top of page

What Does a Privacy Policy Need to Say? The Small Business Compliance Checklist

  • Writer: Aisha McKinney
    Aisha McKinney
  • Aug 19
  • 5 min read

Written by Aisha McKinney, Esq., Principal Attorney & Co-Founder at Zova Law, and Jasmine Johnson Parker, Esq., Co-Founder & Principal Attorney at Zova Law.

 

Quick Answer: A legally compliant small business privacy policy must include five disclosures: (1) what personal data you collect and why, (2) how data is used and shared — including every third-party tool on your website, (3) user rights under applicable state privacy laws, (4) your data retention and deletion policy, and (5) a working contact mechanism for privacy requests. Missing any of these is a specific compliance failure under the FTC Act, CCPA, and the privacy laws of nineteen states with active enforcement in 2026.

 


If you have a contact form, an email list, a checkout page, or any third-party tool on your website, you are legally required to have a privacy policy that discloses specific information about how your business handles personal data. Most small business privacy policies — particularly those generated from free template tools — fail to include at least two of the five required disclosures. This post covers each one, what it needs to say, and what the enforcement consequences look like when it’s missing.

 

Does a Small Business Need a Privacy Policy?

 

Yes. Any business that collects personal information from consumers is subject to privacy obligations. Personal information includes email addresses, names, IP addresses, payment information, device identifiers, and browsing behavior. If your website has a contact form, newsletter signup, checkout process, or any analytics or tracking tool, you are collecting personal information.

 

The primary legal frameworks governing small business privacy in 2026 are FTC Act Section 5 (the federal prohibition on misrepresenting your data practices), the California Consumer Privacy Act (CCPA, which applies to any business collecting data from California residents regardless of where the business is located), and state privacy laws in nineteen additional states with active enforcement.

 

The Five Required Disclosures: What Your Privacy Policy Must Say

 

Disclosure 1: What Data You Collect and Why

Your privacy policy must identify the specific categories of personal information your business collects — identifiers, commercial information, internet activity, geolocation data, inferences. It must also state the business or commercial purpose for each category. ‘We collect information to improve your experience’ is not sufficient. Each purpose must be named explicitly.

 

Disclosure 2: How Data Is Used and Who Receives It

This is the disclosure most small business privacy policies get wrong. If your website uses any third-party tool — Google Analytics, Meta Pixel, email marketing software, advertising networks — those tools receive personal information. Your privacy policy must identify those third parties and explain what they do with the data. Under CCPA, sharing data with advertising platforms for cross-context behavioral advertising constitutes ‘sharing’ in the legal sense even if no payment changes hands, triggering consumer opt-out rights and disclosure obligations.

 

The FTC’s July 2026 complaint against Hims & Hers Health illustrates this principle directly. According to TechCrunch and the FTC’s own press release, the agency alleged that the company used tracking pixels from Meta, Snap, and other platforms that shared user health information with those companies, contrary to the company’s privacy policy disclosures. The allegations have not been proven, but they demonstrate the enforcement theory regulators are applying: the gap between what a privacy policy says and what tracking technology does is an actionable misrepresentation.

 

Disclosure 3: User Rights Under Applicable State Laws

As of 2026, nineteen states have active privacy laws granting consumers rights over their personal data. Under CCPA, these include the right to know what personal information is collected, the right to access a copy, the right to delete, the right to correct inaccurate data, the right to opt out of the sale or sharing of personal information, and the right to non-discrimination for exercising these rights. CCPA violations are assessed at up to $2,663 per unintentional violation and $7,988 per intentional violation. No cure period has been available since January 1, 2023.

 

A nine-state enforcement coalition — the Consortium of Privacy Regulators, formed in April 2025 — coordinates enforcement across California, Colorado, Connecticut, Delaware, Indiana, Minnesota, New Hampshire, New Jersey, and Oregon. A single investigation in one state can expand to all nine without any additional triggering event.

 

Disclosure 4: Data Retention and Deletion

Your privacy policy should state how long you retain different categories of personal information and how it is deleted. Under CCPA, businesses must respond to verified consumer deletion requests within 45 days. The California Privacy Protection Agency received more than 8,000 consumer complaints between July 2023 and September 2025 — roughly 150 per week — and had more than 100 active investigations running simultaneously by early 2026. Most small business privacy policies say nothing about retention periods.

