A privacy policy must disclose who you are and how to contact you, what personal data you collect, why you collect it, who receives it, how long you keep it, what rights people have over it and how to exercise them, and how and when the policy changes. The exact item list comes from the laws that bind you.
Regulators consider the privacy policy to be more than just paperwork. They look at whether what a company says matches what its website and data practices actually do. The FTC extracted $7.8 million from BetterHelp and $16.5 million from Avast because they had said one thing but had done another.
California took a similar approach with Sephora. In 2022, the Attorney General fined Sephora $1.2 million because their website claimed “we do not sell personally identifiable information,” but third-party trackers were selling customer data. It also failed to honor Global Privacy Control signals.
A compliant privacy policy must do more than exist. It must include required disclosures and reflect your actual data practices.
Key takeaways
- No universal US federal mandate exists, but layered statutes (CalOPPA, 20 state laws, GDPR, COPPA, GLBA, HIPAA) and platform contracts (Apple, Google Play, Google Analytics) make a privacy policy effectively mandatory for almost any online business.
- Every regime demands the same disclosure spine: identity, categories, specific purposes, recipients, retention, rights, tracking, security, children, sale/sharing, and the effective date.
- Categories of recipients satisfy the published-policy duty almost everywhere. Naming is compulsory in defined situations (COPPA notices, China’s PIPL, Oregon/Minnesota access requests, GDPR access answers after the Court of Justice’s C-154/21 ruling).
- The policy is judged against reality: the FTC, California AG, and CPPA have turned policy-vs-practice gaps into eight-figure enforcement (Avast, $16.5M; GM, $12.75M), and plaintiffs plead the policy as the broken promise.
- California demands an annual update with a visible date. Everywhere else, inaccuracy is a standing violation, so updates follow vendor and tag changes, not the calendar.
- A disclosure is only as true as your last observation of what the site actually sends; write from observed data flows, not from the vendor register.
This guide includes all the disclosure requirements that businesses must follow in 2026. It also addresses a key issue many overlook: how detailed your policy should be and how to keep it accurate.
Is a privacy policy legally required?
No single US federal law requires every website to have a privacy policy. Instead, requirements come from state laws, industry-specific rules, the GDPR if you handle data from EU residents, and contracts with app stores or analytics providers. Even if none apply, any policy you publish can still be enforced as a promise to your users.
| Regime | Who must comply | What triggers the duty | Mandate type |
| The California Online Privacy Protection Act – CalOPPA (Cal. Bus. & Prof. Code § 22575) | Any operator of a commercial website or online service collecting personal data from California residents | Collection itself; the policy must be conspicuously posted and must state how the operator responds to Do Not Track signals | State statute (since 2004; the first US web-policy mandate) |
| State comprehensive privacy laws (20 in force, 24 enacted as of September 2026) | “Controllers” meeting each state’s applicability test; Texas and Nebraska skip revenue and volume thresholds entirely | Processing state residents’ personal data; every such law requires a reasonably accessible, clear, and meaningful privacy notice | State statutes |
| GDPR, Articles 12–14 (EU’s data protection law) | Any controller processing personal data of people in the EU/EEA, wherever the controller is based | Processing itself; information must be provided in a concise, transparent, intelligible, and easily accessible form | EU regulation |
| COPPA Rule (16 CFR Part 312) | Operators of sites or online services directed to children under 13, or with actual knowledge they collect from children | Collecting personal information from children; notice must appear on the homepage and wherever data is collected | Federal statute + FTC rule |
| GLBA Regulation P (12 CFR Part 1016) | Financial institutions | Customer relationship; initial notice, then annual notices for as long as the relationship lasts | Federal regulation |
| HIPAA Privacy Rule (45 CFR § 164.520) | Covered health plans and health care providers | Holding protected personal health data; a Notice of Privacy Practices (NPP) with prescribed content | Federal regulation |
| Apple App Store Review Guidelines § 5.1.1 | Every app distributed through the App Store | “All apps must include a link to their privacy policy in the App Store Connect metadata field and within the app in an easily accessible manner” | Platform contract |
| Google Play User Data policy | Every app distributed through Google Play, including apps that access no personal data at all | Distribution; policy link required in Play Console and in-app, and it must match the Data safety section | Platform contract |
| Google Analytics Terms of Service § 7 | Any site running Google Analytics | “You must post a Privacy Policy” that discloses your use of Google Analytics and how it collects and processes data | Vendor contract |
One more layer binds businesses no statute touches. Under Section 5 of the FTC Act, “unfair or deceptive acts or practices in or affecting commerce” are unlawful, and the FTC reads a published policy as public promises: diverge from it, and the policy itself becomes the deception. The enforcement record in the second half of this guide runs on that theory. Samuel Levine, Director of the FTC’s Bureau of Consumer Protection, put it plainly in the Avast case:
“Avast’s bait-and-switch surveillance tactics compromised consumers’ privacy and broke the law.”
