HomeGuides › Law & compliance

Law & compliance

What privacy policy does a small business website actually need?

No federal law requires one. CCPA has thresholds most small shops miss. New York's SHIELD Act applies to nearly everyone. What yours needs, plus a checklist.

By BH Web Solutions · Updated 2026-07-29

Most owners have been told two contradictory things: that a privacy policy is legally mandatory, and that nobody reads them so it does not matter. Both are wrong in useful ways. Here is what actually applies to a small business website in New York, what does not, and what a policy needs to say to be worth the page it sits on.

There is no single US law requiring a privacy policy

People expect a federal statute with a clear rule. There is not one. The United States has no comprehensive federal privacy law covering ordinary commercial websites — only a patchwork, and your obligations come from whichever pieces touch your business. Four do most of the work for a small local business.

  • Sector-specific federal laws. The Health Insurance Portability and Accountability Act (HIPAA) covers health plans, health care clearinghouses, and health care providers who transmit claims and similar transactions electronically — plus the vendors that handle protected health information on their behalf, known as business associates. The Gramm-Leach-Bliley Act (GLBA) covers "financial institutions," a category broader than banks that can reach tax preparers, mortgage brokers, collection agencies, and dealers who arrange financing. The Children's Online Privacy Protection Act (COPPA) covers sites directed at children under 13, or any site with actual knowledge it is collecting from them. If none of these describe you they do not apply — but read the GLBA definition before assuming it is not you.
  • Section 5 of the FTC Act, which prohibits unfair or deceptive acts or practices. This is the sleeper. It does not require you to publish a policy. But once you publish one it reads as a promise, and a policy that materially misstates what you actually do can be treated as a deceptive practice. A policy that overstates what you do can be legally worse than no policy at all.
  • State privacy and data security laws, which vary considerably and are where most real obligations live.
  • Contracts you already signed. Google Analytics' terms of service require you to post a privacy policy disclosing your use of cookies and similar data collection. Meta's Business Tools terms impose broadly comparable notice obligations — and, where consent is legally required, a duty to obtain it — on anyone running the Meta Pixel. If you advertise on Google or Meta, or use their tracking, you agreed to have a policy. That is the most concrete "you must" most small businesses will ever meet — and it is contractual, not statutory.

When California's law actually applies to you

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), is the law people name most and understand least. It does not cover every business a Californian can reach. It has thresholds. A for-profit business is covered only if it does business in California and meets at least one of these:

  • Gross annual revenue above the statutory revenue threshold. It was written as $25 million and is adjusted for inflation every other year; the California Privacy Protection Agency set it at $26,625,000 effective January 1, 2025. Check the agency's current published figure rather than trusting a number in an article;
  • Buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year; or
  • Derives 50% or more of annual revenue from selling or sharing personal information.

A kosher grocery in Boro Park, a Monsey caterer, a two-person medical billing office — none of these is likely to hit those numbers, and most small local businesses really are outside CCPA. Two things stop that from being a guarantee. An entity that controls, is controlled by, or shares branding with a covered business can be pulled in even though it clears none of the thresholds on its own. And "doing business in California" is not limited to having an office there, so a New York shop that ships regularly to California customers should at least ask the question. Run your own numbers before concluding you are exempt.

Two caveats. If you are covered and you run a Meta Pixel or similar advertising tracker, that likely counts as "sharing" personal information for cross-context behavioral advertising, which triggers the "Do Not Sell or Share My Personal Information" link and a duty to honor opt-out preference signals such as Global Privacy Control. And CCPA's private right of action is limited to breaches caused by failure to maintain reasonable security, with statutory damages originally set at $100 to $750 per consumer per incident and adjusted for inflation to $107 to $799 as of January 2025. Everything else is enforced by the California Attorney General or the California Privacy Protection Agency, not by private plaintiffs.

More than twenty states have now enacted comprehensive privacy laws — Virginia, Colorado, Connecticut, Texas and Oregon among them, with roughly twenty in force and later ones still phasing in — mostly with thresholds in the same neighborhood: around 100,000 state residents' data in a year, or a smaller number combined with revenue derived from selling data. Texas is the structural exception, exempting businesses that meet the US Small Business Administration's small-business definition instead of using a numeric threshold, while still barring even an exempt small business from selling sensitive personal data without consent. Washington's My Health My Data Act is the one to watch if you are health-adjacent: it treats consumer health data broadly, sets no revenue threshold, and a violation is actionable under Washington's Consumer Protection Act, which is how private plaintiffs get in. Note its reach before you panic, though — it applies to entities that conduct business in Washington or target goods and services at Washington consumers, so it is not automatically a New York problem.

