Privacy Policy Requirements: What You Must Include (2026)
A privacy policy is not optional for most websites and apps operating in the United States or serving users in the European Union. Federal law, state statutes, and international regulations all impose specific disclosure requirements, and the consequences of getting it wrong range from regulatory fines to class action lawsuits. This guide breaks down what the law actually requires, jurisdiction by jurisdiction.
Federal Privacy Policy Requirements
The United States lacks a single, comprehensive federal privacy law. Instead, privacy policy obligations come from a patchwork of sector-specific statutes and regulatory enforcement actions.
FTC Act (Section 5)
The Federal Trade Commission enforces privacy policy compliance primarily through Section 5 of the FTC Act, which prohibits "unfair or deceptive acts or practices." The FTC does not require companies to have a privacy policy, but if a company publishes one, it must follow it. Failing to honor the promises in your privacy policy constitutes a deceptive practice.
The FTC has brought hundreds of enforcement actions against companies for privacy policy violations, resulting in consent orders, multi-million dollar penalties, and mandatory compliance programs. In 2024 alone, the FTC pursued actions against companies for overpromising data deletion, misrepresenting data sharing practices, and using dark patterns to obtain consent.
COPPA (Children's Online Privacy)
The Children's Online Privacy Protection Act (15 USC 6501-6506) imposes the most prescriptive federal privacy policy requirements. Websites and online services directed at children under 13 (or those with actual knowledge they collect data from children under 13) must include a privacy policy that clearly discloses:
- All categories of personal information collected from children
- How the information is used
- Whether information is disclosed to third parties (and to whom)
- A description of parental rights, including the right to review, delete, and refuse further collection
- Contact information for the site operator
- The effective date of the policy
Under the COPPA Rule (16 CFR Part 312), operators must obtain verifiable parental consent before collecting, using, or disclosing a child's personal information. The privacy policy must link directly from the homepage and any page where information is collected from children.
The FTC can impose penalties of up to $50,120 per violation (adjusted for inflation as of 2024) for COPPA violations.
HIPAA (Health Privacy)
The Health Insurance Portability and Accountability Act requires covered entities (healthcare providers, health plans, and healthcare clearinghouses) to provide a Notice of Privacy Practices to patients. This notice must explain how protected health information (PHI) may be used and disclosed, patient rights regarding their PHI, and the entity's legal duties (45 CFR 164.520).
GLBA (Financial Privacy)
The Gramm-Leach-Bliley Act requires financial institutions to provide clear, conspicuous privacy notices explaining their information-sharing practices. The Privacy Rule (Regulation P) mandates annual privacy notices to customers and initial notices to new customers before sharing nonpublic personal information.
California Privacy Policy Requirements
California leads the nation in privacy policy regulation, with multiple overlapping statutes that effectively set the standard for businesses operating online in the US.
CalOPPA (California Online Privacy Protection Act)
CalOPPA (Cal. Bus. & Prof. Code 22575-22579) was the first US law to require commercial websites and online services to post a privacy policy. Its reach extends beyond California: any operator that collects personally identifiable information from California consumers must comply, regardless of where the business is located.
CalOPPA requires the privacy policy to:
- Identify the categories of PII collected and the categories of third parties with whom it may be shared
- Describe the process for notifying users of material changes to the policy
- Identify its effective date
- Disclose how the operator responds to Do Not Track signals
- Disclose whether third parties may collect PII about users' online activities across different websites
- Be conspicuously posted (linked from the homepage using the word "privacy")
Violations of CalOPPA can be enforced by the California Attorney General, with penalties of up to $2,500 per violation after a 30-day cure period.
CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act)
The CCPA, as amended by the CPRA (effective January 1, 2023), imposes the most detailed privacy policy requirements of any US state law. Under Cal. Civ. Code 1798.100(b), businesses that meet the applicability thresholds must disclose in their privacy policy:
Categories of personal information collected in the preceding 12 months, organized by the statutory categories (identifiers, commercial information, internet activity, geolocation, biometric data, professional information, education information, inferences, and sensitive personal information).
Purposes of collection for each category. Generic statements like "to improve our services" are insufficient. The CCPA requires specificity about each business or commercial purpose.
Sources of personal information. Businesses must identify the categories of sources from which personal information is collected.
Third-party sharing and selling. The policy must disclose whether personal information is sold or shared for cross-context behavioral advertising, which categories are sold or shared, and to which categories of third parties.
