If you’re asking a customer to trust a badge, you should know the history of badges. It isn’t flattering. Privacy seals have been around since the late 1990s, and the best-documented ones failed in ways that are easy to describe and hard to avoid. We studied them before we wrote the Nullware Standard. This is what we found and what we changed because of it.
The checks that stopped happening
TRUSTe was, for years, the best-known privacy seal on the web. In November 2014 it settled charges brought by the US Federal Trade Commission. The FTC said TRUSTe had told consumers it recertified companies holding its seal every year, but failed to carry out those annual recertifications in more than 1,000 cases between 2006 and January 2013. It also said that after TRUSTe became a for-profit company in 2008, it didn’t make seal holders update statements describing it as a non-profit. TRUSTe agreed to pay $200,000 and accept extra reporting requirements on its children’s privacy programme. The final order was approved in March 2015.
The badges kept showing on those sites while the checks behind them didn’t happen. Nobody visiting could tell.
The badge that outlived the promise
Self-certification schemes had the same problem at a larger scale.
The EU-US Safe Harbor framework let American companies certify themselves as meeting European privacy principles. In 2008 the Australian consultancy Galexia examined the 1,597 organisations then on the Safe Harbor list. Only 1,109 were current members. Only 348 met even the most basic requirements it tested. And 206 organisations claimed to be members when they weren’t.
The FTC later brought cases on exactly this pattern. In January 2014 it settled with twelve companies, including an NFL club, that had displayed the Safe Harbor mark or claimed current certification after letting it lapse. In September 2019 it settled with five more companies over false claims about Safe Harbor’s successor, Privacy Shield. Four of them had applied but never finished certifying; the fifth had let its certification lapse in 2018 and kept claiming it.
The lesson: a mark that stays up by default will be out of date by default.
The seal that attracted the wrong members
The most uncomfortable finding came from the economist Benjamin Edelman. In 2006 he cross-checked TRUSTe’s certified sites against SiteAdvisor’s safety ratings for more than half a million popular sites. Among TRUSTe-certified sites, 5.4% were rated untrustworthy. Among sites without the seal, the figure was 2.5%. Certified sites were more than twice as likely to be untrustworthy, and the gap held when he controlled for traffic and type of site. The work was later published in the journal Electronic Commerce Research and Applications.
His explanation was adverse selection. Well-known firms gain little from a seal, because people already know them. Unknown and dubious firms gain the most, so they’re the keenest to apply. And a certifier paid per certificate earns nothing by turning people away.
The same study found something more hopeful. BBBOnLine’s privacy seal, which ran a more detailed evaluation of applicants, didn’t show the problem. Its certified sites were slightly more likely to be trustworthy than average. Careful review makes a difference.
What we changed
Each failure above maps to a design decision.
Checks that stopped → expiry that doesn’t depend on us. Certification is valid for 12 months. The badge reads “valid to [month year]”. If a member isn’t re-reviewed in time, their register entry flips to Lapsed automatically. Nobody has to remember, and nobody can quietly skip it. If we fall behind, the register shows that too.
Badges that outlived the promise → a badge that points home. The badge is a static image the member hosts, linking to their record on our domain. The record, not the image, is the source of truth. A badge on a site whose record says Lapsed, Suspended or Removed tells on itself.
Declarations alone → evidence. The Standard has two tiers, and every member meets both. The verified tier, which covers the core rule, needs a data map of where customer data goes (NFS-4.1), a declaration signed by a director (NFS-5.1), and evidence from inside the business: audience lists, conversion settings, email and CRM sync settings. Members give us a right to audit, including a read-only look in their ad accounts on 14 days’ notice (NFS-5.3). The pledged tier is exactly what it says: five published pledges signed by a director. Each member’s record labels which commitments were checked with evidence and which were signed, so no one mistakes one for the other.
Checks once a year → weekly scans, published. Every member’s site is scanned from outside each week, and the date of the last scan shows on their record.
Paid per certificate → fees that pay for review, not for a result. Fees are tiered by staff numbers, from £100 a year for 1–9 staff to £12,000 for 1,000 or more, so a corner shop isn’t priced out and a large firm pays for the longer review it needs. Fees are published and the same for everyone in a band, so nobody under review can pay to smooth the way.
Private judgement → separated and public. The person who evaluates an application is not the person who decides it, and an appeal is heard by someone else again. When a member breaches the Standard, they get 30 days to put it right and a right of reply before anything is published. If they’re removed, the register says so and gives the reason. Removals are part of the record, not something we tidy away.
Marks anyone can copy → a legal backstop. We intend to register the badge as a UK certification mark. That requires publicly filed regulations covering who may use the mark, what it certifies, how we test and supervise, fees and how disputes are settled. Separately, since 6 April 2025 the Digital Markets, Competition and Consumers Act 2024 has banned displaying a trust mark without the necessary authorisation (Schedule 20, paragraph 3) and claiming an approval whose terms aren’t being complied with (paragraph 4). The CMA can fine businesses up to 10% of global turnover for consumer law breaches. That gives a lapsed member a strong reason to take the badge down.
What we can’t promise
It would be odd to write about overconfident seals and end on a guarantee.
- Scans only see what’s public. A scan can spot a pixel. It can’t see a customer list uploaded from an office laptop or a server-to-server conversion feed. That’s why the verified tier needs evidence from inside the accounts and a signed declaration, and why we keep an audit right. A determined member could still mislead us between reviews.
- A review is a snapshot. Sites change weekly. Weekly scans narrow the gap. They don’t close it.
- Pledged isn’t verified. Pledges move into verification as we have capacity. Until then they rest on a director’s signature.
- We’re small and new. Founding members are free until 2028, so for now fees fund less of the work than they will later. We’d rather say so than pretend otherwise.
- We’ll get things wrong. Due process and appeals exist because of that, and it applies to our decisions as much as to members.
What we can promise is that you can check. Every record shows its status, its expiry, its last scan and its data map. Proof beats promises, including ours.
- NFS-4.1 Every member publishes a data map of where customer data goes.
- NFS-5.1 A director signs a declaration that the business meets the Standard.
- NFS-5.3 Members give us audit access, including a read-only look in ad accounts on 14 days’ notice.
- Certification lasts 12 months, statuses are Certified, Lapsed, Left, Suspended and Removed, and breaches get a 30-day cure period, right of reply and appeal. “How reviews work” and “What the badge means” set out the detail.
Sources (10), checked 20 September 2026
- FTC: TRUSTe settles FTC charges it deceived consumers through its privacy seal program, 17 November 2014
- FTC business blog: The FTC’s TRUSTe case, when seals help seal the deal, November 2014
- Benjamin Edelman: Certifications and site trustworthiness, September 2006
- Benjamin Edelman: Adverse selection in online “trust” certifications and search results (PDF)
- Galexia: The US Safe Harbor, Fact or Fiction? (2008)
- FTC: settles with twelve companies falsely claiming to comply with Safe Harbor, 21 January 2014
- FTC: five companies settle allegations they falsely claimed participation in Privacy Shield, 3 September 2019
- Trade Marks Act 1994, Schedule 2 (certification marks)
- Digital Markets, Competition and Consumers Act 2024, Schedule 20
- CMS: DMCC Act consumer elements in force from 6 April 2025