Short answer: There is no single global law that says every website must have a privacy policy, but in practice most businesses that collect personal data are required to publish one under CalOPPA, GDPR, CCPA/CPRA, sector rules, or platform policies. Treat "required by law" as a patchwork — if you have users, analytics, or checkout, you are probably in scope.
United States federal landscape
The US does not have one comprehensive federal privacy law for all websites. Instead, sector and state rules stack:
- CalOPPA (California) — Requires a conspicuous privacy policy if you collect PII from California residents, including online identifiers and cookies in many interpretations
- COPPA — Requires privacy practices disclosure for services directed to children under 13
- GLBA, HIPAA, FCRA — Sector-specific notice requirements for financial, health, and credit data
- FTC Act — Prohibits deceptive practices; privacy statements must match actual data handling
State comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, and others) add rights and disclosure duties similar to CCPA for covered businesses.
GDPR and UK GDPR
If you offer goods or services to people in the EU/UK or monitor their behavior (including analytics on EU visitors), GDPR applies. A privacy notice is mandatory. It must describe lawful bases, retention, transfers, and user rights in clear language.
US companies without EU offices still fall in scope when they target EU customers or track EU users.
CCPA and CPRA (California)
The California Consumer Privacy Act and its CPRA amendments require businesses meeting revenue or data-volume thresholds to provide detailed notices, honor opt-out rights, and disclose sale/sharing of personal information. Even below thresholds, CalOPPA still applies to collection disclosures.
App stores and payment platforms
Apple App Store and Google Play require privacy policy URLs for most apps. Stripe, PayPal, and enterprise procurement teams routinely request legal pages before go-live. These are contractual requirements with the same practical effect as law.
What happens without a privacy policy
| Risk | Consequence |
|---|---|
| Regulatory enforcement | Fines under GDPR, CCPA, and state AG actions |
| App rejection | Store review delays or removal |
| Payment processor hold | Onboarding blocked until legal pages exist |
| Enterprise sales | Security questionnaires fail |
| Customer trust | Higher bounce, support tickets, chargebacks |
Missing a policy does not automatically mean penalties — but false or outdated policies can be worse than none under deceptive practices theories.
"Required" vs "good practice"
Even when a specific statute might not apply to your size or data types, publishing an accurate privacy policy is baseline trust infrastructure. Customers, partners, and search engines expect a footer link.
Clerica's approach: generate standard-depth language from your factual inputs, score clarity on a public rubric, and optionally certify with integrity monitoring so drift is visible — not hidden in a PDF from launch day.
Next steps
- Map what data you actually collect today — not what you plan to collect someday
- Generate a draft with the Privacy Policy Generator
- Link it in your site footer and signup flows
- Update when vendors or product features change
Related: Do I need a privacy policy on my website? · What is a privacy policy? · Compare policy generators · Business FAQ
Clerica does not provide legal advice. Confirm applicability with qualified counsel in your jurisdictions.