Retention periods. The CPRA added a requirement to disclose the retention period for each category of personal information, or the criteria used to determine the period (Cal. Civ. Code 1798.100(a)(3)).
Consumer rights. The policy must describe the right to know, right to delete, right to correct, right to opt out of sale/sharing, and right to limit use of sensitive personal information, along with instructions for exercising each right.
Do Not Sell link. Businesses that sell or share personal information must include a "Do Not Sell or Share My Personal Information" link on their homepage.
The California Privacy Protection Agency (CPPA) and the California Attorney General can impose penalties of $2,500 per unintentional violation and $7,500 per intentional violation or violation involving minors' data.
California's Age-Appropriate Design Code Act
Effective July 1, 2024 (though enforcement was temporarily enjoined), the CAADCA adds requirements for businesses offering online services likely to be accessed by children under 18. Privacy policies must include a data protection impact assessment for features likely to be accessed by minors.
Other State Privacy Policy Requirements
Colorado Privacy Act
Colorado's CPA (effective July 1, 2023) requires controllers to provide a privacy notice that includes: categories of personal data processed, purposes, consumer rights (access, delete, correct, opt out), categories of third parties receiving data, and how to exercise rights. Notably, Colorado requires disclosure of profiling activities and the right to opt out of profiling for decisions with legal or similarly significant effects.
Virginia Consumer Data Protection Act
Virginia's VCDPA (effective January 1, 2023) requires privacy notices covering: categories of data processed, purposes, consumer rights (access, delete, correct, portability, opt out of targeted advertising/sale/profiling), a description of the appeals process if a rights request is denied, and categories of third parties receiving data.
Connecticut, Utah, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, and Others
As of early 2026, over 15 US states have enacted comprehensive privacy laws with privacy policy requirements. See the full US state privacy laws comparison for details. While the specifics vary, most follow the same general template: disclose what you collect, why, who you share it with, how long you keep it, and what rights consumers have. The trend is toward increasing granularity, with newer laws adding requirements for sensitive data disclosures, automated decision-making transparency, and minors' data protections.
GDPR Privacy Policy Requirements
The GDPR imposes the most detailed privacy notice requirements of any global framework. Articles 13 and 14 specify what must be disclosed depending on whether data is collected directly from the data subject or obtained from a third party.
Article 13 (Direct Collection) Requirements
When collecting personal data directly from the data subject, the controller must provide:
- Identity and contact details of the controller (and representative, if applicable)
- Contact details of the DPO (if one exists)
- The purposes of processing and the legal basis for each purpose
- Legitimate interests relied upon (if using that basis)
- Recipients or categories of recipients of the data
- Whether data will be transferred to a third country and the safeguards in place
- Retention period (or criteria for determining it)
- All data subject rights: access, rectification, erasure, restriction, portability, objection
- Right to withdraw consent (if consent is the legal basis)
- Right to lodge a complaint with a supervisory authority
- Whether provision of data is a statutory or contractual requirement
- Existence of automated decision-making, including profiling, with meaningful information about the logic, significance, and consequences
Article 14 (Indirect Collection) Additions
When data is obtained from a source other than the data subject, the controller must additionally disclose the categories of personal data obtained and the source of the data.
Plain Language Requirement
Article 12 requires that all of this information be provided in a "concise, transparent, intelligible and easily accessible form, using clear and plain language." Privacy policies written in dense legal jargon violate this requirement. Several data protection authorities (notably France's CNIL and Ireland's DPC) have cited lack of transparency as the basis for enforcement actions.
GDPR Penalties
Failure to provide adequate transparency (including an insufficient privacy policy) can result in fines of up to 20 million euros or 4% of global annual turnover under Article 83(5)(b).
Plain Language and Accessibility Requirements
Beyond the GDPR's explicit plain language mandate, several US standards and laws push toward readable privacy policies.
The FTC has repeatedly emphasized that privacy policies must be understandable to ordinary consumers. In enforcement actions, the FTC has cited buried disclosures, contradictory statements, and overly technical language as deceptive practices.
Readability benchmarks. While no US law specifies a reading level for privacy policies, best practice (and the standard used in several FTC consent orders) targets an 8th-grade reading level. For cookie-specific disclosure requirements, see our cookie banner requirements guide. Research published by Stanford University and Carnegie Mellon found that most privacy policies require a college reading level, which is well above what regulators expect.
