EFF Privacy Policy
Original documentLAST VERIFIED 2026-10-01
ATTENTION POINTS · 15 TO CHECK · HEURISTIC, NOT LEGAL ADVICE
GDPR / UK-GDPR
5/13 ADDRESSED- Who controls your data (identity & contact of the data controller)GDPR Art. 13(1)(a)
- Data Protection Officer contactGDPR Art. 13(1)(b)
- The legal basis for using your dataGDPR Art. 13(1)(c)
- International transfers and their safeguardsGDPR Art. 13(1)(f) / 46
- Your data-subject rights (access, erasure, portability, object, …)GDPR Arts. 13(2)(b), 15–21
- Whether providing your data is required, and what happens if you don'tGDPR Art. 13(2)(e)
- Automated decision-making or profilingGDPR Arts. 13(2)(f), 22
- Where your data was obtained, if not collected from you (source)GDPR Art. 14(2)(f)
CCPA / CPRA
3/10 ADDRESSED- The categories of sources the data comes fromCCPA §1798.110(c)
- Categories of third parties data is shared/sold toCCPA §1798.115
- A 'Do Not Sell or Share My Personal Information' option (if it sells/shares)CCPA §1798.135(a)
- A 'Limit the Use of My Sensitive Personal Information' option (CPRA)CPRA §1798.135(a)
- Your CCPA rights (know, delete, correct, opt-out, limit, non-discrimination)CCPA §§1798.100–125
- A non-discrimination promise for exercising your rightsCCPA §1798.125
- At least two ways to submit a request, plus a contactCCPA §1798.130
(Note that EFF's Technology Projects, such as HTTPS Everywhere, Privacy Badger, and Certbot, have a different privacy policy, available here) The Electronic Frontier Foundation (EFF) is committed to protecting the privacy and security of data shared with us by visitors to our websites, and by our members and volunteers, to the fullest extent possible while still ensuring our limited funds and resources can fully support our mission. EFF has established this Privacy Policy to…
Show full text