Plain-language summary: Colbertism is an independent economics and markets publication. We collect very little personal data. If you subscribe to our newsletter, we store your email address, an optional first name, and the time you subscribed. If you use the contact form or leave a comment, we store what you send us. Our servers keep routine technical logs for security. We do not collect payment details, precise location, or biometric data, and we never sell or rent personal data to anyone. Advertisements on this site, including Google AdSense, may use cookies to show you ads; you can opt out of personalized advertising at any time, and your form submissions are never shared with any advertising network. This privacy policy explains all of this in detail, along with your rights and exactly how to exercise them.
Effective date: August 13, 2026.
1. Data Controller
This website, Colbertism (the “Site”), is operated by an independent publisher based in the Republic of Indonesia (the “Operator”, “we”, “us”, or “our”). For the purposes of the European Union General Data Protection Regulation (GDPR), the Indonesian Personal Data Protection Law, and comparable statutes, the Operator is the data controller for personal data collected through the Site. Privacy inquiries, requests, and complaints can be emailed to [email protected] or submitted through the contact form, which reaches the Operator directly.
This policy is part of a wider set of Site policies. Reading it together with our Terms of Use, Cookie Policy, and Advertising Disclosure gives the complete picture of how the Site operates. All Site policies are indexed at our legal hub.
2. Scope and Definitions
This policy applies to personal data processed in connection with your use of the Site, its newsletter, its comment sections, and its contact form. It does not apply to third-party websites we link to from articles; those sites have their own privacy practices, and following an outbound link is subject to the destination’s policy, not ours.
In this policy, “personal data” means any information relating to an identified or identifiable natural person, such as a name, an email address, or an IP address. “Processing” means any operation performed on personal data, including collection, storage, use, disclosure, and deletion. “Processor” means a service provider that processes personal data on our behalf and under our instructions.
3. Information We Collect
We follow a strict data-minimization approach: we collect only what a small independent publication needs to function. The complete inventory follows. If a category is not listed here, we do not collect it.
Newsletter Subscription Data
When you subscribe to our newsletter through the on-site subscribe form, we collect:
- your email address (required);
- your first name (optional, used only to personalize the greeting in emails);
- the date and time of your subscription, and a record of your confirmation if double opt-in is used, so we can demonstrate that consent was given.
Newsletter emails may contain standard delivery metrics (whether an email was delivered or bounced). We do not build interest profiles of individual subscribers, and we do not enrich subscriber records with data from any other source.
Contact Form Submissions
When you use the contact form, we collect the name you enter, your email address, the topic you select, the text of your message, and the date and time of submission. We use this information solely to read, route, and answer your message.
Comments
If the Site’s comment feature is enabled on an article and you post a comment, we collect the display name you choose, your email address (not published), the text of your comment, and the time of posting. The Site software may also record the IP address from which a comment was submitted, which is used only for spam prevention and abuse handling. Published comments are visible to all visitors; choose your display name accordingly.
Server Logs
Like virtually every website, our hosting infrastructure automatically records technical log entries for each request. A log entry contains the requesting IP address, the date and time of the request, the URL requested, the HTTP status code, the referrer URL (the page that linked you here, if your browser sends it), and the user agent string (browser and operating system identifiers). We use these logs to keep the Site secure, to detect and block abusive traffic, and to diagnose technical faults. Logs are not used to identify individual readers in the ordinary course of operation.
Aggregate Analytics
We review aggregate, non-identifying statistics about the Site’s use: total page views, most-read articles, approximate country-level distribution of visits, and referral sources. These statistics describe traffic in bulk, not individual people. Where an analytics tool is used, we configure it in the most privacy-preserving mode reasonably available (for example, IP truncation where the tool supports it). Details of any analytics cookies appear in the Cookie Policy.
4. Information We Do Not Collect
For clarity, we state plainly what we do not collect and will not collect under this policy:
- No payment data. The Site sells nothing directly and has no checkout. We never ask for card numbers, bank details, or wallet addresses.
- No precise location. We do not request device geolocation. The only location-related information we see is the coarse, country-level inference that any server can make from an IP address.
- No biometrics. We collect no fingerprints, facial data, or voice data.
- No government identifiers. We never ask for national ID numbers, passport numbers, or tax numbers.
- No purchased data. We do not buy, license, or import personal data about our readers from data brokers or any other source.
- No sale of data, ever. We do not and will not sell, rent, trade, or otherwise monetize personal data. Section 9 states this commitment in full.
5. Purposes and Lawful Bases for Processing
We process personal data only for specified purposes and only where a recognized lawful basis applies. The table below maps each processing activity to its purpose and basis.
| Processing activity | Data involved | Purpose | Lawful basis |
|---|---|---|---|
| Newsletter delivery | Email address, optional first name, subscription timestamp | Sending the newsletter you asked for | Consent (Art. 6(1)(a) GDPR); withdrawable at any time via the unsubscribe link or the contact form |
| Answering inquiries | Contact form name, email, topic, message | Reading and responding to your message | Legitimate interest in corresponding with readers; where your inquiry concerns a contract or legal claim, performance of that matter |
| Comment publication | Display name, email, comment text, submission IP | Displaying reader discussion and preventing spam | Consent for publication of the comment; legitimate interest for spam and abuse prevention |
| Security logging | IP address, user agent, referrer, request details | Detecting attacks, blocking abuse, diagnosing faults | Legitimate interest in keeping the Site available and secure |
| Aggregate analytics | Anonymized or aggregated usage statistics | Understanding which articles readers value | Legitimate interest in editorial planning; consent where a jurisdiction requires it for analytics cookies |
| Advertising delivery | Cookie identifiers and device signals processed by ad partners | Funding the publication through third-party ads | Consent, collected through the mechanisms described in Section 7 and the Cookie Policy |
| Legal compliance | Any of the above, as required | Complying with binding legal obligations and lawful orders | Legal obligation |
Where we rely on legitimate interest, we have balanced that interest against your rights and freedoms and concluded that the processing is limited, expected, and low risk. You may object to legitimate-interest processing as described in Section 15.
6. Cookies in Summary
The Site uses a small number of cookies and similar technologies: strictly necessary cookies that make the Site work, and third-party advertising cookies described in Section 7. We do not use cookies to track you across unrelated websites for our own purposes. Full details, including cookie names, lifetimes, and management instructions for every major browser, are in the Cookie Policy, which forms part of this policy by reference.
7. Third-Party Advertising and Google AdSense
The Site is funded in part by third-party display advertising, which may include Google AdSense. This is the one area where a third party processes visitor data for its own purposes, so we describe it in detail.
- Google, as a third-party vendor, uses cookies to serve ads on the Site. Google’s use of the advertising cookie (historically known as the DoubleClick cookie) enables it and its partners to serve ads to you based on your visit to this Site and other sites on the internet.
- When ad personalization is active, the ads you see may reflect your inferred interests. When it is not, ads are selected contextually (based on the page content) rather than on a profile of you.
- Google may also use certified third-party ad-serving vendors, each of which operates under Google’s program policies.
You can opt out of personalized advertising at any time:
- through Google’s Ads Settings at adssettings.google.com, which controls personalization across Google’s ad services;
- through the Digital Advertising Alliance’s industry opt-out at aboutads.info/choices, which covers many participating ad networks at once;
- for visitors in Europe, through youronlinechoices.eu, the European interactive advertising opt-out portal.
Two commitments are absolute. First, data you submit through our forms (newsletter, contact, comments) is never shared with, sold to, or made accessible to any advertising network, including Google. Ad partners receive only the cookie and device signals their own scripts collect from your browser; our subscriber and correspondence records are kept entirely separate. Second, we accept no sponsored content and no paid placements, so no advertiser influences what we publish or gains any special access to reader data. Our Advertising Disclosure explains the editorial side of these rules.
Affiliate links (pre-commitment). The Site does not currently use affiliate links. If we adopt them in the future, the following rules will apply from day one: affiliate links will be clearly disclosed as described in the Advertising Disclosure; clicking an affiliate link may set a cookie on the merchant’s domain under the merchant’s own policy; we will receive only aggregate commission reporting, never data identifying which reader made which purchase; and we will update this policy and the Cookie Policy before the first affiliate link goes live.
8. Processors and Service Providers
We use a small number of service providers to run the Site. Rather than naming vendors that may change, we describe the categories and the safeguards we require of each:
- Hosting provider: stores the Site’s files, databases, and server logs on our behalf.
- Email delivery service: transmits the newsletter to subscribers and processes bounce and delivery information.
- Spam filtering and security services: screen comment submissions and inbound traffic for abuse.
Every processor we engage must: process personal data only on our documented instructions; keep it confidential; apply appropriate technical and organizational security measures; assist us in honoring data subject rights; delete or return the data when the engagement ends; and refrain from using reader data for its own purposes. Where the law requires it, these obligations are set out in a written data processing agreement.
