Privacy Policies for Online Businesses and Platform Requirements
Federal law regulates privacy by sector and practice rather than through one statute requiring every U.S. website to publish a privacy policy. State laws, FTC enforcement, app stores, advertising platforms, and payment processors often require one. If your site collects email addresses, analytics identifiers, purchase records, location data, device identifiers, advertising data, or account information, the policy should describe the system that collects and uses it.
A privacy policy is the public version of your data map. It describes what your business collects, why you collect it, which parties receive it, how long you retain it, and how consumers exercise applicable rights. The policy also becomes evidence when the written description and the operating product diverge.
A Privacy Policy Is a Representation
Section 5 of the FTC Act prohibits unfair or deceptive acts or practices. A business risks a deception claim when its privacy policy overstates privacy protections, understates tracking, omits advertising disclosures, or describes security measures that the business hasn't implemented.
In 2023, the FTC finalized an order against BetterHelp. The order required the online counseling service to pay $7.8 million for consumer refunds and prohibited it from sharing health data for advertising. The FTC alleged that BetterHelp disclosed sensitive health information to advertising platforms after promising to keep that information private.
In 2024, the FTC finalized an order against Avast requiring $16.5 million in monetary relief. The agency alleged that Avast promised to protect users from online tracking while collecting and selling detailed browsing data through its Jumpshot subsidiary. The order restricts Avast's sale, disclosure, and use of browsing data for advertising.
Both FTC orders concern the relationship between written promises and operating systems. Before your policy says that your business doesn't sell or share personal information, you should map how your advertising, analytics, retargeting, and data enrichment tools work. You should also confirm what each vendor receives and how each vendor uses the information.
California Often Starts the Review
California's Online Privacy Protection Act, commonly called CalOPPA, applies to operators of commercial websites and online services that collect personally identifiable information online from California consumers. The statute doesn't depend on the operator's location.
CalOPPA requires a conspicuously posted privacy policy. The policy must identify the categories of personally identifiable information collected and the categories of third parties with whom the operator may share it. The policy must also state its effective date, explain how consumers receive notice of material changes, and describe any process the operator maintains for reviewing or changing personal information.
Additional disclosures address online tracking. The policy must explain how the operator responds to browser Do Not Track signals or similar mechanisms when the operator tracks consumers over time and across third party websites. It must also disclose whether other parties collect personally identifiable information about a consumer's online activities over time and across different websites.
A homepage link using the word privacy usually satisfies the conspicuous posting requirement when its presentation makes the link noticeable. An online service must make the policy reasonably accessible to consumers. After notice of noncompliance, an operator has 30 days to post a compliant policy. California has pursued CalOPPA violations through the Unfair Competition Law, which authorizes civil penalties of up to $2,500 for each violation.
The CCPA Applies by Threshold
The California Consumer Privacy Act applies to a for profit business that does business in California, determines the purposes and means of processing consumers' personal information, and meets a statutory threshold. Current thresholds include annual gross revenue of at least $26,625,000 or buying, selling, or sharing the personal information of at least 100,000 California consumers or households. A business that derives at least 50% of annual revenue from selling or sharing California consumers' personal information also qualifies.
A covered business must describe its online and offline information practices and explain the rights available to California consumers. The required disclosures include categories of personal information collected, sources, purposes, categories sold or shared, categories disclosed for a business purpose, recipient categories, and instructions for exercising rights. Those collection, sale, sharing, and business purpose disclosures address the preceding 12 months. A business must update the policy at least once every 12 months.
A business that sells or shares personal information must honor qualifying opt out preference signals, including Global Privacy Control. In most circumstances, it must also provide a clear and conspicuous link labeled Do Not Sell or Share My Personal Information, Your Privacy Choices, or Your California Privacy Choices. A business that uses or discloses sensitive personal information beyond the purposes permitted by statute must provide a method for consumers to limit that use or disclosure. California's current guidance explains when these links and rights apply.
California's 2025 regulation package requires careful timing. The regulations became effective January 1, 2026, and businesses subject to the risk assessment requirements began complying on that date. The first cybersecurity audit certifications are due April 1, 2028. Businesses subject to the automated decisionmaking technology requirements must comply beginning January 1, 2027. The California Privacy Protection Agency's implementation schedule controls those dates.
Texas Requires a Separate Analysis
The Texas Data Privacy and Security Act took effect July 1, 2024. Chapter 541 applies to a person that conducts business in Texas or produces a product or service consumed by Texas residents and processes or sells personal data. The statute excludes a person that qualifies as a small business under the Small Business Administration definition, except for the sensitive data sale rule described below. Other entity and data exemptions may apply.
Small businesses receive a broad exemption, with one important exception. A small business must obtain a consumer's consent before selling that consumer's sensitive personal data.
A covered controller must provide a reasonably accessible and clear privacy notice. The notice must identify the categories of personal data processed, the purposes for processing, the methods for exercising rights, and the appeal process. It must also identify the categories of personal data shared with third parties and the categories of third parties that receive the data. A controller that sells sensitive or biometric data must include the statute's prescribed notice in the same location and manner as the privacy notice.