A terminology note before the item lists. US state statutes say “privacy notice,” older and sectoral laws say “privacy policy,” and California’s regulations require the homepage link to include the word “privacy.” The terms describe the same public document; this guide flags the few places where an instrument prescribes the label.
What must every privacy policy contain?
Most regimes ask for the same core elements. What changes is the level of detail, not the basic structure. Build the first draft around that shared structure, then add the requirements unique to each regime.
| Disclosure element | What to write | Demanded by |
| Identity and contact details | Legal entity name, contact channel for privacy inquiries, and, where required, the data protection officer or EU/UK representative | GDPR Art. 13(1)(a)-(b); every US state law; COPPA (all operators’ names and addresses); LGPD Art. 9 |
| Categories of personal data collected | The categories as the statute lists them (CCPA’s category taxonomy; GDPR’s “personal data”), including sensitive categories where processed | CCPA § 1798.130(a)(5); GDPR Art. 13/14; all state laws; GLBA (categories of nonpublic personal information) |
| Purposes of processing | Purpose per category, specific enough for a reader to understand the actual use, not “to improve our services” | GDPR Art. 13(1)(c); CCPA regs (11 CCR § 7011) require purposes that give the consumer “a meaningful understanding”; PIPL Art. 17 |
| Recipients of the data | Who receives personal data: named recipients or categories of recipients, depending on the regime (the anchor question gets its own section below) | GDPR Art. 13(1)(e); CCPA § 1798.130(a)(5) (categories of third parties); COPPA (identities and categories); GLBA (categories of affiliates and nonaffiliated third parties) |
| Retention | How long each category is kept, or the criteria used to decide | GDPR Art. 13(2)(a); CCPA § 1798.100(a)(3); COPPA (a written, posted retention policy since the 2025 amendments); PIPL Art. 17 |
| Consumer/data subject rights and how to exercise them | The rights your regime grants (access, deletion, correction, portability, opt-outs) plus the request methods, at least two under CCPA | GDPR Art. 13(2)(b); CCPA § 1798.130(a)(5); all state laws; HIPAA NPP |
| Cookies and tracking technologies | What trackers run, what they collect, and who receives it; if you use Google Analytics, its contract requires you to say so | CalOPPA § 22575(b)(6); GDPR (via the ePrivacy consent layer); Google Analytics ToS § 7 |
| Security practices | A description of your security policies and practices at the level the regime prescribes | GLBA Reg P § 1016.4(a)(8); state laws (as a “reasonable security” duty); Google Play policy |
| Children’s data | Whether the service is directed to children, and the parental-consent mechanics if it is | COPPA; state laws’ sensitive-data rules covering known children; California’s under-16 sale/sharing statement (11 CCR § 7011) |
| Sale, sharing, and targeted advertising | Whether you sell or share personal data, the categories involved, and the opt-out mechanism; if you do not sell, several regimes make you say so explicitly | CCPA § 1798.130(a)(5) (including the duty to “prominently disclose” that you do not sell or share, if that is the case); Texas TDPSA § 541.103 |
| Changes and effective date | The effective or “last updated” date and how you will notify users of changes | CalOPPA § 22575(b)(3)-(4); HIPAA § 164.520(b)(3); Australia APP 1.3 (“up to date”) |
| International transfers | Whether data crosses borders and under what safeguards | GDPR Art. 13(1)(f); Australia APP 1.4 (likelihood and countries of overseas disclosure); PIPL Art. 39 |
One correction belongs here because it is a common misinclusion: California’s Age-Appropriate Design Code Act is a DPIA duty, not a policy-disclosure duty, and the Ninth Circuit left it partially enjoined in NetChoice v. Bonta (March 12, 2026). Keep it off the policy checklist.
Two things are as important as the list of required items. The first is specificity: California’s rules require you to explain your reasons for collecting information clearly enough that consumers truly understand why you need their data. Vague or generic explanations are not enough.
The second is plain language: GDPR Article 12 says your policy must be easy to read and understand. Research shows why this matters. One study found the average privacy policy is about 2,514 words long, and reading every policy you see in a year would take around 244 hours. Lorrie Cranor believes this number has probably increased since then:
“It might even be worse now, because now we see this real proliferation of third-party content embedded in websites.”
A template or generator can help you create the basic structure of a privacy policy, but that’s all it does. It can’t know which trackers your website uses or which vendors get your form data. The accuracy of your policy depends on what you actually observe on your site.
What does the GDPR add to privacy policy requirements?
The GDPR is the most itemized disclosure regime in force anywhere, and it sets both the form and the content: Article 12 requires the information to be concise, transparent, intelligible, easily accessible, and in clear and plain language, free of charge. The content list is split by where the data came from.
| Disclosure item | When data comes from the person (Art. 13) | When data comes from elsewhere (Art. 14) |
| Controller identity and contact details | Required | Required |
| Data protection officer’s contact details | Required where a DPO exists | Required where a DPO exists |
| Purposes and the legal basis for each purpose | Required; legitimate interests must be described when relied on | Required |
| Recipients or categories of recipients | Required (the formal choice; see the recipient section below) | Required |
| International transfers and their safeguards | Required where applicable | Required |
| Retention period or the criteria for setting it | Required | Required |
| The rights menu: access, rectification, erasure, restriction, portability, objection | Required | Required |
| Right to withdraw consent at any time | Required where processing rests on consent | Required where processing rests on consent |
| Right to lodge a complaint with a supervisory authority | Required | Required |
| Whether providing data is a statutory or contractual requirement, and the consequences of refusing | Required | Not listed |
| Automated decision-making, including profiling: existence, logic, significance, envisaged consequences | Required where applicable | Required where applicable |
| Source of the data, including whether publicly available | n/a (the person is the source) | Required, with categories of sources |
| Timing | At collection | Within one month, at first communication, or before first disclosure, whichever comes first |
Legal basis per purpose is uniquely GDPR (and UK GDPR); US regimes ask for purposes, never the legal theory beneath each one. And Article 14’s one-month clock gives a business buying or receiving data an affirmative duty to go find the data subjects, a duty with no US equivalent. Penalties for transparency violations sit in the GDPR’s top tier: up to €20 million or 4 percent of global annual turnover under Article 83(5)(b).
For the broader framework, see our GDPR explainer.
What does CCPA/CPRA add?
California’s is the most prescriptive US regime: it dictates not just the policy’s contents but its update cadence, its link text, and even a duty to disclose what you don’t do. The policy obligations sit in Cal. Civ. Code § 1798.130(a)(5) and 11 CCR § 7011.
| CPRA-era disclosure item | The duty |
| Rights and how to exercise them | List the consumer rights and describe the request methods; at least two submission channels (typically a web form and a toll-free number) |
| Categories collected (12-month lookback) | The categories of personal information collected in the preceding 12 months, using the statute’s category taxonomy |
| Categories of sources | Where the information comes from, by category |
| Purposes, specifically | The business or commercial purpose per category, specific enough for “a meaningful understanding”; generic labels fail |
| Categories of third parties | The categories of third parties to whom information is disclosed |
| The two lists | Categories sold or shared, and categories disclosed for a business purpose, each covering the preceding 12 months |
| Negative disclosure | If you have not sold or shared personal information, the policy “shall prominently disclose that fact”; silence is not compliance |
| Retention | How long you retain each category, or the criteria used (§ 1798.100(a)(3)) |
| Sensitive personal information | Whether and how you use or disclose sensitive PI, and the right to limit it |
| Under-16 statement | Whether you sell or share the data of consumers under 16 |
| Notice at collection | A separate, just-in-time notice at or before collection, listing categories and purposes (§ 1798.100(b)) |
| Do Not Sell or Share link + GPC | A conspicuous opt-out link, and honoring the Global Privacy Control (GPC) browser signal |
| Annual update + date | Update the policy at least once every 12 months and show the last-updated date |
| Language and accessibility | Available in the languages in which you do business, and accessible to consumers with disabilities |
| Automated decision-making (ADMT) | Pre-use notice, opt-out, and access duties for significant automated decisions phase in under the 2025 regulations package (risk assessments already apply; ADMT duties follow from January 1, 2027). Mechanics: our CCPA compliance guide |
One caution on the word “sale”: the California Consumer Privacy Act defines it as an exchange for monetary or other valuable consideration, which is how routine advertising analytics became “sales”.
