Privacy and Marketing Data Toolkit: Notices, Consent, Adtech, and Rights
By Casey Scott McKay ·
Marketing runs on data, and the rules governing that data now come from a dozen state statutes, several sectoral regimes, a body of contract law, and a wave of litigation applying old wiretapping statutes to ordinary website analytics. This toolkit maps what a brand actually has to do: build a data map, write notices that match reality, honor rights requests, manage consent and opt-out signals, paper the vendors, and keep the adtech stack from creating a sale nobody intended. It covers the special categories that carry the most exposure - biometric data, precise location, health inferences, and information about minors - plus the email and text marketing rules that predate all of it and still generate most of the class actions. It explains where privacy and intellectual property intersect, since the same customer database is an asset in one analysis and a liability in the other. It closes with a cost map, an authorities table, and the forms that paper each step.
IP and Technology > Privacy Data Security | Toolkit | Published 27 October 2024 - Updated 11 March 2025 | Casey Scott McKay - marksy.us
Summary. Marketing runs on data, and the rules governing that data now come from a dozen state statutes, several sectoral regimes, a body of contract law, and a wave of litigation applying old wiretapping statutes to ordinary website analytics. This toolkit maps what a brand actually has to do: build a data map, write notices that match reality, honor rights requests, manage consent and opt-out signals, paper the vendors, and keep the adtech stack from creating a sale nobody intended. It covers the special categories that carry the most exposure — biometric data, precise location, health inferences, and information about minors — plus the email and text marketing rules that predate all of it and still generate most of the class actions. It explains where privacy and intellectual property intersect, since the same customer database is an asset in one analysis and a liability in the other. It closes with a cost map, an authorities table, and the forms that paper each step.
Keywords: privacy notice · consent management · adtech · cookies · pixels · sale and sharing · targeted advertising · opt out · universal opt-out signals · data subject rights · service provider · processor · data protection assessment · sensitive data · biometric · wiretapping claims · email and text marketing · data broker · vendor diligence · data map
Start Here
Perpetua Vasilenko is general counsel of a direct-to-consumer brand with two million customer records, a loyalty program, an app, and a marketing stack assembled over six years by four different agencies.
In one month, four things arrive.
A demand letter alleging that the analytics and advertising pixels on the company's website constitute unlawful interception of communications under a state wiretapping statute, on behalf of a putative class.
A regulatory inquiry asking how the company honors opt-out requests and whether it recognizes universal opt-out signals.
Two hundred and forty rights requests in a single week, following a competitor's publicized breach, from consumers who now want to know what the company holds.
And a diligence request from a potential acquirer asking for the data map, the vendor list, and the consent records.
The company has a privacy notice. It was written four years ago, it describes practices that changed twice since, and nobody can produce a list of what data goes where.
This toolkit answers three questions.
- What do you actually have, and where does it go? The data map is the foundation and almost nobody has one.
- What obligations attach, and which are the ones that generate liability? Not all of them are equal.
- What is the minimum credible program? Because a perfect program is not achievable and a defensible one is.
If you read only one thing, read The Data Behind the Marketing. It maps the obligations that attach to ordinary marketing activity, which is where most brands' exposure actually sits.
Part One: The Data Map
Nothing else in this toolkit works without it, and building it is a weeks-long project that pays for itself immediately.
What to record, per data element or category. What is collected. From whom. Through what mechanism — form, cookie, pixel, SDK, purchase, import, or inference. Why. Where it is stored. Who internally can access it. Which vendors receive it, and under what agreement. How long it is retained. Whether it is sensitive. Whether it is transferred outside the country. And what happens to it on deletion.
Start with the website and app, because that is where the litigation is. Enumerate every tag, pixel, SDK, and script, what each one sends, and to whom. Marketing teams add these without legal review, and the first inventory typically finds several that nobody can account for.
Then the systems. CRM, email platform, loyalty database, support desk, analytics, advertising platforms, data warehouse, and any enrichment or data-broker feeds.
Then the paper. Which vendor has a data processing agreement, which does not, and which agreements predate the current practice.
The findings that recur. Trackers nobody authorized. Data flowing to advertising platforms that constitutes a "sale" or "sharing" under state statutes, triggering opt-out obligations nobody implemented. Retention with no policy at all. Sensitive data collected incidentally. And a privacy notice that describes none of it accurately.