Texas also requires data minimization, reasonable security practices, consent before processing sensitive data, and opt out rights for targeted advertising, data sales, and certain profiling. The Texas Attorney General has exclusive enforcement authority. A violation that continues after the 30 day cure period, or a breach of the required cure statement, is subject to a civil penalty of up to $7,500 for each violation. The Attorney General's TDPSA overview summarizes the duties and enforcement process.
Other State Laws Change the Analysis
Comprehensive state privacy laws require a state by state review. They use different thresholds, exemptions, definitions of sensitive data, appeal procedures, targeted advertising rules, cure periods, and enforcement structures. A fixed state count or list soon becomes outdated and doesn't answer whether a particular law covers your business.
A multistate policy may combine disclosures where the laws align and separate them where they differ. Your policy should use sale terminology only where the governing statute treats the disclosure as a sale, state California rights for covered consumers, and address each additional state's requirements separately. A review of state privacy laws beyond Texas should determine which rights and disclosures belong in your policy.
App Store Rules Require a Policy
App store rules apply independently of state privacy law thresholds. Apple's App Review Guidelines require every app to include a privacy policy link in App Store Connect and in an easily accessible location inside the app. The policy must identify the data collected, collection methods, uses, third party sharing, retention and deletion practices, and methods for revoking consent or requesting deletion.
Google Play's User Data policy requires every app to provide a privacy policy in Play Console and inside the app. The policy must describe access, collection, use, and sharing of user data, along with developer information, a privacy contact, security practices, retention, and deletion. Developers must also complete and maintain an accurate Data safety section that accounts for data practices in the app and its software development kits.
Advertising platforms, payment processors, app software development kits, ecommerce tools, and analytics vendors also impose contractual requirements. If you use customer list matching, retargeting pixels, embedded checkout, mobile software development kits, or conversion APIs, you should review the applicable platform terms before launch. A platform may reject an app or restrict an account even when no regulator has contacted the business.
Reviewing Cookies and Pixels
U.S. cookie compliance generally centers on disclosure, consent or opt out rights, and consumer protection law. Your legal analysis should determine whether cookies, pixels, mobile advertising identifiers, session replay tools, or server conversion tools constitute a sale, sharing, targeted advertising, profiling, or sensitive data processing under applicable state law.
California regulates sharing for cross context behavioral advertising. Texas and other states give consumers rights to opt out of targeted advertising. If your site uses Meta Pixel, Google advertising tags, affiliate pixels, customer matching, data clean rooms, or session replay tools, you should inventory each tool's data practices. You should identify what each tool collects, where the information goes, how the recipient uses it, and whether your consent or opt out mechanism covers the activity.
Analytics and retargeting serve different purposes and often require different disclosures. Health, financial, location, biometric, and children's data also change the legal analysis. You should review each tool's configuration and data flow rather than relying on its product name.
What Your Policy Should Cover
Your policy should identify each category of personal information the business collects. Depending on the product, those categories may include contact information, account information, purchase history, payment information, device and browser data, geolocation, communications, inferences, user content, and sensitive data.
For each category, the policy should state the purposes for collection and use. Those purposes may include providing the service, processing transactions, supporting customers, preventing fraud, maintaining security, analyzing use, personalizing features, marketing, complying with law, and improving the product. If you use personal information for targeted advertising, profiling, automated decisions, or data sales, the policy should describe that use in plain language.
The policy should identify recipients by category and distinguish their roles. Service providers, payment processors, hosting providers, analytics providers, advertising partners, affiliates, professional advisers, regulators, and transaction counterparties don't all use information on the same terms. Your contracts and technical settings should support the roles described in the policy.
A rights section should correspond to the jurisdictions where each right applies. Access, deletion, correction, portability, sale and sharing opt outs, targeted advertising opt outs, profiling rights, sensitive data restrictions, appeals, and nondiscrimination rights differ among states. A single rights section works only when it preserves those differences.
Your policy should state how long you retain personal information or explain the criteria used to determine retention periods. A statement that data remains only as long as necessary requires operational support. You should identify who sets each period, which systems perform deletion, how backups operate, and which legal or tax duties require longer retention.
The Risk in Templates
Copying a privacy policy may turn an undisclosed data practice into a written misrepresentation. A template may say that the business doesn't sell or share personal information while advertising tools transmit identifiers to another company. It may also promise deletion on request while the business lacks a process for deleting data from vendor systems.
Drafting should begin with an inventory of forms, accounts, checkout systems, analytics, cookies, pixels, chat widgets, newsletter tools, customer relationship management systems, payment processors, app software development kits, and support tools. You should then describe the resulting data flows in plain language.
Privacy policies are operating documents. You should confirm their accuracy when you publish them and review them whenever a new tool, vendor, disclosure, or use changes the system.
Related practice area: Privacy Law
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry