Insight

Privacy Policy Requirements: What Your Policy Must Disclose (Guide)

Insight Published 23 min read
Typewriter displaying “Privacy Policy” for an article explaining privacy policy requirements and compliance.

Regulators consider the privacy policy to be more than just paperwork. They look at whether what a company says matches what its website and data practices actually do. The FTC extracted $7.8 million from BetterHelp and $16.5 million from Avast because they had said one thing but had done another.

California took a similar approach with Sephora. In 2022, the Attorney General fined Sephora $1.2 million because their website claimed “we do not sell personally identifiable information,” but third-party trackers were selling customer data. It also failed to honor Global Privacy Control signals.

A compliant privacy policy must do more than exist. It must include required disclosures and reflect your actual data practices.

Key takeaways

  • No universal US federal mandate exists, but layered statutes (CalOPPA, 20 state laws, GDPR, COPPA, GLBA, HIPAA) and platform contracts (Apple, Google Play, Google Analytics) make a privacy policy effectively mandatory for almost any online business.
  • Every regime demands the same disclosure spine: identity, categories, specific purposes, recipients, retention, rights, tracking, security, children, sale/sharing, and the effective date.
  • Categories of recipients satisfy the published-policy duty almost everywhere. Naming is compulsory in defined situations (COPPA notices, China’s PIPL, Oregon/Minnesota access requests, GDPR access answers after the Court of Justice’s C-154/21 ruling).
  • The policy is judged against reality: the FTC, California AG, and CPPA have turned policy-vs-practice gaps into eight-figure enforcement (Avast, $16.5M; GM, $12.75M), and plaintiffs plead the policy as the broken promise.
  • California demands an annual update with a visible date. Everywhere else, inaccuracy is a standing violation, so updates follow vendor and tag changes, not the calendar.
  • A disclosure is only as true as your last observation of what the site actually sends; write from observed data flows, not from the vendor register.

Is a privacy policy legally required? 

No single US federal law requires every website to have a privacy policy. Instead, requirements come from state laws, industry-specific rules, the GDPR if you handle data from EU residents, and contracts with app stores or analytics providers. Even if none apply, any policy you publish can still be enforced as a promise to your users.

RegimeWho must complyWhat triggers the dutyMandate type
The California Online Privacy Protection Act – CalOPPA (Cal. Bus. & Prof. Code § 22575)Any operator of a commercial website or online service collecting personal data from California residentsCollection itself; the policy must be conspicuously posted and must state how the operator responds to Do Not Track signalsState statute (since 2004; the first US web-policy mandate)
State comprehensive privacy laws (20 in force, 24 enacted as of September 2026)“Controllers” meeting each state’s applicability test; Texas and Nebraska skip revenue and volume thresholds entirelyProcessing state residents’ personal data; every such law requires a reasonably accessible, clear, and meaningful privacy noticeState statutes
GDPR, Articles 12–14 (EU’s data protection law)Any controller processing personal data of people in the EU/EEA, wherever the controller is basedProcessing itself; information must be provided in a concise, transparent, intelligible, and easily accessible formEU regulation
COPPA Rule (16 CFR Part 312)Operators of sites or online services directed to children under 13, or with actual knowledge they collect from childrenCollecting personal information from children; notice must appear on the homepage and wherever data is collectedFederal statute + FTC rule
GLBA Regulation P (12 CFR Part 1016)Financial institutionsCustomer relationship; initial notice, then annual notices for as long as the relationship lastsFederal regulation
HIPAA Privacy Rule (45 CFR § 164.520)Covered health plans and health care providersHolding protected personal health data; a Notice of Privacy Practices (NPP) with prescribed contentFederal regulation
Apple App Store Review Guidelines § 5.1.1Every app distributed through the App Store“All apps must include a link to their privacy policy in the App Store Connect metadata field and within the app in an easily accessible manner”Platform contract
Google Play User Data policyEvery app distributed through Google Play, including apps that access no personal data at allDistribution; policy link required in Play Console and in-app, and it must match the Data safety sectionPlatform contract
Google Analytics Terms of Service § 7Any site running Google Analytics“You must post a Privacy Policy” that discloses your use of Google Analytics and how it collects and processes dataVendor contract

One more layer binds businesses no statute touches. Under Section 5 of the FTC Act, “unfair or deceptive acts or practices in or affecting commerce” are unlawful, and the FTC reads a published policy as public promises: diverge from it, and the policy itself becomes the deception. The enforcement record in the second half of this guide runs on that theory. Samuel Levine, Director of the FTC’s Bureau of Consumer Protection, put it plainly in the Avast case:

 “Avast’s bait-and-switch surveillance tactics compromised consumers’ privacy and broke the law.”