New York's SHIELD Act, which does apply to you

Here is the law most New York owners have never heard of and are almost certainly covered by. The Stop Hacks and Improve Electronic Data Security Act (SHIELD Act) amended New York's General Business Law. It has no size threshold and no requirement that you be located in New York. If you own or license computerized data containing the private information of a New York resident, it reaches you.

Two duties follow. The first is breach notification. If private information is exposed you must notify affected New Yorkers, and whenever New York residents have to be notified you must also notify the Attorney General, the Department of State's Division of Consumer Protection, and the State Police — that trio is not scale-dependent. Scale matters somewhere else: if more than 5,000 New York residents are notified at one time, the consumer reporting agencies have to be told as well. Amendments signed in December 2024 tightened the consumer notification deadline to 30 days after discovery of the breach, added the Department of Financial Services to the regulator list for the entities it regulates, and expanded "private information" to cover certain medical information and health insurance information, that last change taking effect in March 2025. Confirm the current text with counsel — this section is amended often.

The second duty matters day to day: implement reasonable administrative, technical, and physical safeguards. The statute gives examples — identifying foreseeable risks, training staff, choosing service providers capable of maintaining safeguards and requiring them by contract, and disposing of private information within a reasonable time after it is no longer needed. Note that "private information" includes a user name or email address together with a password or security question and answer that would open an online account. If your site has customer accounts, that is you.

The safeguards duty scales for small businesses — the breach-notification duty does not, and applies regardless of size. The statute defines a small business as one with fewer than 50 employees, or under $3 million in gross annual revenue in each of the last three fiscal years, or under $5 million in year-end total assets. A qualifying small business complies if its measures suit its size, its activities, and the sensitivity of what it holds. You do not need an enterprise security program. You do need something you can describe.

When GDPR can reach a US business

The EU's General Data Protection Regulation is not triggered by your website being reachable from Europe. Article 3(2) applies it to non-EU businesses in two situations: offering goods or services to people in the EU, or monitoring their behavior within the EU. The regulation's own recitals say plainly that mere accessibility of a site, the presence of an email address or other contact details, or the use of a language generally used in your own country is not enough.

What tips it over is evidence you meant to serve that market. The recitals point to things like offering delivery to EU member states, quoting prices in euros, or referring to customers in the Union as indicators that you envisaged doing business there. A seforim store in Brooklyn that ships to Antwerp and offers EU shipping at checkout is on the wrong side of that line. The same store with a US-only shipping table is not, even if someone in Belgium browses it. London is its own case: the UK left the EU, and UK GDPR plus the Data Protection Act 2018 apply there on broadly similar terms.

The "monitoring" limb is genuinely unsettled. Read literally, tracking EU visitors with advertising pixels might qualify even without targeting Europe; whether it actually does has not been resolved, and reasonable practitioners disagree. In practice regulators have focused on businesses deliberately serving the EU market, and an EU authority pursuing a Monsey plumber is hard to imagine — though that is a judgment about enforcement priorities, not a statement about what the law permits. The maximum fines are real: for the most serious infringements, up to €20 million or 4% of total worldwide annual turnover, whichever is higher. If you do ship to Europe, spend an hour with a lawyer rather than guessing.

Every third-party tool is a disclosure you owe

The most common gap in small business policies is not a missing legal clause. It is that the owner does not know what their own website sends out. Each of these quietly hands a third party your visitor's IP address and browsing activity:

What is on the pageWhat leaves your siteWhat the policy should say
Google Analytics (GA4)Page views, device and approximate location, an identifier, sent to GoogleNamed, with purpose (measuring traffic) and a note that Google processes it
Meta PixelPage views and conversion events tied to a Meta profileNamed, described as advertising, with an opt-out route
Embedded Google MapIP address and browser details to Google on page load, before any clickDisclosed. Most policies miss this entirely
Google Fonts loaded from GoogleIP address to Google on every page viewBetter: host the font files on your own site and remove the issue. A German regional court in Munich treated this transfer as a GDPR violation in January 2022 and awarded the visitor 100 euros — a lower-court decision rather than binding precedent, but a signal worth heeding
YouTube embedCookies and IP to Google (the privacy-enhanced embed domain reduces but does not eliminate this)Disclosed alongside other Google services
Chat, review, or booking widgetWhatever the visitor types, stored on someone else's serverNamed, with what is stored and for how long

Disclosure and consent are separate questions. Whether you need a banner before these load depends mostly on whether GDPR or a state opt-out duty applies to you, which is covered in our guide to cookie consent and website tracking.

