Privacy Policies for Online Businesses and Platform Requirements
A website can collect personal information without triggering one universal federal privacy policy statute, but state laws, FTC enforcement, app stores, advertising platforms, and payment processors often make one necessary. If your site collects email addresses, analytics identifiers, purchase records, location data, device IDs, advertising data, or account information, the policy needs to match the system that collects and uses it.
A privacy policy is the public version of your data map. It describes what the business collects, why, whom it shares with, how long it keeps the data, and how consumers can exercise applicable rights. It also becomes evidence when the policy promises one thing and the product does another.
A Privacy Policy Is a Representation
The FTC Act prohibits unfair or deceptive acts or practices. A business exposes itself to a deception claim when its privacy policy overpromises, understates tracking, hides advertising disclosures, or describes security practices the business hasn't implemented.
In 2023, the FTC finalized an order against BetterHelp requiring the online counseling service to pay $7.8 million and prohibiting it from sharing consumer health data for advertising. The order followed allegations that BetterHelp shared health information with advertising platforms after promising to keep that information private. It also required consent procedures, a privacy program, deletion requests, and retention limits.
In 2024, the FTC finalized an order against Avast requiring $16.5 million in consumer redress. The agency alleged that Avast promised to protect users from online tracking while selling browsing data through its subsidiary Jumpshot. The order bans the company from selling or licensing browsing data for advertising.
Both cases turned on the distance between the written promise and the running system. Before the policy states that the business doesn't sell or share personal information, map how the advertising, analytics, retargeting, and data enrichment tools operate in fact. The sentence gets published once and compared against the stack thereafter.
California Often Starts the Review
California's Online Privacy Protection Act, usually called CalOPPA, applies to operators of commercial websites and online services that collect personally identifiable information online from California consumers. The statute doesn't depend on where the business is headquartered. If your commercial website collects covered information from California residents, CalOPPA may apply.
CalOPPA requires a conspicuously posted privacy policy. The policy must identify the categories of personally identifiable information collected, the categories of third parties with whom that information may be shared, the process for consumers to review and request changes if the operator maintains one, how consumers receive notice of material policy changes, the policy's effective date, how the operator responds to browser do not track signals or similar mechanisms, and whether third parties may collect information about a consumer's online activities over time and across different websites.
CalOPPA treats a privacy policy as conspicuously posted when the policy appears on the homepage or first significant page, or when a homepage link, icon, or other noticeable hyperlink takes the user to it. A text link can include the word privacy, use capital letters, use larger or contrasting type, or otherwise call attention to the link.
After notice of noncompliance, CalOPPA provides the operator 30 days to cure. Penalties often enter through California's Unfair Competition Law, which authorizes civil penalties up to $2,500 per violation.
CCPA Applies by Threshold
A for profit business doing business in California comes under CCPA if it meets one of three thresholds. As of Jan. 1, 2025, the revenue threshold is $26,625,000 in annual gross revenue, adjusted from the original $25 million threshold. A business may also qualify if it annually buys, sells, or shares the personal information of 100,000 or more California consumers or households, or if it derives 50% or more of annual revenue from selling or sharing consumers' personal information.
A business subject to CCPA must provide detailed notices about its collection, use, retention, sale, sharing, and disclosure of personal information. The privacy policy must describe categories of personal information collected in the preceding 12 months, categories of sources, business or commercial purposes, categories sold or shared, categories disclosed for a business purpose, and the consumer rights available under the statute. The CCPA regulations require a comprehensive description of online and offline information practices and a conspicuous privacy link that uses the word privacy. California also requires covered businesses to review and update the policy at least once every 12 months. Regulations approved in September 2025 and effective January 1, 2026 added risk assessment, phased cybersecurity audit, and automated decision making requirements for covered processing.
A business subject to CCPA that sells or shares personal information must provide a Do Not Sell or Share My Personal Information link or use a compliant alternative method. A business that uses or discloses sensitive personal information for purposes beyond those authorized by the statute must provide a Limit the Use of My Sensitive Personal Information link or a compliant alternative. Collection of sensitive information alone doesn't trigger that link.
California regulations require businesses to process Global Privacy Control and other opt out preference signals as valid opt out requests for sale and sharing. A privacy policy that describes opt out rights but a website that ignores the signal tells regulators where to look. The California Attorney General and CPPA enforce the CCPA, and CPPA enforcement since March 2025 has focused on opt out rights, data minimization, and data broker compliance.
Texas Requires Its Own Analysis
The Texas Data Privacy and Security Act, codified in Texas Business and Commerce Code Chapter 541, took effect July 1, 2024. It applies to a person that conducts business in Texas or produces a product or service consumed by Texas residents, processes or sells personal data, and doesn't qualify as a small business under the Small Business Administration definition. Small businesses receive a broad exemption, but they must obtain consent before selling sensitive personal data.
Chapter 541 requires a reasonably accessible privacy notice with the categories of personal data processed, the purposes for processing, how consumers can exercise their rights and appeal a decision, the categories of personal data shared with third parties, the categories of third parties receiving the data, and the methods consumers can use to submit rights requests. If the controller sells sensitive data or biometric data, Chapter 541 requires specific notice language in the same location and manner as the privacy notice.