 

Disclosure 5: A Working Contact Mechanism for Privacy Requests

Under CCPA, businesses must provide at least two methods for consumers to submit privacy requests — typically a dedicated email address and a web form. Both must be functional and monitored. A privacy email address with no one assigned to it is not compliant. Tractor Supply was fined $1.35 million by the CPPA in September 2025 after its opt-out webform had no effect on actual data sharing.

 

How Often Should a Privacy Policy Be Updated?

 

A privacy policy should be reviewed and updated any time the business adds a new data collection tool, changes how it uses or shares personal data, begins collecting new categories of information, or when new state privacy laws take effect. For most small businesses operating with analytics and any advertising tools, an annual review is the minimum. Quarterly is better given the pace of state-level privacy law changes in 2024–2026.

 

Frequently Asked Questions About Small Business Privacy Policies

 

Does a small business need a privacy policy?

Yes, if your business collects any personal information — which includes email addresses, contact form submissions, payment information, and data collected by website analytics or tracking tools. The FTC Act applies to all businesses engaging in interstate commerce, and state privacy laws apply based on where your customers are located, not where your business is based.

 

Do I need a privacy policy for my email list?

Yes. Collecting email addresses for marketing is personal information collection. Your policy must disclose that you collect email addresses, why, how they’re used, whether they’re shared with your email platform, and how subscribers can unsubscribe and request deletion.

 

Does CCPA apply to small businesses?

CCPA applies to for-profit businesses that meet one of three thresholds: annual gross revenue over $25 million, buying or selling the personal information of 100,000+ consumers per year, or deriving 50%+ of annual revenue from selling consumer personal information. Many small businesses don’t meet these thresholds. However, the FTC Act’s prohibition on deceptive practices applies to all businesses regardless of size. If your privacy policy makes promises about data protection, the FTC can enforce those promises.

 

What happens if my privacy policy is out of date?

If your policy describes data practices that don’t match what your business currently does — particularly regarding third-party tracking tools added since the policy was written — the gap is a potential FTC Act Section 5 violation. California’s 30-day cure period was eliminated in 2023, meaning there is no grace window after a violation is identified.

 

How much do privacy policy violations cost?

Under CCPA, civil penalties are $2,663 per unintentional violation and $7,988 per intentional violation, assessed per affected consumer. A single incident affecting 1,000 consumers could generate penalties of $2.6M for unintentional violations or $7.9M for intentional ones. Under the FTC Act, the FTC can seek civil penalties, injunctive relief, and consumer redress.

 

 

 

If your privacy policy came from a free template, hasn’t been reviewed since you added tracking tools, or you’re not certain it covers your actual data practices — the Legal Gap Consultation at Zova Law is the right starting point. In 30 minutes, we surface exactly what your current privacy infrastructure is missing, what the enforcement risk of each gap is, and what a compliant policy would need to say for your specific business. Book at legalgap.zovalaw.com.

Comments


ZOVA-Secondary-Logo-With-Tagline-Full-Color.png

Powered by Zova Platform.
Licensed in Georgia & Florida.
© 2026 Zova Law. All rights reserved.

ATTORNEY ADVERTISING DISCLAIMER

The contents of this website should not be construed as legal advice regarding any specific facts or circumstances. All materials were prepared Zova Law, LLC (formerly operating as Evolutionary Ventures Law Group, LLC)  (a Florida law firm organized as a limited liability company, Phone: (716) 687-0409) and are provided for general informational purposes only. Receipt of this information does not create an attorney‑client relationship with Zova Law or any of its attorneys.

You should not act or rely on any information contained herein without seeking professional legal counsel. Prior results referenced in these materials do not guarantee or predict similar outcomes in other matters. Attorneys at Zova Law are licensed in Florida and Georgia. The firm cannot represent clients in all jurisdictions without associating locally licensed counsel and/or obtaining admission in that jurisdiction for a limited purpose.

The attorneys responsible for the content of this website are Aisha McKinney and Jasmine Parker.

COMPANY

 

Blog

Media & Press

 


 

  • Facebook
  • Instagram
  • LinkedIn
  • TikTok

AMCKINNEY@ZOVALAW.COM  · 716- 687-0409 · ZOVALAW.COM


 

bottom of page