One warning aimed squarely at therapy practices, ABA providers, and medical billing companies: advertising trackers on pages where patients identify themselves or describe conditions have drawn substantial regulatory attention and litigation. The federal guidance is unsettled rather than settled: in June 2024 a federal district court in Texas vacated part of the HHS Office for Civil Rights bulletin on online tracking technologies in American Hospital Association v. Becerra, and HHS withdrew its appeal — which narrowed the government's stated position without resolving what is actually permissible. If you are a HIPAA covered entity or a business associate, treat a Meta Pixel on an intake or portal page as something to clear before installing, not after.

What a policy has to actually say

Strip the boilerplate and a good policy answers six questions in language a customer can follow.

  1. What do you collect? Split it into what the visitor hands you (name, phone, delivery address, order contents, the message they typed) and what is gathered automatically (IP address, pages viewed, device type).
  2. Why? Tie each category to a purpose. "We keep your delivery address to deliver your order and to speed up your next one." Not "for business purposes."
  3. Who else sees it? Name the categories and, where you can, the actual companies: your host, payment processor, email platform, delivery service, analytics provider.
  4. How long do you keep it? A real answer. "Order records for seven years for tax purposes; contact form messages for twelve months, then deleted." If CCPA/CPRA does cover you, stating the retention period for each category — or the criteria you use to set it — is an actual statutory requirement rather than a nicety.
  5. How does someone reach you and ask for deletion? A working email address and phone number, and what happens when someone asks. If you cannot honor a deletion request because you do not know where the data lives, that is a system problem to fix, not a drafting problem.
  6. When was it last updated? An effective date. A policy dated four platform migrations ago tells a regulator more than you want it to.

Why copying another business's policy backfires

It is the most common mistake, and the failure mode is specific: a borrowed policy describes the wrong business. It will claim you collect payment card details when Stripe handles them and you never see a card number, making you look responsible for something you are not. It will reference a mobile app you do not have, or a California opt-out process you never built. And it will omit what you actually do — the WhatsApp order line, the paper delivery slips in the back office, the customer list sitting in your email platform.

Under FTC Section 5, the gap between what your policy claims and what you do is where the liability lives. A short, accurate policy describing a simple business is far stronger than a long borrowed one describing a company you are not.

Contact forms and email lists: where small sites leak

Forms store more than owners realize

Most website contact forms do not simply email you. Services like Formspree, FormSubmit, WPForms, and Gravity Forms will, depending on the product and how it is configured, keep a copy of every submission on their servers or in your site's database — and in several of them that copy sits there indefinitely unless you change a setting. That is a second copy of everything a customer typed, in a system you are not thinking about. Behavior differs between products and plans, so check the ones you actually run rather than assuming.

The free-text box is what makes this awkward. A caterer's "tell us about your event" field collects dates and guest counts. A therapy practice's "how can we help?" field collects health information. A travel agency asking for passenger details collects dates of birth and passport numbers. Those last two are worth being precise about: neither a date of birth nor a passport number is, on its own, "private information" as the SHIELD Act defines it — that list runs to Social Security numbers, driver's license and non-driver ID numbers, financial account and card numbers, biometric data, the newly added medical and health insurance information, and account credentials. But they are exactly the raw material identity theft is built from, several other states' breach laws do reach passport numbers, and you gain nothing by holding them loosely.

Four fixes: ask for the minimum you need; never collect Social Security numbers or full card numbers through a web form; turn off database storage if you only need the email; set a deletion schedule. If you are HIPAA-covered, check whether the form provider will sign a Business Associate Agreement — most inexpensive ones will not, which rules them out for intake.

Email consent is looser than people think. Texting is not

The federal CAN-SPAM Act governs commercial email and is an opt-out regime, not opt-in. It requires accurate sender information, a non-deceptive subject line, a valid physical postal address in every message, a clear unsubscribe mechanism, and honoring opt-outs within 10 business days. You remain responsible even when a marketing company sends on your behalf. Civil penalties are assessed per email and the statutory maximum is adjusted for inflation — it currently sits in the low $50,000s per message. Read that as a ceiling a court could impose in an FTC enforcement action, not a price list: real penalties are negotiated against the conduct, the scale, and the company's ability to pay, and CAN-SPAM gives individual recipients no right to sue. The arithmetic on a bulk send still deserves respect.