Penalties adjust for inflation: as of January 1, 2025, $2,663 per violation and $7,988 per intentional violation or one involving known minors, plus statutory damages of $107 to $799 per consumer per incident in private breach actions (CPPA adjustment notice; next adjustment is January 2027).
For applicability thresholds, rights mechanics, and enforcement details, see What is CCPA? and the compliance guide.
What do the other state laws add?
Twenty states have relevant data privacy laws in force as of September 2026, and four more (Alabama, Louisiana, Oklahoma, Vermont) are enacted with future effective dates, per the IAPP state privacy legislation tracker.
Read this table as deltas, not entries: nearly all these laws demand the same baseline notice, and only a few add genuine extras. The baseline is a reasonably accessible, clear, and meaningful privacy notice disclosing personal data categories processed, purposes, consumer rights and how to exercise them (including appeal), categories of data shared with third parties, and categories of those third parties. Texas’s § 541.102(a) is a verbatim example of the pattern.
| Delta | State(s) | What your policy must do beyond the baseline |
| Prescribed sale notices, verbatim | Texas | If you sell sensitive data, post the exact sentence “NOTICE: We may sell your sensitive personal data.”; if you sell biometric data, “NOTICE: We may sell your biometric personal data.” Both appear “in the same location and in the same manner” as the privacy notice, and both stack if you do both (TDPSA § 541.102(b)-(c)) |
| No applicability thresholds | Texas, Nebraska | No revenue or data-volume floor: the law reaches any non-exempt business that is not a Small Business Administration (SBA)-defined small business, and even small businesses may not sell sensitive data without consent (Neb. Rev. Stat. § 87-1103) |
| Named-recipient list on request | Oregon, Minnesota | Consumers can demand a list of the specific third parties that received their data; this is an access-request duty, not a policy-naming duty. Full analysis in the recipient section below (ORS 646A.574; Minn. Stat. § 325M.14) |
| Update and dating duties beyond the baseline | California | Annual update plus last-updated date (covered in the California section above); most other states demand accuracy without a fixed cadence |
| Penalty structure | All | Attorney-general enforcement, typically up to $7,500 per violation (Texas: § 541.155, AG-only, 30-day cure, no private right of action); cure periods vary, and some have sunset |
Everything else the state wave adds (opt-out preference signals, sensitive-data consent, data-protection assessments) binds your data handling practices more than your policy text. The notice contents stay close to the baseline.
There are two practical takeaways. First, most businesses use one main privacy policy with an extra section for state-specific rights, especially California. Second, the list of state laws changes often, so any count of “how many states” have privacy laws will quickly become outdated.
What do sectoral laws and non-US regimes add?
If you operate in a regulated sector, a second disclosure layer sits on top of general laws. Each row below is the delta that matters for your policy, not the whole statute.
