Most small business websites are required by law to have a privacy policy, and many also need a cookie consent notice. Here is what you need to know and what to do about it.
- Every website that collects personal information (contact forms, email signups, analytics) likely needs a privacy policy
- Over 20 U.S. states now have comprehensive privacy laws on the books, with more on the way
- California’s CalOPPA applies to any business collecting data from California residents, with no size exemption
- Cookie consent notices are required if your site uses analytics, advertising pixels, or other non-essential tracking
- Penalties for non-compliance range from thousands of dollars per violation to lawsuits from consumers
- Keeping policies current is an ongoing requirement, not a one-time task
- Professional solutions make compliance affordable and automatic
Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and vary by jurisdiction. Consult a qualified attorney for guidance specific to your business.
If your business has a website with a contact form, collects email addresses, runs Google Analytics, or accepts online payments, the short answer is: yes, you almost certainly need a privacy policy. And depending on what tracking tools your site uses, you may need a cookie consent notice too.
Many small business owners assume privacy laws only apply to large corporations or tech companies. That is not the case. Privacy regulations have expanded significantly over the past few years, and enforcement agencies are actively investigating businesses of all sizes.
Here is what you should understand and what you can do about it.
What Counts as “Collecting Personal Information”?
You might think your website does not collect much data. But if any of the following are true, you are collecting personal information:
- Your site has a contact form that asks for a name, email, or phone number
- You use Google Analytics or any analytics tool that tracks visitor behavior
- Your site has an email signup or newsletter subscription
- You accept online payments through any payment processor
- You use Facebook Pixel, Google Ads tags, or any advertising tracking code
- Your site uses cookies for any purpose beyond basic functionality
If even one of these applies, your website is collecting personally identifiable information (PII). And once you are collecting PII, privacy laws start to apply.
Why Privacy Laws Apply to Small Businesses
There is a common misconception that privacy regulations are only for big companies. While some laws do have revenue or data-volume thresholds, others apply broadly to any business with a website.
CalOPPA Has No Size Threshold
California’s Online Privacy Protection Act (CalOPPA) requires any website or online service that collects personally identifiable information from California residents to post a conspicuous privacy policy. There is no revenue minimum, no employee count, and no data-volume threshold. If your website collects personal information and a single California resident visits it, CalOPPA applies to you.
20+ States Now Have Comprehensive Privacy Laws
As of mid-2026, more than 20 U.S. states have enacted comprehensive consumer privacy laws, including California, Virginia, Colorado, Connecticut, Texas, Oregon, Minnesota, Maryland, and many others. Several additional states have laws taking effect in 2026 and 2027.
Each law has slightly different thresholds and requirements, but most share common elements:
- Consumer rights to access, correct, and delete personal data
- Opt-out rights for targeted advertising and data sales
- Transparency requirements through published privacy policies
- Reasonable security measures to protect stored data
Texas is worth noting specifically. The Texas Data Privacy and Security Act (TDPSA) has no revenue or volume threshold for most of its requirements. It applies to any business that conducts business in Texas or serves Texas residents and processes personal data.
GDPR Reaches Beyond Europe
If any visitor from the European Union or European Economic Area lands on your website, the General Data Protection Regulation (GDPR) can apply. Even a single EU visitor can trigger obligations. GDPR requires a clear, plain-language privacy policy that details what data you collect, why you collect it, how long you keep it, and how visitors can exercise their rights.
The Bottom Line on Applicability
For a small business with a website that serves customers across the United States, the practical reality is that at least one (and probably several) privacy laws apply to you. The safest approach is to maintain a comprehensive privacy policy that addresses the requirements of all applicable laws.
What About Cookie Consent?
Cookies and tracking technologies add another layer of compliance. If your website uses Google Analytics, Facebook Pixel, advertising tags, or even embedded YouTube videos, your site is placing cookies on visitors’ browsers.
In the United States, several state privacy laws require you to disclose your cookie usage and provide opt-out options, particularly for cookies used in targeted advertising.
Under GDPR and UK regulations, the requirements are stricter. Websites must get active consent from visitors before placing any non-essential cookies. A simple “This site uses cookies” banner is not enough. You need a mechanism that blocks non-essential tracking until the visitor opts in.
For most small business websites, this means:
- A cookie policy that explains what cookies your site uses and why
- A cookie consent banner that gives visitors the ability to accept or decline non-essential cookies
- Actual enforcement of those preferences (non-essential cookies should not load until consent is given)
What Happens If You Do Not Have a Privacy Policy?
