Data Privacy (GDPR, CCPA)
If you collect any personal data — emails, phone numbers, names — you must comply with data privacy laws.
GDPR (Europe)
Applies if you target EU residents, regardless of where you're based.
Key Requirements:
Consent — Clear opt-in before collecting data (no pre-checked boxes)Purpose limitation — Only use data for the stated purposeRight to access — Users can request their dataRight to erasure — Users can request data deletionData breach notification — Report breaches within 72 hoursPrivacy policy — Must be clear, accessible, and up-to-dateFor IBs, this means:
Your email signup form needs explicit consent checkboxYou can't share leads with brokers without consentYou need a privacy policy on your websiteEvery email must have an unsubscribe optionCCPA (California, USA)
Key Requirements:
Tell users what data you collect and whyUsers can opt out of data sellingUsers can request data deletion"Do Not Sell My Personal Information" link requiredPractical Checklist for IBs
Privacy policy on your website
Cookie consent banner (for EU traffic)
Explicit opt-in for email marketing
Unsubscribe link in every email
Don't buy or sell email lists
Store data securely (encrypted, access-controlled)
Delete data when users request it
Document what data you collect and why
Email Marketing Compliance
Only email people who explicitly opted inInclude your business name and address in emailsProvide clear unsubscribe mechanismHonor unsubscribe requests within 10 business daysDon't use deceptive subject lines