
Celestine Bahr

Celestine Bahr
Director Legal, Compliance & Data Privacy
Celestine Bahr oversees all legal issues at Usercentrics, including IT and data protection law, compliance, and contract and competition law. In her career she has also focused on employment and product law and has specialized legal training in IT and employment law. Celestine has worked at large and small organizations, from Deutsche Telekom to joining Usercentrics as it was coming out of startup mode. She is trained as a data protection officer and mediator, and provides mentorship to junior legal staff.
You can find Celestine on:
Articles
Guide
Jun 26, 2025
Facebook privacy policy: A complete guide for businesses
Learn how Facebook’s privacy policy affects your business. See what data is collected, how it’s used, and what your responsibilities are.
Read more
Article

Jun 3, 2025
What is the GDPR right to be forgotten? Data deletion requests explained
The GDPR right to be forgotten enables individuals in EU/EEA to request the deletion of their personal data under specific circumstances. Learn the six grounds for erasure, the time limit to take action, and how organizations can handle deletion requests properly.
Read more
Article

May 13, 2025
GDPR penalties: What is the maximum fine for GDPR breaches?
GDPR fines make headlines because of their high dollar values. We look at why companies may be fined, who enforces the GDPR, who is responsible for compliance, and how companies can protect themselves against GDPR violations.
Read more
Article

May 9, 2025
Who is responsible for GDPR compliance?
Data controllers and processors are mainly responsible for ensuring that their data collection and processing is GDPR-compliant. Data protection authorities in EU countries manage GDPR enforcement.
Read more
Article

Mar 27, 2025
The ePrivacy Directive, GDPR, and future of EU privacy regulation: What it means for your business
The ePrivacy Directive and GDPR impact companies doing business in the EU. How are their requirements evolving, and how will data privacy compliance and enforcement change now that the push for the ePrivacy Regulation has been abandoned? We look at ePrivacy, cookies and data protection in the EU.
Read more
Article

Mar 5, 2025
UK government demands access to Apple users’ encrypted data
Under a controversial law, the UK government demanded that Apple provide access to currently encrypted files and user data stored in Apple’s cloud servers. The action would give the UK government access to worldwide user data, however, not just Apple users in the UK.
Read more
Article

Feb 27, 2025
European Court of Justice fines European Commission for US data transfer violation
A login option on a conference website the European Commission managed made it possible for personal data to be transferred to the United States without authorization or adequate security measures. We look at the complaint, how the violation happened, and how it was resolved.
Read more
Article

Feb 19, 2025
EU regulators scrutinize DeepSeek for data privacy violations
Chinese AI company DeepSeek has caused a stir with its R1 model. EU regulators are also paying attention and expressing concern over the app’s collection and use of EU residents’ personal data. We look at why data protection authorities are investigating and what action they’re taking.
Read more
Article

Feb 11, 2025
Understanding the New York SHIELD Act
The New York SHIELD Act affects any business handling New York state residents' private information. With specific security requirements, breach notification deadlines, and new protected data categories from March 2025, businesses worldwide must understand their obligations.
Read more
Guide
Feb 7, 2025
Guide: "Do Not Sell Or Share My Personal Information" notices
Learn what a "Do Not Sell Or Share My Personal Information" notice is, who it applies to, and how to create one for your website.
Read more
Guide
Feb 6, 2025
A guide to AI disclaimers: Why have one and how to create it
Learn about AI disclaimers, whether your website needs one, and how to create one to build trust with your audience.
Read more
Guide
Feb 4, 2025
30-day money-back guarantee: Why have one and how to create it
Learn about 30-day money-back guarantees, which businesses can offer them, and how to write your own.
Read more
Article

Feb 3, 2025
New regulatory updates for cookie use in Norway: What to know and how to comply
Norway’s data privacy protections have become stricter and in line with EU standards, with regulatory updates for cookie use taking effect as part of the E-Com Act (Ekomloven). We explore what the new rules are, how companies can comply with them, and what penalties are for violations.
Read more
Guide
Jan 31, 2025
Amazon affiliate disclosure: What you need to know
Learn about what an Amazon affiliate disclosure is, where to include it on your website, and discover affiliate disclosure examples and best practices.
Read more
Article