(FTC press release, February 22, 2024).

A terminology note before the item lists. US state statutes say “privacy notice,” older and sectoral laws say “privacy policy,” and California’s regulations require the homepage link to include the word “privacy.” The terms describe the same public document; this guide flags the few places where an instrument prescribes the label.


What must every privacy policy contain?

Most regimes ask for the same core elements. What changes is the level of detail, not the basic structure. Build the first draft around that shared structure, then add the requirements unique to each regime.

Disclosure elementWhat to writeDemanded by
Identity and contact detailsLegal entity name, contact channel for privacy inquiries, and, where required, the data protection officer or EU/UK representativeGDPR Art. 13(1)(a)-(b); every US state law; COPPA (all operators’ names and addresses); LGPD Art. 9
Categories of personal data collectedThe categories as the statute lists them (CCPA’s category taxonomy; GDPR’s “personal data”), including sensitive categories where processedCCPA § 1798.130(a)(5); GDPR Art. 13/14; all state laws; GLBA (categories of nonpublic personal information)
Purposes of processingPurpose per category, specific enough for a reader to understand the actual use, not “to improve our services”GDPR Art. 13(1)(c); CCPA regs (11 CCR § 7011) require purposes that give the consumer “a meaningful understanding”; PIPL Art. 17
Recipients of the dataWho receives personal data: named recipients or categories of recipients, depending on the regime (the anchor question gets its own section below)GDPR Art. 13(1)(e); CCPA § 1798.130(a)(5) (categories of third parties); COPPA (identities and categories); GLBA (categories of affiliates and nonaffiliated third parties)
RetentionHow long each category is kept, or the criteria used to decideGDPR Art. 13(2)(a); CCPA § 1798.100(a)(3); COPPA (a written, posted retention policy since the 2025 amendments); PIPL Art. 17
Consumer/data subject rights and how to exercise themThe rights your regime grants (access, deletion, correction, portability, opt-outs) plus the request methods, at least two under CCPAGDPR Art. 13(2)(b); CCPA § 1798.130(a)(5); all state laws; HIPAA NPP
Cookies and tracking technologiesWhat trackers run, what they collect, and who receives it; if you use Google Analytics, its contract requires you to say soCalOPPA § 22575(b)(6); GDPR (via the ePrivacy consent layer); Google Analytics ToS § 7
Security practicesA description of your security policies and practices at the level the regime prescribesGLBA Reg P § 1016.4(a)(8); state laws (as a “reasonable security” duty); Google Play policy
Children’s dataWhether the service is directed to children, and the parental-consent mechanics if it isCOPPA; state laws’ sensitive-data rules covering known children; California’s under-16 sale/sharing statement (11 CCR § 7011)
Sale, sharing, and targeted advertisingWhether you sell or share personal data, the categories involved, and the opt-out mechanism; if you do not sell, several regimes make you say so explicitlyCCPA § 1798.130(a)(5) (including the duty to “prominently disclose” that you do not sell or share, if that is the case); Texas TDPSA § 541.103
Changes and effective dateThe effective or “last updated” date and how you will notify users of changesCalOPPA § 22575(b)(3)-(4); HIPAA § 164.520(b)(3); Australia APP 1.3 (“up to date”)
International transfersWhether data crosses borders and under what safeguardsGDPR Art. 13(1)(f); Australia APP 1.4 (likelihood and countries of overseas disclosure); PIPL Art. 39

One correction belongs here because it is a common misinclusion: California’s Age-Appropriate Design Code Act is a DPIA duty, not a policy-disclosure duty, and the Ninth Circuit left it partially enjoined in NetChoice v. Bonta (March 12, 2026). Keep it off the policy checklist.

Two things are as important as the list of required items. The first is specificity: California’s rules require you to explain your reasons for collecting information clearly enough that consumers truly understand why you need their data. Vague or generic explanations are not enough.

