illustration graphic of cybercriminal stealing personal data from a website that has no data protection and privacy protocols in place.

4 Data Protection and Privacy Elements You Cannot Do Without

Your website is under constant attack from cybercriminals trying to steal personal data and without any data protection and privacy protocols in place, you could be breaking the law and held accountable.

Cybercrime is incredibly costly to individuals and businesses with a global cost of 8.44 trillion US Dollars (7.77 trillion euros) in 2022 and a projected cost rising to 23.84 trillion US Dollars (21.96 trillion euros) in 2027.

estimated cybercrime worldwide up to 2027 statistical graph by

data source

It’s therefore not surprising that countries worldwide are creating and enforcing data protection and privacy laws to safeguard individuals and businesses.

But before we can talk about the safeguards, we should first clarify what we mean by data protection and privacy and the impact on individuals and businesses when personal data falls into the wrong hands.

Data privacy relates to how information (or data) shared with a third party is managed and the necessary safeguards put in place to protect that data based on its relative importance.

Data held on individuals by businesses or organisations used to be locked away in filing cabinets.

Today that same data is held digitally making it more easily accessible to those that need it but also more susceptible to being stolen by those wanting to sell it.

But why is personal data so valuable?

We are in the Information Age where selling data about individuals is hugely profitable and where companies like Google and Meta/Facebook can benefit from using personal data for targeting their online ads.

3b Website Logo

See How We Can Attract More Customers To Your Website

  • 3 Months FREE Web hosting
  • Mobile-First & Responsive Design
  • Unlimited Updates

But acquiring information on individuals goes far beyond businesses making money.

The UK’s Information Commissioner’s Office (ICO) highlights the personal impact:

…if personal data falls into the wrong hands, people could be harmed. Depending on the situation, they could become victims of identity theft, discrimination or even physical harm.


And it’s not just your company’s data but also your customer’s data that could be targeted.

As the website owner, you are responsible for the data protection and privacy of all people’s data (employees and customers) that you hold on your web server.

If you don’t put any safeguards in place then you could be liable for any personal data that is stolen.

1. SSL Protection

SSL should be your first line of defence regarding web data protection and privacy.

SSL actually stands for Secure Sockets Layer and prevents others from reading and modifying the information you share during the transfer between two systems using data encryption to scramble the content.

Data encryption takes place using something called an SSL Certificate.

This is a digital certificate which authenticates your website (i.e. proves that you are who you say you are) and contains a “public key” to scramble data whilst in transit.

Any cybercriminals that try to access the data in transit will only see gibberish.

illustration of how encryption works with ssl certificate using public and private keys.

A private key is then used to unscramble the data which you only have the access to.

Related Article

How to Select the Best SSL Certificate for your Website

If your web visitors can register personal details, including subscribing to receive newsletters or using a payment gateway, then implementing SSL on your website is critical.

However, as well as data protection and privacy, SSL also shows visitors that your website is trustworthy, gives them confidence that you are who you say you are, and improves your search engine page rankings.

2. Cookies Policy

It is highly likely you have already experienced the option to accept Cookies when browsing websites.

Whilst reading this article at some point you will have been asked to accept our own Cookies policy.

But what exactly are Cookies?

A Cookie is a small text file that is transferred from the website you are visiting and stored in your web browser containing personal information about your browsing preferences for that particular website.

The original purpose was to improve your browsing experience.

image used under the fair use policy courtesy of Cookieyes

However, with personal data being so valuable today, Cookies have become a key tool to collect information about your website visits and track what you browse.

Cookies Policy Inside the EU/UK

In May 2018, the Global Data Protection Regulation (GDPR) was introduced as the new framework for data protection and privacy laws within the European Union.

As part of this framework, cookies were requalified as “personal data” and therefore subject to the GDPR.

This means companies are only allowed to collect data through the use of cookies if consent is first given by the user.

If you are found to be in breach of the GDPR, fines of up to 10 million euros or up to 2% of global turnover (whichever is higher) can be imposed.

Cookies Policy Outside the EU/UK

When it comes to the use of Cookies outside the EU/UK, it becomes a little more complicated.

Whilst most countries have some form of data protection and privacy laws, the strength of those laws varies from country to country.

The US for example has very weak data protection and privacy laws compared to most other developed countries and essentially websites do not require a Cookies Policy.

However, countries like Canada, Mexico and Nigeria have much stricter data protection and privacy laws though not as strict as the GDPR for the EU/UK.

You also need to add a Cookies Consent Banner to your website for first-time visitors.

This allows the visitor to view exactly what data you are wanting to collect whilst they are on your website.

But beware, some Cookies Consent Banners purposefully make it difficult to reject their data collection procedures (e.g. no visible deny/reject button) so as to push the visitor to accept.

