Yes, almost every U.S. commercial website needs a conspicuously posted privacy policy. If you collect names, emails, or run analytics scripts, the single most important action you can take this week is posting an accurate footer link that spells out what you collect and why. If your business hits certain revenue or data thresholds, you'll also need consumer opt-out mechanics on top of that baseline.
TL;DR:
- Posting a footer privacy link and a clear notice-at-collection are the most immediate fixes for compliance across all U.S. states.
- California's CalOPPA applies universally, requiring a conspicuous privacy policy regardless of business size or revenue.
- Businesses crossing specific revenue or data thresholds must add opt-out links and disclose data selling practices, especially if they have California visitors.
- Regularly auditing your data collection, vendor agreements, and updating your policy annually reduces the risk of regulatory penalties.
- Mobile-friendly, accessible privacy links on every page and ongoing monitoring of broken links are key to maintaining compliance.
Table of Contents
- What a Privacy Policy for a Website Actually Needs to Cover
- Which State Laws Actually Require a Posted Privacy Policy
- How to Draft a Privacy Policy Step by Step
- Where to Post Links, Icons, and Cookie Notices
- Keeping the Policy Current Without Losing Track
- Common Compliance Mistakes That Trigger Real Risk
- What a Real Privacy Page Looks Like in Practice
- Where Small Businesses Should Focus First
- Get Your Privacy Page Built Right the First Time
- Sources
What a Privacy Policy for a Website Actually Needs to Cover
A privacy policy for a website isn't a legal ornament. It's a functional document that tells visitors, regulators, and your own team exactly how personal information moves through your site. Get the core clauses right, and you've covered roughly 80 percent of what state law expects from a small or medium business.
Here's the checklist worth building your policy around:
- Categories of personal information collected — name, email, phone, IP address, payment details, location data if you gather it.
- Purposes for collection — why you're gathering it (order fulfillment, marketing emails, appointment scheduling).
- Third parties you share data with — payment processors, email platforms, analytics tools, ad networks.
- Retention periods — how long you keep records after a customer's last interaction.
- Consumer rights — access, deletion, and correction requests, plus how to submit them.
- Children's notice — a statement that you don't knowingly collect data from children under 13, required under COPPA if your site could attract younger visitors.
- Notice-at-collection — a short disclosure shown at the moment data is gathered, not buried three pages deep.
- Contact information — a real email or form, not a dead-end "no-reply" address.
- Effective date — so visitors and regulators know when the policy was last updated.
Plain language beats legal jargon every time. Instead of "we may utilize third-party service providers to effectuate transactional processing," write "we use Stripe to process your payments." UC Berkeley's guidance on privacy statements makes the same point: clarity builds trust and reduces the chance a regulator flags your language as misleading.
You only need legal-basis language (consent, legitimate interest, contract) if you're serving European visitors under GDPR. Skip it if your traffic is domestic. To turn a data inventory into policy language, walk through every form, cookie, and vendor integration on your site, then write one plain sentence per data type describing what happens to it.
Pro Tip: Draft your policy in a layered structure: a short summary at the top for casual readers, then a detailed section below for anyone who wants specifics on vendors and retention. This satisfies disclosure requirements without scaring off the average visitor with a wall of text.
Which State Laws Actually Require a Posted Privacy Policy
California's CalOPPA is the law doing the most work here, and it applies regardless of your company's size or revenue. Any commercial website collecting personally identifiable information from California residents must conspicuously post a privacy policy under Cal. Bus. & Prof. Code § 22575(b). Because California residents visit sites based in every state, this statute functions as a de facto national baseline for U.S. businesses.
CCPA and its amendment, CPRA, layer on additional obligations, but only for businesses that cross specific thresholds:
- Gross annual revenue over a substantial threshold, or
- Buying, selling, or sharing personal information of a large number of consumers or households annually, or
- Deriving a significant portion of annual revenue from selling or sharing personal information.
If you clear one of those bars, you owe consumers a "Do Not Sell or Share My Personal Information" link and expanded rights disclosures. Regulators aren't sitting still on this, either. The California Privacy Protection Agency approved amendments in July 2025 adding mandatory cybersecurity audits and rules governing automated decision-making technology, signaling that enforcement expectations keep tightening.
Delaware and Nevada each impose their own posting duties, generally mirroring CalOPPA's conspicuous-posting standard with lower thresholds than CCPA. A quick checklist for figuring out your exposure: Do you have any California visitors? (Assume yes.) Do you sell data to third parties? Do you exceed $25 million in revenue? If you answered no to the last two, you're likely in baseline-posting territory rather than full consumer-rights territory. Either way, you need the policy.
How to Draft a Privacy Policy Step by Step
Building a website data protection policy from scratch feels bigger than it is once you break it into stages.