The second is plain language: GDPR Article 12 says your policy must be easy to read and understand. Research shows why this matters. One study found the average privacy policy is about 2,514 words long, and reading every policy you see in a year would take around 244 hours. Lorrie Cranor believes this number has probably increased since then:

“It might even be worse now, because now we see this real proliferation of third-party content embedded in websites.”

(Princeton Engineering interview, November 2021).

A template or generator can help you create the basic structure of a privacy policy, but that’s all it does. It can’t know which trackers your website uses or which vendors get your form data. The accuracy of your policy depends on what you actually observe on your site.


What does the GDPR add to privacy policy requirements?

The GDPR is the most itemized disclosure regime in force anywhere, and it sets both the form and the content: Article 12 requires the information to be concise, transparent, intelligible, easily accessible, and in clear and plain language, free of charge. The content list is split by where the data came from.

Disclosure itemWhen data comes from the person (Art. 13)When data comes from elsewhere (Art. 14)
Controller identity and contact detailsRequiredRequired
Data protection officer’s contact detailsRequired where a DPO existsRequired where a DPO exists
Purposes and the legal basis for each purposeRequired; legitimate interests must be described when relied onRequired
Recipients or categories of recipientsRequired (the formal choice; see the recipient section below)Required
International transfers and their safeguardsRequired where applicableRequired
Retention period or the criteria for setting itRequiredRequired
The rights menu: access, rectification, erasure, restriction, portability, objectionRequiredRequired
Right to withdraw consent at any timeRequired where processing rests on consentRequired where processing rests on consent
Right to lodge a complaint with a supervisory authorityRequiredRequired
Whether providing data is a statutory or contractual requirement, and the consequences of refusingRequiredNot listed
Automated decision-making, including profiling: existence, logic, significance, envisaged consequencesRequired where applicableRequired where applicable
Source of the data, including whether publicly availablen/a (the person is the source)Required, with categories of sources
TimingAt collectionWithin one month, at first communication, or before first disclosure, whichever comes first

Legal basis per purpose is uniquely GDPR (and UK GDPR); US regimes ask for purposes, never the legal theory beneath each one. And Article 14’s one-month clock gives a business buying or receiving data an affirmative duty to go find the data subjects, a duty with no US equivalent. Penalties for transparency violations sit in the GDPR’s top tier: up to €20 million or 4 percent of global annual turnover under Article 83(5)(b). 

For the broader framework, see our GDPR explainer.


What does CCPA/CPRA add?

California’s is the most prescriptive US regime: it dictates not just the policy’s contents but its update cadence, its link text, and even a duty to disclose what you don’t do. The policy obligations sit in Cal. Civ. Code § 1798.130(a)(5) and 11 CCR § 7011.

CPRA-era disclosure itemThe duty
Rights and how to exercise themList the consumer rights and describe the request methods; at least two submission channels (typically a web form and a toll-free number)
Categories collected (12-month lookback)The categories of personal information collected in the preceding 12 months, using the statute’s category taxonomy
Categories of sourcesWhere the information comes from, by category
Purposes, specificallyThe business or commercial purpose per category, specific enough for “a meaningful understanding”; generic labels fail
Categories of third partiesThe categories of third parties to whom information is disclosed
The two listsCategories sold or shared, and categories disclosed for a business purpose, each covering the preceding 12 months
Negative disclosureIf you have not sold or shared personal information, the policy “shall prominently disclose that fact”; silence is not compliance
RetentionHow long you retain each category, or the criteria used (§ 1798.100(a)(3))
Sensitive personal informationWhether and how you use or disclose sensitive PI, and the right to limit it
Under-16 statementWhether you sell or share the data of consumers under 16
Notice at collectionA separate, just-in-time notice at or before collection, listing categories and purposes (§ 1798.100(b))
Do Not Sell or Share link + GPCA conspicuous opt-out link, and honoring the Global Privacy Control (GPC) browser signal
Annual update + dateUpdate the policy at least once every 12 months and show the last-updated date
Language and accessibilityAvailable in the languages in which you do business, and accessible to consumers with disabilities
Automated decision-making (ADMT)Pre-use notice, opt-out, and access duties for significant automated decisions phase in under the 2025 regulations package (risk assessments already apply; ADMT duties follow from January 1, 2027). Mechanics: our CCPA compliance guide

One caution on the word “sale”: the California Consumer Privacy Act defines it as an exchange for monetary or other valuable consideration, which is how routine advertising analytics became “sales”. 

