Compliance
Plain-English guides to the web-related laws and standards that affect your business — from privacy and accessibility to payment security.
- Difficulty
- Beginner
Running a website means operating under a set of legal and technical standards. Some apply to nearly every business. Others depend on your industry, where your customers live, or what kind of data you collect.
This section explains what each law or standard means, who it affects, and what we do to help you stay on the right track. We focus on the practical side — the things that show up in your website build and ongoing care plan.
Quick summary
Most small businesses run into three things: privacy law (because you collect enquiries and run analytics — which law reaches you depends on where your customers are), cookie consent (because of those analytics), and accessibility (the ADA covers businesses that are open to the public, and the Justice Department's position is that this includes what they offer on the web). Two more apply only to some businesses: HIPAA if you are a health plan, a healthcare clearinghouse, or a healthcare provider who sends health information electronically for billing and similar transactions — or you handle patient information for one — and PCI if you take card payments. None of this is a one-off task — compliance is a habit that gets checked as your site changes.
These are guides, not legal advice
Every article in this section includes an important disclaimer: Chykalophia is a design and web agency, not a law firm. These articles explain concepts and describe best practices. For binding compliance decisions, please consult a qualified attorney.
If you only read three things
- GDPR basics — it can reach a US business that offers goods or services to people in the EU, or monitors their behaviour there.
- ADA & WCAG: web accessibility — the ADA reaches what a business open to the public offers online, and it is far cheaper to build in than to retrofit.
- Cookie consent law — the everyday-visible compliance question.
The path through this section
See what you are collecting. Before any law makes sense, read Tracking, cookies & privacy so you know what your website is actually gathering about visitors.
Find out which privacy rules reach you. GDPR basics and CCPA & CPRA basics explain who each law covers — often further than business owners expect.
Get the cookie banner right. Cookie consent law: when & how covers when a banner is required. Cookie consent & banners explained covers how the one on your site works.
Check accessibility. ADA & WCAG is the legal frame; the Accessible content checklist is the practical to-do list behind it.
Handle the industry-specific pieces. HIPAA basics for websites if you handle health information, and PCI compliance for online stores if you take card payments.
Work out which privacy rules apply to you
GDPR basics for businesses
What the EU's privacy law means for your website, even if your business isn't in Europe.
CCPA & CPRA basics for businesses serving California
California's consumer privacy law and what it means for businesses serving California residents.
Get cookies & consent right
The cookies & privacy path, in order
- Tracking, cookies & privacy — what your site collects, in plain English.
- Cookie consent & banners explained — how the banner works day to day.
- Cookie consent law: when & how — when a banner is legally required.
- GDPR basics and CCPA & CPRA basics — the laws behind the banner.
- Data privacy basics for your business — the everyday habits that keep you out of trouble.
Make your site usable by everyone
Handle sensitive data & card payments
HIPAA basics for websites handling health info
If your site handles health information, here is what you need to know.
PCI compliance for online stores
How payment card security standards apply to your e-commerce site.
Related sections
- Analytics & tracking — cookies, tracking pixels, and privacy-aware analytics
- Content, images & accessibility — the hands-on side of web accessibility
- Accepting payments online — how payments work and why card data never touches your site
- Keeping your accounts & website safe — passwords, two-factor auth, and data privacy basics
- Industry guides — the compliance points that matter most in your line of work
- Website care & maintenance — ongoing checks that keep your site compliant over time
Need a hand?
Last updated
Subscription business websites
How subscription-based businesses can build websites that convert visitors into subscribers, retain members, and handle recurring billing reliably.
GDPR basics for businesses
What the EU's General Data Protection Regulation means for your website, even if your business is based outside Europe.