually Cracks Down On

PECR enforcement has a very different pattern from GDPR enforcement, dominated for years by nuisance calls and texts, with cookie enforcement rising more recently. Here's what the ICO actually prioritizes.

Updated Sep 5, 2026Read guide →
Guide

PECR and Cookie Consent: What Your Banner Actually Needs to Do

The ICO's expectations for a compliant cookie banner are more specific than most implementations account for. Here's exactly what a PECR-compliant banner needs to do, technically.

Updated Sep 4, 2026Read guide →
Guide

PECR and Email Marketing: When You Can and Cannot Send

A scenario-by-scenario guide to when PECR actually lets you send a marketing email, cold prospects, existing customers, purchased lists, referrals, and where the line sits for each.

Updated Sep 4, 2026Read guide →
Guide

The Soft Opt In Explained: PECR's Exception for Existing Customers

The soft opt-in lets you email existing customers about similar products without fresh consent, but only if you satisfy all four conditions. Here's exactly what each one requires.

Updated Sep 4, 2026Read guide →
Guide

Do PECR Rules Apply to My Website's Cookies?

If your site has any UK visitors and sets non-essential cookies, PECR almost certainly applies. Here's how the cookie rule actually works and where the exemptions genuinely sit.

Updated Sep 3, 2026Read guide →
Comparison

PECR vs GDPR: Where the Two Rules Overlap and Where They Differ

PECR and GDPR cover a lot of the same ground but aren't the same law, and they don't always agree on the details. Here's a side-by-side comparison of where each one actually governs what.

Updated Sep 3, 2026Read guide →
Guide

What Is PECR and How Does It Work Alongside GDPR?

PECR is the UK law that governs cookies, marketing emails, and electronic communications, sitting alongside GDPR rather than being replaced by it. Here's what PECR actually is.

Updated Sep 3, 2026Read guide →