Penalties adjust for inflation: as of January 1, 2025, $2,663 per violation and $7,988 per intentional violation or one involving known minors, plus statutory damages of $107 to $799 per consumer per incident in private breach actions (CPPA adjustment notice; next adjustment is January 2027). 

For applicability thresholds, rights mechanics, and enforcement details, see What is CCPA? and the compliance guide.


What do the other state laws add?

Twenty states have relevant data privacy laws in force as of September 2026, and four more (Alabama, Louisiana, Oklahoma, Vermont) are enacted with future effective dates, per the IAPP state privacy legislation tracker. 

Read this table as deltas, not entries: nearly all these laws demand the same baseline notice, and only a few add genuine extras. The baseline is a reasonably accessible, clear, and meaningful privacy notice disclosing personal data categories processed, purposes, consumer rights and how to exercise them (including appeal), categories of data shared with third parties, and categories of those third parties. Texas’s § 541.102(a) is a verbatim example of the pattern.

DeltaState(s)What your policy must do beyond the baseline
Prescribed sale notices, verbatimTexasIf you sell sensitive data, post the exact sentence “NOTICE: We may sell your sensitive personal data.”; if you sell biometric data, “NOTICE: We may sell your biometric personal data.” Both appear “in the same location and in the same manner” as the privacy notice, and both stack if you do both (TDPSA § 541.102(b)-(c))
No applicability thresholdsTexas, NebraskaNo revenue or data-volume floor: the law reaches any non-exempt business that is not a Small Business Administration (SBA)-defined small business, and even small businesses may not sell sensitive data without consent (Neb. Rev. Stat. § 87-1103)
Named-recipient list on requestOregon, MinnesotaConsumers can demand a list of the specific third parties that received their data; this is an access-request duty, not a policy-naming duty. Full analysis in the recipient section below (ORS 646A.574; Minn. Stat. § 325M.14)
Update and dating duties beyond the baselineCaliforniaAnnual update plus last-updated date (covered in the California section above); most other states demand accuracy without a fixed cadence
Penalty structureAllAttorney-general enforcement, typically up to $7,500 per violation (Texas: § 541.155, AG-only, 30-day cure, no private right of action); cure periods vary, and some have sunset

Everything else the state wave adds (opt-out preference signals, sensitive-data consent, data-protection assessments) binds your data handling practices more than your policy text. The notice contents stay close to the baseline. 

There are two practical takeaways. First, most businesses use one main privacy policy with an extra section for state-specific rights, especially California. Second, the list of state laws changes often, so any count of “how many states” have privacy laws will quickly become outdated.


What do sectoral laws and non-US regimes add?

If you operate in a regulated sector, a second disclosure layer sits on top of general laws. Each row below is the delta that matters for your policy, not the whole statute.

RegimeWho it coversWhat the notice must disclose (the delta)
COPPA Rule, 16 CFR § 312.4 (amended rule fully operative; compliance date April 22, 2026)Sites and services directed to children under 13, or knowingly collecting from themThe name, address, phone, and email of every operator; what is collected and how; disclosure practices including the “identities and specific categories” of third parties; a written data-retention policy posted in the notice; parental review, refusal, and deletion rights. Civil penalties run $53,088 per violation (16 CFR § 1.98)
GLBA Regulation P, 12 CFR §§ 1016.4, 1016.6Financial institutionsCategories of nonpublic personal information collected and disclosed; categories of affiliates and nonaffiliated third parties who receive it; the opt-out explanation; your security policies and practices
HIPAA Notice of Privacy Practices, 45 CFR § 164.520Covered health plans and providersUses and disclosures with at least one example per purpose; individual rights; the entity’s duties, including the statement that it is “required to abide by the terms of the notice currently in effect”; complaint routes; effective date; prompt revision after any material change
Illinois BIPA, 740 ILCS 14/15(a)Private entities possessing biometric identifiersA written policy, “made available to the public,” establishing a retention schedule and destruction guidelines (destruction when the purpose is satisfied or within three years of last interaction). BIPA carries a private right of action at $1,000 (negligent) to $5,000 (intentional/reckless) per violation

One disambiguation worth printing: “the Privacy Act” means different things in different countries. In the US, it is the 1974 statute governing federal agencies; it doesn’t apply to your business. In Australia, the Privacy Act 1988 is the main private-sector law, and its APP 1 is a genuine policy mandate (below). Same name, opposite relevance.

