AIDS RESEARCH CENTER Privacy-first health website checklist PURPOSE AND NECESSITY - List every category of information the site receives. - Remove any field, identifier, cookie or log not necessary for the stated service. - Do not collect diagnosis, test, exposure or sexual-history information for general education. - Explain strictly necessary operational processing in plain language. SEARCH AND NAVIGATION - Keep sensitive onsite searches in browser state or a URL fragment when possible. - Do not send search terms to analytics, advertising or personalization systems. - Prevent saved pages and preferences from becoming an account-linked health profile. - Use clear external-link notices and privacy-preserving referrer behavior. COOKIES, EMBEDS AND THIRD PARTIES - Do not install advertising or behavioral analytics cookies. - Avoid social-media pixels, embedded chat widgets and unnecessary third-party fonts. - Review every external script, iframe, video and map for data transmission. - Document the purpose, recipient, retention and user choice for every necessary third party. FORMS AND CONTACT - Prefer a direct user-initiated email client link when a server form is unnecessary. - Do not publish a contact address broadly when a contextual contact control is sufficient. - Tell users not to submit health records, passwords or identity documents. - Collect the minimum information needed to handle the specific request. LOCAL DEVICE FEATURES - Use local browser storage only for optional device-local preferences. - Name each local-storage key and explain what it contains. - Provide a visible way to clear saved data. - Never imply local storage is anonymous if other identifiers are added later. SECURITY AND RETENTION - Limit operational logs to availability, security and abuse prevention. - Restrict access, keep retention short and prohibit secondary profiling use. - Publish a responsible security-reporting route. - Review downloads and outbound links for compromise or misdirection. GOVERNANCE - Maintain a dated privacy policy, cookie notice, terms, ethical statement and change history. - Make material privacy changes visible before or when they take effect. - Reassess the design whenever a new form, account, embed, analytics tool or AI feature is proposed. Reference principles: - European Commission data-protection principles: https://commission.europa.eu/law/law-topic/data-protection/information-business-and-organisations/principles-gdpr_en - WHO data principles: https://www.who.int/data/principles/ This checklist is educational and is not legal advice.