Skipping a privacy policy is not just a technicality. There are real consequences:
Financial penalties. Fines vary by law, but they add up quickly. Under the CCPA, penalties can reach $2,663 per unintentional violation and $7,988 per intentional violation. Under GDPR, fines can reach up to €20 million or 4% of global annual revenue, whichever is higher. Even state-level enforcement actions against small businesses have resulted in fines of $100,000 or more.
Consumer lawsuits. Some privacy laws, including California’s CCPA, grant consumers a private right of action. That means individual consumers can sue your business for damages, typically between $100 and $750 per incident in data breach cases.
Lost trust. Nearly half of American consumers say they have stopped buying from a company over privacy concerns. A missing privacy policy signals to visitors that your business may not take their data seriously.
Platform and partner issues. Google, Facebook, Apple, and many advertising platforms require websites to have a privacy policy in order to run ads or use their services. Without one, you may lose access to tools your business depends on.
A Privacy Policy Is Not a One-Time Task
Even if you have a privacy policy today, keeping it current is an ongoing obligation. Privacy laws are changing constantly. New state laws are going into effect every year, existing laws are being amended, and enforcement priorities are shifting.
California’s CCPA requires businesses to update their privacy policy at least once every 12 months. Other laws have similar expectations. If your policy references outdated practices or fails to account for new legal requirements, it may not protect you even if it exists on your website.
This is one of the most common gaps we see when working with small business websites. The site has a privacy policy, but it was written three years ago and has not been touched since. That policy may be doing more harm than good if it no longer reflects current requirements.
What Can You Handle In-House?
Writing a basic privacy policy from scratch is possible, but it requires understanding which laws apply to your business, what disclosures each law requires, and how to keep the policy updated as laws change. For most small business owners, that is not a realistic use of time.
There are a few options:
- Hire an attorney to draft a custom privacy policy. This can cost anywhere from $500 to $3,000 or more, and you will likely need to pay again whenever laws change.
- Use a free template. Some free privacy policy templates exist online, but they tend to be generic and may not address the specific laws that apply to your business. They also will not update themselves.
- Use a professional policy generator. Services like Termageddon take a different approach. You answer questions about your business and website, and the tool generates a compliant privacy policy, terms of service, cookie policy, and cookie consent solution tailored to your specific situation. Founded by a licensed privacy attorney and recognized by the International Association of Privacy Professionals (IAPP), Termageddon covers dozens of privacy laws including GDPR, CCPA/CPRA, CalOPPA, VCDPA, and all the new state laws going into effect.
The real advantage of a tool like Termageddon is automatic updates. When privacy laws change or new laws go into effect, your policies update automatically through an embed code on your website. You do not have to monitor legislation or pay an attorney to rewrite your policy every time something changes.
How We Help Our Clients Stay Compliant
At B. McGuire Marketing, we include privacy policy and cookie consent setup as part of our website services. We use Termageddon to generate and maintain compliant policies for our clients’ websites because it is the most comprehensive solution we have found, and the automatic updates mean our clients stay protected without having to think about it.
The cost works out to less than 50 cents per day for a complete set of auto-updating website policies: privacy policy, terms of service, cookie policy, cookie consent, and disclaimer. That is a small price compared to the cost of a single compliance violation.
If your website does not have a privacy policy or cookie consent notice, or if you are not sure whether your current policy is up to date, we would be happy to help. Call or text us at (404) 689-1331 to learn more about how we can get your website compliant.
Does my business need a privacy policy if I only operate in one state?
Probably, yes. Your website is accessible to visitors from every state and potentially from other countries. Laws like CalOPPA in California apply based on where your visitors are located, not where your business is based. If a single California resident fills out your contact form, CalOPPA requires you to have a privacy policy. Given the number of state privacy laws now in effect, operating in just one state does not limit your exposure.
Is a cookie consent banner the same as a cookie policy?
No. A cookie consent banner is the visible notice that appears when someone visits your site, giving them the option to accept or decline non-essential cookies. A cookie policy is the full document that explains what cookies your site uses, what they do, and how visitors can manage them. Most compliance frameworks require both: the banner to collect consent and the policy to provide transparency.
Can I just copy a privacy policy from another website?
This is not a good idea. Every business collects different types of data, uses different tools, and may be subject to different laws. A privacy policy copied from another site will not accurately reflect your practices, which can create more legal risk than having no policy at all. Privacy laws require that your policy be accurate and specific to your business.