
- Products
- Services
- Solutions
By Regulation
- Resources
Our Latest Blog

- Partner With Us
By Regulation
Effective Date: 01 July 2025
Privacy Pillar (“we,” “our,” “us”) is committed to safeguarding your privacy. This Privacy Notice describes the categories of personal information collected, the purposes for such collection, and the manner in which it is processed, used, and disclosed, in accordance with applicable data protection laws. in compliance with applicable laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant data privacy regulations.
We also aim to comply with other data protection laws applicable in the jurisdictions in which we operate, including but not limited to the UK GDPR, Virginia CDPA, Colorado Privacy Act, and India’s Digital Personal Data Protection Act (DPDP), where applicable.
In this Privacy Notice:
These definitions are provided to ensure that the terms used in this Privacy Notice are clear and understandable.
We may collect the following categories of personal information:
Data from business partners, social media platforms or publicly available sources.
Subject to applicable laws and regulations, the personal information collected by us may be used for one or more of the following purposes:
Personalization and User Experience: To analyze user preferences and behavior for the purpose of personalizing content, recommendations, and communications, and to improve user experience and engagement with our services.
We may disclose or otherwise make available your personal information to third parties under the following circumstances, subject to applicable data protection laws:
We undertake reasonable efforts to ensure that all third parties with whom personal information is shared comply with applicable data protection laws and implement adequate safeguards to uphold the privacy and security of such information.
We use cookies and similar tracking technologies on our website to enhance your browsing experience, analyze site traffic, personalize content, and deliver relevant advertisements. These technologies help us understand how you interact with our website and improve its functionality.
We use Cookies and similar tracking technologies to track the activity on Our Service and store certain information. Tracking technologies used are beacons, tags, and scripts to collect and track information and to improve and analyze Our Service. The technologies We use may include:
Cookies can be classified as:
We use both Session and Persistent Cookies for the purposes set out below:
These cookies allow you to share content on social media platforms and may track your interaction with such content.
These are cookies that have not yet been classified into a specific category. We are working to update their descriptions.
Third-party cookies are small files that websites, other than the one you are visiting, place on your device. These cookies track your actions across different sites. For example, if you look for running shoes online, you might later see ads for those shoes or other sports gear on other websites and social media platforms like Instagram. This happens because third-party cookies remember your browsing history. They use that information to show you ads that match your interests, helping advertisers reach you with relevant offers.
We obtain user consent for cookies through a pop-up banner that appears when you first visit our website. This banner provides information about the types of cookies we use and gives you the option to manage your cookie preferences.
You can manage or disable cookies at any time through your browser settings or by using our cookie banner provided on our website.
Cookies are classified into two types: “persistent” cookies and “session” cookies. Persistent cookies stay on your device for a specific duration or until you decide to delete them. In contrast, session cookies are temporary and are removed when you close your browser.
We may share cookie data with third parties such as Google Analytics and The IAB for analytics and advertising purposes. These third parties may use the information for their own purposes in accordance with their privacy policies.
Subject to applicable data protection laws and depending on your jurisdiction, you may have the following rights in relation to your personal information:
To exercise any of the above rights, or to obtain further information regarding your rights, please submit a request through our “DSAR FORM” or contact us at privacy@privacypillar.com. When you contact us, please provide your full name, email address and the specific type of request you are making. We will respond to your request within 30 days.
We retain personal information for no longer than is necessary to fulfill the purposes for which it was collected, as outlined in this Privacy Notice, unless a longer retention period is required or permitted by applicable law. Specifically, personal information may be retained for the following purposes:
Retention periods may vary depending on the nature of the data and the context in which it is processed. For instance, transactional or financial data may be retained for a legally mandated period to ensure compliance with applicable tax or accounting regulations.
Upon expiry of the applicable retention period, or upon fulfillment of the purposes for which the personal information was collected (whichever is later), we will securely delete, anonymize, or otherwise render the personal information inaccessible, unless further retention is required by law.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk associated with the processing of personal information. These measures are designed to protect personal information against unauthorized access, alteration, disclosure, or destruction and include, but are not limited to:
We also encourage users to take reasonable steps to protect their personal information, including the use of strong, unique passwords and maintaining the confidentiality of their account credentials.
While we take commercially reasonable efforts to safeguard personal information, no method of transmission over the Internet or method of electronic storage is entirely secure. Accordingly, we cannot guarantee absolute security.
If you access or use our services from a jurisdiction outside the United States, please be aware that your personal information may be transferred to, stored in, and processed in the United States or in other jurisdictions where our affiliates, service providers, or business partners are located. These jurisdictions may not offer the same level of data protection as your home country.
To ensure that such cross-border data transfers are conducted in compliance with applicable data protection laws, we implement appropriate safeguards, including but not limited to:
By using our services and providing us with your personal information, you acknowledge and consent to the transfer, processing, and storage of your personal information in jurisdictions outside your country of residence, including the United States, subject to the safeguards described herein.
Our services are not directed to, and we do not knowingly collect or solicit personal information from, individuals under the age of 13 (or such other minimum age as may be prescribed by applicable data protection laws in the relevant jurisdiction). If you are under the applicable age threshold, you are not permitted to use our services or submit any personal information to us.
If we become aware that we have inadvertently collected personal information from a child in violation of applicable law, we shall take immediate steps to delete such information from our records and systems.
If you are a parent or legal guardian and believe that your child has provided personal information to us without your consent, you are encouraged to contact us using the contact details provided in this Privacy Notice so that we may take appropriate action in accordance with applicable legal requirements.
If you are located in the European Union (EU), European Economic Area (EEA), or the United Kingdom (UK), your personal data is processed in accordance with the General Data Protection Regulation (GDPR). We are committed to ensuring that your data is handled with the utmost care and in full compliance with the GDPR.
In accordance with Article 6 of the GDPR, we process personal data only where a valid legal basis exists. The lawful bases upon which we rely include the following:
We ensure that any reliance on a legitimate interest is supported by a documented balancing test in accordance with GDPR requirements.
If you are a data subject located in the EU, EEA, or UK, you may exercise your data protection rights as set out in the “Your Rights as a Data Subject” section of this Privacy Notice.
Where personal data is transferred outside the European Economic Area (“EEA”) to a country that does not offer an adequate level of data protection as determined by the European Commission, such transfers shall be conducted in full compliance with the General Data Protection Regulation (GDPR).
To ensure an adequate level of protection for your personal data, we implement appropriate safeguards, including but not limited to the following:
Additional technical, organizational, and contractual measures may also be implemented to enhance the security and confidentiality of personal data transferred internationally.
For further information regarding the legal mechanisms relied upon for international data transfers or to request a copy of the relevant safeguards, please contact us at privacy@privacypillarcom.
Under the GDPR, you have the following rights concerning your personal data:
We do not make decisions based solely on automated processing that would have legal or similarly significant effects unless required by law or based on explicit consent.
To exercise any of these rights, please contact us at privacy@privacypillar.com. We will respond to your request within one month, as required by the GDPR. In some cases, if your request is complex or involves multiple requests, we may take up to two additional months to respond—but we will inform you of any delay.
This section applies to California residents and explains your rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA). We are committed to ensuring that you are fully informed about how your personal data is collected, used, and shared in accordance with California privacy laws.
As a California resident, you have the following rights under the CCPA/CPRA:
How to Exercise Your Rights
To exercise your rights under the CCPA/CPRA, you may submit a request by contacting us at:
We will verify your identity before processing your request. In most cases, we will respond to your request within 45 days, in accordance with the CCPA.
Under the CCPA/CPRA, we are required to disclose whether we “sell” personal information. We do not sell personal information to third parties. If we decide to sell or share your personal data in the future, we will update this policy and provide you with the opportunity to opt out.