Jan 30, 2025
The BeReal case: Use of dark patterns for app consent?
Privacy advocacy group noyb filed a complaint against social networking app BeReal for allegedly manipulating its users into consenting to specific uses of their data. Is consent by banner fatigue a violation of the GDPR? We look into the case.
Read more
Article

Jan 28, 2025
Oregon Consumer Privacy Act (OCPA): An Overview
The Oregon Consumer Privacy Act (OCPA), in effect since July 1, 2024, imposes obligations on businesses operating in Oregon. Companies must comply with its provisions regarding the processing, sharing, and protection of Oregon residents’ personal data.
Read more
Guide
Jan 28, 2025
Protect your company’s music and jingles using a music copyright notice
Discover how to protect your company’s music, jingles, and brand identity across your website and social media using music copyright notices.
Read more
Guide
Jan 21, 2025
Protect your intellectual property using a copyright all rights reserved notice
The copyright "All rights reserved" notice indicates that a copyright holder owns all exclusive rights. See all rights reserved examples and get tips.
Read more
Guide
Jan 20, 2025
No responsibility disclaimer examples and template to safeguard your business
Find out what a no responsibility disclaimer is, who should use it, and how to create one. We also include some no responsibility disclaimer examples.
Read more
Guide
Jan 16, 2025
Terms of Service template: customize for your site
Learn how to create a Terms of Service policy for your website with this customizable template so you can stay legally compliant and increase trust with users.
Read more
Guide
Jan 16, 2025
A guide to affiliate link disclaimers with examples
Learn what an affiliate link disclaimer is, who needs one, and how to create your own.
Read more
Article

Jan 13, 2025
CCPA penalties and fines: What are the consequences of noncompliance?
Read more
Guide
Jan 9, 2025
A guide to “all sales are final” policies and how to create one
Learn everything you need to know about all sales are final policies and how you can protect your business while fostering trust with your customers.
Read more
Article

Jan 8, 2025
Québec Law 25: an overview
Québec Law 25 modernizes privacy laws for the Canadian province, introducing stricter rules for obtaining consent, protecting personal information, and individuals' rights. Learn what this means for organizations that operate in Québec, and how they can comply with the law’s requirements.
Read more
Guide
Jan 8, 2025
Copyright examples and explanation: Protect your website
Understand what copyright law protects and see examples of copyrighted content so you can protect your website and comply with regulations.
Read more
Guide
Jan 8, 2025
A guide to limitation of liability
Learn everything you need to know about limitation of liability and how to protect your business and bottom line.
Read more
Article

Jan 3, 2025
What is a Data Protection Officer and does your company need one?
A Data Protection Officer can be essential for complying with privacy regulations and protecting personal data. By understanding evolving legal requirements, a DPO helps build a strong foundation for data protection and long-term success.
Read more
Article

Jan 3, 2025
Australia’s Online Safety Amendment (Social Media Minimum Age) Bill: Will the social media ban for teens work?
Australia has passed a strict new law banning much social media access for children under age 16. The ban is intended to address safety and mental health concerns for children and teens online. Access to various social platforms is prohibited and implementing age-gating measures is required.
Read more
Guide
Dec 25, 2024
What to know about views expressed disclaimers
Learn everything you need to know about views expressed disclaimers. Discover their importance, examples, and best practices for including them on your website.
Read more
Guide
Dec 25, 2024
Your guide to creating medical disclaimers for your website
See health and medical disclaimer examples, and learn the difference between the two so you can add the right disclaimer to your site.
Read more
Guide
Dec 25, 2024
How to create your website copyright footer
Learn everything you need to know about website copyright footers, from how to write one to how to implement it on various CMS systems.
Read more
Guide
Dec 25, 2024
How to protect your channel with a YouTube copyright disclaimer
Discover what you need to know about YouTube copyright disclaimers, including the types, how to write one, and how they help with copyright law compliance.
Read more
Article