Keep it current. A data map is a living document with an owner, updated whenever a vendor, a tag, or a collection point changes. See Marketing Privacy Compliance Checklist.
Part Two: The Notice
It must be accurate. A notice describing practices the company does not follow is a deceptive practice under 15 U.S.C. § 45, and it is the easiest enforcement case in the field because the proof is the company's own document.
It must be complete in the way the applicable statutes require: categories collected, sources, purposes, categories disclosed and to whom, retention, rights and how to exercise them, and — where applicable — whether personal information is sold or shared for targeted advertising.
It must be findable and readable. A conspicuous link, plain language, and a structure a person can navigate.
It must be versioned and archived. The notice in force on the date of collection governs that collection, and a company that keeps only the current version has lost the document that answers most questions about the past.
Material changes require notice, and in some circumstances consent, before applying new practices to previously collected data.
Just-in-time notices at collection points — a form, a permission prompt, a cookie banner — do work the main notice cannot, and are increasingly expected.
The drafting discipline that matters most: write the notice from the data map, not from a template. A template notice describes a hypothetical company. See The Legal Layers of a Website; Website and App Launch Legal Checklist.
Part Three: Adtech, Where the Liability Is
The advertising stack generates more privacy exposure than any other part of a marketing operation, for three reasons.
Reason one: it moves data to third parties. Pixels, tags, and SDKs transmit information about individuals to advertising platforms in real time. Under several state statutes, that transmission can constitute a "sale" or "sharing" for cross-context behavioral advertising even where no money changes hands — which triggers notice and opt-out obligations most companies have not implemented.
Reason two: it is invisible to the people responsible for it. Tags are deployed through tag managers by marketers and agencies. Legal is rarely consulted. The stack drifts continuously.
Reason three: old statutes are being applied to it. A substantial body of litigation applies state wiretapping and interception statutes — some drafted decades before the web — to session recording, chat tools, and advertising pixels, on the theory that a third party intercepted a communication between the visitor and the site. The claims are contested, the outcomes vary, and the settlements are real. Several of the statutes carry statutory damages, which is what makes the class actions viable.
What to do about it.
- Inventory every tag and know what each transmits.
- Configure consent management so that trackers requiring consent do not fire before it is given, and so that opt-outs actually propagate to the platforms.
- Recognize universal opt-out signals where required.
- Restrict sensitive-category tags entirely, particularly on pages implying health, financial, or similar inferences.
- Review chat, session replay, and analytics tools specifically, because those are the subject of most of the litigation.
- Paper every vendor, and use the contractual designations — service provider, processor, or third party — that the statutes attach consequences to.
See Building a Privacy Compliance Program for a Consumer Brand.
Part Three-and-a-half: The Wiretapping Wave, Explained
The single most active area of marketing-privacy litigation applies statutes written for telephone calls to ordinary web analytics, and practitioners need to understand the theory even where they think it is wrong.
The theory. State wiretapping and interception statutes prohibit intercepting the contents of a communication without the consent of the parties. Some require the consent of all parties; some require only one. The plaintiff's argument is that when a visitor communicates with a website, a third-party pixel, session-replay script, or chat provider simultaneously receives the contents of that communication — and that the third party is an interceptor who had no consent from the visitor.
Why it has traction. Several of these statutes carry statutory damages per violation, which makes class treatment economically viable regardless of actual harm. The federal analogue at 18 U.S.C. § 2511 and its definitional section at 18 U.S.C. § 2510 supply the vocabulary, and the stored-communications theory at 18 U.S.C. § 2701 is pleaded alongside it.
The defenses. Consent, where a conspicuous disclosure and an affirmative action can be shown. The party exception, where the recipient is a party to the communication rather than a third-party interceptor. The absence of "contents" where only non-content metadata is transmitted. The service-provider characterization, where the vendor acts solely at the site operator's direction. And, in some jurisdictions, the argument that the statute does not reach internet communications at all.
What actually determines the outcome in practice. Whether the operator can document what fired, when, for whom, and with what disclosure. A company with a tag inventory, dated consent-management configuration records, and archived notice versions can construct a defense. A company without them is negotiating from ignorance about its own website.
The practical program. Inventory the tags. Configure consent so that non-essential trackers do not fire before an affirmative action. Make the disclosure conspicuous rather than buried. Be especially conservative with chat, session replay, and anything on a page implying a sensitive inference. Archive the configuration history. And review any vendor whose product replays or records user sessions with particular care, because those are the tools the claims cluster around.