9. No Sale or Rental of Personal Data
We do not sell personal data. We do not rent it. We do not trade it, share it for cross-context behavioral advertising, or disclose it to third parties for their own marketing. This applies to every category of data described in this policy and to every reader, regardless of where you live. This commitment has no exceptions and will survive any future change in how the Site is funded. If the Site were ever transferred to a new operator (for example, through a sale of the publication), personal data would be transferred only as part of that succession, the new operator would be bound by this policy, and subscribers would be notified in advance with a clear opportunity to unsubscribe first.
We disclose personal data outside the processor relationships in Section 8 only if a law that binds us compels the disclosure, or if disclosure is strictly necessary to establish, exercise, or defend legal claims. We will resist overbroad demands to the extent the law allows.
10. International Data Transfers
The Operator is based in Indonesia, and our hosting and email infrastructure may be located in other countries, including the United States and member states of the European Union. Google and other advertising vendors typically process data in the United States. Where personal data of readers in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country without an adequacy decision, we rely on appropriate safeguards, principally the European Commission’s Standard Contractual Clauses (or their UK and Swiss equivalents) as incorporated into our providers’ data processing terms, together with the data-minimization practices described throughout this policy. Transfers of Indonesian personal data abroad are conducted consistently with the transfer requirements of the Indonesian Personal Data Protection Law.
11. Data Retention
We keep personal data only as long as the purpose for which it was collected requires, then delete or anonymize it. Concrete schedules per data type:
| Data type | Retention period | Notes |
|---|---|---|
| Newsletter subscription data | Until you unsubscribe, then removed from the active list within 30 days | We may retain a minimal suppression record (a hashed form of the email address) to make sure we never email you again |
| Contact form submissions | 24 months from the close of the correspondence | Kept so we can follow up on ongoing matters; deleted earlier on request unless a legal claim requires retention |
| Comments | As long as the related article remains published | You may request deletion of your comment at any time via the contact form |
| Server logs | 90 days on a rolling basis | Entries linked to an active security incident may be preserved until the incident is resolved |
| Aggregate analytics | Indefinitely | Contains no personal data once aggregated or anonymized |
| Backups | Rolling cycle of no more than 35 days | Deleted data may persist in encrypted backups until the cycle completes, after which it is gone |
12. Security Measures and Their Limits
We apply technical and organizational measures proportionate to the modest sensitivity of the data we hold: TLS encryption for all connections to the Site, access to administrative systems restricted to the Operator and protected by strong authentication, prompt application of security updates to the Site software, least-privilege access for any processor, and separation of subscriber data from public-facing systems where practicable.
We are honest about the limits. No website, ours included, can guarantee absolute security. Transmission over the internet always carries some risk, and a sufficiently determined attacker can defeat even well-configured defenses. What we can promise is that we hold little data worth stealing, we protect what we hold with reasonable care, and we will tell you promptly if something goes wrong, as Section 13 describes.
13. Data Breach Notification
If we become aware of a personal data breach affecting Site data, we will: (a) investigate and contain it without delay; (b) notify the competent supervisory authority within the timeline applicable law requires (72 hours under the GDPR where it applies; 3 x 24 hours in writing under the Indonesian Personal Data Protection Law); (c) notify affected individuals without undue delay whenever the breach is likely to result in a real risk to them, using the email address on file or a prominent notice on the Site; and (d) describe in plain language what happened, what data was involved, what we have done, and what you can do. We will not conceal, minimize, or delay disclosure of a breach for reputational reasons.
14. Children’s Privacy
The Site publishes economics and markets analysis for a general adult readership and is not directed at children. We do not knowingly collect personal data from children under 13 years of age (or under the higher age that applies in some jurisdictions, up to 16, where consent of a parent is required). If you believe a child has submitted personal data to us, contact us through the contact form and we will delete it promptly. Parents and guardians may exercise all rights in Section 15 on a child’s behalf.
15. Your Rights
You have rights over your personal data regardless of where you live, because we extend the strongest applicable framework to all readers as a matter of policy. Depending on your jurisdiction, these rights arise under the GDPR, the UK GDPR, the California Consumer Privacy Act as amended (CCPA/CPRA), the Indonesian Personal Data Protection Law, or similar statutes.
Rights You Can Exercise
- Access: obtain confirmation of whether we process your personal data and receive a copy of it.
- Rectification (correction): have inaccurate data corrected and incomplete data completed.
- Erasure (deletion): have your data deleted, for example when you withdraw newsletter consent or ask us to remove a comment.
- Restriction: require us to stop actively using your data while a dispute about it is resolved.
- Portability: receive the data you provided to us in a structured, commonly used, machine-readable format (for our data, typically a CSV or plain-text export).
- Objection: object to processing based on legitimate interest, and to any direct marketing at any time.
- Withdrawal of consent: withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. Every newsletter email contains a one-click unsubscribe link.
- No discrimination: we will never degrade your access to the Site, its content, or its features because you exercised a privacy right.
- Complaint: lodge a complaint with a supervisory authority, including the data protection authority of your country of residence, your place of work, or the place of an alleged infringement. We would appreciate the chance to resolve your concern first, but you are never required to contact us before complaining.
Exact Procedure and Response Time
- Open the contact form and select the topic that best matches a privacy request (or state “privacy request” in your message).
- Tell us which right you are exercising and, where relevant, which data it concerns (for example, “delete my newsletter subscription” or “send me a copy of my contact form messages”).
- Submit the form using the email address associated with the data where possible; this is the fastest path through verification.
- We will acknowledge receipt and respond substantively within 30 days of receiving your request. If a request is unusually complex, we may extend this once by a further period permitted by applicable law, and we will tell you within the first 30 days why the extension is needed.
- All rights requests are handled free of charge. If a request is manifestly unfounded or excessive (for example, repeated identical requests), we may charge a reasonable administrative fee or decline it, and we will explain why in writing.
16. Identity Verification
Before acting on a rights request, we verify that the requester is the person the data concerns, using the least intrusive method that provides reasonable assurance. In practice: for newsletter and contact form data, we verify by matching the email address you write from (or confirm control of) against the address on file, typically by sending a confirmation link to that address. For comments, we match the email address recorded with the comment. We will never ask for government ID, a photograph, or payment information to verify identity, because we hold nothing sensitive enough to justify collecting more data in order to delete less. If we cannot verify a request after reasonable attempts, we will explain what is missing; if verification ultimately fails, we will decline the request rather than risk disclosing or deleting someone else’s data. Authorized agents acting for a data subject must provide evidence of their authority.
17. California Privacy Notice
This section supplements the policy for California residents under the CCPA/CPRA. In the preceding 12 months we have collected the following categories of personal information as defined by the statute: identifiers (name, email address, IP address) and internet or other electronic network activity information (server log entries, cookie identifiers set by ad partners). We collect them from you directly and from your browser automatically, for the purposes in Section 5. We have not sold personal information and have not shared it for cross-context behavioral advertising, and we will not do so. We do not use or disclose sensitive personal information within the meaning of the CPRA. California residents may exercise the rights to know, access, correct, delete, and non-discrimination through the procedure in Section 15. Because we do not sell or share personal information, no “Do Not Sell or Share” link is required; nonetheless, our advertising configuration honors the opt-out signals described in Section 7, and where our platform recognizes the Global Privacy Control signal we treat it as a valid opt-out preference.
18. Indonesian Personal Data Protection Law
The Operator is subject to Indonesian Law No. 27 of 2022 on Personal Data Protection (the “PDP Law”). We acknowledge our obligations under the PDP Law as a personal data controller, including the obligations of lawful basis, purpose limitation, accuracy, security, breach notification within 3 x 24 hours, and facilitation of data subject rights, which parallel the rights listed in Section 15. Indonesian data subjects may exercise their PDP Law rights through the same procedure and with the same 30-day response commitment described above. Nothing in this policy limits any right you hold under the PDP Law.
19. Governing Framework
This policy is governed by the laws of the Republic of Indonesia, without depriving you of protections granted by mandatory data protection law of your own jurisdiction that applies to our processing of your data. General terms governing use of the Site, including limitation of liability, are in the Terms of Use; nothing in that document reduces your statutory privacy rights.
20. Changes to This Privacy Policy
We review this policy at least annually and whenever our practices change. Each revision carries a new effective date at the top of the page. For material changes (for example, a new category of data collected, a new processor category, or the introduction of affiliate links under Section 7), we will post a notice on the Site for at least 30 days before or upon the change taking effect, and newsletter subscribers will be informed in the next scheduled email. Continued use of the Site after the effective date of a revision constitutes acceptance of the revised policy to the extent the law permits; where a change requires fresh consent (such as a new consent-based processing purpose), we will ask for it rather than assume it. Previous versions are archived and available on request through the contact form, so you can always see exactly what changed and when.
21. Questions and Contact
Questions, concerns, rights requests, and complaints about this policy or our data practices should be submitted through the contact form. Please mention “privacy” in your topic or message so we can prioritize it. We respond to substantive privacy inquiries within 30 days, as described in Section 15. Information about the publication itself is on the about page, and the full set of Site policies is available at colbertism.com/legal/.