A website compliance audit against a website compliance checklist: the legal requirements for websites, and website legal compliance in practice

Updated

A website compliance audit asks whether the site carries what the law requires of it and behaves the way the law requires it to. For a small business the list is shorter than the word compliance suggests and longer than most sites manage: a privacy policy that matches what the site collects, terms that match what it sells, pricing and review practices that follow the federal guides, email that follows the commercial email rules, and whatever the business's own industry requires, from a licence number to a health privacy notice. This page sets out the audit as a website compliance checklist, which is also the shape of the compliance record Stagenix keeps. It is a checklist, not a legal opinion; what your particular site must carry is a question for your lawyer.

The pages every commercial site is expected to carry

A privacy policy that states what is collected, how it is used and who it is shared with, matching what the site actually does; California's online privacy law requires one of any commercial site collecting personal information from its residents, and a contact form collects personal information. Terms of use or terms of sale matching what the site does: a shop needs sale terms, a booking site needs booking terms, a brochure site needs little. A returns and shipping policy if goods are sold. Contact details for the business, including a physical address where the email rules or a consumer law requires one.

The behaviours the audit checks

Consent: whether the site asks before setting cookies and tracking, where its audience's law requires it. Pricing: whether former prices, comparisons and free offers follow the federal guides against deceptive pricing. Reviews and endorsements: whether reviews are genuine and disclosed and paid links are disclosed under the endorsement guides and the consumer reviews rule. Email: whether every marketing email carries a real sender, an address and a working unsubscribe. Subscriptions: whether any recurring charge is disclosed and cancellable as the automatic renewal rules require. Each is a row on the checklist with a yes, a no, or a not applicable.

Industry rules, and turning the list into a record

A regulated trade carries its own rows: a licence number in advertising for contractors and salons in states that require it, a health privacy notice and a compliant intake form for a practice, lawyer advertising rules for a firm, the self-storage act for a facility. Add those rows from your own industry's rules. Then the audit is the checklist worked through with evidence against each row, a screenshot or an address, a date and a name, and it is redone when the site or the law changes. That record is what a business shows when it is asked, and what the audit page on this site is for.

Questions people ask about website compliance audit

Does a small business website really need a privacy policy?

If it has a contact form, analytics or a newsletter sign-up, it collects personal information, and the widely applicable state law requires a policy. It is the cheapest page on the site to get right.

Is a cookie banner required in the United States?

Federal law does not require one; several state privacy laws require notice and opt-outs for certain tracking, and any site serving European visitors is under their consent rules. The audit records which apply to your audience.

Is this checklist a legal opinion?

No. It is the set of questions a compliance audit asks. What your site must carry depends on where you sell, what you sell and to whom, and that is your lawyer's answer.

Sources

Related answers

Start Stagenix ProKeep the scope, not the inbox thread