And the non-US regimes, one row each:

RegimeThe disclosure duty in one row
United KingdomUK GDPR mirrors the EU item list, and the ICO adds the operative detail: your privacy information must state your purposes and your lawful basis for each (ICO guide to lawful basis)
CanadaPIPEDA’s “openness” principle requires making “specific information about its policies and practices” readily available, in a form that is generally understandable (PIPEDA, Schedule 1, clause 4.8); Quebec’s Law 25 adds its own notice duties
AustraliaAPP 1 requires a “clearly expressed and up to date” APP privacy policy, available free of charge, listing seven prescribed items including whether you disclose overseas and to which countries (OAIC, Australian Privacy Principles)
BrazilLGPD Article 9 grants the data subject facilitated access to the specific purpose, form and duration of processing, controller identification and contact, data-sharing information and purpose, and the Article 18 rights; consent is void if the information given is misleading or not transparent (Lei 13.709/2018, in Portuguese)
ChinaPIPL Article 17 requires handlers, before processing, to truthfully, accurately, and fully inform individuals in conspicuous form and clear language of the handler’s name and contact, the purposes and methods, the categories of data, the retention period, and the methods for exercising rights; any change triggers a fresh notice (DigiChina/Stanford translation)

The pattern across all five: the spine travels. Identity, purposes, categories, recipients, retention, rights. What changes per jurisdiction is granularity and timing.


Do you have to name every recipient, or are categories enough?

In most cases, listing categories of recipients is enough for your privacy policy. You only need to name specific recipients in certain situations. For example, Oregon’s law is often misunderstood: you only have to provide a list of specific third parties if someone asks, not in your published policy.

Diagram showing three privacy disclosure records: the published policy, access-request response, and internal compliance record.

What the GDPR actually says

Article 13(1)(e) requires “the recipients or categories of recipients.” That “or” is a real choice at the policy level: a well-defined category is compliant. The confusion starts at the access right. In January 2023, the Court of Justice of the EU ruled in C-154/21 (RW v Österreichische Post) that on an access request, the controller must disclose the actual identity of the recipients whenever that is possible. 

Categories suffice only where identification is impossible, or the request is manifestly unfounded or excessive, and the choice belongs to the data subject, not the controller. The court did not rewrite Article 13: your policy may still say “categories,” but your access-request answer may have to say names. A controller that cannot name its recipients cannot comply. That is the ruling’s operational bite.

What US state laws actually say

Every comprehensive US state law writes its proactive notice duty in categories: categories of personal data shared, and categories of third parties receiving it. None requires the published policy to enumerate recipients by name. This is a categories-based system by design.

The Oregon exception

Oregon’s Consumer Privacy Act gives a consumer the right to obtain, “at the controller’s option, a list of specific third parties, other than natural persons, to which the controller has disclosed” either that consumer’s data or any consumer’s data (ORS 646A.574(1)(a)(B)). Minnesota’s law grants the same right in nearly identical words (Minn. Stat. § 325M.14, subd. 1(h)). It is a response duty: it activates when someone asks, not when you publish. The controller chooses which list to give: your recipients or its full recipient list. 

Where naming is compulsory anyway

  • Children’s services. COPPA’s online notice must state the “identities and specific categories” of third parties, one of the only name-required policy duties in US law.
  • China. PIPL Article 23 requires notifying individuals of the recipient’s name and obtaining separate consent before providing data to another handler. Article 39 does the same for cross-border provision. Categories don’t satisfy it.
  • Consent integrity. Brazil’s LGPD voids consent built on misleading or incomplete disclosure (Art. 9 § 1), which makes vague recipient language a consent problem, not just a notice problem.
  • Contract and platform layers. Google Play’s policy must state the parties data is shared with, and GDPR Article 28 processor contracts make the controller-processor chain documentary even where the public policy stays categorical.