We may disclose personal data to third parties for a business purpose (e.g., providing services, analytics, etc.), but this does not constitute a sale under the CCPA/CPRA.
Under the CPRA, sensitive personal information includes data such as Social Security numbers, driver’s license numbers, and financial account details. We take extra care in handling sensitive personal data, and we do not use or share this type of data for purposes other than those explicitly stated in this policy or required by law.
If you are concerned about the processing of sensitive personal information, please contact us at privacy@ privacypillar.com.
Privacy regulations in certain U.S. states, including California and Delaware, require website operators to disclose how they respond to web browser “Do Not Track” (DNT) signals related to online behavioral tracking. Privacy Pillar adheres to the data protection standards described in this Privacy Notice and does not monitor or respond to “Do Not Track” (DNT) signals or similar browser-based mechanisms.
This section applies to individuals located in India and explains your rights under the Digital Personal Data Protection Act, 2023 (DPDP Act). We are committed to ensuring that your personal data is collected, processed, stored, and shared in a transparent and secure manner, in full compliance with applicable Indian data protection laws.
We process your personal data only when we have a lawful reason to do so, as required under the Digital Personal Data Protection Act, 2023. This means your data will be collected and used only when:
We will not process your personal data for any other reason without a valid legal basis.
We collect and process your personal data only after obtaining your clear, specific, informed, and unambiguous consent, as required under the DPDP Act, 2023. You have full control over your consent and may choose to grant or withhold it for specific purposes of data processing.
You also have the right to withdraw your consent at any time. If you choose to do so, we will stop processing your personal data from the date of withdrawal, unless we are required to retain or process it under any applicable law.
As a Data Principal under the Digital Personal Data Protection Act, 2023, you are entitled to exercise the following rights regarding your personal data:
To exercise any of these rights, please contact our Grievance Officer using the details provided below. We will respond in accordance with the timelines prescribed under the Act.
If you have any concerns, complaints, or grievances related to the processing of your personal data or this Privacy Notice, you may reach out to privacy@privacypillar.com. We are committed to addressing your concerns in a timely and transparent manner.
We will acknowledge your complaint within 24 hours of receipt and aim to resolve it within 7 working days, in accordance with the provisions of the DPDP Act, 2023.
We may update this Privacy Notice periodically. Any significant changes will be communicated to you in advance via email or through a notice on our website. The updated Privacy Notice will include a new effective date.
For questions or concerns about this Privacy Notice or our data practices, contact us at:
Email: privacy@privacypillar.com
Address: 103 Carnegie Center Dr STE 300, Princeton, NJ. 08540
By using our services, you agree to the terms of this Privacy Notice.
New Jersey Data Privacy Act (NJDPA)
Effective Date: January 15, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumer or 25,000+ consumers with 50% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $10,000 for 1st violation and up to $20,000 for subsequent violations |
Florida Digital Bill of Rights (FDBR)
Effective Date: July 1, 2024
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| gross annual revenue of at least $1 billion or 50% or more revenue from targeted advertising | Access, Delete, Correct, Opt-Out, Portability |
Up to $50,000 per violation |
Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
Effective Date: January 1, 2026
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumers or 10,000+ consumers with 20%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
$10,000 per violation and between $100 – $500 for each intentional disclosure of personal data |
Dedicated Data Privacy Laws in Michigan
Michigan does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Indiana Consumer Data Protection Act (INCDPA)
Effective Date: January 1, 2026
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ consumers with data 50%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Tennessee Information Protection Act (TIPA)
Effective Date: July 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumer or 10,000+ consumers with 20% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Kentucky Consumer Data Protection Act (KCDPA)
Effective Date: January 1, 2026
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ consumers with data 50%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Minnesota Consumer Data Privacy Act (MCDPA)
Effective Date: July 31, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ consumers with data 25%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Dedicated Data Privacy Laws in West_Virginia
West_Virginia does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Washington D.C.
