Hans Skillrud, co-founder of Termageddon and former agency owner, delivered a focused and practical session on website compliance for web agencies. His core argument is straightforward: privacy laws are proliferating rapidly across the globe, they apply to businesses regardless of where those businesses are located, and the common excuses agencies and clients use to avoid dealing with compliance simply will not hold up in court.
The session covered the four main types of website policies (privacy policy, cookie policy with consent tools, terms of service, and disclaimer), explaining the purpose of each and the circumstances under which each is required. Hans then shifted to agency- specific advice, arguing that agencies have a professional and practical obligation to educate clients about compliance requirements, even though legal responsibility ultimately rests with the website owner. He introduced Termageddon's free Website Policy Waiver as a concrete tool agencies can use to document that they have informed clients of their obligations, protecting the agency if a client later tries to assign blame.
The session closed with a live Q&A covering topics including how to convince reluctant clients, which laws apply when a website serves international visitors, GDPR and multilanguage policy support, and whether Termageddon is platform-specific.
Key takeaways
- 01Fines for privacy law violations begin at $2,500 per website visitor whose rights have been infringed, and lawsuits can start at $5,000 per affected visitor. These numbers are not theoretical.
- 02Privacy laws protect people, not businesses. A law protecting California residents can apply to any business collecting data from Californians, regardless of where that business is physically located.
- 03The number of active privacy laws is growing constantly. Multiple new U.S. state laws and international updates were either recently passed or about to take effect at the time of recording.
- 04Any website that collects user data needs a privacy policy. This includes virtually any modern website with a contact form, analytics, embedded maps, video embeds, marketing pixels, or booking tools.
- 05A static, copied, or AI-generated privacy policy is not a compliant solution. Policies must be kept current as laws change.
- 06Cookie consent banners must offer a genuine, equal choice to accept or deny tracking. A banner with only an accept button, or a visually prominent accept and a hidden decline, is non-compliant.
- 07It is the website owner's legal responsibility to comply with privacy laws, not the web agency's. However, agencies should document that they have informed clients of this responsibility.
- 08Termageddon's free Website Policy Waiver gives agencies a practical mechanism to get that documentation in writing, with clients acknowledging the information and selecting a course of action.
- 09A good automated policies solution should identify which laws apply, generate the required policy content, update automatically when laws change, and notify the account holder when updates occur.
Session Overview and Framing
Hans structured his presentation around three main areas: What do website policies actually do?
What is the purpose of each individual policy type?
How can agencies protect themselves?
He also promised a summary slide at the end that attendees could screenshot as a single-image reference covering all key points.
Before diving in, Hans addressed the psychological barrier that many web professionals face around this topic. He observed that web designers often shy away from compliance conversations because the subject feels intimidating and technical. His response to this was direct: you do not need a law degree to tell a client that website policies are important.
Simply alerting a client to the existence of legal requirements is already far ahead of the advice many website owners receive, which is often "you're a small business, you don't need to worry about this." Hans framed his goal for the session as helping attendees deliver compliance information confidently while also protecting their own agencies in the process.
What Website Policies Actually Do
Hans distilled the purpose of website policies into two things:
- Help you comply with laws.
- Limit your liability, meaning avoid fines and lawsuits.
Policies accomplish this by explaining a business's practices and the rules for using the website. Hans was emphatic that this framing is the single most important takeaway from the session. He challenged a common assumption: that fines and legal action only happen to large companies. He used Facebook's multi-billion-euro fines as an example of the kind of headline that gives small businesses a false sense of security.
The reality, Hans explained, is that fines do not start at that scale: Fines for privacy law violations can begin at $2,500 per website visitor whose rights have been infringed.
Lawsuits can begin at $5,000 per website visitor whose privacy rights have been infringed.
Hans illustrated the practical impact with a concrete hypothetical: if 50 customers from California visited a small business website and someone filed a lawsuit at $5,000 per visitor, the resulting liability could be financially devastating. He pointed out that many privacy laws can apply from the moment a business collects data from just a single website visitor.
Limit your liability, meaning avoid fines and lawsuits.
Privacy Policy: Purpose and Scope
What a Privacy Policy Is A privacy policy is an explanation of a website owner's privacy practices. This includes: What user data is collected What is done with that data Who that data is shared with Any other relevant privacy-related disclosures required by applicable laws Hans noted that the legal term for user data is "personally identifiable information" (PII), and that either term is acceptable in conversation. He defined PII as anything that can be used to identify an individual, including: Name Email address Phone number Physical address Device information Browser history
Hans walked through a list of common website features that collect PII, making the point that virtually every modern website is already collecting personal data in some form.
- Contact forms (name, email).
- Newsletter signup forms.
- Third-party analytics tools such as Google Analytics, which collects IP address and other data and shares it with Google.
- Google Map embeds.
- Video embeds such as YouTube and Vimeo.
- Marketing pixels and scripts: Facebook Pixel, LinkedIn Insight Tag, Google Ads, Twitter Ads, Reddit Pixel.