Dec 20, 2024
The Video Privacy Protection Act (VPPA) explained
The Video Privacy Protection Act (VPPA) was passed in 1988 to protect video rental history and viewing data. Today, its application extends to online video platforms like streaming services. Learn how US courts are interpreting the law and what steps to take for your business to comply.
Read more
Article

Dec 17, 2024
A complete overview of student privacy laws around the world
Student data privacy laws protect confidential information about students’ enrollment, academic performance, financial arrangements, and more. Understand worldwide regulations that educational institutions must abide by.
Read more
Article

Dec 13, 2024
The European Accessibility Act (EAA): an overview
The European Accessibility Act (EAA) sets accessibility standards for products and services across the EU, aiming to improve inclusion for people with disabilities and older adults. Learn what it covers, who must comply, and how to prepare for the June 2025 enforcement deadline.
Read more
Article

Dec 12, 2024
What you need to know about the 7 principles of GDPR
If you operate in the EU or serve EU customers, it’s important to understand the 7 GDPR principles and how to apply them to your data practices. Below are clear examples and actionable steps you can take to help your business stay compliant and build trust.
Read more
Guide
Dec 9, 2024
A guide to shipping policies and free template
Learn about shipping policies and how to create your own to protect your business and deliver better customer experience in our comprehensive guide.
Read more
Guide
Dec 9, 2024
No refund policy: guide and template
Learn everything you need to know about what no refund policies are and how to create one in this comprehensive guide.
Read more
Guide
Dec 9, 2024
A guide to email disclaimers with customizable templates
Learn what an email disclaimer is, the different types, and see examples to guide you when crafting your own.
Read more
Article

Dec 3, 2024
CCPA vs GDPR: key differences and similarities
The CCPA/CPRA and the GDPR are landmark data privacy regulations that impact organizations worldwide. We look at the differences and similarities between the two laws, and how organizations can achieve compliance with both.
Read more
Article

Dec 3, 2024
CCPA vs CPRA: Key differences for businesses to know
The CCPA and CPRA give consumers control over their personal information and impose obligations on businesses. This guide explains differences between the two laws, ways the CPRA amends or replaces the CCPA, new consumer rights under the CPRA, and businesses’ compliance requirements.
Read more
Guide
Nov 28, 2024
Fair use disclaimer: complete guide with template
Learn what a fair use disclaimer is and whether your website could need one, then create your own with our customizable template.
Read more
Article

Nov 25, 2024
What you need to know about data processing agreements (DPAs)
A Data Processing Agreement (DPA) is a legal contract that outlines how personal data should be shared, processed, and secured between businesses and their third-party providers. It ensures that businesses remain compliant with data protection laws.
Read more
Article

Nov 25, 2024
A guide to CIPP certification: What it is and how to get it
Data privacy is only growing in importance, and CIPP certification could be a valuable credential to those working in or transitioning into the field. Learn about what this certification is, how it can benefit your career, and how to earn it.
Read more
Article

Oct 11, 2024
Health Insurance Portability and Accountability Act (HIPAA): An overview
The Health Insurance Portability and Accountability Act (HIPAA) is a US federal law that came into effect in 1996. It covers collection, use, and security requirements for protected health information in healthcare and healthcare insurance industries.
Read more
Article

Sep 20, 2024
Rhode Island Data Transparency and Privacy Protection Act explained
The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA) takes effect January 1, 2026, introducing important safeguards for data privacy and customer rights in the state. Businesses must familiarize themselves with the law and its implications for data handling practices.
Read more
Article

Sep 19, 2024
California Consumer Privacy Act (CCPA) – an overview
In effect since January 1, 2020, the California Consumer Privacy Act (CCPA) was the first US state-level consumer privacy law. It established consumers’ rights, set obligations for businesses, and influenced subsequent privacy regulations in other states.
Read more
Article

Sep 17, 2024
Utah Consumer Privacy Act (UCPA): an overview
The UCPA provides rights to consumers and places responsibilities on businesses to protect consumer data and use it compliantly. We explore its key provisions and what they mean for both consumers and companies.
Read more
Article