Chapter 541 also requires a controller to limit collection to what is adequate, relevant, and reasonably necessary for disclosed purposes, maintain reasonable data security practices, obtain consent before processing sensitive data, and provide opt out rights for targeted advertising, sale, and certain profiling. The attorney general has exclusive enforcement authority, and a violation after the cure period can result in a civil penalty of up to $7,500 per violation.
Other State Laws Change the Policy
Twenty states have comprehensive consumer privacy laws in effect as of July 2026, with Florida's applying to a narrower group of large technology companies. Oklahoma, Louisiana, Alabama, and Vermont enacted comprehensive laws in 2026 with future effective dates. Virginia, Maryland, and Connecticut also passed significant amendments this year, so any state count remains a snapshot. California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Delaware, Iowa, Indiana, Tennessee, Montana, New Jersey, New Hampshire, Nebraska, Kentucky, Rhode Island, Minnesota, Maryland, and Florida each require state specific review. Indiana, Kentucky, and Rhode Island took effect January 1, 2026.
These laws share concepts and differ on thresholds, exemptions, sensitive data, appeals, targeted advertising, cure periods, and enforcement. A multistate privacy policy can group rights where the laws align and separate them where the laws differ. Avoid calling every disclosure a sale, treating every user as a California consumer, or assuming a California policy covers Texas, Colorado, and Virginia without changes.
Platform Rules Can Force the Issue
App stores and advertising platforms can require a privacy policy even when a business falls below state privacy law thresholds. Apple requires all apps to include a privacy policy link in App Store Connect and inside the app. The policy must identify what data the app or service collects, how it collects the data, all uses of that data, third party sharing, retention and deletion practices, and how a user can revoke consent or request deletion.
Google Play requires all apps to post a privacy policy link in Play Console and a privacy policy link or text inside the app. Google requires the policy to disclose how the app accesses, collects, uses, and shares user data, including developer contact information, data types, sharing parties, secure handling procedures, retention, and deletion. Google also requires a data safety section that matches the app's privacy disclosures.
Ad platforms, payment processors, app SDKs, ecommerce tools, and analytics vendors can impose similar requirements. If you use customer list matching, retargeting pixels, embedded checkout, mobile SDKs, or conversion APIs, you should check the platform terms before launch. A platform can suspend an account or reject an app even when no regulator has contacted the business.
Cookies and Pixels Belong in the Policy
United States cookie compliance usually turns on disclosure, opt out rights, and consumer protection rules rather than a European style banner model. For many businesses, the harder question is whether cookies, pixels, mobile advertising identifiers, or server side conversion tools amount to a sale, sharing, targeted advertising, profiling, or sensitive data issue under state law.
California treats sharing personal information for cross context behavioral advertising as a regulated activity. Texas, Colorado, Connecticut, Virginia, and other states provide consumers with opt out rights for targeted advertising. A site using Meta Pixel, Google advertising tags, affiliate pixels, data clean rooms, customer match tools, or session replay tools deserves a tool by tool inventory. Identify what each tool collects, where the data goes, whether the vendor acts as a service provider or a third party, and whether the consent or opt out mechanism covers it.
Analytics alone may require fewer disclosures than retargeting or data enrichment. Health, financial, location, biometric, and children's data can change the answer. You should review the tool configuration, not just the vendor name.
What Your Policy Should Cover
Your policy should identify each category of personal information the business collects, including account information, contact information, purchase history, payment related information, device data, browser data, geolocation, communications, inferences, user generated content, and sensitive data if your product collects it.
For each category, the policy should state the purpose for collection and use. Common purposes include providing the service, processing transactions, customer support, fraud prevention, security, analytics, personalization, marketing, legal compliance, and product improvement. If you use data for targeted advertising, profiling, automated decisions, or data sales, the policy should say so in terms a consumer can understand.
The policy should name recipients by category. Service providers, payment processors, hosting providers, analytics providers, advertising partners, affiliates, professional advisers, regulators, and transaction counterparties don't all serve the same role. The policy should distinguish vendors that process data for you from third parties that use data for their own purposes.
State privacy rights should track the states where those rights apply. Access, deletion, correction, portability, opt out of sale, opt out of sharing, opt out of targeted advertising, opt out of certain profiling, limitation of sensitive data use, appeal rights, and nondiscrimination rights don't apply the same way everywhere. A single rights section can work, but it should avoid giving rights to users who don't have them or withholding rights from users who do.
The policy should describe how long the business retains personal information or the criteria used to set retention periods. Some laws require retention disclosures, and regulators expect retention claims to match practice. If you say you keep data only as long as needed, you should know who determines the period, which systems delete the data, which backups retain it, and which legal or tax obligations justify longer retention.
The Risk in Templates
Copying a privacy policy can expose a business faster than silence. If a template says the business doesn't sell personal information while the site shares hashed emails with an advertising platform, the template turns a tracking issue into a misrepresentation issue. If it promises deletion on request while the vendor stack can't delete the data, the promise becomes the problem.
Drafting starts with an inventory of what the website collects through forms, accounts, checkout, analytics, cookies, pixels, chat widgets, newsletter tools, customer relationship management systems, payment processors, app software development kits, and customer support tools. Describe that system in plain language.
Privacy policies are operating documents. Keep the policy accurate on the day it is posted and update it whenever a new tool, vendor, pixel, or data use changes the system.
Related practice area: Privacy Law
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry