Chykalophia Docs
Compliance

Compliance

Plain-English guides to the web-related laws and standards that affect your business — from privacy and accessibility to payment security.

Difficulty
Beginner

Running a website means operating under a set of legal and technical standards. Some apply to nearly every business. Others depend on your industry, where your customers live, or what kind of data you collect.

This section explains what each law or standard means, who it affects, and what we do to help you stay on the right track. We focus on the practical side — the things that show up in your website build and ongoing care plan.

Quick summary

Most small businesses run into three things: privacy law (because you collect enquiries and run analytics — which law reaches you depends on where your customers are), cookie consent (because of those analytics), and accessibility (the ADA covers businesses that are open to the public, and the Justice Department's position is that this includes what they offer on the web). Two more apply only to some businesses: HIPAA if you are a health plan, a healthcare clearinghouse, or a healthcare provider who sends health information electronically for billing and similar transactions — or you handle patient information for one — and PCI if you take card payments. None of this is a one-off task — compliance is a habit that gets checked as your site changes.

These are guides, not legal advice

Every article in this section includes an important disclaimer: Chykalophia is a design and web agency, not a law firm. These articles explain concepts and describe best practices. For binding compliance decisions, please consult a qualified attorney.

If you only read three things

  1. GDPR basics — it can reach a US business that offers goods or services to people in the EU, or monitors their behaviour there.
  2. ADA & WCAG: web accessibility — the ADA reaches what a business open to the public offers online, and it is far cheaper to build in than to retrofit.
  3. Cookie consent law — the everyday-visible compliance question.

The path through this section

See what you are collecting. Before any law makes sense, read Tracking, cookies & privacy so you know what your website is actually gathering about visitors.

Find out which privacy rules reach you. GDPR basics and CCPA & CPRA basics explain who each law covers — often further than business owners expect.

Get the cookie banner right. Cookie consent law: when & how covers when a banner is required. Cookie consent & banners explained covers how the one on your site works.

Check accessibility. ADA & WCAG is the legal frame; the Accessible content checklist is the practical to-do list behind it.

Handle the industry-specific pieces. HIPAA basics for websites if you handle health information, and PCI compliance for online stores if you take card payments.

Work out which privacy rules apply to you

The cookies & privacy path, in order

  1. Tracking, cookies & privacy — what your site collects, in plain English.
  2. Cookie consent & banners explained — how the banner works day to day.
  3. Cookie consent law: when & how — when a banner is legally required.
  4. GDPR basics and CCPA & CPRA basics — the laws behind the banner.
  5. Data privacy basics for your business — the everyday habits that keep you out of trouble.

Make your site usable by everyone

Handle sensitive data & card payments

Need a hand?

If you're stuck, email support@chykalophia.com and we'll help. Include your website address and a screenshot if you can.

Last updated

On this page