- E-commerce functionality.
- Security embeds such as reCAPTCHA, which also shares data with Google.
- Booking tools such as Calendly.
He emphasized that many of these features not only collect data but also transmit it to third parties. Google Analytics, for example, takes user data like IP address and sends it to Google to power the analytics dashboard. This sharing arrangement has its own compliance implications.
Privacy Laws Apply Based on the Visitor, Not the Business Location This was one of the most emphatic points in the session. Privacy laws are written to protect people, and they apply based on where the website visitors are located, not where the business is located.
Hans used himself as an example: based in Chicago, his website receives traffic from California. California's privacy laws may apply to him because Californians are visiting his site and their data is being collected. The physical location of his business in Illinois is irrelevant to California's legal framework.
He acknowledged that this concept took him a while to fully grasp himself, and he highlighted it as a critical understanding for anyone building or operating websites.
The Growing Landscape of Privacy Laws Hans noted that privacy legislation is expanding rapidly. At the time of recording, he referenced multiple recent developments: Alabama had just passed a new privacy law.
Connecticut's privacy law amendments were set to take effect within approximately two months of the recording.
Australia's privacy law changes were expected in November of the same year.
GDPR in Europe and the UK Data Protection Act remain broadly applicable for websites with European traffic.
The implication is that the compliance landscape is not static. A privacy policy that was accurate last year may already be outdated.
Hans drew the key conclusion from this: a static policy is no longer sufficient. Website owners need a strategy to keep policies updated as new laws pass and existing laws are amended.
Cookie Policy and Consent Solutions
What a Cookie Policy Is A cookie policy is a separate, standalone policy that explains the cookies placed on website visitors' browsers. This includes cookies used for: Marketing purposes Analytics Functional features Essential site operations Hans noted that a cookie policy is only required under some privacy laws, not all of them.
This reinforced his broader point that the correct first step for any website owner is to identify which laws apply to them, because the applicable laws determine which policies and disclosures are required.
Cookie Consent Banners Cookie consent banners (also called consent tools, consent banners, cookie pop-ups, or consent solutions) are the visible interface through which websites obtain user permission for data collection and tracking.
Hans made a significant distinction here regarding opt-in versus opt-out defaults: Some laws allow users to be opted in by default to third-party tracking (such as Google Analytics or Facebook Pixel).
Other laws require users to be opted out by default, meaning tracking only begins after they affirmatively consent.
Because of this variation, Hans argued that a compliant consent banner must present a genuinely equal choice between accepting and declining. He specifically called out the following as non-compliant banner designs: A banner with only an accept button and no decline option A banner where the accept button is large and prominent while the decline button is visually hidden or made difficult to find Any design that makes it structurally harder to decline than to accept He stated that these non-compliant designs can result in fines or lawsuits under applicable laws.
Terms of Service
Terms of service (also referred to as terms and conditions, terms, or terms of use) detail the rules for using a website and the website owner's responsibilities regarding the site.
When Terms of Service Are Required Terms of service are required for e-commerce websites because they help comply with consumer protection laws. Specifically, they provide the mechanism for disclosing: Refund policies Shipping policies Cancellation policies Why Terms of Service Are Valuable for Almost Any Website Beyond e-commerce requirements, Hans argued that terms of service are beneficial for virtually any modern website because they can include: A copyright notice A third-party link disclosure A list of prohibited uses of the website He summarized the function of a terms of service document bluntly: it is a structured list of reasons why website visitors cannot successfully sue the website owner. Given how broad its protective value is, he recommended it as a standard inclusion for most websites.
Disclaimer
A disclaimer functions as an extension to a terms of service document. Hans described it as providing transparency to website visitors about specific disclosures the site owner needs to make.
Disclaimers are not needed by every website, but they are important for sites that fall into any of the following categories: Websites that include affiliate links Websites that sell advertising space to third parties Websites that sell health products or provide health advice, fitness tips, or similar content Websites that provide financial advice or information that could be interpreted as financial guidance Websites that provide legal advice or information that could be interpreted as legal guidance Websites featuring testimonials Hans framed the disclaimer as a tool specifically for avoiding lawsuits in contexts where the nature of the content creates a potential for misunderstanding or misplaced reliance.
How Agencies Can Protect Themselves
This section was described by Hans as the "meat and potatoes" of the session, and the part he was most focused on delivering to an agency audience.
The Core Principle: Educate Clients and Document It Hans opened with a clear statement of legal reality: it is the website owner's responsibility to comply with applicable laws, not the agency's. He cautioned agencies to review their client contracts carefully. If a contract includes language promising that the website will be compliant with every privacy law, he would recommend consulting an attorney about revising that clause, because taking on that obligation is not something he would personally recommend.
However, he drew a clear distinction between legal responsibility and professional responsibility. When an agency builds a contact form, installs analytics, or sets up any other data-collecting feature for a client, it is good professional practice to document that the client has been informed of the resulting legal obligations.
