Ignoring Terms of Use and their importance within a website, especially now with the LGPD, is a common error that both consumers and website owners often make.
Consumers tend to disregard them, while website owners often simply copy them from other sites and overlook the key points.
After all, who wants to waste time reading these documents or thinking about their development, right? Wrong! Of course, reading them doesn't promise a literary delight, I know that much.
However, it is necessary to ensure the safety of both the user and the page owner. It's not for nothing that they are present in most of those ubiquitous cookie banners out there...
So, don't waste any more time and read below to learn everything about them and how Terms of Use have become essential in the era of LGPD.
Terms of Use correspond to a document that provides detailed information about how a website functions, the contracting of services/products offered (or the use of information present), and the limits of responsibilities for both parties.
In essence, it's a textual document containing rules for the operation and use of the website and its services. These services can be commercial, informational, service-oriented, and so on.
Terms like Terms of Use, LGPD, Privacy Policies, data collection... there are so many terms that come up in discussions about data protection and website obligations that navigating the internet now requires a dictionary and a degree.
Calma, mesmo que você já seja o [Encarregado de Dados](https://goadopt.io/en/blog/responsibilities-of-a-data-protection-officer/) do seu site, por livre espontânea pressão, estamos aqui para te ajudar! :D
Mas você não precisa disso tudo para entender como esses termos conversam e qual é a importância deles. Hoje veremos de forma simples e sem complicações que exijam termos técnicos sobre o assunto.
## And what are Terms of Use for?
Terms of Use serve as a contract!
Can you imagine signing a contract without reading it in advance? Or even copying any contract that concerns rules meant to protect you, without knowing if they apply to your case?
Well, that's why ignoring Terms of Use is no longer an option. In fact, it's a major irresponsibility, let's admit it.
It serves to establish rules for users or customers to use the website or platform. In other words, when you accept the terms, you accept the conditions set by the page. When you make a purchase on an e-commerce site, you're following the rules imposed there.
Of course, this document also follows rules like the Consumer Protection Code, but in general, the contract is imposed by the website. Therefore, it's the website's responsibility to develop it with quality, transparency, and accessibility (easy readability).
Similarly, it's the visitor's responsibility to read the terms, and if they don't agree with them, they should leave the site or stop using it. After all, if they agree, they should adhere to its limits (provided they're not abusive, but that's a legal matter).
In summary, Terms of Use serve to establish the limits of website use, its responsibilities, the correct use of services, the duties and rights of each party, and what is offered there.
It's also worth noting that each type of Terms is different. After all, a news website doesn't offer the same services (nor does it have the same responsibilities) as a page that sells products.
Therefore, thinking about this document is always very important for website owners. Similarly, it's important for you, the reader, as it indicates your rights and duties.
## What's the relationship between Terms of Use and LGPD?
Terms of Use are part of the transparency that websites owe to their visitors and users. They go hand in hand with Privacy Policies. These indicate how the treatment, collection, and security of data that may be collected there are carried out.
And it's precisely these documents that formalize the central themes of the [LGPD, the General Data Protection Law (in Portuguese)](https://goadopt.io/blog/lgpd-lei-geral-de-protecao-de-dados/). It is recent and came into effect in August 2020.
Therefore, more than ever, it's essential for websites to pay attention to the need to develop these documents that affect the privacy and rights of consumers/visitors in accordance with LGPD. Otherwise, they risk receiving significant penalties. Among these, quite significant fines.
Although many websites choose to present them in a single document, it is of paramount importance that they are available on the website in separate and unique documents. In other words, one for the Terms of Use and another for the Privacy Policy.
While the Terms of Use limit the use of data and services available there, responsibilities of the parties, rights, duties, and intellectual property, Privacy Policies provide information on the treatment and collection of data from users and visitors.
## How to develop the Terms of Use for my website?
When creating the Terms of Use in accordance with LGPD, there are some essential considerations.
Firstly, although the Terms of Use correspond to a contract for the use of the website and its services, it does not require legal language. In fact, the clearer it can be, the better!
After all, it's essential for all visitors to be able to understand the terms presented, as they relate to their rights and duties in using the page. Therefore, remember to keep it simple.
Another issue concerns the specificity of the terms. Remember that we mentioned the (terrible) habit of some websites that simply copy the Terms of Use from others? Well, that's wrong precisely because this document should relate specifically to what each page offers.
For example, an informational website, an e-commerce website, and one that offers online calculation tools will each have specific and different Terms of Use. Even among e-commerce websites, this varies.