Policy vs request vs record: the three-records separation

RegimeThe published policy must discloseOn access request you must produceInternal record you must keep
GDPRRecipients or categories (Art. 13/14)Actual recipient identities where possible (Art. 15, per C-154/21)Records of processing incl. categories of recipients (Art. 30)
CCPA/CPRACategories of third partiesCategories of third parties + specific pieces of PIContracts with each service provider/contractor
Oregon / MinnesotaCategories of third partiesList of specific third parties, controller’s option which listWhatever makes that list producible in 45 days
Texas and baseline statesCategories of third partiesCategoriesAssessment and contract records
COPPAIdentities and categories of third partiesParental access to the child’s dataWritten retention policy
GLBACategories of affiliates and nonaffiliatesn/a (no access right)n/a
Recipient granularity spectrum showing when privacy disclosures use recipient categories, specific names on request, or mandatory named recipients.

So: do jurisdictions actually conflict? Rarely, and not here. What looks like conflict is granularity difference plus one timing difference: some duties attach to the document, others to the request. The real tensions are practical, not legal. 

Naming every subprocessor in a public policy collides with readability and goes stale within weeks. Categories stay true longer but answer less. A naming promise you cannot fulfill because you have never observed where the data goes is worse than an honest category. You cannot disclose recipients you have not mapped, which is why tracing what your site actually sends must precede writing.


What happens when the privacy policy meets reality? 

A privacy policy is judged against what your site actually does. The gap between the two is now the single most productive enforcement theory in US privacy law. These are the mistakes regulators and plaintiffs keep citing:

  1. The flatly false sentence. Sephora’s site said “we do not sell personal information” while its trackers sold customer data. The Attorney General’s case led with that sentence.
  2. The stale policy. Tractor Supply’s policy had not been updated in four years and no longer notified consumers of their rights. The CPPA made it the largest fine in its history.
  3. Categories that no longer match the vendors. A new tag, agency pixel, or AI vendor silently widens the gap between disclosed categories and the real recipient list.
  4. Generic purposes. “To improve our services” fails California’s meaningful-understanding standard and tells the reader nothing.
  5. Missing negative disclosures. California requires you to say prominently when you do not sell or share; silence reads as concealment.
  6. Opt-outs that exist on paper only. Disney’s $2.75 million settlement (2026) punished opt-out toggles that did not apply across services and devices. The policy promised a control the product did not deliver.
Enforcer / regimeLegal theoryCase (dated)Outcome
FTC, Section 5 deceptionPolicy promises contradicted by actual sharingBetterHelp (Mar. 2023)$7.8M; banned from sharing health data for advertising
FTC, Health Breach Notification Rule (HBNR)Undisclosed health-data disclosures; first HBNR actionGoodRx (Feb. 2023)$1.5M civil penalty
FTC, Section 5 deceptionSold browsing data while promising to block trackingAvast (Feb. 2024)$16.5M; sale ban
California AG, CCPAFailed to disclose data sales; ignored GPC; missed the cure windowSephora (Aug. 2022)$1.2M; policy must affirmatively disclose the sale
CPPA, CCPANo compliant privacy policy; no job-applicant notice; broken opt-outsTractor Supply (Sep. 2025)$1.35M; quarterly tracking-tech scans; 4-year officer certification
California AG, CCPASold driver location and behavior data; “never disclosed the sales”General Motors (May 2026)$12.75M
California AG, CCPATracking on a health site contrary to disclosuresHealthline (Jul. 2025)$1.55M; settlement requires “accurate online disclosures and privacy policy”
GDPR, top fine tierTransparency and information-duty breachesArticle 83(5)(b)Up to €20M or 4% of global annual turnover
Private plaintiffsStatutory damages and the published promise as exhibitCCPA breach actions: $107–$799 per consumer per incident (CPPA adjustment); BIPA: $1,000–$5,000 per violationClass complaints plead that the defendant “violated its own Privacy Policy”

“There are no more excuses,” California AG Rob Bonta said when announcing the Sephora settlement: 

“Follow the law, do right by consumers, and process opt-out requests made via user-enabled global privacy controls”

(press release).

Diagram comparing privacy policy claims with actual website data flows to ad pixels, data brokers, and session replay tools.

Keeping your privacy policy accurate is an ongoing responsibility. Several laws make this clear:

DutyRegimeThe requirement
Annual updateCCPA/CPRAUpdate the policy at least once every 12 months, with the last-updated date displayed (11 CCR § 7011(e)(4))
Prompt revisionHIPAARevise the Notice of Privacy Practices promptly after any material change
CurrencyAustralia APP 1The policy must be “clearly expressed and up to date” as a standing condition
Change noticeCalOPPA, PIPLState how users will be notified of changes (CalOPPA); notify individuals of changes to any notified item (PIPL Art. 17)
ConsistencyGoogle PlayThe privacy policy and the Play Console Data Safety form must match, or the app faces removal

California’s twelve-month duty is the only hard calendar in US law, but every regime treats an inaccurate policy as a current violation, so “reviewed when someone remembers” is non-compliant everywhere in effect. The triggers are operational. A new vendor, tag, form field, purpose, or state law taking effect can falsify the document overnight. 


