The Marketing Tools on Your Website Are Probably Breaking Privacy Laws You’ve Never Heard Of

Donata Stroink-Skillrud, privacy attorney and co-founder of Termageddon, on why “I didn’t know my website was tracking that” isn’t a legal defense, and what to actually do about it.

Here’s the moment in this conversation that got me: Donata Stroink-Skillrud has lost count of how many business owners she’s told, “your website has Google Analytics on it,” only to hear back, “what? I had no idea. I don’t even know how to log in.” That’s not a rare case. That’s the default state of most small business websites right now, running trackers nobody remembers installing, collecting data nobody’s using, and creating legal exposure nobody’s aware of.

Donata is a privacy attorney and the co-founder and president of Termageddon, a company that generates and automatically updates privacy policies, cookie policies, and terms of service as the underlying laws change. She’s also a fellow at the American Bar Foundation and chairs the ABA’s e-privacy committee, so this isn’t a marketer’s take on privacy, it’s a lawyer’s, and it shows in how precisely she breaks down where businesses actually get exposed.

What Counts as “Personal Data,” and Does Your Website Actually Collect It?

Most business owners assume privacy law is something that applies to big tech companies, not to them. Donata’s answer to that is blunt: if your site has a contact form, an email signup, e-commerce, analytics, advertising, or even an embedded YouTube video or Google Map, it’s collecting personal data. And personal data isn’t just financial or health information, it’s any information that could identify someone: names, emails, phone numbers, physical addresses, IP addresses.

“Privacy laws are sort of unique in the sense that they protect consumers and not individuals. What that means is that privacy laws outside of your state or country can apply to you even if you’re not located there as a business.”
— Donata Stroink-Skillrud, Co-founder and President, Termageddon

That framing changes everything. It’s not about where your business is registered. It’s about where the people visiting your site are located. And these laws are actively enforced against small businesses, not just enterprises, with real fines and lawsuits attached.

Why Can a Single Marketing Tool Create Legal Risk You Didn’t Have Yesterday?

This is the section every marketer on our team needed to hear. Donata’s example: take a website for a florist in Chicago with zero tracking installed. The moment that business adds Google Analytics or an advertising pixel, and a visitor from the EU lands on the site, that business is suddenly subject to GDPR. A tool installed to help marketing can single-handedly pull a business into a legal framework it was never part of before.

“A lot of these tools can actually subject a business to new laws that they weren’t previously subject to. And it can also open up a lot of compliance risks.”
— Donata Stroink-Skillrud, Co-founder and President, Termageddon

She pointed to California specifically, where businesses are getting sued under the California Invasion of Privacy Act for tracking website visitors through analytics, advertising, and heat mapping tools without consent, with settlements landing anywhere from $50,000 to $100,000. And it’s often for tools nobody’s actively using anymore.

“There are people, businesses who ran Facebook ads five years ago and have zero intention of running ads again. Their campaigns have ended, they’re done with that, and the Facebook pixel is still running for years on end for no reason.”
— Donata Stroink-Skillrud, Co-founder and President, Termageddon

That’s a data hygiene problem as much as a legal one. I’ll admit this one hit close to home. We found the same issue on our own site after a redesign: the cookie consent pop-up was asking visitors for permission, but clicking “no” wasn’t actually disabling all the trackers behind it. Donata had a name for that.

“There’s a lot of what we call placebo consent banners out there, where all of these services are firing without the user actually ever interacting, or they fire if they click no.”
— Donata Stroink-Skillrud, Co-founder and President, Termageddon

If you haven’t tested what happens when someone clicks “decline” on your own site’s cookie banner, that’s worth doing this week, not eventually.

Why Doesn’t the US Have One Federal Privacy Law, and What Does That Mean for You?

The honest answer here surprised me a little, mostly because Donata was so direct about it. She doesn’t think a federal privacy law is coming anytime soon.

“I can almost bet that we will not get one this year or anywhere in the near future. I mean, we have a hard time keeping the government open in the first place.”
— Donata Stroink-Skillrud, Co-founder and President, Termageddon

Instead, we’re stuck with a growing patchwork of state laws, each with different requirements, different consumer rights, and different disclosure rules, none of which necessarily overlap. For a company like BDEX, that means registering with each state individually and tracking a constantly shifting set of obligations. For smaller businesses, it means the compliance bar keeps moving without a single source of truth to check against.

What Are the First Three Things a Business Should Actually Do?

Given how overwhelming this can sound, I asked Donata to boil it down. Her answer was refreshingly practical, not a 40-point legal checklist.

“The first requirement is figure out which privacy laws apply to you, because that’s how you’ll know what standards you need to meet. The second thing I would do is review my site and see what can be taken off of it. Then I would get my policies in place and get the consent solution in place.”
— Donata Stroink-Skillrud, Co-founder and President, Termageddon

Step two is the one most businesses skip. Before you worry about writing the perfect privacy policy, go look at what your site is actually running. Open developer tools, see what’s firing, and remove anything you’re not actively using. It’s the fastest way to shrink your risk before you even touch the legal language.

The Bigger Picture

The thing that stuck with me most is Donata’s reframe of privacy as a competitive advantage, not just a compliance cost.

“I really think that privacy can actually be a competitive advantage for businesses. So much of this is just treating others like you want to be treated. If people don’t want your emails and you keep sending it to them, they’re not going to read them, and they’re not going to buy from you.”
— Donata Stroink-Skillrud, Co-founder and President, Termageddon

That’s the part that applies to every business we work with, data company or not. Consumers are increasingly willing to leave a site, or a brand, that doesn’t respect their data. In a world where trust is getting harder to earn and easier to lose, treating privacy as table stakes instead of an afterthought isn’t just about staying out of court. It’s about staying in business with the people who actually want to hear from you.

Connect with Donata Stroink-Skillrud on LinkedIn or learn more about automated privacy policy compliance at termageddon.com.

This article was adapted from an episode of Deconstructing Data, BDEX’s weekly podcast on data-driven marketing. Tune in live every Thursday at 4:15 PM Eastern on LinkedIn.


About BDEX: For companies that need clean identity data to power their products, BDEX offers unmatched quality and execution. Visit bdex.com and click “Talk to an Expert” to get started.

Watch the full episode: Data Privacy and Compliance in Modern Marketing