Chapter 13

E-Business: Selling and Marketing Online

E-commerce architecture, CCPA/CPRA privacy compliance, online security, and digital legalities

⏱ 22 min read • ⚖ California Law & Practice Guide

📋 Executive Summary

Building an online presence requires integrating digital technology with legal compliance. This chapter explores website development strategies, e-commerce platforms, payment gateways, intellectual property ownership of digital assets, website terms of service, and California's nation-leading consumer privacy laws (CalOPPA, CCPA, CPRA).

💡 Key Takeaways & Core Concepts

  • Core Principle: California's Consumer Privacy Act (CCPA) and Privacy Rights Act (CPRA), along with CalOPPA, require commercial websites that collect personal data from California residents to post a comprehensive Privacy Policy.
  • Core Principle: Ensure that independent web developers sign a written 'Work Made for Hire' and Copyright Assignment Agreement; otherwise, the developer retains underlying legal copyright to your website code and custom design.
  • Core Principle: E-commerce websites must maintain Payment Card Industry Data Security Standard (PCI-DSS) compliance and utilize secure SSL/TLS encryption for all transaction processing.
  • Core Principle: Website Terms of Use / Terms of Service protect your business by establishing dispute resolution rules, limiting liability, and defining acceptable user behavior.
  • Core Principle: Online sales to customers in other states can trigger economic sales tax nexus obligations following the Supreme Court's South Dakota v. Wayfair decision.

✅ California Practical Action Checklist

1

Publish CalOPPA & CCPA Compliant Privacy Policy

Disclose categories of personal data collected, third-party sharing, cookie tracking, and consumer opt-out rights.

2

Draft Website Terms of Use

Define intellectual property ownership, limitation of liability, disclaimers of warranty, and California governing law/venue.

3

Execute IP Assignment with Web Developers

Ensure written contract explicitly assigns all copyrights, source code, and graphic assets to your company.

4

Ensure PCI-DSS Compliance & SSL/TLS Encryption

Utilize tokenized payment gateways (Stripe, PayPal, Square) so raw credit card numbers never touch your web server.

5

Secure Domain Name in Company Name

Register domain names under your official business entity name and maintain administrative registrar control.

📖 Key Terminology Glossary

CalOPPA (California Online Privacy Protection Act)

California law mandating that any commercial website collecting Personally Identifiable Information (PII) from California consumers must post a conspicuous privacy policy.

CCPA / CPRA

California Consumer Privacy Act / California Privacy Rights Act; landmark laws granting California residents rights to know, delete, correct, and opt-out of the sale/sharing of their personal data.

Work Made for Hire / IP Assignment

A written legal doctrine transferring statutory copyright ownership from an independent contractor creator to the hiring company.

PCI-DSS (Payment Card Industry Data Security Standard)

A set of mandatory technical security standards established by major credit card brands to protect cardholder data during electronic transactions.

Economic Nexus

A legal threshold established by states requiring remote online sellers to collect and remit state sales tax once sales volume or transaction count exceeds statutory levels.

❓ Chapter Q&A & Self-Assessment

Test your comprehension of this chapter. Click each card below to reveal the answer and statutory explanation.

Q1
If you pay an independent web developer $5,000 to build your website without a written contract, who legally owns the website's copyright?
▾
🎯 Direct Answer:

Under U.S. copyright law, the independent developer automatically owns the copyright; the hiring business merely receives an implied non-exclusive license to use it.

📚 Legal & Practical Explanation:

Under the Copyright Act, independent contractors own the intellectual property they create unless there is a written agreement signed by both parties designating the work as a 'Work Made for Hire' and containing an explicit assignment of all copyright and patent rights to the client.

Q2
What are the mandatory disclosures required in a website Privacy Policy under California law (CalOPPA & CCPA)?
▾
🎯 Direct Answer:

Categories of personally identifiable information collected, categories of third parties with whom data is shared, process for consumers to review and request changes, how the site responds to 'Do Not Track' signals, and an effective date.

📚 Legal & Practical Explanation:

CalOPPA applies to any website worldwide that collects personal data from California residents. Failure to post a compliant privacy policy can lead to civil enforcement actions and substantial statutory fines from the California Attorney General.

Q3
Why should small e-commerce stores use hosted payment gateways (like Stripe or Shopify Payments) rather than storing credit card details on their own server?
▾
🎯 Direct Answer:

To minimize PCI-DSS compliance scope and liability; tokenized gateways handle sensitive credit card numbers directly on their secure servers, insulating your business from card theft liability.

📚 Legal & Practical Explanation:

Storing unencrypted credit card numbers on your own web server requires intense, expensive annual PCI security audits. If your server is breached, penalties and forensic liability can exceed hundreds of thousands of dollars.