Does Your Website Need a Privacy Policy? What US Businesses Should Know

A friend of mine runs a small bakery with a simple website: a menu, some photos, a contact form, and a newsletter signup. When she asked me whether she really needed a privacy policy, I figured the answer would be complicated. It turned out to be surprisingly simple. If her site collects any personal information at all, and that contact form alone meant it did, she almost certainly needed one.

That surprises a lot of small business owners, because there’s no single federal law in the US that says every website must have a privacy policy. But a mix of state laws, industry rules, and the terms of the tools most websites rely on adds up to the same practical conclusion. Below I’ll walk through why, what a privacy policy should say, and where cookie banners fit in.

I’m not a lawyer, and this isn’t legal advice. Privacy laws differ by state and country and change frequently, so it’s worth having a professional review your policy, especially if you collect sensitive information or serve customers outside the US.

The Short Answer

If your website collects personal information from visitors, including names, email addresses, phone numbers, or data gathered through analytics and advertising tools, you should have a privacy policy for most commercial websites that describes nearly every site, since even a basic contact form or newsletter signup collects personal details.

does my website need a privacy policy

Why California Law Matters Even If You’re Not in California

The law most responsible for making privacy policies standard across the US is the California Online Privacy Protection Act, known as CalOPPA. It took effect in 2004 and was the first US law to require commercial websites to post a privacy policy. It applies to operators of commercial websites and online services that collect personally identifiable information from California residents, no matter where the business itself is located.

Because it’s hard to run a website that never gets a visitor from California, CalOPPA effectively applies to most US businesses with an online presence. The California Attorney General has sent formal notices to companies that failed to post compliant policies, and the state has made it easy for consumers to report violations. The law firm ArentFox Schiff has a useful summary of what CalOPPA requires, including disclosing the categories of personal information collected, the kinds of third parties it’s shared with, and how the site responds to “Do Not Track” signals from browsers.

Other Laws That Can Require a Privacy Policy

California isn’t the only source of these requirements. A growing number of states have passed comprehensive privacy laws that require covered businesses to publish detailed privacy notices explaining what data they collect, why, and what rights consumers have. Most of these laws apply only to businesses above certain size or data-volume thresholds, but they’re expanding, and the list of states keeps getting longer.

Several federal laws apply to specific situations. Websites directed at children under 13, or that knowingly collect information from them, fall under the Children’s Online Privacy Protection Act, which has strict notice and parental consent rules. Health care providers deal with HIPAA, and financial institutions have their own privacy notice requirements. If you have customers or visitors in the European Union or the UK, the GDPR and its UK equivalent come with detailed transparency requirements of their own.

The Tools You Use Probably Require One Too

Even setting the law aside, many of the services that power a typical website require you to have a privacy policy as a condition of using them. Analytics platforms, advertising networks, email marketing tools, and app stores commonly include this in their terms. If you use tracking pixels or run ads that retarget visitors, those platforms generally expect you to disclose that data collection to your users.

Business texting is another example. If you send text messages to customers, carriers expect your privacy policy to state that mobile information won’t be shared with third parties for marketing purposes. It’s one of the most common reasons a 10DLC registration gets rejected, and it ties into the broader rules around SMS consent.

What a Privacy Policy Should Include

The exact contents depend on which laws apply to you, but a solid privacy policy for a US business usually explains what personal information you collect and how you collect it, whether through forms, purchases, cookies, or third-party tools. It should say why you collect that information and how you use it, and which kinds of outside companies you share it with, such as payment processors, email platforms, or analytics providers. Many of those vendors are handling data on your behalf, which is where the difference between a data controller and a processor comes into play.

A good policy also describes the use of cookies and similar tracking technologies, how people can access, correct, or delete their information if they have those rights, how long you keep data, how you protect it, and how visitors can contact you with questions. It should carry an effective date and explain how you’ll let people know when it changes.

Your Policy Has to Match What You Actually Do

This is the part people overlook. A privacy policy isn’t just a document you post and forget. It’s a set of promises to your visitors, and regulators take those promises seriously. If your policy says you never share data with advertisers while your site runs retargeting pixels, you’ve made a misleading statement, and the Federal Trade Commission has a long history of going after companies whose actual practices don’t match what their policies say.

That’s also the main risk with free templates and policy generators. They can be a reasonable starting point, but a template written for someone else’s business may promise things you don’t do or leave out things you do. Before publishing, go through your site and list every tool that touches visitor data, then make sure the policy reflects all of them.

Do You Need a Cookie Banner?

This question gets tangled up with privacy policies, but it’s a separate issue, and the answer depends a lot on where your visitors are.

In the European Union, websites generally need consent before placing non-essential cookies, such as those used for analytics or advertising, on a visitor’s device. That’s why so many European sites show a consent banner with accept and reject options before any tracking starts.

The US mostly takes a different approach. There’s no general federal requirement to get consent before using cookies. Instead, several state privacy laws give consumers the right to opt out of the sale or sharing of their personal information, which can include data collected by advertising cookies. Businesses covered by those laws may need to offer a clear way to opt out, such as a link on their site, and some states require honoring browser-based opt-out signals like Global Privacy Control. For many smaller US businesses that don’t meet those laws’ thresholds, a full consent banner isn’t legally required, although disclosing cookie use in your privacy policy still is.

If you have meaningful traffic from Europe, or you rely heavily on advertising cookies, a consent management tool is usually worth the setup time.

Where to Put It

Make your privacy policy easy to find. The most common approach is a link in the footer of every page, labeled with the word “privacy.” It also helps to link to it anywhere you collect information, such as next to a signup form or at checkout. CalOPPA specifically requires the policy to be posted conspicuously, and burying it several clicks deep defeats the purpose.

Final Thoughts

For almost any business website that collects personal information, the answer to whether you need a privacy policy is yes. CalOPPA alone reaches most US sites, state privacy laws are adding more requirements every year, and the platforms you depend on usually require one anyway.

The good news is that writing one mostly comes down to being honest about what your site does. List the data you collect, the tools that collect it, who you share it with, and what choices visitors have. Keep it current as your site changes, and make sure every promise in it is one you’re actually keeping.

You may also like...

Shares