Online terms, privacy policies and cookie banners

Online terms set the rules for using a website, app, or digital service, while a privacy policy explains how personal information is collected and used. Cookie banners may be needed when a business uses cookies or similar technologies that are not strictly necessary for the service.

Jurisdiction
General — United States, England & Wales, Canada, Australia
Topic
Privacy
Last updated
Sep 26, 2026
Editorial status
Not yet reviewed by a licensed attorney

General legal information, published for everyone. It does not apply the law to anyone’s particular situation and is not legal advice. Laws change and differ by place; check the primary sources below.

Quick summary

  • Online terms set the rules for using a website, app, or digital service, while a privacy policy explains how personal information is collected and used.
  • Cookie banners may be needed when a business uses cookies or similar technologies that are not strictly necessary for the service.
  • The legal result usually depends on how clearly users were informed, whether they actively agreed, what the business actually does, and the law of the user’s location.

What it means

Online terms set the rules for using a website, app, or digital service, while a privacy policy explains how personal information is collected and used. Cookie banners may be needed when a business uses cookies or similar technologies that are not strictly necessary for the service.

The legal result usually depends on how clearly users were informed, whether they actively agreed, what the business actually does, and the law of the user’s location.

How the law works

How the law usually works

Online terms. Website or app terms can form a contract if users receive reasonable notice of them and show agreement. A checkbox saying “I agree,” a signed electronic agreement, or a prominent button linked to the terms generally provides stronger evidence than a link in a website footer, sometimes called “browsewrap.”

Terms commonly address:

  • What the service provides and what users may do
  • Prices, renewals, cancellation, and refunds
  • Intellectual property and user-generated content
  • Account suspension or termination
  • Disclaimers, warranties, and limits on liability
  • Dispute resolution, governing law, and arbitration

A court may refuse to enforce a term that was hidden, surprising, ambiguous, inconsistent with the sign-up process, or unfair under consumer-protection law. Businesses also generally cannot contract out of mandatory rights, such as certain refund, cancellation, privacy, or consumer guarantees.

Privacy policies. A privacy policy is usually a notice rather than a complete contract. It should accurately explain the information collected, the purposes of collection, disclosures to service providers, international transfers, retention, security practices, user rights, and how to contact the business. A business may face regulatory or contractual consequences if its actual practices do not match its policy.

Privacy laws commonly require transparency and a lawful basis, permission, or another recognized justification for processing personal information. Consent is not always required for every activity, but it usually must be informed, specific where required, freely given, and capable of being withdrawn.

Cookies and similar technologies. Cookies can remember logins, measure traffic, personalize content, or deliver targeted advertising. Strictly necessary cookies are often treated differently from analytics, advertising, or cross-site tracking cookies. A banner that merely says “by continuing, you agree” may not meet stricter consent requirements, especially if non-essential cookies are placed before a real choice is made.

Common processes

  1. Identify the service and users. A business commonly records what it sells, where users are located, what data it collects, which vendors receive it, and what cookies or software trackers are active.
  1. Prepare terms and privacy notices. Terms are commonly drafted for the particular business rather than copied from another site. The privacy notice is usually matched to actual data flows, including payment processors, hosting companies, analytics providers, advertising partners, children’s data, and international transfers.
  1. Design the sign-up process. Businesses commonly put important terms near registration or checkout, use a clear acceptance action, identify the version accepted, and retain records of the wording and date. Privacy notices are usually displayed before collection. Separate consent may be used for marketing or optional tracking.
  1. Configure cookie choices. A consent tool may classify cookies, prevent optional cookies from loading until permission is given, offer “reject” as clearly as “accept,” and let users change their choice later. Businesses commonly keep a record of consent and vendor settings.
  1. Publish and maintain the documents. Updates are commonly shown with an effective date and a summary of material changes. If a change affects existing contractual rights, the business may need advance notice, a fresh acceptance, or another legally effective process. A privacy-policy update does not automatically authorize new uses of data.
  1. Handle requests or disputes. Users commonly contact the business to ask for access, correction, deletion, withdrawal of consent, a refund, or an explanation of tracking. Businesses usually check identity, preserve relevant records, and respond within the applicable legal period. A dispute may then proceed through a complaint regulator, payment provider, ombudsman, arbitration, or court, depending on the terms and local law.