Aug 19, 2024
Minnesota Consumer Data Privacy Act (MCDPA) – an overview
The Minnesota Consumer Data Privacy Act (MCDPA) takes effect on July 31, 2025, establishing new standards for data privacy and consumer protection in the state. Businesses preparing for compliance must understand the key provisions and implications for consumer rights to ensure a smooth transition.
Read more
Article
Jun 28, 2024
Maryland Online Data Privacy Act: an overview
The Maryland Online Data Privacy Act takes effect on October 1, 2025. It includes stricter privacy compliance requirements than other US states and impacts businesses that operate in Maryland.
Read more
Article
Jun 25, 2024
Nebraska Data Privacy Act: an overview
The Nebraska Data Privacy Act comes into effect on January 1, 2025 and has significant regulatory implications for businesses operating in the state.
Read more
Article
Jun 13, 2024
Understanding the Washington My Health My Data Act: a comprehensive guide
The Washington My Health My Data Act is a state-level data privacy law that focuses solely on consumer health data, but it has wide-reaching implications for businesses both in and out of the state.
Read more
Article

Jun 3, 2024
Brazil’s General Data Protection Law / Lei Geral de Proteção de Dados (LGPD) – an overview
Brazil’s LGPD builds on existing Brazilian law and the legislation was influenced by the GDPR. We look at how it addresses consumer rights, companies’ responsibilities, and enforcement.
Read more
Article
May 26, 2024
How the EU Data Act affects businesses and consumers
The European Union's Data Act sets new rules to regulate the way data holders and users can manage and use the vast amounts of data generated from connective devices. We look at what this means for personal and non-personal data sharing, and the obligations laid down by the regulation.
Read more
Article
May 26, 2024
Canada's Personal Information Protection and Electronic Documents Act (PIPEDA): An Overview
Canada’s data privacy law has been active since 2020, through big changes in digital markets and business and personal reliance on the internet. PIPEDA has been updated multiple times, and is again due for an overhaul. Learn about PIPEDA compliance requirements, the 10 Principles, and more.
Read more
Article

Apr 18, 2024
Digital Markets Act uncovered: top 30 DMA questions answered
We provide answers to the most frequently asked questions about the Digital Markets Act (DMA). Gain insights into the latest regulatory measures and discover how they are shaping the digital landscape and impacting businesses.
Read more
Article
Apr 15, 2024
New Hampshire Data Privacy Act (NHDPA): An Overview
The New Hampshire Privacy Act is the 14th state-level data privacy law passed in the United States. It was the first data privacy bill passed in 2024, on January 18, prior to New Jersey’s, but New Hampshire’s governor signed it into law later, on March 6. It comes into effect January 1, 2025.
Read more
Article

Apr 12, 2024
TCF 2.2 publishers’ guide: updates, insights, and best practices
The Interactive Advertising Bureau (IAB) has recently announced the latest version of its Transparency and Consent Framework (TCF) — TCF v2.2. In this blog post, we'll explore the key updates in TCF v2.2 and what they mean for the digital advertising industry.
Read more
Article

Apr 5, 2024
New Jersey Data Privacy Act (NJDPA): An Overview
The New Jersey Data Privacy Act is the 15th state-level data privacy law passed in the United States. It was the second data privacy bill passed in 2024, after New Hampshire’s, but New Jersey’s governor signed it into law on January 16, 2024. It comes into effect one year from that date.
Read more
Article