And a note on the adjacent theories. The same conduct is pleaded under video privacy statutes where media is involved, under state consumer protection statutes, and — where health inferences are implicated — under health-specific state statutes with their own private rights of action. The factual inventory answers all of them; the legal analysis differs by claim.
Part Four: Rights Requests
State privacy statutes give consumers rights to know, access, delete, correct, port, and opt out, with deadlines and appeal mechanisms.
Build the intake before the volume arrives. A designated channel, an identity verification process proportionate to the sensitivity of the request, a tracking system, and a calendar.
Verification is the hard part. Too little and you disclose to an impostor; too much and you have created an obstacle regulators treat as a denial.
Deletion is harder than it sounds. It must reach backups, analytics systems, vendors, and any enrichment feeds — and it must respect the exceptions, which include legal obligations, security, and completing a transaction.
Opt-outs must propagate. An opt-out honored in the CRM and not passed to the advertising platforms is not honored.
Authorized agents may submit requests on a consumer's behalf, and high-volume agent submissions are now common.
Keep metrics. Several regimes require reporting on request volumes and response times, and the metrics are also the evidence that the program functions.
Appeals. Several statutes require an appeal mechanism with its own deadline, and a program without one fails on process rather than substance.
Part Five: The Categories That Carry the Most Risk
Biometric identifiers. Face templates, fingerprints, and voiceprints are governed by statutes that require notice, written consent, and a retention schedule, and at least one carries a private right of action with statutory damages that has produced very large recoveries. Any feature involving face detection, virtual try-on, or voice identification should be reviewed before launch, not after.
Precise geolocation. Sensitive under most state statutes, requiring consent or an opt-out depending on the regime, and a recurring subject of enforcement.
Health and health inferences. Even where a brand is outside the healthcare regulatory perimeter, marketing that implies a health condition can create sensitive-category obligations, and health-adjacent pixels have been a focus of both regulators and plaintiffs.
Children and teens. Collection from children under thirteen carries its own regime with verifiable parental consent requirements, and several states now add protections for older minors. Any product plausibly attractive to minors needs an age-gating decision made deliberately.
Financial account information, which brings sectoral obligations alongside the general ones.
Genetic data, governed by specific statutes in several states.
The common rule for all of them: if the marketing stack collects any of these, restrict the tags, obtain the consent the statute requires in the form it requires, set retention, and document the assessment. Data protection assessments are mandatory for certain processing under several statutes and are the artifact regulators ask for first.
Part Six: Email, Text, and the Old Rules
The oldest rules generate the most litigation, and they are frequently overlooked by programs focused on the new state statutes.
Commercial email is governed by 15 U.S.C. § 7704, which requires accurate header and subject information, identification as an advertisement, a valid physical postal address, a functioning opt-out mechanism, and honoring opt-outs promptly. Enforcement is regulatory rather than private in most circumstances, and the requirements are simple enough that violations are usually carelessness.
Text messaging is governed by 47 U.S.C. § 227 and its implementing rules, and it carries a private right of action with statutory damages per message. Prior express written consent is required for marketing texts, revocation must be honored, and the consent record is the entire defense. This is the single largest source of marketing-related class action exposure for consumer brands, and the fix is unglamorous: capture consent properly, store the record, and honor revocation immediately.
Telemarketing rules add do-not-call obligations, calling-time restrictions, and identification requirements.
Fax, improbably, still generates litigation.
The practical rule. Consent records are the defense. A brand that cannot produce, for a given phone number, the date, time, source, and text of the disclosure the consumer saw when they consented does not have a defense, whatever its platform reports. Require that record from every vendor and every list source, and retain it for as long as the number is marketed to plus the limitations period.
Part Six-and-a-half: Breach, and the Day the Program Is Tested
Every program is eventually tested by an incident, and the response is judged against the preparation.
Know the notification triggers before the incident. All states require notification of security breaches involving defined categories of personal information, with varying triggers, timelines, content requirements, and regulator-notification thresholds. Sectoral regimes add their own. The analysis takes days if it starts at the incident and hours if the mapping was done in advance.
The data map is the incident response plan's foundation. The first question in any incident is what data was affected, and a company without a map spends the first week discovering what it holds instead of responding.