Multi-language requirements. The GDPR requires the privacy notice to be in the language of the data subjects served. Under the CCPA, businesses must provide privacy notices "in the languages in which they provide" their products or services. California regulations specifically require that the notice be available in every language the website or app supports.
Accessibility. Under the Americans with Disabilities Act (ADA) and Section 508 of the Rehabilitation Act, privacy policies on government and publicly accessible websites should be compatible with screen readers and meet WCAG 2.1 AA standards. Several courts have extended ADA web accessibility requirements to private websites.
How Often to Update Your Privacy Policy
No US federal law specifies an update frequency. However, practical requirements effectively mandate regular reviews:
- CCPA: The policy must include the date it was last updated and must be reviewed and updated at least once every 12 months (CCPA Regulations 11 CCR 7011).
- CalOPPA: Requires description of the process for notifying users of material changes.
- GDPR: No specific update frequency, but the policy must be accurate at all times. Material changes to processing activities require updated notices.
Best practice is to review the privacy policy whenever:
- A new category of personal data is collected
- Data is shared with a new category of third parties
- A new privacy law takes effect in a jurisdiction where you operate
- Processing purposes change
- A data breach occurs that changes your security posture
Common Privacy Policy Mistakes
Several recurring errors expose businesses to enforcement risk:
Copy-paste templates. Generic privacy policy generators produce policies that may not accurately reflect the business's actual data practices. Regulators have fined companies for privacy policies that described data practices the company did not actually engage in (and vice versa).
Overpromising on data deletion. Stating that data "will be deleted upon request" without accounting for legal retention obligations, backup systems, or third-party data sharing creates a deceptive practice if the company cannot actually fulfill the promise.
Missing the "sale" definition. Under the CCPA, "sale" includes sharing personal information for monetary or "other valuable consideration." Many companies fail to disclose ad-tech partnerships, analytics sharing, and data broker relationships that constitute a "sale" under this broad definition.
Burying the opt-out. Both the CCPA and GDPR require that opt-out mechanisms and rights descriptions be easy to find. Requiring consumers to navigate through multiple pages to find opt-out links has been cited in enforcement actions.
Not covering all data sources. Privacy policies often describe website data collection but omit offline data collection, mobile app data, IoT device data, or data obtained from third-party brokers.
Sources and References
This article provides general legal information about privacy policy requirements across US and international jurisdictions. Privacy laws change frequently and vary by state and country. Consult an attorney for advice specific to your situation.
Frequently Asked Questions
Is a privacy policy legally required for all websites?
Not under federal law alone. However, CalOPPA requires any commercial website or app collecting personal information from California residents to post a privacy policy, which effectively covers most US-facing websites. If you process data from EU residents, the GDPR independently requires a privacy notice. Over 15 US states now have comprehensive privacy laws with notice requirements.
What is the penalty for not having a privacy policy?
Under CalOPPA, the California Attorney General can impose $2,500 per violation after a 30-day cure period. Under the CCPA, penalties reach $2,500 per unintentional violation and $7,500 per intentional violation. The GDPR allows fines up to 20 million euros or 4% of global annual turnover. COPPA violations carry penalties of up to $50,120 per violation.
How often should a privacy policy be updated?
The CCPA requires annual review and update. There is no specific federal frequency requirement, but best practice calls for updating whenever data collection practices change, new third-party sharing begins, or a new privacy law takes effect in a jurisdiction where you operate. The policy must always accurately reflect current practices.
Does the GDPR require a privacy policy?
The GDPR requires a 'privacy notice' or 'transparency information' under Articles 13 and 14, which functions like a privacy policy. It must disclose the identity of the data controller, DPO contact details, purposes and legal bases for processing, retention periods, data subject rights, and information about international transfers. It must be written in clear, plain language.
What must a CCPA privacy policy include?
The CCPA requires disclosure of categories of personal information collected, purposes of collection, sources of data, third-party sharing and selling practices, retention periods for each category, and a description of all consumer rights with instructions for exercising them. Businesses that sell data must include a 'Do Not Sell or Share My Personal Information' link.
Do I need a separate privacy policy for my mobile app?
Both Apple's App Store and Google Play require apps to have a privacy policy, and the policy must be accessible both within the app and on the app store listing. If your app's data practices differ from your website, a separate or supplemental policy is recommended. CalOPPA and the CCPA apply to mobile apps the same way they apply to websites.