- Run a 30-minute data audit. List every form, analytics tool, CRM, and payment processor on your site. Note what data each one touches.
- Map your vendors. Check the terms of service for tools like Google Analytics or your payment gateway. Many vendor contracts require you to disclose their presence, independent of state law.
- Draft clauses from your audit. Convert each data point into one plain sentence: "We collect your email through our contact form to respond to inquiries."
- Write your notice-at-collection text. This is the short blurb shown right where data is gathered, like next to a signup box.
- Implement opt-out links and cookie banners. Add a footer link and, if you meet CCPA thresholds, a homepage "Your Privacy Choices" link.
- Test everything. Click the policy link on mobile and desktop, check it against a screen reader, and confirm every internal link actually loads.
Pro Tip: Test your privacy policy link the same way a first-time visitor would, on a phone, with one thumb, in bad lighting. If you have to hunt for it, so will regulators reviewing your site for compliance.
Where to Post Links, Icons, and Cookie Notices
"Conspicuous posting" has a practical meaning: a footer link labeled "Privacy" on every page, in text that contrasts against the background, generally satisfies CalOPPA's standard. Vague hyperlinks buried in a sitemap don't count.
- Footer link on every page, not just the homepage.
- Homepage placement for the "Do Not Sell or Share" or "Your Privacy Choices" link if you meet CCPA thresholds.
- Mobile-friendly tap targets, since a large share of traffic never touches a desktop.
- Keyboard focusability so screen-reader and keyboard-only users can reach the policy without a mouse.
Nearly every site running analytics or ad-network scripts needs a policy, because those platform contracts often create their own disclosure obligation on top of state law. If your opt-out mechanics feel like more than a static link, a consent management platform can automate the banner and preference center. That's usually overkill for a five-page brochure site, but worth considering once you're running multiple ad pixels.
Keeping the Policy Current Without Losing Track
Review your privacy policy on a fixed schedule, and don't let it drift for years while your tech stack changes underneath it.
- Set an annual review date. Calendar it like a tax deadline.
- Update immediately after material changes — a new tracking pixel, a new vendor, or a new use for existing data.
- Log every consumer request. Keep a simple spreadsheet with the date received, request type, verification method, action taken, and closure date. That's often enough documentation for a small business to show good faith if audited.
Common Compliance Mistakes That Trigger Real Risk
The failures that draw regulator attention are rarely exotic.
- Hidden trackers or ad pixels never mentioned in the policy text.
- Stale disclosures referencing vendors you dropped two years ago.
- A missing or broken opt-out link on a site that clears CCPA thresholds.
- A policy written in dense legalese nobody, including your own staff, actually understands.
Pro Tip: Run a broken-link check on your privacy page every quarter. A dead opt-out link is one of the fastest ways to turn a minor oversight into a documented compliance failure.
Fix the visible gaps yourself this week. Bring in an attorney once you're dealing with cross-border data, a data breach, or CCPA's full consumer-rights machinery.
What a Real Privacy Page Looks Like in Practice
Kirk & Co Software's own privacy policy is a working example: a footer link on every page, plain-language clauses, and a real contact method for requests. Pairing it with a terms of service page shows how the two documents work together rather than duplicating each other. For agencies building similar pages, PRYDE Designs' breakdown of professional-services page types is a useful reference for structuring legal and notice pages that visitors actually read.
Where Small Businesses Should Focus First
Fix visibility this week: a footer link and accurate notice-at-collection text solve most of your baseline exposure immediately. Next, map every tracker and vendor on your site and check whether you clear CCPA's revenue or data-volume thresholds. Vendor data-processing agreements and a formal annual review can wait until next quarter, but don't let them wait forever.
— Elijah
Get Your Privacy Page Built Right the First Time
Some web design companies write and implement privacy pages as part of custom website builds for local businesses, avoiding generic templates.

That means your notice-at-collection text, footer link placement, and cookie disclosures get coded directly into your site's structure, tested on mobile, and checked against keyboard accessibility rather than pasted in as an afterthought. For contractors and home service businesses juggling CRM data, Kirk CRM keeps client records organized in one place, which makes writing an accurate data inventory far simpler when you sit down to draft your policy. If you run a plumbing, HVAC, or landscaping business and want your privacy page built alongside a site that actually converts visitors into calls, look at the plumbing company website services Kirk & Co Software offers, or reach out through the Kirk & Co Software site to get a scan of your current setup and a clear next step for fixing what's missing.
This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.
Sources
- Website Privacy Policy Requirements in the US (2026)
- You Have a Website Privacy Policy, but Does Your Website Comply with U.S. Data Privacy Laws?
- How to Write an Effective Website Privacy Statement | Information Security Office
- Does My Website Need a Privacy Policy? Complete Guide (2026) | Legal Tank