Preserve. Logs, images, and the vendor's records. Evidence degrades and vendors overwrite.
Coordinate privilege deliberately. Forensic investigations conducted for business purposes are frequently discoverable; those structured properly for legal advice may not be. The structure must be established at the outset.
Vendor breaches are your breaches, notification-wise. Where a processor is compromised, the notification obligations generally run to the controller, and the contract determines what assistance the vendor must provide. This is why breach-notification timelines in vendor agreements matter — a vendor with a thirty-day notice obligation has consumed most of your statutory window.
Regulatory exposure follows the program, not the incident. Regulators rarely fault a company for being breached; they fault it for practices the breach revealed — data retained without purpose, security controls that were represented and not implemented, and notices describing protections that did not exist. Which returns to the point of the whole toolkit: the map, the notice, the retention schedule, and the vendor register are the artifacts that determine how the worst day goes.
Part Seven: Vendors
Most personal data leaves the company, and the contracts determine what happens to it.
Diligence before onboarding. What the vendor collects, where it processes, who it subprocesses to, what security it maintains, and whether its own practices match its representations.
The right contractual designation. Statutes attach different obligations to service providers or processors than to third parties, and the designation must match what the vendor actually does. Calling an advertising platform a service provider does not make it one if it uses the data for its own purposes.
Required terms. Purpose limitation, no selling or retaining the data outside the relationship, assistance with rights requests, security obligations, breach notification, subprocessor controls, audit rights, and deletion or return at termination.
Flow-down. Obligations must reach subprocessors, and the vendor must be accountable for them.
International transfers require their own mechanisms where they occur.
Verification. A contractual promise nobody checks is an assumption. Periodic review of the vendor list against the data map catches the vendor that was added by a marketing team without an agreement — which is the most common vendor finding.
Part Eight: Where Privacy Meets Intellectual Property
The same customer database is an asset in one conversation and a liability in another, and practitioners who work in both should hold the distinction clearly.
Ownership is not the same as lawful use. A company may own a database outright and be prohibited from using it in the way it intends. Ownership questions are answered by contract and by the thin protection available to compilations; use questions are answered by privacy law and by the notice in force when the data was collected. See Who Owns the Data.
Data acquired by scraping carries both problems. The access and contract analysis governs whether the collection was lawful; the privacy analysis governs whether the personal data within it can be used at all. See Running or Defending a Data Scraping Program; Data Collection and Scraping Risk Checklist.
In a transaction, customer data is valued and constrained. A buyer paying for a customer list is paying for something whose usability depends on the notices in force when it was collected and on whether the transfer itself is permitted. Several statutes address transfers in mergers; the notice may not. See IP Due Diligence Toolkit.
Endorsement and personality rights overlap. Using a person's data to market is a privacy question; using their name or likeness is a publicity question, and the two arrive together in influencer programs. See Your Face Is Not Public Domain; Endorsements, Influencers, and the Law of Paid Praise.
And training data. Feeding customer data into a model raises purpose-limitation questions under the privacy regime and ownership questions under the intellectual property regime, and both need answers before the pipeline is built. See AI, Content, and IP Toolkit; Generative AI IP Compliance Checklist.
Part Nine: The Minimum Credible Program
For a mid-sized consumer brand with no dedicated privacy function, this is the defensible baseline.
A data map, current, owned by a named person.
A notice written from the map, versioned and archived.
A tag inventory and a consent management platform, configured so that consent and opt-out actually control what fires, with universal opt-out signal recognition where required.
A rights request intake with verification, tracking, deadlines, and an appeal path.
A vendor register reconciled to the data map, with data processing agreements in place and correct designations.
A retention schedule that someone applies.
Consent records for email and text that can be produced for any individual.
Restrictions on sensitive categories, with assessments documented where required.
An incident response plan with the notification analysis pre-mapped.
And an annual review covering all of the above, because every one of these decays.
See Building a Privacy Compliance Program for a Consumer Brand.
Part Ten: Cost Map
| Item | Relative cost | When | |---|---|---| | Data map and tag inventory | Moderate, one-time plus upkeep | First | | Notice rewritten from the map | Low | After the map | | Consent management platform | Moderate, recurring | Immediately | | Rights request tooling and process | Low to moderate | Before volume arrives | | Vendor agreement remediation | Moderate | Rolling | | Data protection assessments | Low per assessment | Where required | | Consent record remediation for text marketing | Low, and urgent | Immediately | | Defending a pixel class action | Very high | The counterfactual | | Regulatory inquiry response | High | Unplanned |
The ratio. The whole baseline program costs less than the defense of one class action, and the class actions cluster on exactly the practices the baseline addresses.