| Regime | Who it covers | What the notice must disclose (the delta) |
| COPPA Rule, 16 CFR § 312.4 (amended rule fully operative; compliance date April 22, 2026) | Sites and services directed to children under 13, or knowingly collecting from them | The name, address, phone, and email of every operator; what is collected and how; disclosure practices including the “identities and specific categories” of third parties; a written data-retention policy posted in the notice; parental review, refusal, and deletion rights. Civil penalties run $53,088 per violation (16 CFR § 1.98) |
| GLBA Regulation P, 12 CFR §§ 1016.4, 1016.6 | Financial institutions | Categories of nonpublic personal information collected and disclosed; categories of affiliates and nonaffiliated third parties who receive it; the opt-out explanation; your security policies and practices |
| HIPAA Notice of Privacy Practices, 45 CFR § 164.520 | Covered health plans and providers | Uses and disclosures with at least one example per purpose; individual rights; the entity’s duties, including the statement that it is “required to abide by the terms of the notice currently in effect”; complaint routes; effective date; prompt revision after any material change |
| Illinois BIPA, 740 ILCS 14/15(a) | Private entities possessing biometric identifiers | A written policy, “made available to the public,” establishing a retention schedule and destruction guidelines (destruction when the purpose is satisfied or within three years of last interaction). BIPA carries a private right of action at $1,000 (negligent) to $5,000 (intentional/reckless) per violation |
One disambiguation worth printing: “the Privacy Act” means different things in different countries. In the US, it is the 1974 statute governing federal agencies; it doesn’t apply to your business. In Australia, the Privacy Act 1988 is the main private-sector law, and its APP 1 is a genuine policy mandate (below). Same name, opposite relevance.
And the non-US regimes, one row each:
| Regime | The disclosure duty in one row |
| United Kingdom | UK GDPR mirrors the EU item list, and the ICO adds the operative detail: your privacy information must state your purposes and your lawful basis for each (ICO guide to lawful basis) |
| Canada | PIPEDA’s “openness” principle requires making “specific information about its policies and practices” readily available, in a form that is generally understandable (PIPEDA, Schedule 1, clause 4.8); Quebec’s Law 25 adds its own notice duties |
| Australia | APP 1 requires a “clearly expressed and up to date” APP privacy policy, available free of charge, listing seven prescribed items including whether you disclose overseas and to which countries (OAIC, Australian Privacy Principles) |
| Brazil | LGPD Article 9 grants the data subject facilitated access to the specific purpose, form and duration of processing, controller identification and contact, data-sharing information and purpose, and the Article 18 rights; consent is void if the information given is misleading or not transparent (Lei 13.709/2018, in Portuguese) |
| China | PIPL Article 17 requires handlers, before processing, to truthfully, accurately, and fully inform individuals in conspicuous form and clear language of the handler’s name and contact, the purposes and methods, the categories of data, the retention period, and the methods for exercising rights; any change triggers a fresh notice (DigiChina/Stanford translation) |
The pattern across all five: the spine travels. Identity, purposes, categories, recipients, retention, rights. What changes per jurisdiction is granularity and timing.
Do you have to name every recipient, or are categories enough?
In most cases, listing categories of recipients is enough for your privacy policy. You only need to name specific recipients in certain situations. For example, Oregon’s law is often misunderstood: you only have to provide a list of specific third parties if someone asks, not in your published policy.

What the GDPR actually says
Article 13(1)(e) requires “the recipients or categories of recipients.” That “or” is a real choice at the policy level: a well-defined category is compliant. The confusion starts at the access right. In January 2023, the Court of Justice of the EU ruled in C-154/21 (RW v Österreichische Post) that on an access request, the controller must disclose the actual identity of the recipients whenever that is possible.
Categories suffice only where identification is impossible, or the request is manifestly unfounded or excessive, and the choice belongs to the data subject, not the controller. The court did not rewrite Article 13: your policy may still say “categories,” but your access-request answer may have to say names. A controller that cannot name its recipients cannot comply. That is the ruling’s operational bite.
What US state laws actually say
Every comprehensive US state law writes its proactive notice duty in categories: categories of personal data shared, and categories of third parties receiving it. None requires the published policy to enumerate recipients by name. This is a categories-based system by design.
The Oregon exception
Oregon’s Consumer Privacy Act gives a consumer the right to obtain, “at the controller’s option, a list of specific third parties, other than natural persons, to which the controller has disclosed” either that consumer’s data or any consumer’s data (ORS 646A.574(1)(a)(B)). Minnesota’s law grants the same right in nearly identical words (Minn. Stat. § 325M.14, subd. 1(h)). It is a response duty: it activates when someone asks, not when you publish. The controller chooses which list to give: your recipients or its full recipient list.
Where naming is compulsory anyway
- Children’s services. COPPA’s online notice must state the “identities and specific categories” of third parties, one of the only name-required policy duties in US law.
