About The Author
Brian Dordevic
Founder of Alpha Efficiency
From $4/hour virtual assistant to running a leading Chicago web design agency. I will help you occupy the minds of your ideal customers, improve your aesthetics, and increase sales.
The Americans with Disabilities Act (ADA), California Consumer Privacy Act (CCPA), and General Data Protection Regulation (GDPR) are standards to which all businesses are held accountable. With high awareness of these acts, website owners are actively taking steps to be compliant with all the relevant laws, policies, acts, and regulations. This article will be discussing these regulations in order to help keep you informed as to how they may apply to your business, as well as the possible complications and penalties if you fail to comply with these acts.

ADA is the abbreviation which means the American with Disabilities Act. This act was first signed into law on July 26,1990. It was created to prevent discrimination against individuals with disabilities, and brought about many important updates, such as wheelchair-accessible entrances, wheelchair-accessible restrooms, and telephone options for individuals who are hearing impaired or have speech difficulties. During the ‘90s, the internet was just beginning to gain in popularity, and accessibility concerns were not yet apparent. Times have changed, and the internet has become a staple in most people’s lives. Consequently, problems for individuals with disabilities have arisen since they are unable to use websites in the same manner. While specific laws like the initial ADA law are not in place, some guidelines are considered to be the gold standard for website accessibility. They outline everything that designers and developers need to consider while creating a website. Some examples include:
While screen readers use alt tags and captions to identify and read the image appropriately to visually impaired users, search bots use them too for the means of determining the contents of an image. For ADA compliance, videos you share on your website need to have a readable transcript. This will also supply search engines with keyword-rich text, which incidentally also serves as a positive gain for your website traffic.
CCPA is a data privacy law that establishes new consumer rights for California state residents relating to access, deletion, and sharing of personal information that is collected by businesses.
Consumers have the right to know what companies are doing with their personal data. In order for businesses to achieve CCPA compliance, they must disclose their data collection and sharing practices to consumers. Consumers must be allowed to exclude their data from being shared with third parties. This is why companies need to update their privacy policies. In addition, they must have a visible footer on their website with the ability to opt-out of data sharing.
CCPA applies to any business in California. It also applies to companies that conduct business in the state of California, or whose customers (or potential customers) are residents of, and meet one of the following criteria:
The major provisions of CCPA are:
CCPA law determines that all violators and non-compliant parties will be penalized with monetary fees and may also result in the loss of clients and business reputation. As you can see, these penalties are serious and hard to ignore. The non-complying businesses may face:
The fines for CCPA are not as costly as the GDPR, but sizable data breaches for thousands of consumers easily add up. For example, if a business violated the rights of 10,000 consumers, penalties for non-compliance could reach a staggering $7,500,000.
The General Data Protection Regulation is considered to be the most significant change in data privacy laws in over 20 years. It was the starting point for the CCPA, both are centered around personal data and what businesses are allowed to do with it. Just like the CCPA, GDPR applies to you regardless of where your business is based, where you process your data, or where you store your data. If you are advertising to, or doing business with individuals, including travelers, within the European Union (EU) or the UK, GDPR applies. Simply put, the GDPR gives individuals within the EU and UK the opportunity to consent to specific uses of their data.
The rules state that businesses must explain consent in an easy-to-understand and easily accessible format. Consent cannot be provided in a pre-checked box and cannot be a requirement for a completely separate process. Also, consent must have an expiration date after which it has to be re-attained. Besides consent, GDPR compliance includes other rights for EU and UK residents. Data breach notification and the right to data erasure are covered by this as well.
GDPR applies to businesses that have:
The major provisions of GDPR are:
The GDPR sets a maximum fine of 20 million euros or 4% of annual global turnover, whichever is greater. However, not all DGPR infringements lead to data protection fines, as supervisory authorities can take other actions like:
There are two tiers of an administrative fine for non-compliance with the GDPR:
As GDPR breach fines are discretionary, they are imposed on a case-to-case basis and should be effective, proportionate, and dissuasive. The lower level of penalties can be issued for infringements of articles:
The higher level penalties can be issued for infringements of articles:
According to DataPrivacyLaw.com, personal data refers to “information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.”
Personal information includes, but is not limited to:
Personal information doesn’t include information that is publicly available, which means lawfully made available whether through federal, state, or local government records, provided no conditions are associated with information as such. Also, “publicly available” doesn’t include biometric information that a company or business collects without the consumer’s knowledge.
To translate into common language, personal data includes:
Besides following all the regulations necessary to comply with these acts, businesses need to make sure they are ready and willing to clear all the data collected from residents upon request. However, there are occasions when a business can keep the data despite a customer’s request. This can only happen if:
While we can’t argue with the fact that technology has made our lives easier, we must remain cognizant of the potential negatives that it’s daily use may have on us. If there were no regulations about the use and selling of our personal data, it could be misused in ways one wouldn’t want to even begin to imagine. This is why it is critical to follow the GDPR, CCPA, and ADA guidelines. Our motivation should not only be avoiding penalties for non-compliance, but also working together to make the internet a safer and friendlier place for all users.
Recent Post
Brian Dordevic
A Guide to Enterprise Mobile Application Development
READ MORE
Brian Dordevic
Enterprise UX Research: 5 Key Steps for Ensuring Top-Level Designs
READ MORE
Brian Dordevic
Scrapbook Style Web Design: 5 Layering Ideas to Nail This Trend
READ MORE