Almost every legal problem a corporate website produces was created by someone acting reasonably. A marketing coordinator needed an image for a product page and found one. A developer registered the domain quickly so the launch would not slip, using the account they already had. An agency set up the advertising account because the client did not have one yet. A designer added a chat widget because the sales team asked for it. Nobody did anything obviously wrong, and years later the company discovers it does not own its own domain, cannot prove it licensed an image, or has a third party receiving the contents of every form its visitors start to fill in.
That is the pattern this section is about. These are not exotic risks. They are the ordinary consequences of the way corporate websites actually get built — incrementally, by several parties, under time pressure, with no single person holding the whole picture. The exposure accumulates quietly and surfaces at the worst possible moment: during diligence, at the end of an agency relationship, or in an envelope from a law firm.
Who this section is for
The rest of this site is written for marketers. This section is written for the people who carry the consequences — company officers, general counsel, finance and operations leaders, and the executives who sign contracts they may not have read closely.
It assumes you are intelligent and not technical. The value it adds is the part a law firm article usually leaves out: how the technology actually works. Why the registrant field in a domain record matters more than the invoice. What a stock photo licence actually grants and what it does not. What a tracking pixel transmits and to whom. Which of your evidence a platform will have deleted on a schedule before anyone thinks to preserve it. Understanding the mechanics is what lets you ask counsel the right question rather than a general one.
What is not here
This is not legal advice, and it is not written by attorneys. Every page in this section says so, at the top and at the bottom, because the distinction matters. These pages describe how issues generally work, what usually determines exposure, and what questions are worth asking. They cannot tell you the answer for your company, your facts, or your jurisdiction. For that you need a qualified attorney licensed where you operate, and several of these areas are unsettled enough that two competent lawyers will give you different readings.
Where the law is genuinely contested, these pages say so rather than picking a side. Two topics in particular — whether and when bidding on a competitor's trademark creates liability, and the wiretap-style theories being brought over website tracking — are actively disputed, jurisdiction-dependent, and moving. On those pages the disagreement is the content. A page that told you confidently how those come out would be misleading you.
You will also not find statistics here about how many companies get sued or what the average settlement is. Those figures circulate widely in marketing material for compliance products and almost none of them trace back to a source that can be checked. Where a number matters, it is a statutory one, and it is cited.
How the issues group together
Things you own, or think you do. Domain names, website code and design, content, and advertising accounts. The recurring theme is that ownership follows records and written agreements, not payment and not intent. A company that paid for a website does not automatically own the copyright in it. A company whose brand is on a domain is not automatically the registrant. These are the issues most likely to surface during a transaction, and the cheapest to fix before one.
Things you put on the site. Images, copy, claims about your product, and testimonials from customers. The exposure here runs in both directions — you may be using something you do not have rights to, and someone may be using yours. The evidence that resolves either question is usually thin, because nobody kept the licence records or documented what was published when.
Things the site does to visitors. Tracking, analytics, advertising pixels, session replay, chat, and the forms that collect data. This is the newest area and the fastest moving. The common failure is not a decision to do something aggressive; it is that no one at the company can produce an accurate list of what is running on the site and what each thing transmits.
Things that happen when it goes wrong. How a dispute actually proceeds, what technical evidence is needed, and how quickly that evidence disappears. If you read only one page in this section, and nothing has gone wrong yet, read the one on website data as evidence — because default retention settings across analytics, search, and advertising platforms destroy the record on a schedule, and no internal litigation hold reaches a third-party platform automatically.
What to do with this
Most of what these pages recommend is not legal work. It is inventory. Who is the registrant of every domain the company uses. Where every image on the site came from and what licence covers it. Which contracts assign intellectual property and which merely grant a licence. Who administers each advertising and analytics account. What tags are running and what they send. Almost none of that requires a lawyer to establish, and having it established is what makes the lawyer's time useful when you do need it.
The companies that handle these issues well are not the ones with the best contracts. They are the ones that can answer basic questions about their own website in an afternoon.