5.20 Promote Responsible Data Practices
The organization has devised and implemented a responsible data strategy that prioritizes data privacy and promotes more ethical uses of data, including disposal and data sustainability practices.
Criteria
- Privacy Policy: The organization has a public-facing privacy policy in place and supports existing privacy laws such as the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and so on. This policy must be accessible for all visitors, including those with accessibility and reading comprehension needs, and abide by plain English best practices to avoid jargon, technical language, and legalese.
- Data Ownership: The organization can show measurable progress over time on how it respects data privacy and ownership, including a visitor’s “right to be forgotten” and provides the ability to export data.
- Data Protection: The organization supports new and emerging legislation related to data privacy, data sustainability, and responsible data practices.
Impact
High
Effort
Medium
Benefits
- Economic:
Organizations that prioritize data privacy and other responsible data practices benefit from reduced risk and costs, increased resilience, and, often, better relationships with customers and other stakeholders.
GRI
- materials: High
- energy: High
- water: High
- emissions: High
Example
- The Airbnb Privacy Policy includes compliance with emerging legislation, data ownership, and measurable progress through previous versions. The Telegram Privacy Policy includes detailed data practices, references to local legislation, and shows change over time. The Slack Trust section is inclusive of privacy, security, compliance, ownership, and more; including a description of how data informs search, Machine Language, and Artificial Intelligence. Finally, CodePen has a beautifully structured terms of service agreement, written in plain English, and is easy to understand.
Resources
- 10 CCPA Compliance Tips For Web Developers
- 17 Countries with GDPR-like Data Privacy Laws
- A privacy-friendly Do Not Track (DNT) Policy
- Beyond GDPR: Data Protection Around The World
- California Consumer Privacy Act (CCPA)
- Developer’s Guide To GDPR
- GDPR Checklist
- General Data Protection Regulation (GDPR)
- [GPFEDS] 1.6 – Strategy (Data Collection) (PDF)
- [GPFEDS] 7.2 – Back-End (Data Retention) (PDF)
- [GPFEDS] 8.8 – Hosting (Hot / Cold Data) (PDF)
- How To Protect Your Users With The Privacy By Design Framework
- Is GDPR Good for the Environment?
- Learn How To Write a Privacy Policy in a Few Easy Steps
- Learn Privacy
- Privacy by design
- State Of GDPR Part 1
- State Of GDPR Part 2
- The environmental benefits of privacy-focussed web design
- Ultimate CCPA Compliance Checklist
- United Nations [SDGS] Goal 10 (Inequality)
- United Nations [SDGS] Goal 13 (Climate Change)
- United Nations [SDGS] Goal 16 (Sustainable Society)
- United Nations [SDGS] Goal 17 (Global Partnership)