What the website is really doing
Many websites and apps run third-party code that sends information about visitors to advertising, analytics, or session-recording providers. Whether that sharing is disclosed accurately, and whether visitors were asked where the law requires it, has become a frequent basis for claims under wiretap, video privacy, and consumer protection statutes. Health-related websites draw particular scrutiny, because even a page visit can reveal something sensitive. The privacy policy has to describe what the site does today, not what it did at launch. A scan of the live site by someone who knows what to look for is often the most useful first step in privacy compliance work.
Marketing and minors
Calls and text messages carry consent rules under federal law and in a number of states, and those rules are litigated heavily, so how consent was obtained and recorded matters. Email marketing has its own federal requirements, including a working way to unsubscribe. Information about children falls under a separate federal regime, and New York has added its own rules for the online data of minors. Loyalty programs and referral offers that collect data in exchange for a benefit can raise additional questions in some states. These areas are often owned by marketing rather than legal, which is why compliance gaps tend to collect there.
Starting with what is live
We generally begin a privacy compliance review with the live website and apps, the current privacy policy, recent marketing campaigns, and the list of tracking and messaging vendors. We then compare what is collected and shared with what is disclosed and consented to. Gaps are ranked by how exposed they are to claims and complaints rather than by how they look on a checklist. Closing the largest mismatches between disclosure and practice usually comes first, followed by a process that keeps new tools from going live without review. That ongoing review works when it is owned by someone with authority over both marketing and legal.