LLC Register
  • Start your business

    • Start an LLC
    • Form a Business
    • File an S-Corp Election
    • Hire a Registered Agent

    Filings & compliance

    • Articles of Organization
    • Certificate of Formation
    • Operating Agreement
    • EIN & Tax ID Number
    • Foreign Qualification
    • Change Registered Agent
    • Annual Report
    • Stay Compliant

    Not sure where to start?

    Pick your state to see LLC filing fees.

    CaliforniaFiling fee $70

    Form your LLC in California →
    Help me decide →
  • Resources
  • About Us
Start my LLC
  • Start your business
    • Start an LLC
    • Form a Business
    • File an S-Corp Election
    • Hire a Registered Agent
    Filings & compliance
    • Articles of Organization
    • Certificate of Formation
    • Operating Agreement
    • EIN & Tax ID Number
    • Foreign Qualification
    • Change Registered Agent
    • Annual Report
    • Stay Compliant

    Not sure where to start?

    Pick your state to see LLC filing fees.

    CaliforniaFiling fee $70

    Form your LLC in California →
  • Resources
  • About Us
Start my LLC
LLC Register
  1. Home
  2. ›
  3. Resources
  4. ›
  5. Business Compliance

Top 10 Website Compliance Mistakes to Avoid

The most common website compliance mistakes include posting a copied privacy policy that doesn't match actual data practices, relying on unenforceable browsewrap terms, ignoring cookie opt-out signals once a state privacy law applies, sending marketing email or texts without proper consent and opt-out handling, overlooking accessibility barriers, and promising shipping timelines the business can't meet. Each ties to a specific federal or state rule enforced by agencies including the FTC, FCC and DOJ.

By LLC Register · Last reviewed October 2, 2026

Read Comprehensive Guide
LLC Register

Key Takeaways

  • A mismatched privacy policy is itself a violation

    The FTC can pursue a business under Section 5 of the FTC Act for publishing a privacy policy that misrepresents its actual data practices, regardless of whether any other privacy law applies.

  • Browsewrap terms are the weakest form of agreement

    Courts are considerably more reluctant to enforce terms and conditions linked only in a footer than terms a customer affirmatively agreed to, such as by checking a box before checkout.

  • Marketing email and text messages are governed by different rules

    Email falls under the FTC's CAN-SPAM Act, with a per-message penalty of up to $53,088, while marketing texts fall under the FCC's TCPA, with statutory damages of $500 to $1,500 per message.

  • There's no official certification for an accessible website

    The Department of Justice points businesses toward the Web Content Accessibility Guidelines as a benchmark under Title III of the ADA, but no federal process certifies a website as compliant.

Start Your LLC
In this article
  • Comprehensive Guide
  • Practical Considerations

Comprehensive Guide

Mistake 1: Posting a Privacy Policy That Doesn't Match Actual Practices

Almost every commercial website needs a privacy policy under California's Online Privacy Protection Act, but copying a template and never updating it is a common and risky shortcut. The FTC can treat a privacy policy that misrepresents what a business actually collects, uses or shares as a deceptive practice under Section 5 of the FTC Act, independent of any other privacy law. See our guide on privacy policy requirements for what a compliant policy has to disclose.

Mistake 2: Relying on Browsewrap Terms and Conditions

Posting terms and conditions only as a footer link, with no required action from the customer, is known as a browsewrap agreement, and courts have been far more reluctant to enforce it than a clickwrap agreement, where the customer checks a box before completing a purchase. A business that wants to rely on an arbitration clause or a liability limitation needs customers to have clearly agreed to it, not just had the opportunity to find it.

Mistake 3: Ignoring Cookie Consent and Opt-Out Signals

Once a business meets a specific state privacy law's threshold, such as California's $26.625 million revenue figure, it has to post a clear opt-out link and, in states including California, Colorado and Connecticut, honor an automated browser signal like Global Privacy Control without requiring the visitor to click anything on the site. A business that assumes a generic cookie banner covers this, without actually configuring it to detect these signals, hasn't met the requirement.

Mistake 4: Sending Marketing Email Without Meeting CAN-SPAM's Checklist

The CAN-SPAM Act requires accurate header information, a truthful subject line, a clear ad disclosure, a valid physical postal address, and a working opt-out mechanism honored within 10 business days, for every commercial email, business-to-business messages included. The FTC can seek a civil penalty of up to $53,088 per violating email, a figure that applies per message rather than per campaign.

Mistake 5: Texting Customers Without Proper TCPA Consent

Sending marketing texts generally requires the recipient's prior express written consent, specific to the business, not an inference from a past purchase. Since an FCC rule change effective April 11, 2025, businesses also have to honor an opt-out made through any reasonable method, not only a specific keyword like STOP, and process it within 10 business days. TCPA violations can carry statutory damages of $500 to $1,500 per text.

Mistake 6: Assuming Automated Accessibility Scans Are Enough

An automated scan catches some accessibility barriers, missing text alternatives for images or obviously poor color contrast, but can't fully evaluate whether a keyboard-only user can complete a multi-step process like checkout. Title III of the ADA doesn't name one mandatory technical standard, so businesses generally work toward the Web Content Accessibility Guidelines as DOJ's referenced benchmark, which a scan alone doesn't confirm.

Mistake 7: Promising Shipping Timelines the Business Can't Meet

The FTC's Mail, Internet, or Telephone Order Merchandise Rule requires shipping within the time stated, or 30 days if none is stated, and requires a delay notice with a cancellation option if that timeline can't be met. A business that advertises fast shipping without a fulfillment process to back it up is exposed here regardless of how the delay happened.