Another point to consider is the LGPD's delineations regarding the roles of [Data Controller and Data Processor](https://goadopt.io/en/blog/differences-data-controller-data-processor/). This is because these roles can often be confused or even inverted during the provision of services.
After all, they must contain information about the types of products they sell, the data required for purchase, among other issues that are extremely unique to each business.
Finally, remember that the Terms of Use must include, in addition to the delineation of services, limitations of responsibilities and obligations, as well as copyright and industrial property statements.
With all of this, it is possible to ensure LGPD-compliant, secure, clear, and complete Terms of Use! If you want, you can use the [AdOpt Terms of Use](https://goadopt.io/termos-de-uso) as a reference.
## Want to delve deeper into the subject?
We have another article that helps you with [tips for when you need to update your Terms](https://goadopt.io/en/blog/notification-to-users-terms-of-use/).
Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.
Is there an ideal and _foolproof_ Privacy Policy? This is one of the most difficult questions to answer nowadays. Especially considering all the jurisprudence already established in Europe with the GDPR, the extensive history of cases, and the numerous tips we see in the market. Not to mention the judicial decisions that are already emerging in Brazil with the LGPD.
Brazilian LGPD - General Data Protection Law brought with it several acronyms and specific terms. Many of them are imported from other countries and regulations. One of them is ROPA (Record Of Processing Activities), adapted in Brazil to Registros das Atividades de Tratamento. An essential document for any DPO, Data Processor.
A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.
The Data Protection Officer, or DPO, is a new position that emerged all over the globe with the new privacy regulations, and more recently at the LGPD. Although it already existed in other international legislations, such as the EU's GDPR, it is still a novelty here since 2020. Along with it comes the possibility of outsourcing, known as DPO as a Service (DPOaaS).
How do you deal with a profession that didn't even exist a few years ago and is now mandatory in companies? That's precisely the question that arises when we think of the figure of the Data Protection Officer or DPO.
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Iowa ICDPA explained: the longest response deadline of all US state privacy laws (90 days), 90-day cure period, opt-out for sensitive data, limited deletion scope, no right to correct, and how it compares to UCPA, VCDPA, and OCPA.
Brings a new era of consumer rights—and at the heart of it is the Data Subject Access Request (DSAR). This article is your go-to guide for understanding what a DSAR is, how to handle it properly, and why your business needs a streamlined process to stay compliant and build trust with Texas consumers.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Discover what the New Hampshire Privacy Act (NHDPA) means for your business. Learn about compliance steps, consumer rights, penalties, and how to simplify it all with AdOpt, a Google-certified CMP.
Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
AdOpt CMP: Google-certified consent platform with prior blocking, granular choices, encrypted logs, and GTM/Consent Mode
Learn what your TIPA Privacy Policy must include to comply with the Tennessee Information Protection Act from consumer rights and targeted advertising disclosures to the NIST affirmative defense, appeal mechanisms, and how to keep your notice aligned with your operational program.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
The Texas Data Privacy and Security Act (TDPSA) introduces sweeping changes to how businesses collect, use, and disclose personal data—and your privacy policy is now a frontline compliance tool. This article is a comprehensive guide for any company serving Texas residents, explaining how to align your privacy practices with the new legal standards.
Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
What the Virginia VCDPA requires from your Privacy Policy: the 5 mandatory content categories, sensitive data obligations, targeted advertising disclosure, and the appeal process explained.
What the Virginia VCDPA requires from your Cookies Policy: targeted advertising disclosure, consent standards, tracker categories, opt-out mechanisms, and the 30-day cure period explained.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Cookies Policy: Do Not Sell or Share link, GPC compliance, sale vs sharing distinction, sensitive PI opt-out, and annual updates.
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
How to handle DSARs under the Colorado CPA: 5 consumer rights, portability limited to twice per year, Universal Opt-Out Mechanism, 24-month record retention, and District Attorney enforcement.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
How to handle DSARs under the Connecticut CTDPA: 5 consumer rights, opt-outs without mandatory authentication, 60-day appeal deadline, 15-day consent revocation, and AG-only enforcement.
What the Oregon OCPA requires from your Privacy Policy: actively monitored contact channel, detailed third-party descriptions, derived data in scope, GPC from January 2026, and the elimination of the cure period.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
Oregon OCPA DSAR guide: the L.O.C.K.E.D. rights, opt-out without authentication, derived data in deletion scope, 15-day revocation deadline, GPC from January 2026, and the elimination of the cure period.
20 Sep 2023
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications