Do You Need a Privacy Policy for Your Small Business Website?
Short answer: almost certainly yes, but not necessarily for the reason you'd guess. Here's the honest version, including the parts most guides skip.
Last updated: August 2026
The short answer
If your website collects any personal information at all, a name, an email address, even just analytics data through a tool like Google Analytics, you're in territory where a privacy policy is expected, and often required. The complicated part isn't whether you need one. It's which specific laws apply to your specific business, and that depends on where your visitors are, what you collect, and how big your business is.
The state privacy law patchwork
As of 2026, more than 20 US states have passed comprehensive consumer privacy laws, on top of the EU's GDPR and California's older CalOPPA and newer CCPA/CPRA. Most of those state laws set a size threshold before they apply: commonly something like $25 million or more in annual revenue, or handling personal data for 100,000 or more consumers a year. Most small businesses fall below those thresholds.
That's the part a lot of guides leave out: falling below a state law's threshold doesn't mean no law applies to you. It just means that particular law doesn't.
What still applies if you're below the threshold
Three things commonly apply regardless of your size:
- CalOPPA. California's Online Privacy Protection Act requires a conspicuously posted privacy policy from any commercial website collecting personal information from California residents, with no revenue or size threshold. If you have any California visitors, and most public websites do, this one applies to you.
- Sector-specific federal laws. COPPA (children's data), HIPAA (health data), and similar laws apply based on what you collect and who you serve, not your revenue.
- Third-party tool requirements. Google Analytics, Google AdSense, Stripe, and most other tools you're likely already using require you to have a privacy policy as a condition of using their service, independent of what any government law requires.
In practice, that combination means the vast majority of public business websites need a privacy policy, whether or not any single comprehensive state law technically applies to them.
When you clearly need one, no ambiguity
- You have a contact form, email signup, or any way for visitors to submit their information
- You use Google Analytics, Google AdSense, or any similar tracking or advertising tool
- You sell anything online, or process payments in any form
- You have visitors from California, the EU, or the UK (most public websites do, even unintentionally)
- You collect information from anyone under 13
If none of these apply, meaning your site is genuinely static with zero data collection of any kind, you may be one of the rare exceptions. That's an uncommon situation for an active business website in 2026.
Frequently asked questions
My business is too small for any of this to apply to me, right?
Size alone doesn't exempt you the way many business owners assume. CalOPPA has no revenue threshold, and your own third-party tools (analytics, ad networks, payment processors) typically require a privacy policy regardless of your size.
Do I need a different privacy policy for each state?
No. A single, well-written privacy policy that accounts for the strictest requirements you're likely to encounter (typically GDPR and CCPA/CPRA) generally covers you across the patchwork, rather than needing separate state-by-state versions.
What happens if I just don't have one?
Consequences range from a mismatched-expectations problem with users to real regulatory exposure, depending on which laws actually apply to your business. Beyond legal risk, not having one is also a fairly visible trust signal to visitors who go looking for it and find nothing.
Related reading: what GDPR and CCPA actually require, once you've confirmed one or both apply to you.
Sources
- California Online Privacy Protection Act (CalOPPA), Cal. Bus. & Prof. Code §§ 22575–22579
- General overview of the 2026 US state comprehensive privacy law landscape (20+ states), cross-referenced across multiple current legal and compliance-industry sources as of August 2026
The count of states with comprehensive privacy laws changes as new legislation passes. This page describes the general landscape as of the date above, not a specific state-by-state legal determination for your business. Verify your specific obligations with a lawyer, especially if you're near any revenue or data-volume threshold.