Mistake 8: Auto-Renewing Subscriptions Without Clear Disclosure

If a website sells anything that auto-renews, the Restore Online Shoppers' Confidence Act requires clearly disclosing the recurring charge, getting the customer's express agreement before billing, and providing an easy way to cancel. Burying the auto-renewal term in a long terms-and-conditions document, rather than disclosing it clearly at the point of purchase, is a common gap.

Mistake 9: Treating a Children's Website the Same as Any Other

A site or service directed at children under 13, or one with actual knowledge it's collecting their data, has to meet the Children's Online Privacy Protection Act's separate requirements, including a specific privacy policy for children's data and verifiable parental consent before collecting it. General-audience compliance steps don't satisfy this heightened standard.

Mistake 10: Treating Website Compliance as a One-Time Launch Task

A privacy policy, terms and conditions, and an accessibility review all reflect a website as it exists on the day they're written. Adding a new checkout flow, a new tracking tool, or a new product category without revisiting these documents is one of the most common ways a previously compliant website drifts out of compliance without anyone noticing until a complaint arrives.

Practical Considerations

Most of These Mistakes Share a Root Cause

Across this list, the common thread is a document or setting that was copied, installed, or configured once and never revisited as the business changed. A privacy policy, a cookie banner, and a terms-and-conditions page all need periodic review against what the website actually does now, not what it did when they were first published.

Different Rules Have Different Enforcers

The FTC enforces CAN-SPAM, COPPA, and general deceptive-practices claims; the FCC enforces the TCPA; the Department of Justice addresses ADA Title III; and state attorneys general and privacy agencies enforce their own state privacy laws. A business that only tracks one of these agencies can still be exposed under another.

Fixing a Mistake Doesn't Erase Past Exposure

Correcting a noncompliant practice going forward is necessary but doesn't retroactively resolve liability for messages already sent or data already mishandled under the old practice. Document when a fix was made, since that timeline can matter if a past practice is ever questioned.

This Is Not Legal Advice

Which of these rules apply to your specific website depends on your size, your state, your industry, and what your site actually does. Talk to a business attorney familiar with website compliance, particularly before launching a texting program, an auto-renewing subscription, or a site aimed at children.

Related Resources

  • Privacy Policy Requirements for Business Websites

    Learn when a business website legally needs a privacy policy, what it must disclose, and why it has to match your actual data practices.

  • Website Accessibility Compliance: What Businesses Should Know

    Learn website accessibility compliance basics for businesses, including the ADA's Title III standard, WCAG guidance, and common access barriers.

  • E-Commerce Compliance Checklist

    Review an e-commerce compliance checklist covering sales tax nexus, privacy policies, email marketing rules, shipping disclosures, and subscriptions.

Sources

The official sources used for this article.

FTC: CAN-SPAM Act compliance guide for business

ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business

FTC: Mail, Internet, or Telephone Order Merchandise Rule

ftc.gov/legal-library/browse/rules/mail-internet-or-telephone-order-merchandise-rule

FTC: Children's Online Privacy Protection Rule (COPPA)

ftc.gov/business-guidance/privacy-security/childrens-privacy

ADA.gov: Guidance on web accessibility and the ADA

ada.gov/resources/web-guidance

eCFR: 47 CFR Part 64, Subpart L (TCPA rules)

ecfr.gov/current/title-47/chapter-I/subchapter-B/part-64/subpart-L

California Business and Professions Code: Sections 22575-22579 (CalOPPA)

leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=22.&article=

Created by: LLC RegisterLast reviewed October 2, 2026

Updated: October 2, 2026

Frequently Asked Questions

What's the most common website compliance mistake small businesses make?

Posting a privacy policy or terms and conditions copied from a template, or from another website, without updating it to match what the business actually does. The FTC can treat a privacy policy that misrepresents actual practices as deceptive on its own, separate from any other law.

Does a small business with no employees still need to worry about website compliance?

Yes. Requirements like CalOPPA's privacy policy rule, the CAN-SPAM Act, and the TCPA apply based on what a website collects or how it markets, not on the business's employee count. Employee-based thresholds mainly appear in state privacy laws like the CCPA, which use revenue or data-volume figures instead.

Can marketing emails or texts sent before a compliance fix still create liability?

Yes. Correcting a noncompliant practice protects future messages, but it doesn't erase liability for messages already sent under the old process. Keep a record of when a fix was made in case a past message is ever questioned.

Is website compliance a one-time project or an ongoing requirement?

Ongoing. A privacy policy, terms and conditions, and an accessibility review all reflect the website as it existed when they were written, and adding new features, tools, or product types without revisiting them is one of the most common ways a compliant site drifts out of compliance.

Form your business with LLC Register

$99 a year for a registered agent, with LLC formation in year one and annual report filing included. State fees are passed through at cost.

Start Your LLC
LLC Register

Any questions?

We're available Monday through Friday from 9am - 6pm CST

Start your business

Start an LLCForm a BusinessFile an S-Corp ElectionHire a Registered Agent

Filings & compliance

Articles of OrganizationCertificate of FormationOperating AgreementEIN & Tax ID NumberForeign QualificationChange Registered AgentAnnual ReportStay Compliant

Company

ResourcesContact UsPrivacy PolicyTerms of Service360 Legal

LLC Register helps entrepreneurs form and maintain their LLC with fast, guided filings and ongoing compliance support. This site provides general information and is not a substitute for legal or tax advice.

LLC Register is not a law firm and does not provide legal advice. Communications with LLC Register are not protected by attorney-client privilege.

Powered by 360Legal