- China. PIPL Article 23 requires notifying individuals of the recipient’s name and obtaining separate consent before providing data to another handler. Article 39 does the same for cross-border provision. Categories don’t satisfy it.
- Consent integrity. Brazil’s LGPD voids consent built on misleading or incomplete disclosure (Art. 9 § 1), which makes vague recipient language a consent problem, not just a notice problem.
- Contract and platform layers. Google Play’s policy must state the parties data is shared with, and GDPR Article 28 processor contracts make the controller-processor chain documentary even where the public policy stays categorical.
Policy vs request vs record: the three-records separation
| Regime | The published policy must disclose | On access request you must produce | Internal record you must keep |
| GDPR | Recipients or categories (Art. 13/14) | Actual recipient identities where possible (Art. 15, per C-154/21) | Records of processing incl. categories of recipients (Art. 30) |
| CCPA/CPRA | Categories of third parties | Categories of third parties + specific pieces of PI | Contracts with each service provider/contractor |
| Oregon / Minnesota | Categories of third parties | List of specific third parties, controller’s option which list | Whatever makes that list producible in 45 days |
| Texas and baseline states | Categories of third parties | Categories | Assessment and contract records |
| COPPA | Identities and categories of third parties | Parental access to the child’s data | Written retention policy |
| GLBA | Categories of affiliates and nonaffiliates | n/a (no access right) | n/a |

So: do jurisdictions actually conflict? Rarely, and not here. What looks like conflict is granularity difference plus one timing difference: some duties attach to the document, others to the request. The real tensions are practical, not legal.
Naming every subprocessor in a public policy collides with readability and goes stale within weeks. Categories stay true longer but answer less. A naming promise you cannot fulfill because you have never observed where the data goes is worse than an honest category. You cannot disclose recipients you have not mapped, which is why tracing what your site actually sends must precede writing.
What happens when the privacy policy meets reality?
A privacy policy is judged against what your site actually does. The gap between the two is now the single most productive enforcement theory in US privacy law. These are the mistakes regulators and plaintiffs keep citing:
- The flatly false sentence. Sephora’s site said “we do not sell personal information” while its trackers sold customer data. The Attorney General’s case led with that sentence.
- The stale policy. Tractor Supply’s policy had not been updated in four years and no longer notified consumers of their rights. The CPPA made it the largest fine in its history.
- Categories that no longer match the vendors. A new tag, agency pixel, or AI vendor silently widens the gap between disclosed categories and the real recipient list.
- Generic purposes. “To improve our services” fails California’s meaningful-understanding standard and tells the reader nothing.
- Missing negative disclosures. California requires you to say prominently when you do not sell or share; silence reads as concealment.
- Opt-outs that exist on paper only. Disney’s $2.75 million settlement (2026) punished opt-out toggles that did not apply across services and devices. The policy promised a control the product did not deliver.
| Enforcer / regime | Legal theory | Case (dated) | Outcome |
| FTC, Section 5 deception | Policy promises contradicted by actual sharing | BetterHelp (Mar. 2023) | $7.8M; banned from sharing health data for advertising |
| FTC, Health Breach Notification Rule (HBNR) | Undisclosed health-data disclosures; first HBNR action | GoodRx (Feb. 2023) | $1.5M civil penalty |
| FTC, Section 5 deception | Sold browsing data while promising to block tracking | Avast (Feb. 2024) | $16.5M; sale ban |
| California AG, CCPA | Failed to disclose data sales; ignored GPC; missed the cure window | Sephora (Aug. 2022) | $1.2M; policy must affirmatively disclose the sale |
| CPPA, CCPA | No compliant privacy policy; no job-applicant notice; broken opt-outs | Tractor Supply (Sep. 2025) | $1.35M; quarterly tracking-tech scans; 4-year officer certification |
| California AG, CCPA | Sold driver location and behavior data; “never disclosed the sales” | General Motors (May 2026) | $12.75M |
| California AG, CCPA | Tracking on a health site contrary to disclosures | Healthline (Jul. 2025) | $1.55M; settlement requires “accurate online disclosures and privacy policy” |
| GDPR, top fine tier | Transparency and information-duty breaches | Article 83(5)(b) | Up to €20M or 4% of global annual turnover |
| Private plaintiffs | Statutory damages and the published promise as exhibit | CCPA breach actions: $107–$799 per consumer per incident (CPPA adjustment); BIPA: $1,000–$5,000 per violation | Class complaints plead that the defendant “violated its own Privacy Policy” |