Part Eleven: What Happened at Perpetua's Company
The tag inventory found sixty-one tags, of which the marketing team could account for twenty-two. Nine transmitted data to advertising platforms in ways that constituted sharing for targeted advertising under two state statutes, with no opt-out implemented. Four were on pages that implied health-adjacent inferences. Three belonged to agencies the company no longer worked with.
The pixel demand letter was defended, and the defense was substantially shaped by what the inventory showed: several of the challenged tools had been removed before the claim period, consent had been obtained for others, and the company could document what fired when. The matter settled for a fraction of the initial demand, and the negotiating position came entirely from the inventory.
The regulatory inquiry was answered with the data map, the vendor register, the rights request metrics, and a remediation plan with dates. Regulators respond considerably better to a documented plan with gaps acknowledged than to an assertion of compliance.
The two hundred and forty rights requests were the operational crisis, and the fix was process: a designated intake, a proportionate verification step, a tracker with deadlines, and templates. The volume dropped to a manageable trickle within six weeks.
The diligence request was the reason the whole program got funded. A buyer asking for a data map is a buyer who will discount for its absence, and the company's inability to produce one was worth more in the negotiation than every regulatory consideration combined — which is a cynical observation and also, reliably, the one that unlocks the budget.
Part Twelve: The Ten Findings a Data Map Always Produces
Every first inventory turns up substantially the same list, which is useful to know because it makes the project predictable and the budget defensible.
One: tags nobody authorized. Deployed by an agency, a former employee, or a vendor's own script, still firing years later.
Two: data flowing to advertising platforms that constitutes sharing for cross-context behavioral advertising, with no opt-out mechanism implemented.
Three: a privacy notice that describes a different company. Written once, never revised, describing collection points that no longer exist and omitting several that do.
Four: no retention policy anywhere. Everything kept forever, because deleting requires a decision and keeping does not.
Five: sensitive data collected incidentally. Precise location in an app that does not need it, health inferences from browsing behavior, or biometric processing inside a feature nobody flagged.
Six: vendors with no data processing agreement, usually added by a marketing team through a self-service signup.
Seven: text marketing with no producible consent records. The platform reports a consent flag; nobody can produce what the consumer saw. Under 47 U.S.C. § 227, that is the whole defense, and it is missing.
Eight: opt-outs honored in one system and not propagated to the advertising platforms, which means the opt-out is not honored.
Nine: an app SDK that transmits more than the app's own disclosure describes, discovered only when someone reads the SDK documentation.
Ten: no owner. Privacy sits between legal, marketing, and engineering, and the work that has no owner does not get done.
What to do with the list. Present it as the expected output rather than as a series of failures, sequence the remediation by exposure rather than by ease, and fix the ownership problem first — because a program with an owner will close the other nine over time, and a program without one will reproduce them.
A last word on sequencing. Do the map first, always. Every other artifact in this toolkit — the notice, the consent configuration, the vendor register, the retention schedule, the incident plan — is derived from it, and a program that starts anywhere else is building on assumptions about a system nobody has examined.
A Suggested Reading Path
If you have a specific problem right now, branch:
- A pixel or wiretapping claim. The Data Behind the Marketing → Building a Privacy Compliance Program for a Consumer Brand.
- Rights requests are arriving. Marketing Privacy Compliance Checklist.
- You are launching a site or app. The Legal Layers of a Website → Website and App Launch Legal Checklist.
- You are acquiring or collecting data. Who Owns the Data → Data Collection and Scraping Risk Checklist.
- Influencers and endorsements. Endorsements, Influencers, and the Law of Paid Praise → Building an Influencer and Endorsement Compliance Program.
If you are building the program from nothing, read in this order:
- The Data Behind the Marketing — the obligations that attach to ordinary marketing.
- Building a Privacy Compliance Program for a Consumer Brand — the program.
- Marketing Privacy Compliance Checklist — the operating discipline.
- Website and App Launch Legal Checklist — the collection points.
- Who Owns the Data — ownership versus lawful use.
Primary Authorities
| Authority | Rule, in one line | |---|---| | 15 U.S.C. § 45 | Unfair or deceptive acts; a notice that misdescribes practice is the easiest case. | | 15 U.S.C. § 7704 | Commercial email: headers, identification, postal address, and opt-out. | | 15 U.S.C. § 7706 | Enforcement of the commercial email requirements. | | 47 U.S.C. § 227 | Restrictions on automated calls and texts; private right of action with statutory damages. | | 15 U.S.C. § 6501 | Children's online privacy definitions and scope. | | 15 U.S.C. § 6502 | Verifiable parental consent for collection from children. | | 15 U.S.C. § 6801 | Financial institutions' obligation to protect customer information. | | 15 U.S.C. § 6802 | Limits on disclosure of nonpublic personal financial information. | | 15 U.S.C. § 1681b | Permissible purposes for consumer reports; relevant to enrichment and screening. | | 18 U.S.C. § 2510 | Federal wiretap definitions; the framework state analogues follow. | | 18 U.S.C. § 2511 | Interception prohibition; the theory behind pixel litigation. | | 18 U.S.C. § 2701 | Stored communications; the companion theory. | | 18 U.S.C. § 1030 | Computer access; relevant to collection from third-party sources. | | 16 C.F.R. Part 312 | Children's online privacy rule: notice, consent, retention, and security. | | 16 C.F.R. Part 314 | Safeguards for customer information at covered financial institutions. | | 16 C.F.R. Part 255 | Endorsements; the disclosure layer over influencer data practices. |
Forms and Templates
The data map is the form that matters, and it is a spreadsheet rather than a legal document: one row per data element or category, with columns for collection point, purpose, storage, internal access, vendors, retention, sensitivity, transfers, and deletion path. Everything else in the program is generated from it, and a program built without it is a set of assertions.
The privacy notice should be drafted from the map and versioned with dates. Archive every version permanently; the version in force at collection is the one that governs, and it is the document a regulator or a plaintiff will ask for.
The vendor data processing agreement should be a standard the company imposes rather than a form it accepts. Purpose limitation, no independent use, rights-request assistance, security, breach notification with a short deadline, subprocessor controls with flow-down, audit rights, and return or deletion at termination. Reconcile the signed agreements against the vendor register quarterly.
License Agreement Template is the starting structure where data is licensed rather than transferred — to an analytics partner, a co-marketing counterparty, or a licensee — and a data license needs three things a trademark license does not: a field-of-use restriction tied to the purposes disclosed in the notice, a prohibition on re-identification, and a deletion obligation with certification. See Draft License Agreement.
Related Toolkits and Checklists
Advertising and Marketing Law Toolkit covers the substantive advertising rules that operate alongside the data rules, and the two programs share the same stakeholders. Right of Publicity and Personal Brand Toolkit covers the personality-rights layer.
Software, Data, and Open Source Toolkit covers data ownership and the scraping analysis. AI, Content, and IP Toolkit covers the training-data questions.
Marketplace and Platform Liability Toolkit and Online Brand Protection Toolkit cover the platform relationships through which much marketing data flows. IP Due Diligence Toolkit covers the transactional examination of the data asset.
Related Documents
Articles
- The Data Behind the Marketing — the obligations on ordinary marketing.
- Who Owns the Data — ownership versus lawful use.
- The Legal Layers of a Website — the collection points.
- Your Face Is Not Public Domain — the personality overlay.
- Endorsements, Influencers, and the Law of Paid Praise — where privacy and disclosure meet.
- Who Owns What the Machine Made — the training-data question.
Guides
- Building a Privacy Compliance Program for a Consumer Brand
- Running or Defending a Data Scraping Program
- Building an Influencer and Endorsement Compliance Program
- Deploying Generative AI Without Losing Your IP
Checklists
- Marketing Privacy Compliance Checklist
- Website and App Launch Legal Checklist
- Data Collection and Scraping Risk Checklist
- Generative AI IP Compliance Checklist
Toolkits
- Advertising and Marketing Law Toolkit
- Software, Data, and Open Source Toolkit
- AI, Content, and IP Toolkit
- Right of Publicity and Personal Brand Toolkit
Templates & Forms
- License Agreement Template — the base for a data license, with the three additions.
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Privacy obligations vary by state, sector, and date. Marksy is not a law firm.