Comply with GDPR, CCPA, and industry standards for user data handling.
Post compliant privacy policy on website.
Post terms of service.
Implement data subject request mechanisms if applicable.
Document what data is collected and where it flows.
Regularly test security posture (SOC2 prep).