Mar 28, 2024
The EU’s General Data Protection Regulation (GDPR) – an overview
The EU’s GDPR is a well-known, influential European data privacy law. We look at how it addresses consumer rights, companies’ responsibilities, and enforcement.
Read more
Article
Mar 18, 2024
Tailoring Asian businesses’ marketing strategies for European privacy compliance and success
Both Asia and Europe are large geographies with significant audience and business opportunities. However, there are particular business challenges, and data privacy regulation is an especially important consideration for Asian companies looking to establish a foothold in European markets.
Read more
Article
Mar 5, 2024
What is a sovereign cloud why is it important for your data protection strategy?
Companies increasingly take to the cloud to store data, and sovereign clouds can help comply with regulatory requirements. Learn how an EU Sovereign Cloud impacts data sovereignty and residency as required by EU laws like the General Data Protection Regulation (GDPR).
Read more
Article
Jan 18, 2024
How the European Digital Markets Act (DMA) shapes user privacy and consent management
The European Digital Markets Act (DMA) came into force in November 2022 and gatekeepers have been nominated by the European Commission. But how does the DMA privacy law impact user privacy and consent management?
Read more
Article
Jan 16, 2024
What is the Google EU user consent policy?
Google's EU user consent policy sets the foundation for responsible data handling in digital advertising. We explore how websites that have received a noncompliance notice from Google can use a Consent Management Platform (CMP) to enable compliance and avoid suspension from Google's platforms.
Read more
Article

Jan 5, 2024
Delaware Personal Data Privacy Act (DPDPA): An Overview
The Delaware Personal Data Privacy Act is the twelfth state-level data privacy law passed in the United States. It’s considered one of the more consumer-friendly state-level data privacy laws. The DPDPA was signed by Delaware’’s governor on September 11, 2023 and comes into effect January 1, 2025.
Read more
Article
Jan 3, 2024
Data privacy regulation in 2024: what we’re watching
Data privacy saw a lot of change and advancement in 2023. More regulations, more requirements from businesses and more consumer expectations. There is unprecedented opportunity for innovation and 2024 promises that change will accelerate even faster. Let’s look at what to expect in data privacy.
Read more
Article

Nov 2, 2023
US privacy law compliance for EU companies
If you are an EU company looking to do business in the US, this article provides you with some of the answers you will need to know about the US Privacy Law.
Read more
Article
Aug 18, 2023
Saudi Arabia Personal Data Protection Law (PDPL): An Overview
The Saudi Arabia Personal Data Protection Law came into effect in March 2022, though enforcement did not begin for a year. The PDPL is quite similar to the EU’s GDPR in scope.
Read more
Article
Aug 17, 2023
Understanding the EU-U.S. Data Privacy Framework: What it means for your data?
The European Union and United States again have an adequacy agreement governing privacy and security for international data transfers. The Data Privacy Framework went into effect July 10th, providing new safeguards for EU residents and enabling US companies to self-certify.
Read more
Article
Aug 16, 2023
What is the best protection method for sharing PII?
Companies collect consumers’ data to improve user experiences, target advertising, and more. When organizations obtain and share personally identifiable information (PII) in the course of business operations, they have to ensure that it’s protected.
Read more
Article
Jul 28, 2023
Understanding the Florida Digital Bill of Rights (FDBR): A complete overview
The Florida Digital Bill of Rights is the tenth state-level data privacy law passed in the United States, with a critical focus on online social media platforms and the protection of children.
Read more
Article
Jul 27, 2023
Texas Data Privacy and Security Act (TDPSA): An Overview
The Texas Data Privacy and Security Act is the eleventh comprehensive state-level data privacy law passed in the United States, signed into law within days of Florida’s regulation.
Read more
Article
Jul 25, 2023
How does the GDPR affect B2B sales?
GDPR compliance applies to personal data used for B2B sales and marketing operations just as it does to B2C operations. It’s as important to build trust with partners as with customers. We look at how the GDPR affects the B2B outbound sales process and how organizations can achieve compliance.
Read more
Article
Jul 18, 2023
Guide to the EU AI Act
The EU AI Act was adopted in March 2024, making it the world’s first comprehensive AI regulation. It has become influential on future AI legislation around the world. Usercentrics delves into what the EU AI regulation includes, who it affects, and what it means for data privacy.
Read more
Article

Jun 29, 2023
Indiana Consumer Data Protection Act (INCDPA): An Overview
The Indiana Consumer Data Protection Act is the seventh state-level data privacy law passed in the United States, signed into law May 1, 2023.
Read more
Article

