Business guide

Is a Privacy Policy Required by Law?

Short answer: There is no single global law that says every website must have a privacy policy, but in practice most businesses that collect personal data are required to publish one under CalOPPA, GDPR, CCPA/CPRA, sector rules, or platform policies. Treat "required by law" as a patchwork — if you have users, analytics, or checkout, you are probably in scope.

United States federal landscape

The US does not have one comprehensive federal privacy law for all websites. Instead, sector and state rules stack:

  • CalOPPA (California) — Requires a conspicuous privacy policy if you collect PII from California residents, including online identifiers and cookies in many interpretations
  • COPPA — Requires privacy practices disclosure for services directed to children under 13
  • GLBA, HIPAA, FCRA — Sector-specific notice requirements for financial, health, and credit data
  • FTC Act — Prohibits deceptive practices; privacy statements must match actual data handling

State comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, and others) add rights and disclosure duties similar to CCPA for covered businesses.

GDPR and UK GDPR

If you offer goods or services to people in the EU/UK or monitor their behavior (including analytics on EU visitors), GDPR applies. A privacy notice is mandatory. It must describe lawful bases, retention, transfers, and user rights in clear language.

US companies without EU offices still fall in scope when they target EU customers or track EU users.

CCPA and CPRA (California)

The California Consumer Privacy Act and its CPRA amendments require businesses meeting revenue or data-volume thresholds to provide detailed notices, honor opt-out rights, and disclose sale/sharing of personal information. Even below thresholds, CalOPPA still applies to collection disclosures.

App stores and payment platforms

Apple App Store and Google Play require privacy policy URLs for most apps. Stripe, PayPal, and enterprise procurement teams routinely request legal pages before go-live. These are contractual requirements with the same practical effect as law.

What happens without a privacy policy

RiskConsequence
Regulatory enforcementFines under GDPR, CCPA, and state AG actions
App rejectionStore review delays or removal
Payment processor holdOnboarding blocked until legal pages exist
Enterprise salesSecurity questionnaires fail
Customer trustHigher bounce, support tickets, chargebacks

Missing a policy does not automatically mean penalties — but false or outdated policies can be worse than none under deceptive practices theories.

"Required" vs "good practice"

Even when a specific statute might not apply to your size or data types, publishing an accurate privacy policy is baseline trust infrastructure. Customers, partners, and search engines expect a footer link.

Clerica's approach: generate standard-depth language from your factual inputs, score clarity on a public rubric, and optionally certify with integrity monitoring so drift is visible — not hidden in a PDF from launch day.

Next steps

  1. Map what data you actually collect today — not what you plan to collect someday
  2. Generate a draft with the Privacy Policy Generator
  3. Link it in your site footer and signup flows
  4. Update when vendors or product features change

Related: Do I need a privacy policy on my website? · What is a privacy policy? · Compare policy generators · Business FAQ

Clerica does not provide legal advice. Confirm applicability with qualified counsel in your jurisdictions.

Publish with proof

Generate policies customers can verify

Use Clerica's free generator for privacy and terms, see your clarity rubric score, and upgrade to Certified when you want Verified directory placement and integrity monitoring.

Generate a policy free
← All guides