Fair Information Practices

Web companies collect personal information — at sign-in, at checkout, on subscription forms — but it’s not obvious what policies and procedures make that collection fair, secure, and legally sound, and privacy law is fragmented across jurisdictions rather than offering one clear standard to design against.

Web companies collect personal information — at sign-in, at checkout, on subscription forms — but it’s not obvious what policies and procedures make that collection fair, secure, and legally sound, and privacy law is fragmented across jurisdictions rather than offering one clear standard to design against.

The term fair information practices originates with the U.S. Privacy Act of 1974 (binding only on U.S. government agencies), but its logic went on to shape privacy law worldwide. The most influential descendant is the European Union’s Directive 95/46/EC (effective October 1998), which lets EU member states block data transfers to any non-EU country that doesn’t guarantee “an adequate level of protection.” Because the United States has no comparable national privacy law, the U.S. Department of Commerce and European Commission created a safe harbor framework: American companies could self-certify against seven principles and be treated as Directive-compliant for EU data transfers. (This specific safe harbor mechanism was later struck down by EU courts and replaced by successor frameworks — the underlying seven principles below are documented as the historical shape of the practice, not as current EU-U.S. compliance mechanics.)

The Directive itself was repealed and replaced by the General Data Protection Regulation (GDPR), effective May 2018 — a regulation rather than a directive, so it applies directly and uniformly across EU member states without requiring national transposition. GDPR keeps the same underlying fair-information-practices logic but sharpens it considerably, with its own consent-design, data-subject-rights, and default-setting requirements — see GDPR (General Data Protection Regulation) for those. The safe harbor mechanism below was replaced first by the EU-U.S. Privacy Shield (2016), which courts invalidated in 2020 (the Schrems II ruling), and most recently by the EU-U.S. Data Privacy Framework (2023) — the seven principles remain useful as the shape underlying all of these successor frameworks, not as a description of which one is currently in force.

Beyond the EU, several other jurisdictions layer their own standards on top of this same baseline: the U.S. healthcare sector has its own dedicated framework, HIPAA (Health Insurance Portability and Accountability Act); children’s data collection specifically is governed by COPPA (Children's Online Privacy Protection Act); and California has enacted three of its own, in sequence — CalOPPA (California Online Privacy Protection Act) (the first U.S. state law requiring a posted privacy policy at all), and CCPA / CPRA (California Consumer Privacy Act / California Privacy Rights Act) (granting broader consumer data rights, since amended by the CPRA).

The seven safe harbor principles

  1. Notice — tell people what data you collect, why, who you might disclose it to, and how they can limit that use.
  2. Choice — let people opt out of disclosure to third parties or use beyond the original purpose; require affirmative opt-in for sensitive information specifically.
  3. Onward transfer — apply notice and choice before passing data to a third party; if that third party is acting as your agent, bind it to the same principles contractually.
  4. Access — let individuals see, correct, amend, or delete their own data, except where that’s disproportionately burdensome or would violate someone else’s rights.
  5. Security — take reasonable precautions against loss, misuse, and unauthorized access, disclosure, alteration, or destruction.
  6. Data integrity — keep data relevant, reliable, accurate, complete, and current for its stated purpose.
  7. Enforcement — back the other six with real, affordable recourse mechanisms, verification that commitments are actually implemented, and consequences for noncompliance.

The Federal Trade Commission’s (FTC) four practices (U.S. domestic baseline)

Safe harbor applies only to U.S. companies transacting with EU individuals; there is far less legal structure governing purely domestic U.S. sites. A May 2000 FTC report recommended (without making legally binding) four practices as a reasonable general-purpose baseline:

  1. Have a clear, conspicuous Privacy Policy. Typically footer-linked on every page, but made especially prominent on the homepage, checkout, and account-creation pages.
  2. Let people choose how their information is used beyond its primary purpose. A shipping address collected to fulfill an order is a primary use; using the same address for marketing is a secondary use requiring separate choice — see Privacy Preferences for how that choice gets surfaced in an interface.
  3. Tell people what information you hold about them, through an Account Management facility that lets them review and correct it.
  4. Take reasonable precautions to protect it — secure connections, security-tested custom software, current security patches, clear internal handling policies, and periodic audits.

Safe harbor applies only to U.S. companies transacting with EU individuals; there is far less legal structure governing purely domestic U.S. sites.

Fair information practices are a compliance floor, not a design pattern by themselves — they set what a site must disclose and allow, while Privacy Policy and Privacy Preferences cover how that gets built into the actual interface a customer sees.

Fair information practices are a compliance floor, not a design pattern by themselves — they set what a site must disclose and allow, while Privacy Policy and Privacy Preferences cover how that gets built into the actual interface a customer sees.

Patterns

Principles

Standards

Sources

The Design of Sites: Pattern Group E — Building Trust and Credibility is this page’s E3 Fair Information Practices pattern source — the seven safe-harbor principles and the FTC’s four-practice domestic baseline documented above.

Created Thu Jul 02 2026 00:00:00 GMT+0000 (Coordinated Universal Time) Updated Fri Aug 21 2026 00:00:00 GMT+0000 (Coordinated Universal Time)