Washington D.C. does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Washington
Washington does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Wisconsin
Wisconsin does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Alaska
Alaska does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Louisiana
Louisiana does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Kansas
Kansas does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Vermont
Vermont does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Maine
Maine does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Mississippi
Mississippi does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Missouri
Missouri does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in North_Carolina
North_Carolina does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Georgia
Georgia does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Alabama
Alabama does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Arkansas
Arkansas does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in New_Mexico
New_Mexico does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Arizona
Arizona does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Nevada
Nevada does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Idaho
Idaho does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Wyoming
Wyoming does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in South_Dakota
South_Dakota does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in North_Dakota
North_Dakota does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in Hawaii
Hawaii does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
South_Carolina does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Connecticut Data Privacy Act (CTDPA)
Effective Date: July 1, 2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ 25%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $500,000 per violation |
Dedicated Data Privacy Laws in Massachusetts
Massachusetts does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Dedicated Data Privacy Laws in Ohio
Ohio does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Dedicated Data Privacy Laws in Illinois
Illinois does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Dedicated Data Privacy Laws in Oklahoma
Oklahoma does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Dedicated Data Privacy Laws in Pennsylvania
Pennsylvania does not have a comprehensive consumer data privacy and protection law, nor are any bills making progress at this time. However, it is protected by some privacy-related legislation.
Dedicated Data Privacy Laws in NewYork
New York does not have an official comprehensive consumer privacy law. However, there are a few privacy-related regulations in force and a few introduced bills moving through the state government.
Maryland Online Data Privacy Act (MODPA)
Effective Date: Oct 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumers or 10,000+ consumers with 20%+ revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
up to $10,000 per violation, and up to $25,000 for repeated violations |
Delaware Personal Data Privacy Act (DPDPA)
Effective Date: January 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumer or 10,000+ consumers with 20% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
up to $10,000 per violation |
Effective Date: January 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumer or 10,000+ consumers with 25% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
up to $10,000 per violation |
Virginia Consumer Data Privacy Act (VCDPA)
Effective Date: January 1, 2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumer or 25,000+ consumers with 50% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Texas Data Privacy and Security Act (TDPSA)
Effective Date: July 1, 2024
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 35,000 consumer or 10,000+ consumers with 20% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Oregon Consumer Privacy Act (OCPA)
Effective Date: July 1, 2024
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumer or 25,000+ consumers with 25% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Montana Consumer Data Privacy Act (MTCDPA)
Effective Date: October 1, 2024
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 50,000 consumer or 25,000+ consumers with 25% revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Not specified |
Iowa Consumer Data Protection Act (ICDPA)
Effective Date: January 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumer or 25,000+ consumers with 50% revenue from data sales |
Access, Delete, Portability Opt-Out |
Up to $7,500 per violation |
Nebraska Data Privacy Act (NDPA)
Effective Date: January 1, 2025
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| Annual gross Revenue exceeding $10 million or buying/selling/sharing personal information of 50,000 or more consumers or 50%+ revenue from data sales | Access, Delete, Correct, Opt-Out, Portability |
Up to $7,500 per violation |
Effective Date: July 1, 2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| 100,000 consumers or 25,000+ 25%+ revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
Up to $20,000 per violation with a total maximum penalty of $500,000 |
Utah Consumer Privacy Act (UCPA)
Effective Date: December 31, 2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| $25M revenue and 100,000 consumer or 25,000+ consumers with 50% revenue from data sales |
Access, Delete, Opt-Out, Portability |
Up to $7,500 per violation |
California Consumer Privacy Act (CCPA)/CPRA
Effective Date : January 1, 2020/2023
| Applicability | Consumer Rights | Penalties |
|---|---|---|
| $25M revenue, 50,000 consumers, or 50%+ revenue from data sales |
Access, Delete, Correct, Opt-Out, Portability |
$2,500 per violation; $7,500 for intentional violations |
Adding {{itemName}} to cart
Added {{itemName}} to cart