Public privacy notice
Clear, accessible notice of categories collected, purposes, third parties, rights, and contact channel
Rights response within 45 days
Respond to consumer rights requests within 45 days (extendable by 45 more with notice)
Data processing agreements
Written contracts with processors restricting their processing to the controller's documented instructions
Data protection assessments
Document risk assessment for targeted advertising, sale, profiling, sensitive data processing
Honour universal opt-out signals (GPC)
Recognise the Global Privacy Control browser signal as a valid opt-out (where required)
Reasonable security practices
Administrative, technical, physical safeguards appropriate to the data's sensitivity
Data minimisation + purpose limitation
Collect only what is adequate, relevant, and reasonably necessary for the disclosed purposes
Opt-in for sensitive data + minors 13–17
Affirmative consent before sensitive data processing; opt-in for targeted ads or sale of data of consumers known to be 13–17 (one of the broadest teen protections)