What are the COPPA privacy policy requirements for children's sites?
COPPA requires sites directed at children under 13 to disclose all categories of data collected, how data is used, third-party sharing, parental rights (review, delete, refuse further collection), and operator contact information. The policy must link from the homepage and every page where child data is collected. Verifiable parental consent is required before collection.
Can I use a privacy policy template or generator?
Templates can provide a starting point, but regulators have fined companies for using generic policies that do not accurately describe their actual data practices. Any template must be customized to reflect the specific categories of data collected, actual sharing practices, applicable laws, and real consumer rights. A misleading privacy policy is worse than a missing one from an enforcement perspective.
Updates
Governing law re-checked for recent changes
The Law Behind This Article
This article rests on 3 statutory provisions held in our own legal record, each retrieved from the official source. Tap a section to read the operative text.
California Business and Professions Code
§ 22575In force
(a) An operator of a commercial Web site or online service that collects personally identifiable information through the Internet about individual consumers residing in California who use or visit its commercial Web site or online service shall conspicuously post its privacy policy on its Web site, or in the case of an operator of an online service, make that policy available in accordance with paragraph (5) of subdivision (b) of Section 22577. An operator shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance. (b) The privacy policy required by subdivision (a) shall do all of the following: (1) Identify the categories of personally identifiable information that the operator collects through the Web site or online service about individual consumers who use or visit its commercial Web site or online service and the categories of third-party persons or entities with whom the operator may share that personally identifiable information.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leginfo.legislature.ca.gov
California Civil Code
§ 1798.100In forcecited in 4 of our articles
General Duties of Businesses that Collect Personal Information (a) A business that controls the collection of a consumer’s personal information shall, at or before the point of collection, inform consumers of the following: (1) The categories of personal information to be collected and the purposes for which the categories of personal information are collected or used and whether that information is sold or shared. A business shall not collect additional categories of personal information or use personal information collected for additional purposes that are incompatible with the disclosed purpose for which the personal information was collected without providing the consumer with notice consistent with this section. (2) If the business collects sensitive personal information, the categories of sensitive personal information to be collected and the purposes for which the categories of sensitive personal information are collected or used, and whether that information is sold or shared.
Official text (excerpt) · as of 2026-07-28 · Read the full section at leginfo.legislature.ca.gov
Also relied on in: California Sues 23andMe's Successor Over Genetic Data Breach (2026), Employee Data Privacy: Employer Obligations by State (2026), Data Retention Laws by Country (2026): GDPR, CJEU and Global Rules
Code of Federal Regulations Title 45
§ 164.520Notice of privacy practices for protected health information.In force
(a) Standard: Notice of privacy practices —(1) Right to notice. Except as provided by paragraph (a)(3) or (4) of this section, an individual has a right to adequate notice of the uses and disclosures of protected health information that may be made by the covered entity, and of the individual's rights and the covered entity's legal duties with respect to protected health information. (2) Notice requirements for covered entities creating or maintaining records subject to 42 U.S.C. 290dd-2. As provided in 42 CFR 2.22, an individual who is the subject of records protected under 42 CFR part 2 has a right to adequate notice of the uses and disclosures of such records, and of the individual's rights and the covered entity's legal duties with respect to such records. (3) Exception for group health plans.
Official text (excerpt) · as of 2026-07-28 · Read the full section at ecfr.gov
Search our full record of US law — 1.79 million sections, every state + federal →
Sources and References
- FTC Act Section 5 - Unfair or Deceptive Acts or Practices(ftc.gov).gov
- COPPA (15 USC 6501-6506)(law.cornell.edu)
- COPPA Rule (16 CFR Part 312)(law.cornell.edu)
- HIPAA Notice of Privacy Practices (45 CFR 164.520)(law.cornell.edu)
- CalOPPA (Cal. Bus. & Prof. Code 22575)(leginfo.legislature.ca.gov).gov
- CCPA Section 1798.100(leginfo.legislature.ca.gov).gov
- CPPA Regulations (11 CCR 7011)(cppa.ca.gov).gov
- GDPR Article 13 - Transparency Requirements(gdpr-info.eu)
- GDPR Article 12 - Transparent Information and Communication(gdpr-info.eu)
- GDPR Article 83 - Administrative Fines(gdpr-info.eu)
- GLBA Privacy Rule (Regulation P)(law.cornell.edu)