Technology and Software

Technology & Software Privacy Law

A software business can fall under several privacy regimes at once, depending on whose data it handles and in what role. This guide describes which laws reach apps, platforms and SaaS providers, how they allocate duties between the business and its customers, and what they require for children’s data, interface design, security and individual rights requests.

Which Laws Reach a Software Business

A technology company rarely falls under a single privacy regime. State comprehensive statutes apply based on thresholds and on where users are located. COPPA applies based on the audience of the service. Sector-specific rules apply based on what data is handled: HIPAA where the company is a business associate of a covered entity, GLBA where it is significantly engaged in financial activities, FERPA obligations flowing through contract where it serves schools. Section 5 of the FTC Act applies regardless, to any company making representations about privacy or security.

The GDPR reaches a US company with no European establishment through Article 3, where it offers goods or services to people in the EU or monitors their behaviour there. Neither trigger depends on having a European entity, European staff or European infrastructure. Behavioural monitoring is the limb that catches companies unaware, because ordinary analytics and advertising instrumentation on a site with European visitors can satisfy it.

Controller, Processor, Service Provider

Every modern privacy statute distinguishes the party that decides why and how data is processed from the party that processes it on instructions. The GDPR calls them controller and processor; US state statutes call them controller and processor or business and service provider. The classification is not chosen by the parties: it follows from who actually determines the purposes.

What the parties do control is whether the required contract exists. Without it, a vendor is a third party rather than a processor, and a transfer to that vendor may be a sale under state law and an unlawful disclosure under the GDPR. The required terms are broadly consistent across regimes: limited processing purposes, confidentiality obligations, security measures, restrictions on subprocessors, assistance with individual rights requests and breach notification, and deletion or return at the end of the engagement.

COPPA and the Under-13 Question

COPPA applies to operators of websites and online services directed to children under 13, and to operators with actual knowledge that they collect personal information from a child under 13. Directedness is assessed on the totality of the evidence: subject matter, visual and audio content, use of animated characters or child-oriented activities, music, age of models, presence of child celebrities, language, advertising placed on the service, and any competent evidence about the actual audience.

Where the rule applies, the operator must post a clear privacy notice, provide direct notice to parents, obtain verifiable parental consent before collection, give parents access to and the ability to delete their child’s information, refrain from conditioning participation on collecting more than is reasonably necessary, retain the information only as long as needed, and maintain reasonable security. Personal information includes persistent identifiers used for behavioural advertising, which is why the rule reaches services that collect no name or address at all. Several states now impose additional age-appropriate design obligations that extend past 13.

Consent, Dark Patterns and Interface Design

Consent has become an interface question rather than a policy question. Where consent is the lawful basis under the GDPR it must be freely given, specific, informed and unambiguous, given by a clear affirmative act, and as easy to withdraw as to give. Pre-ticked boxes, bundled consent and continued browsing do not satisfy it.

US state law approaches the same problem through the dark patterns concept: a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making or choice. Agreement obtained through such an interface does not constitute consent. In practice both frameworks converge on symmetry, on the absence of manipulative framing, and on whether the more privacy-protective option is as easy to reach as the other.

Security as a Legal Obligation

Few US statutes specify security controls, but most impose an obligation to maintain reasonable security appropriate to the data and the risk. The content of reasonable is supplied from elsewhere: the FTC’s enforcement record under Section 5, published frameworks such as the NIST Cybersecurity Framework, and sector rules such as the amended GLBA Safeguards Rule where they apply.

The recurring findings in FTC data security matters are consistent enough to function as a specification in their own right: credentials stored without adequate protection, no multi-factor authentication on administrative access, unpatched known vulnerabilities, unnecessary retention of data past its purpose, absent segmentation allowing lateral movement, no logging or monitoring capable of detecting intrusion, and no assessment of the security of vendors given access to systems.

Individual Rights and the Engineering Behind Them

State statutes and the GDPR grant broadly similar rights: access, deletion, correction, portability, and opt-out of targeted advertising, sale and certain profiling. Response deadlines are typically 45 days under state law, extendable once, and one month under the GDPR.

The obligations are systems obligations rather than policy obligations. Answering an access request requires knowing every store holding data about a person. Deletion requires propagating through backups, logs, analytics platforms, data warehouses and every processor that received the data. Correction requires the same propagation with a different payload. Opt-out of targeted advertising requires a signal to reach every downstream platform. A privacy notice can be drafted in an afternoon; the ability to honour what it promises is architectural.

International Transfers

Transferring personal data out of the EU requires a transfer mechanism. For most US companies that means the Standard Contractual Clauses, supported by a transfer impact assessment considering whether the law of the destination country undermines the protections the clauses promise, with supplementary measures where it does. The EU-US Data Privacy Framework offers an alternative for organisations that self-certify and maintain that certification, subject to ongoing legal challenge in the European courts.

Data localisation requirements in other jurisdictions operate on a different principle entirely, requiring that certain data remain physically within the country, which is an infrastructure constraint rather than a contractual one.

Frequently Asked Questions

When does COPPA apply to my app?

When the service is directed to children under 13, or when the operator has actual knowledge that it collects personal information from a child under 13. The FTC weighs subject matter, visual and audio content, characters, music, advertising and other evidence of the intended audience rather than any single factor.

Does the CCPA apply to an early-stage company?

Only if it crosses a threshold: revenue over 25 million dollars, personal information of 100,000 or more California consumers or households, or 50 percent or more of revenue from selling or sharing personal information. Other state comprehensive laws use different thresholds, so applicability has to be checked state by state.

What is a dark pattern under these laws?

California defines it as a user interface designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision-making or choice. Consent obtained through one does not count as consent.

Do I need a written contract with my vendors?

State privacy laws generally require one before a vendor can be treated as a service provider or processor rather than a third party. Without the required terms, sending data to that vendor may itself be a sale or a share.

What does Section 5 of the FTC Act add on top of privacy statutes?

It prohibits unfair or deceptive acts or practices, and applies whether or not a privacy statute covers the company. In privacy matters the FTC has used it against statements in a privacy policy that do not match actual practice, and against data practices causing substantial injury consumers cannot reasonably avoid.

Sources

This guide describes what these documents say. Follow them to check the description against the source.

  1. California Consumer Privacy Act, Cal. Civ. Code 1798.100 et seq. statute
  2. California Privacy Protection Agency, CCPA regulations regulation
  3. 16 CFR Part 312 — Children’s Online Privacy Protection Rule regulation
  4. Section 5 of the FTC Act, 15 U.S.C. 45 statute
  5. FTC cases and proceedings enforcement action
  6. NIST Cybersecurity Framework technical standard

Reporting, not legal advice. This guide describes privacy law using publicly available primary sources, which are linked at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.