Jun 22, 2023
Montana Consumer Data Privacy Act (MTCDPA): An Overview
The Montana Consumer Data Privacy Act is the ninth state-level data privacy law passed in the United States, signed into law the same day as Tennessee’s.
Read more
Article

Jun 21, 2023
Tennessee Information Protection Act (TIPA): An Overview
The Tennessee Information Protection Act is the eighth state-level data privacy law passed in the United States, signed into law the same day as Montana’s.
Read more
Article

May 31, 2023
California's Privacy Scrutiny: What Should App Publishers Prepare For?
California regulators have set their sights on mobile app compliance with CCPA in 2023, and app makers with users in the Golden State need to be prepared. In this article, we cover what legislators are looking at and how you can turn this threat into an opportunity with optimized consent management.
Read more
Article
May 25, 2023
Iowa Consumer Data Protection Act (ICDPA): An Overview
The Iowa Consumer Data Protection Act is the sixth state-level data privacy law passed in the United States and like Utah’s is considered quite “business-friendly”.
Read more
Article
Mar 8, 2023
Nevada Privacy of Information Collected on the Internet from Consumers Act (NPICICA) and Amendment SB-260: An Overview
The NPICICA precedes California’s data privacy laws and is more specific to data privacy on websites and other online properties.
Read more
Article

Feb 1, 2023
Japan Act on the Protection of Personal Information (APPI): An Overview
Japan has had data privacy laws for two decades. The APPI has notable differences from the GDPR, and was most recently amended in 2020.
Read more
Article

Dec 16, 2022
Connecticut Data Privacy Act (CTDPA): An overview
The Connecticut Data Privacy Act is the fifth state-level privacy law passed in the United States and is the most consumer-friendly one to date.
Read more
Article

Apr 14, 2022
South Africa’s Protection of Personal Information Act (POPIA): A complete guide
South Africa’s POPIA is a data privacy law that preceded the GDPR by five years. We look at how it addresses consumer rights, companies’ responsibilities and enforcement.
Read more
Article
Nov 18, 2021
The Telecommunications Telemedia Data Protection Act (TTDPA): what’s changed for companies
As of December 2021, a new data protection law with an expanded scope will apply to companies in or operating in Germany.
Read more
Article
Nov 3, 2021
Children’s Online Privacy Protection Act (COPPA) - An Overview
The Children’s Online Privacy Protection Act is a federal law in the United States that came into effect in 2000 and protects personal information of children under 13.
Read more
Article
Nov 3, 2021
China’s Personal Information Protection Law - An Overview of PIPL
We look at what China’s Personal Information Protection Law means for the data privacy rights of citizens and for companies’ responsibilities.
Read more
Article
Oct 20, 2021
Canada's Consumer Privacy Protection Act - an overview
Canada’s B-C11 would greatly modernize the country’s privacy law. We will take a look at one of the two acts it includes, the Consumer Privacy Protection Act.
Read more
Article

Oct 19, 2021
Colorado Privacy Act: An overview
The Colorado Privacy Act is the third state-level privacy law passed in the US. It reflects consistency with other states’ laws and evolving legal thought.
Read more
Article
Oct 18, 2021
Italian DPA announces new guidelines and tighter deadlines
How can you make sure to navigate data privacy correctly? This article provides you with the relevant information regarding GDPR in Italy.
Read more
Article
Sep 13, 2021
European Data Protection Board guidelines for consent
In this article, we have compiled a summary of the most important points from the European Data Protection Board's, new guidelines for Consent.
Read more
Article

Aug 30, 2021
POPIA vs GDPR: an overview
What is POPIA compliance, and how does it compare to GDPR compliance? You can learn this and more in our POPIA Vs GDPR article.
Read more
Article

Aug 31, 2020
Poland: New data protection regulations including consent under GDPR
Read more
Article

May 24, 2019
European elections: Websites of German top candidates checked on GDPR compliance
European elections: A check shows that the candidates' websites are far from being GDPR compliant. Learn more!
Read more