The Website Policy Waiver Termageddon offers a free resource called the Website Policy Waiver. Hans described how it works: It is presented to the client, explaining that the website being built will collect user data and that this may require compliance with applicable privacy laws.
The client signs the waiver, acknowledging that they have been informed of these obligations.
The waiver presents the client with options for how to proceed, such as doing nothing, engaging Termageddon's services, or hiring an attorney.
Regardless of which option the client selects, the agency now has signed documentation proving they informed the client of their legal responsibilities.
Hans emphasized the practical protective value of this documentation. If a client later receives a legal demand letter (for example, for $50,000 in damages related to a privacy law violation), and tries to argue the agency should have handled compliance, the signed waiver establishes that the client was informed and made their own choice.
He specifically noted that this situation is more likely to arise with past clients than new ones. New clients are often receptive to signing the waiver when they are excited about a new website build, and Hans estimated that around 90% or more will proceed to sign up for compliance services at that point. Past clients are harder to convert, but the waiver and a pre-written email sequence (available through Termageddon's agency partner program) can still help.
Professional Options for Clients. Hans outlined what he considers legitimate, professional options for addressing compliance: hiring a lawyer, or in the UK a solicitor, who specializes in privacy and consumer protection law and has a strategy for keeping up with the evolving legal landscape, or using a reputable website policies generator such as Termageddon.
He outlined what a good generator should do: identify the laws that apply to the specific website, generate the required policy content, automatically update the policies when laws change, and notify the account holder by email when updates are pushed.
What Not to Do
- Copying a policy from another website.
- Using ChatGPT or similar AI tools to generate a policy.
- Telling clients they are too small to need to worry about it.
His reasoning: these approaches will not hold up legally, they will not update when laws change, and they create a false sense of security that can have real financial consequences.
Termageddon: Platform Overview and Pricing
Hans provided a brief product pitch for Termageddon, acknowledging the bias openly: Auto-updating policy solution Includes a privacy law identifier to determine which laws apply Covers more laws, rules, and regulations than any other solution according to Hans Attorney-founded (his wife, who he described as "the real brains of the operation") Pricing: $119 per year to protect an entire website Agency partner program: agencies receive a complimentary license for their own website when they join, with the expectation that they may recommend the service to clients He also mentioned a special landing page for Web Agency Summit attendees at Termageddon.com/WAS where new agency partners could receive two complimentary licenses instead of one, along with additional free education resources and pre-written email sequences for client outreach.
Platform Compatibility In response to a question during Q&A, Hans clarified that Termageddon is not WordPress-specific and works on all platforms. The implementation works as follows: Policy text is delivered via embed codes that are copy-pasted into the relevant pages on the website.
The consent tool is installed in the header of the website.
When a visitor loads the page, they see the policies, but Termageddon controls the underlying content. When laws change, updated disclosures are pushed automatically to all policy pages, and account holders are notified by email.
Q&A Section
How to Convince Reluctant Clients An attendee asked for advice on convincing clients who understand the service intellectually but are resistant to acting on it. Hans's response centered on the waiver: He does not believe in "pushing" Termageddon. He believes in pushing education.
Getting a client to sign the waiver is the moment passive awareness becomes documented acknowledgement of responsibility.
For new website builds, the signing rate is high (he estimated around 90%).
For past clients, it is harder. He recommended using Termageddon's pre-written email sequences (available to agency partners) and attaching the waiver to those emails.
The core motivation for the agency should be self-protection. If a client refuses to comply and later receives a $50,000 demand letter, the signed waiver ensures the agency is not in the frame.
Which Laws Apply When a Website Serves Multiple Territories An attendee posed a scenario: a website hosted in Singapore, operated by a Thai company selling tourist tours, getting most of its traffic from Europe. Hans's response: Tourism companies are particularly exposed to multi-jurisdictional compliance because their business model actively attracts people from different countries and legal jurisdictions.
Because privacy laws protect people regardless of where the business is located, GDPR and the UK Data Protection Act are likely relevant given the European traffic.
If the site also receives traffic from Canada or the US, those laws should also be investigated.
The answer in any multi-jurisdiction scenario is the same: identify which laws apply, then make the disclosures required under each of them.
He reiterated that this is not legal advice and recommended consulting qualified legal counsel for specific situations.
GDPR and Multilanguage Support An attendee (identified in the transcript as "Uti") asked about GDPR compliance and specifically about multilanguage support, referencing German as an example.
Hans confirmed that Termageddon has covered GDPR since its inception. On multilanguage support: The consent banner already supports German.
Policy documents are currently English-only.
Many German-speaking users have been translating the policy content themselves.
Multilanguage support for policy documents is described as a top priority.
A major feature release was planned for the following September, with multilanguage support to be deployed shortly after, targeting end-of-year availability.
About the speaker
Hans Skillrud
Co-founder of Termageddon
Hans Skillrud is co-founder of Termageddon, a privacy policy generator built for web professionals, and a former agency owner himself. He now focuses on helping agencies understand and navigate the fast-growing landscape of privacy law.