opinion

Privacy Notices Shouldn’t Be Treated as an Afterthought

Privacy Notices Shouldn’t Be Treated as an Afterthought

After years of preaching about the importance of website operators posting their privacy practices on their websites, another state has joined the party.

Known as Nevada SB 538, Nevada law went into effect last month requiring operators of websites and online services must post a public notice regarding their privacy practices.

The exponential increase in data breaches is forcing all states to take a hard look at their existing laws and make changes now.

Nevada is the third state to pass such a law. California started the trend back in 2004, with the California Online Privacy Protection Act and was joined by Delaware last year with the Delaware Online and Privacy Protection Act.

Much like the California and Delaware requirements, Nevada now requires that website operators must: 1) identify the categories of personally identifiable information collected through the site; 2) identify the categories of third parties with whom personally identifiable information may be shared; 3) disclose whether third parties may collect information about a consumer’s online activities over time and across different websites when the consumer uses the site; 4) provide information about the process for reviewing and requesting changes to personally identifiable information collected through the site; and 5) list an effective date.

It is important to understand that Nevada considers the following to be personally identifiable information:

  • A first and last name;
  • A home or other physical address which includes the name of a street and the name of a city or town;
  • An electronic mail address;
  • A telephone number;
  • A Social Security number; and,
  • An identifier that allows a specific person to be contacted either physically or online.

When it comes to penalties for failing to comply with the new Nevada law, the Nevada attorney general may pursue civil enforcement within 30 days following notification of noncompliance.

However, notification of noncompliance is not required where a website operator’s notice “contains information which constitutes a knowing and material misrepresentation or omission that is likely to mislead a consumer.” In plain English, if you knowingly lie in your privacy notice, then the attorney general does not need to provide notice before coming after you.

The Nevada law allows for injunctive relief and a civil penalty “not to exceed $5,000 for each violation.” It should be noted that the Nevada law does not include a private right of action (i.e. third-party lawsuits or non-attorney general enforcement actions).

As of now, it’s unknown how soon and how aggressively the Nevada attorney general will pursue violations of the new statute, but given the nature of the cyber world we now live in I suspect that it will not be long before we see enforcement actions commencing.

Reminder: this law became effective Oct. 1, meaning that if you are not in compliance then you are now potentially subject to enforcement action.

Both California and Delaware’s laws require that the privacy notice must be “conspicuously” made available and provide guidance on how that standard is to be achieved but the Nevada law only states that the privacy notice must be available “in a manner reasonably accessible by consumers.”

Additionally, Nevada’s law does not require an operator to disclose how it responds to web browser “do not track” signals; does not apply to entities unless they purposefully direct activities toward Nevada, consummate some transaction with the state or a resident, or purposefully avail themselves of the privilege of conducting activities in Nevada; and excludes operators located in Nevada whose revenue is primarily delivered from sources other than online services and whose website receives fewer than 20,000 unique visitors per year.

If you are hoping that Nevada will be the last state to join California and Delaware then I would not recommend that you hold your breath. The exponential increase in data breaches is forcing all states to take a hard look at their existing laws and make changes now.

Government officials have clearly drawn a line in the sand and will be especially aggressive against those website operators who blatantly misrepresent their privacy practices.

Privacy notices, aka privacy policies, should not be treated as an afterthought.

Online business operators need to ensure that their privacy notices are fully compliant with applicable law and ensure that no misrepresentations are being made.

Stealing (“borrowing”) another website’s privacy notice is nothing more than a game of high stakes Russian roulette.

This article does not constitute legal advice and is provided for your information only and should not be relied upon in lieu of consultation with legal advisors in your own jurisdiction It may not be current as the laws in this area change frequently. Transmission of the information contained in this article is not intended to create and the receipt does not constitute, an attorney-client relationship between sender and receiver.

Corey D. Silverstein is the managing and founding member of the Law Offices of Corey D. Silverstein P.C., which focuses on representing all areas of the adult industry. His clientele includes hosting companies, affiliate programs, content producers, processing companies, website owners and performers, just to name a few. Silverstein can be reached by email at corey@myadultattorney.com; his site, MyAdultAttorney.com and Porn.law; or by telephone at (248) 290-0655.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

profile

WIA Profile: Samantha Beatrice

Beatrice credits the sex positivity of Montreal for ultimately inspiring her to pursue work in adult entertainment. She had many friends working in the industry, from sex workers to production teams, so it felt like a natural fit and offered an opportunity to apply her marketing and social media savvy to support people she truly believes in and wants to see succeed.

Women In Adult ·
opinion

Understanding the Latest Server Processors

Over the last decade, we mostly stopped talking about CPU performance. Recently, however, there has been a seismic and exciting change in the CPU landscape, due to innovation by a chip company called Advanced Micro Devices (AMD).

Brad Mitchell ·
opinion

User Choice, Privacy and the Importance of Education in AV

As we discussed last month, age verification in the adult sector is critical to ensuring legal compliance with ever-evolving regulations, safeguarding minors from inappropriate content and protecting the privacy of adults wishing to view adult content.

Gavin Worrall ·
opinion

Maintaining Payment Processing Compliance When the Goalpost Keeps Moving

VIRP is the new four-letter word everyone loves to hate. The Visa Integrity Risk Program went into effect last year, and affects several business types — including MCC 5967, which covers adult and anything else with nudity, and MCC 7273, dating services that don’t allow nudity.

Jonathan Corona ·
opinion

Making the Most of Your Sales Opportunities

The compliance road has been full of twists and turns this year. For many, it’s been a companywide effort just to make it across that finish line. Hopefully, most of us can now return our attention to some important things we’ve left on the back burner for months — like driving revenue.

Cathy Beardsley ·
profile

YourPaysitePartner Marks 25-Year Anniversary Amid Indie Content Renaissance

For 25 years, YourPaysitePartner has teamed up with stars and entrepreneurial brands to bring their one-stop-shop adult content dreams to life — and given the indie paysite renaissance of the past few years, the company’s efforts have paid off in spades.

Alejandro Freixes ·
opinion

WIA Profile: B. Wilde

B. Wilde considers herself a strategic, creative, analytical and entertaining person by nature — all useful traits for a “marketing girlie,” a label she happily embraces.

Women In Adult ·
opinion

Proportionality in Age Verification

Ever-evolving age verification (AV) regulations make it critical for companies in the adult sector to ensure legal compliance while protecting the privacy of adults wishing to view adult content. In the past, however, adult sites implementing AV solutions have seen up to a 60% drop in traffic as a result.

Gavin Worrall ·
opinion

Goodbye to Noncompete Agreements in the US?

A noncompetition agreement, also known as a noncompete clause or covenant not to compete, is a contract between an employer and an employee, or between two companies.

Corey D. Silverstein ·
opinion

The Search for Perfection in Your Payments Page

There has been a lot of talk about changes to cross sales and checkout pages. You have likely noticed that acquirers are now actively pushing back on allowing merchants to offer a negative option, upsell or any cross sales on payment pages.

Cathy Beardsley ·
Show More