I would avoid using these as they don’t promote your website as being trustworthy.

The following should be clearly visible on any Cookie Consent Banner:

example of a cookies consent banner to ensure to comply with data protection and privacy laws
  1. Accept – This accepts the default data collection settings
  2. Deny – This stops any cookie from being used to collect your data
  3. View Preferences – This provides the visitor information on what the default settings are for collecting data and generally will include opt-out options to save (e.g. marketing purposes)
  4. Policies – Links to details on how cookies are to be used and the overarching privacy policy

Once a Cookie has been accepted/denied the banner will no longer reappear.

There currently is no law to say that you have to force a renewal of Cookies at any time.

However, the ePrivacy Directive highly recommends that you should set up your banner to renew at least once a year.

Our Recommendation

The Cookies Policy Complianz plugin for WordPress is really easy to use. TermsFeed is another great Cookies Policy solution for websites that don’t use WordPress or if you prefer to not use plugins.

Both are free and include inside and outside the EU/UK as well as a free customisable Cookies Consent Banner.

3. Privacy Policy

It used to be just the super large companies like Apple, Google and Meta/Facebook that would need to provide data protection and privacy policies but things have changed over the last few years.

The reality is that any website that handles information about an individual needs to clearly state what data they are collecting about them and how they plan to use this data.

This is called a Privacy Policy.

Just like Cookie Consent, data protection and privacy laws vary between countries.

However, the general consensus is that even if you don’t need a Privacy Policy by law in your country, you should still have one as it is the right thing to do.

It is important that you are completely transparent in your Privacy Policy.

It is likely you use third-party services to improve the user experience of your website, monitor and analyse user behaviour and maybe even display adverts.

All third-party services you use, and how you intend to use the data collected, must be disclosed in your Privacy Policy.

Typical third-party services include:

  • Google Analytics
  • Google Adwords
  • Facebook
  • Twitter
  • Google Web Fonts
  • YouTube
  • Disqus

Our Recommendation

The privacy policy generator from Termly complies with GDPR, CCPA and PIPEDA laws and is easy to create and install on your website.

Read our own Privacy Policy.

It is good practice to include your Privacy Policy in the footer of your website.

4. Terms of Use Policy

Including Terms of Use (sometimes called Terms of Service or Terms and Conditions) on your website sets out clear rules associated with the use of your website and all its content to the user.

This is a foundation agreement, and a legally binding contract, for the relationship between you and the users/customers.

Whilst what goes into the Terms of Use depends on your business, there are a few things that are considered standard that should be included:

  • Company owner and contact details
  • VAT No. (if applicable)
  • Reference links to Privacy and Cookie policies
  • Last updated date

In addition, your Terms of Use should include, and be explicit on the following:

Make it clear that you own your website data (e.g. content, logo, web design, graphics etc…) and that it is protected by international copyright laws.

Copying or reusing any content without permission is expressly prohibited.

Limitation Liability

Include a clause expressing that you cannot be held liable for any errors or inaccuracies in the content you have made available, or any impacts those errors or inaccuracies cause.

Prevent Abuses

Set out the rules and guidelines on how you expect users to use your website, product and services and that you have the right to terminate the accounts and access of anyone who commits abuses.

Abuses could include offensive language, spamming, posting defamatory content, lewd content etc…

Governing Law

Be explicit in which country(s) the Terms of Use agreement has legal jurisdiction in.

Our Recommendation

The Terms of Use generator for small businesses by TermsFeed is free and easy to set up.

Key Takeaways

Data Protection and Privacy

If you own a website, SSL is your first line of defence against cybercriminals.

If your website stores personal data on individuals, whether it is a single email address for subscribing to a blog or extensive contact and credit card details, it is your responsibility how you store, manage and protect their information.

It is also your responsibility to inform the user on how their stored data is to be used and to give them the ability to opt out of it being used for purposes they don’t agree with.

Check the data protection and privacy laws in your country and take the necessary actions to protect people’s personal data.

Failure to act could be costly for you and for them.

Are you looking for

Affordable Web Design?

Hello, I’m David Christopher. I provide quality web design for startups, small businesses and sole traders at amazing prices.

Maybe we can work together?

woman shaking hands after closing sales lead with social media marketing strategy

About David Christopher

He is the founder of 3B Website Design.  He has over 25 years of experience in digital media, marketing and communications with 20 years working for a Fortune 500 company, heading up Digital Media & Communications for EMEA.

Security & Data Protection

February 8, 2023

Are you looking for

Affordable Web Design?

Hello, I’m David Christopher. I provide quality web design for startups, small businesses and sole traders at amazing prices.

Maybe we can work together?


avatar of David Christopher for the website design blog

Want to Increase Web Traffic?

Join our mailing list to receive the latest web design and digital marketing stuff.

You have Successfully Subscribed!