How does MELURNA help?

Everything above assumes you know what your site actually sends. That assumption is what the cases above broke on: disclosures are written from the vendor register and contract file, while the real recipient list lives in the tag container, form handler, and fourth-party scripts your vendors load.

MELURNA is built on the observed side of that gap. It tracks data flows from the moment data enters your site through all the third parties and beyond, showing exactly what information is shared and with whom. 

MELURNA compares what your policy promises with what actually happens, just like regulators do. It also checks if user choices, like opt-outs or Global Privacy Control signals, really change who gets the data. Continuous monitoring helps you spot changes, like new tags or vendors, that could make your policy inaccurate between reviews. All findings are mapped to over 30 compliance frameworks and come with timestamped evidence for your legal team.

What MELURNA does not do is write your privacy policy or provide legal advice. You and your legal team are responsible for drafting the policy. What it does is give you the evidence you need, so you know where your regulated data goes before a regulator or a plaintiff’s expert finds out.

Request a demo to see how data moves through your own website.


Next steps

Audit your current policy against the disclosure spine above and mark every element your regimes require but the document lacks. Then close the evidence gap. See what your site actually sends, and to whom, before a regulator runs the same comparison for you. If California is your binding regime, continue with What is CCPA? and the CCPA compliance guide; if your immediate problem is tracking coverage, start with how data privacy risk actually happens.


FAQs

Is a privacy policy legally required?

Not under one universal US federal law. It becomes mandatory in layers: CalOPPA for any commercial site collecting data from California residents, the 20 in-force state comprehensive laws, GDPR for anyone processing EU residents’ data, sectoral rules like COPPA, GLBA, and HIPAA, and platform contracts (Apple, Google Play, Google Analytics) that require one as a condition of distribution. Even where nothing mandates a policy, a published one is enforceable against you under FTC Act Section 5.

Do I have to name every third party in my privacy policy?

Almost never. GDPR Article 13(1)(e) makes “recipients or categories of recipients” a formal choice, and every US state notice duty is categories-based. Naming becomes compulsory in specific situations: COPPA notices (identities and categories), China when providing data to another handler (PIPL Art. 23), and on request in Oregon and Minnesota, where consumers can demand a list of the specific third parties that received their data.

How often must a privacy policy be updated?

California sets the only hard US calendar: at least every 12 months, with the last-updated date shown. HIPAA requires prompt revision after material changes, Australia requires the policy to be “up to date” as a standing condition, and every regime treats an inaccurate policy as a live violation. Operationally, the update triggers are new vendors, new tags, new data uses, and new laws taking effect.

Is a privacy policy the same as a privacy notice?

In practice, yes: the terms describe the same public document. US state statutes tend to say “privacy notice,” sectoral and older laws say “privacy policy,” and California’s regulations require the homepage link to include the word “privacy.” A few instruments prescribe the label, so follow the form rule of the regime you are writing under.

What happens if my privacy policy is wrong?

The policy becomes the evidence against you. The FTC treats a false policy as a deceptive practice under Section 5 (BetterHelp, $7.8M, and Avast, $16.5M). California’s AG and the CPPA fine disclosure failures directly (Sephora, $1.2M, Tractor Supply, $1.35M, and GM, $12.75M). GDPR transparency breaches sit in the top fine tier, up to €20M or 4 percent of global turnover. And plaintiff firms quote the policy verbatim in class complaints as the promise you broke.

Does a template or generator make me compliant?

It gives you compliant structure, not compliant content. A template cannot know which trackers fire on your checkout page, which vendors receive your form data, or whether your opt-out actually works, and those are precisely the facts regulators check first. Use templates for skeleton and wording. Verify the substance against what your site observably does.


DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information, and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.


Reference

Cite this page

Dany Mirza. “Privacy Policy Requirements: What Your Policy Must Disclose (Guide).” Melurna, September 24, 2026. https://www.melurna.com/blog/privacy-policy-requirements/