Privacy Policy Requirements for Business Websites
Under California's Online Privacy Protection Act, any commercial website that collects personal information from California residents must conspicuously post a privacy policy, which in practice means almost any U.S. business website needs one, since excluding California visitors specifically isn't realistic for most sites. A compliant policy discloses what personal information you collect, how you use and share it, and how to contact you, and the FTC can treat a policy that misrepresents your actual practices as a deceptive business practice.
By LLC Register · Last reviewed October 1, 2026
Comprehensive Guide
Why Almost Every Business Website Needs One
The baseline requirement to actually post a privacy policy, rather than just protect data responsibly, comes from California's Online Privacy Protection Act, known as CalOPPA. It requires any operator of a commercial website or online service that collects personal information from California residents to conspicuously post a privacy policy, with no revenue or company-size threshold attached to this specific requirement. Because it's impractical for most online businesses to identify and exclude California visitors, CalOPPA functions in practice as a near-universal requirement for any commercial website that collects information like names, email addresses or other identifiers through forms, accounts, or analytics.
What a Privacy Policy Generally Has to Disclose
Under CalOPPA, a compliant privacy policy identifies the categories of personally identifiable information the site collects and the categories of third parties it may share that information with, describes the process for a visitor to review and request changes to their information where the operator provides one, states the policy's effective date, and describes how the operator notifies visitors of material changes. Beyond CalOPPA's baseline, if a state comprehensive privacy law also applies to your business, such as once you cross that state's revenue or data-volume threshold, your policy generally needs to add that state's specific disclosures, commonly including the categories of data collected and sold or shared, the purposes for processing, and how a consumer can exercise rights like access, deletion, or opting out of sale or sharing.
Your Policy Has to Match What You Actually Do
Posting a privacy policy isn't just a box to check; the FTC can bring an enforcement action under Section 5 of the FTC Act against a business whose actual data practices contradict what its privacy policy says, treating the mismatch itself as a deceptive practice regardless of whether any other privacy law applies. In practice, this means a generic, copied privacy policy that describes practices your business doesn't actually follow is a bigger risk than having a shorter, accurate one. Write the policy to reflect what your site genuinely does: what you collect, why, who you share it with, and how long you keep it.
Children's Sites Face an Additional, Specific Rule
If your website or online service is directed at children under 13, or you have actual knowledge that you're collecting personal information from children under 13, the Children's Online Privacy Protection Act requires posting a privacy policy describing your information practices for children's data specifically, in addition to obtaining verifiable parental consent before collecting it. This is a more detailed, child-specific requirement layered on top of the general privacy policy obligation.
Where and How to Post It
CalOPPA requires the policy to be "conspicuously posted," which its own text defines to include a link labeled "Privacy Policy" placed on the website's home page or the first significant page after entering the site, in a way that's noticeable, such as a different color or in a footer that's clearly visible without requiring the visitor to scroll. A privacy policy buried several clicks deep, or labeled ambiguously, doesn't meet this standard.
Keeping the Policy Current
Review and update your privacy policy whenever your actual data practices change, such as adding a new analytics tool, a new category of data collection, or a new third-party service that receives customer data. CalOPPA and most state privacy laws expect operators to describe how they'll notify users of material changes, so follow your own stated process, whether that's an updated effective date, a banner notice, or a direct notification, when you make one.
A Privacy Policy Isn't the Same as Terms and Conditions
A privacy policy specifically addresses what personal data you collect and how you handle it. Terms and conditions cover the broader rules for using your site and buying from your store, including returns, liability and dispute resolution. Most commercial websites need both, as separate documents, even though they're sometimes linked next to each other in a site's footer. See our guide on terms and conditions for e-commerce websites for what that separate document covers.
Practical Considerations
A Template Policy Is a Starting Point, Not a Finished One
A generic privacy policy template can give you the right structure, but it won't accurately describe your specific tools, vendors and data practices unless you customize it. Given that the FTC can treat an inaccurate policy as deceptive on its own, review any template against what your business actually does before publishing it.
Your Vendors' Practices Become Part of Your Disclosure
If you use third-party analytics, advertising, or marketing tools that collect visitor data on your behalf, your privacy policy needs to account for that sharing, not just data you collect directly through your own forms. Review what each tool on your site actually does with visitor data before finalizing what you disclose.
Don't Treat This as a One-Time Document
A privacy policy written once at launch and never revisited tends to drift out of sync with a growing business that's added new tools, data types, or states of operation since. Reviewing it alongside other annual compliance tasks helps keep it current rather than discovering the mismatch during a complaint or audit.
This Is Not Legal Advice
Which specific disclosures your privacy policy needs depends on your state privacy law exposure, whether your site reaches children, and your actual data practices, all of which are fact-specific and change over time. Talk to a privacy attorney if your business collects data at meaningful scale or operates in a state with a comprehensive privacy law that applies to you.
Sources
The official sources used for this article.
California Business and Professions Code: Sections 22575-22579 (CalOPPA) | leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=22.&article= |
|---|---|
FTC: Privacy and security enforcement | ftc.gov/business-guidance/privacy-security |
FTC: Children's Online Privacy Protection Rule (COPPA) | ftc.gov/business-guidance/privacy-security/childrens-privacy |
California Privacy Protection Agency: CCPA FAQ | cppa.ca.gov/faq.html |
Created by: LLC RegisterLast reviewed October 1, 2026
Updated: October 1, 2026
Frequently Asked Questions
Is a business legally required to have a privacy policy on its website?
In practice, almost always. California's Online Privacy Protection Act requires any commercial website collecting personal information from California residents to post one, with no revenue or size threshold, and since most sites can't realistically exclude California visitors, this reaches nearly every commercial website.
Where should a privacy policy link appear on a website?
CalOPPA requires it to be conspicuously posted, generally meaning a clearly labeled link, such as "Privacy Policy," on the home page or the first significant page a visitor reaches, in a noticeable spot like a footer, rather than buried several clicks deep.
What happens if a privacy policy doesn't match a business's actual data practices?
The FTC can pursue the business under Section 5 of the FTC Act, treating a privacy policy that misrepresents actual practices as a deceptive act, regardless of whether a specific state privacy law also applies.
Do websites aimed at children need a different privacy policy?
Yes. A site or service directed at children under 13, or one with actual knowledge it collects their data, must post a privacy policy describing its information practices for children specifically, under COPPA, and must also get verifiable parental consent before collecting that data.
Form your business with LLC Register
$99 a year for a registered agent, with LLC formation in year one and annual report filing included. State fees are passed through at cost.