Deadlines and time limits

Deadlines vary substantially by jurisdiction and by the type of claim. Typical examples include:

  • Privacy access or correction requests may have response periods ranging from a reasonable period to about 30 days or one month, sometimes with permitted extensions.
  • Some UK distance-selling rules commonly provide a 14-day cancellation period, subject to exceptions for services that have begun and certain digital content.
  • Contract claims commonly have limitation periods of about two to six years in many places, but the period can be longer or shorter depending on the claim, the jurisdiction, a written agreement, or a limitation clause.
  • A chargeback or payment dispute may have a much shorter deadline set by the card network or payment provider.
  • Regulatory complaints may be accepted after an event but are often more effective when made promptly.

These are only typical ranges. The applicable deadline should be confirmed with the relevant court, regulator, payment provider, or a licensed attorney where you live.

Documents that usually matter

Useful records commonly include:

  • The terms and privacy policy in force when the account or purchase was made
  • Screenshots or archived copies of the sign-up, checkout, and cookie-banner screens
  • Acceptance logs showing the user, date, time, version, and method of agreement
  • Cookie scans, tracker inventories, consent logs, and vendor contracts
  • Order confirmations, invoices, renewal notices, cancellation requests, and refund records
  • Privacy requests and the business’s responses
  • Marketing permissions, unsubscribe records, and relevant customer communications
  • Records of policy changes and notices sent to users
  • Data-processing, hosting, advertising, and payment-provider agreements

How it differs by jurisdiction

United States. Electronic contracts are generally recognized under the federal Electronic Signatures in Global and National Commerce Act and state electronic-transactions laws. Enforceability often turns on notice and assent, with clickwrap generally stronger than passive notice. The Federal Trade Commission can challenge deceptive privacy promises or unfair practices. Privacy rules are a mixture of federal sector-specific laws and state laws. California’s California Consumer Privacy Act, as amended, gives qualifying consumers rights that can include access, deletion, correction, opting out of sale or sharing, and limits concerning sensitive personal information. Other states have different coverage, definitions, and deadlines. US cookie requirements are not uniform nationwide.

England and Wales. The UK General Data Protection Regulation, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 are central. Non-essential cookies and similar technologies generally require prior consent, while strictly necessary technologies may be exempt. Consumer terms must also comply with the Consumer Rights Act 2015; unfair terms may not bind consumers. Online consumer contracts can involve cancellation and information duties, with exceptions for some services and digital content.

Canada. The federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies to many private-sector organizations, while Alberta, British Columbia, and Quebec have important private-sector privacy regimes of their own. Consent must generally be meaningful and appropriate to the sensitivity and purpose of the information. Quebec’s privacy legislation has introduced additional notice, governance, consent, and breach-related requirements. Canada does not have one general cookie-banner rule equivalent to the UK’s PECR approach, but tracking can still raise privacy, consent, and deceptive-practices issues.

Australia. The Privacy Act 1988 and Australian Privacy Principles commonly require notice about collection and handling of personal information. Australian privacy law does not create a general cookie-consent rule identical to the UK model, although cookies may involve personal information and businesses must consider their actual practices. The Australian Consumer Law can restrict unfair contract terms and misleading privacy or service representations. State and territory laws, sector rules, and rules for direct marketing may also matter.

When people consult a lawyer

Legal advice is especially useful when a business:

  • Sells subscriptions, financial products, health services, or services to children
  • Tracks users for advertising or combines data from multiple sources
  • Operates across countries or transfers data internationally
  • Uses arbitration, automatic renewal, broad disclaimers, or unusual cancellation terms
  • Has received a regulator inquiry, data complaint, demand letter, or lawsuit
  • Has suffered a data breach or cannot follow its published privacy policy
  • Wants to make a significant change to existing terms or data uses

Primary sources

  • StatuteUnited States: Federal Trade Commission Act, 15 U.S.C. §§ 41–58, Federal Trade Commission official materials:United States (federal)

Links go to official or widely used free sources. Check that a source is current before relying on it. Browse all sources →

Last updated
Sep 26, 2026
Jurisdiction
General — United States, England & Wales, Canada, Australia
Written by
House Legal editorial (AI-generated, earlier format)