Skip to main content

Do I need a privacy policy on my website?

Yes, and not for the reason you have been told. The state privacy laws mostly do not reach you. Two other rules do, and neither has a size threshold.

VicouUpdated on August 30, 20269 min read
The mascot beside a privacy policy posted on the wall, a short contact form on the counter below

Almost certainly yes, and probably not because of the law you have been reading about. The big state privacy laws have size thresholds that most small businesses fall well under. Two other things reach you regardless of size: California’s older online privacy law, and the terms of the analytics tool sitting on your site right now.

This sits alongside the other legal question small US sites get wrong, which is whether your website needs to be ADA compliant. This is general information, not legal advice, and I am not a lawyer: what follows describes rules as they are written, not a ruling on your own business. If a decision here matters to you, and it does the moment you conclude that a law does not reach you, get it confirmed by a lawyer licensed in your state.

If you are still assembling the site, what pages a small business website needs covers where the policy page fits.

What actually triggers the requirement?

Not your revenue. What you collect. The question gets asked both ways round, do I need a privacy policy and does my website need a privacy policy, and the answer is the same either way: it depends on what the site gathers, not on how big you are.

You are collecting personal information if your site has any of these, which is nearly every small business site:

  • a contact form, even just name and email
  • an email newsletter signup
  • Google Analytics, or any other analytics
  • an advertising pixel from any platform
  • a booking or appointment tool
  • a checkout

If you have none of those, and your site is genuinely a static page with a phone number on it, the picture is different. That describes very few sites.

Do the state privacy laws apply to me?

Usually not, and this is where most articles on this topic mislead by omission.

Around twenty states now have comprehensive consumer privacy laws in effect. They get written about as though they apply to everyone. They come with thresholds, and small businesses are generally under them.

Law Typical thresholds
California, CCPA and CPRA annual revenue above roughly $26.6 million, indexed to inflation from the original $25 million, or the data of 100,000 consumers, or half of revenue from selling personal data
Virginia-style laws, adopted in many states the data of 100,000 consumers, or 25,000 consumers plus half of revenue from selling data
Rhode Island, among the lowest the data of 35,000 residents

A local business with a contact form is not near any of those numbers. So if the CCPA is the reason you thought you needed a policy, it is probably not your reason.

⚠️ Thresholds change, and they are indexed. Do not treat any of these as settled for your business without checking, particularly if you are growing or if you handle data for other companies.

Then what does reach a small business?

Two things, and neither cares how big you are.

1. California’s online privacy law, CalOPPA. Older than the CCPA and structured completely differently. As written, at Cal. Bus. & Prof. Code sections 22575 to 22579, it applies to operators of commercial websites and online services that collect personally identifiable information from California residents, requires a privacy policy to be conspicuously posted, and carries no revenue threshold and no small business exemption in its text. Since you cannot prevent Californians from visiting your site, this is the rule most often read as reaching an ordinary commercial site. Whether it reaches yours is a call for a lawyer and not for me, and it is worth twenty minutes of one.

2. The terms of the tools you already installed. This is the one nobody expects, and it is the clearest of the lot. The US terms for Google Analytics say it directly, in section 7:

“You must post a Privacy Policy and that Privacy Policy must provide notice of Your use of cookies, identifiers for mobile devices … You must disclose the use of Google Analytics, and how it collects and processes data.”

That is a contract you agreed to when you installed the tag. Advertising platforms have comparable requirements. If you added an analytics or advertising tool, you took on an obligation to publish a policy, regardless of any statute.

What has to be in it?

The point is that it describes what your site actually does. A policy that describes somebody else’s site is not a policy, it is a liability with your name on it.

At a minimum, in plain language:

  1. What you collect, item by item. Name and email from the form. Analytics data. Anything a pixel gathers.
  2. How you collected it. Forms, cookies, analytics, advertising tools.
  3. Why, for each item. To answer inquiries. To measure traffic.
  4. Who else sees it. Your analytics provider, your email tool, your booking tool. Name them.
  5. How long you keep it.
  6. How someone asks for their data, or asks you to delete it, with a real address that a person reads.
  7. When it was last updated.

What goes wrong with a generated policy?

Not that it is generated. That nobody reads it afterward.

Generators produce a reasonable starting document, and for a small site that is a legitimate way to begin. The failure is downstream: the policy says you use tools you do not, omits the ones you do, promises a retention period nobody follows, and names a contact address that goes nowhere.

🛑 An inaccurate privacy policy is worse than a missing one. A missing policy is a gap. An inaccurate one is a published, dated, written statement about your own practices that happens to be false, made by you, on your own site.

Three things to do with any generated policy before you publish it:

  • Read it all the way through, and delete every section describing something you do not do.
  • List your tools and check each one appears. Analytics, email, booking, chat, advertising, payments.
  • Send a test message to the contact address in it, and make sure somebody receives it.

What do I do about this on the sites I build?

I include a privacy policy page in the site structure, and I do not write your policy for you.

That is a boundary rather than a shortcut. A privacy policy has to describe your business, the tools you chose, the data you keep and how long you keep it. Writing that on your behalf would mean writing a legal statement about facts I do not have, in a field where I am not qualified. I am not a lawyer, and this article is not legal advice.

What the packages do is give the page a place, so the policy is linked from every page and easy to find. The rest is you, a generator you have read carefully, or a lawyer if your business handles anything sensitive: health information, children’s data, or personal data on behalf of other companies.

If you sell, you need terms of sale as well, which is a separate document with a separate job.

See what each package includes

The questions that come next

Do I need a cookie banner too?
That is a different question from the policy, and for a US-only small business the answer is often no. Cookie consent banners come mainly from European rules and from specific state requirements around selling or sharing personal data. What you do need, regardless, is to disclose your use of cookies in the policy itself, which the Google Analytics terms require directly.
Does a privacy policy protect me from anything?
It removes one specific failure, which is not having disclosed what you collect, and it answers the one requirement I have read at the source: the Google Analytics terms tell you to post a policy. It does not protect you from mishandling data, from a breach, or from having written something inaccurate. The protective part is the accuracy, not the existence of the page.
Where should the link go?
In the footer of every page, in the same place site-wide, with the words "Privacy Policy" rather than something clever. Add it next to any form that collects information, because the moment someone is about to type their email is the moment the disclosure is actually useful. Being conspicuous is part of the requirement, not a design preference.

Want a view on your own case?

Tell me your trade and what you already have. I will tell you what is worth doing, even when the answer is “not yet”.

Get a call back

Read next

All articles