Do you have a tech platform that collects personal information from users? What types of personal information need to be protected, how should it be protected, and what legal documents are required for this protection? This article will go over the basis of data protection.
What Is Personal Information?
Personal information, by legal definition, includes, but isn’t limited to the following information about your users:
Contact: names, email and mailing addresses, and phone numbers
Identification: SSNs, passport numbers, and driver’s license numbers
Account: login information, account preferences, and customized settings
Payment: credit card numbers, bank account and routing numbers, and other financial account information
Device: IP addresses and operating system information
Use of Platform: pages visited, times and dates of visits, and actions on each page
Other: GPS and geolocation information and cookies tracking
Tech startups are required by standard legal practice to disclose to users the types of personal information that they are collecting and how they plan on using it. Examples of use cases include:
1. Offering services like identity verification, account management, and various technical support
2. Ensuring that customers or clients meet the age requirements for accessing the platform and rejecting those who are underage or overage
3. Using cookies and location-specific information to deliver personalized advertisements, recommendations, and platform features
4. Processing payments within the platform and to and from third parties
5. Providing personalized customer support through account preference information
6. Identifying fraudulent activity, disputes, security breaches, and other unlawful or forbidden uses of the platform
7. Improving the platform by analyzing user activity
How Should Personal Information Be Protected?
There are no specific rules on how personal information should be protected, but your user privacy policy should describe your data protection policies in at least some detail. Will you be using servers outside the United States? Will you be keeping physical copies of the data at an office? How will you prevent, in legalese, the “theft, disclosure, alteration, destruction, unauthorized access, or loss” of this personal information?
In the United States, personal information is normally stored for at least five years, unless tech startups need to keep it for longer due to regulatory considerations. You may find it helpful to maintain an independent drive (from the rest of your platform) to ensure that your users comply with anti-money laundering laws and to protect yourself from lawsuits.
Other sections you may want to include are:
1. If there is a security breach, what systems do you have in place to restore the confidence of and mitigate the damage caused by the breach to your users? What type of notice will you give, and what compensation would you be willing to provide? These are additional things to think about when drafting your privacy policy.
2. How will users be able to retrieve their personal information? Most privacy policies allow users to download a copy of their personal information or request that it be removed from the platform. You may want to consider how deletion would work. Would you want to keep a “ghost copy” to protect yourself from future lawsuits, or would you allow users to fully erase all traces of themselves from the platform?
What Legal Documents Are Required To Protect Personal Information?
As mentioned above, the typical document that the protection of personal information goes into would be your privacy policy. With that said, there may be more “informal” contracts elsewhere throughout your platform. An example would be the popup that shows when users confirm the submission of personal information to your platform. Another example would be the terms and conditions that users sign upon joining your platform, which would either incorporate the clauses of or link to a privacy notice or policy.
Wrapping up
At the end of the day, the protection of personal information is something that you want to take seriously. There are countless news stories every day of tech startups being sued for data breaches or losses. A class action could be costly and bankrupt your business. The purpose of having a privacy policy is to let users know what they can expect, so that if something goes wrong, they know who to sue (and hopefully, that will not be you).