Note what CAN-SPAM does not require: prior consent. Adding a customer who ordered from you to your newsletter is not a federal violation. It is still a bad idea, because purchased and scraped lists destroy deliverability and every reputable email platform's terms require permission independently of what the statute says. Marketing email to people in the EU is a different regime — the ePrivacy Directive, as implemented by each member state, generally requires prior opt-in, measured against GDPR's standard for what counts as valid consent.

Text messaging is a different world. Under FCC rules implementing the Telephone Consumer Protection Act (TCPA), marketing texts require prior express written consent, and the statute carries damages of $500 per violation, trebled to as much as $1,500 for willful or knowing violations, counted per message and enforceable by the recipient personally. That written-consent requirement is currently contested — the Eleventh Circuit vacated the FCC's "one-to-one consent" rule in 2025, and a federal appeals court has since questioned the FCC's authority to impose a written-consent requirement at all — but the live dispute is about how consent must be documented, not about whether you need it, and the private right of action is not in doubt. One sloppy blast to an unconsented list is a real financial risk in a way that email is not. More detail in our guide to email and SMS marketing law.

What it costs, and what actually goes wrong

On cost — these are our own rough figures from working with small clients, not survey data, and quotes vary a great deal by market and complexity — a reputable policy generator tends to run in the tens to low hundreds of dollars a year, while a lawyer drafting one for a small business generally lands in the high hundreds to low thousands. A sensible middle path is to generate a draft, have your developer correct it against the actual site, then have a lawyer review it if you handle health data, take payments directly, or sell into Europe.

On consequences, in descending order of likelihood: Google or Meta restricting an ad account over policy requirements; a demand letter from a firm running automated scans for missing disclosures or tracking pixels — the same pattern as website accessibility letters, which is why ADA accessibility is worth reading alongside this; a customer complaint to a state Attorney General; and a breach that triggers real notification duties. That ordering reflects what we see landing on small clients rather than any measured ranking. State AG enforcement against a small local shop is uncommon. A breach is not. The safeguards duty is where your effort is best spent.

The checklist to hand your developer

  1. List every third-party script on the site: analytics, advertising pixels, maps, fonts, video embeds, chat, reviews, booking tools. Remove the ones no longer in use.
  2. Self-host web fonts rather than loading them from Google's servers. It removes a disclosure obligation and usually makes the site faster.
  3. List every form and where its submissions go — email, site database, third-party dashboard, or all three. Set retention on each.
  4. Confirm no form asks for a Social Security number, full card number, or health detail it does not need.
  5. Confirm the site is served over HTTPS on every page, and that any admin or customer accounts have real passwords and two-factor authentication.
  6. List every place customer data lives outside the website: email platform, spreadsheets, POS system, delivery app, WhatsApp.
  7. Write the policy from that inventory. Include an effective date, a working contact email, and a plain description of the deletion process.
  8. Link the policy in the footer on every page, including checkout.
  9. Re-check the list whenever a tool is added, and at minimum once a year.

If you are building or rebuilding a site, this belongs in the initial scope rather than a scramble afterward — it is much cheaper to map data flows while the site is being designed. You can start a project or call 845-587-0531 with questions.

The short version

  • No single federal law requires a privacy policy for a small business website. Obligations come from a patchwork: sector laws like HIPAA, the FTC Act's ban on deceptive practices, state laws, and the contracts you signed with Google and Meta.
  • CCPA/CPRA has real thresholds — an inflation-adjusted revenue figure (currently $26,625,000), buying, selling, or sharing the personal information of 100,000 consumers or households, or half your revenue from selling or sharing data. Most small local businesses fall below all three and are not covered, but check rather than assume.
  • New York's SHIELD Act has no size threshold and does apply. Its reasonable-safeguards duty scales to small businesses; its breach-notification duty does not scale at all.
  • GDPR reaches you if you offer goods or services to people in the EU — shipping there, pricing in euros — not merely because your site is reachable from there.
  • Analytics, advertising pixels, embedded maps, and Google-hosted fonts all send visitor data to third parties and all belong in your policy. Self-host your fonts.
  • Never copy another business's policy. A policy that misdescribes what you do can be treated as a deceptive practice under FTC Section 5; a short accurate one beats a long borrowed one.

Want this handled properly?

We build websites and online stores for businesses that need them to actually work — in English and Yiddish. Tell us what you're trying to do and we'll tell you straight what it takes.