“There are no more excuses,” California AG Rob Bonta said when announcing the Sephora settlement:
“Follow the law, do right by consumers, and process opt-out requests made via user-enabled global privacy controls”

Keeping your privacy policy accurate is an ongoing responsibility. Several laws make this clear:
| Duty | Regime | The requirement |
| Annual update | CCPA/CPRA | Update the policy at least once every 12 months, with the last-updated date displayed (11 CCR § 7011(e)(4)) |
| Prompt revision | HIPAA | Revise the Notice of Privacy Practices promptly after any material change |
| Currency | Australia APP 1 | The policy must be “clearly expressed and up to date” as a standing condition |
| Change notice | CalOPPA, PIPL | State how users will be notified of changes (CalOPPA); notify individuals of changes to any notified item (PIPL Art. 17) |
| Consistency | Google Play | The privacy policy and the Play Console Data Safety form must match, or the app faces removal |
California’s twelve-month duty is the only hard calendar in US law, but every regime treats an inaccurate policy as a current violation, so “reviewed when someone remembers” is non-compliant everywhere in effect. The triggers are operational. A new vendor, tag, form field, purpose, or state law taking effect can falsify the document overnight.
How does MELURNA help?
Everything above assumes you know what your site actually sends. That assumption is what the cases above broke on: disclosures are written from the vendor register and contract file, while the real recipient list lives in the tag container, form handler, and fourth-party scripts your vendors load.
MELURNA is built on the observed side of that gap. It tracks data flows from the moment data enters your site through all the third parties and beyond, showing exactly what information is shared and with whom.
MELURNA compares what your policy promises with what actually happens, just like regulators do. It also checks if user choices, like opt-outs or Global Privacy Control signals, really change who gets the data. Continuous monitoring helps you spot changes, like new tags or vendors, that could make your policy inaccurate between reviews. All findings are mapped to over 30 compliance frameworks and come with timestamped evidence for your legal team.
What MELURNA does not do is write your privacy policy or provide legal advice. You and your legal team are responsible for drafting the policy. What it does is give you the evidence you need, so you know where your regulated data goes before a regulator or a plaintiff’s expert finds out.
Request a demo to see how data moves through your own website.
Next steps
Audit your current policy against the disclosure spine above and mark every element your regimes require but the document lacks. Then close the evidence gap. See what your site actually sends, and to whom, before a regulator runs the same comparison for you. If California is your binding regime, continue with What is CCPA? and the CCPA compliance guide; if your immediate problem is tracking coverage, start with how data privacy risk actually happens.
FAQs
Is a privacy policy legally required?
Not under one universal US federal law. It becomes mandatory in layers: CalOPPA for any commercial site collecting data from California residents, the 20 in-force state comprehensive laws, GDPR for anyone processing EU residents’ data, sectoral rules like COPPA, GLBA, and HIPAA, and platform contracts (Apple, Google Play, Google Analytics) that require one as a condition of distribution. Even where nothing mandates a policy, a published one is enforceable against you under FTC Act Section 5.
Do I have to name every third party in my privacy policy?
Almost never. GDPR Article 13(1)(e) makes “recipients or categories of recipients” a formal choice, and every US state notice duty is categories-based. Naming becomes compulsory in specific situations: COPPA notices (identities and categories), China when providing data to another handler (PIPL Art. 23), and on request in Oregon and Minnesota, where consumers can demand a list of the specific third parties that received their data.
How often must a privacy policy be updated?
California sets the only hard US calendar: at least every 12 months, with the last-updated date shown. HIPAA requires prompt revision after material changes, Australia requires the policy to be “up to date” as a standing condition, and every regime treats an inaccurate policy as a live violation. Operationally, the update triggers are new vendors, new tags, new data uses, and new laws taking effect.
Is a privacy policy the same as a privacy notice?
In practice, yes: the terms describe the same public document. US state statutes tend to say “privacy notice,” sectoral and older laws say “privacy policy,” and California’s regulations require the homepage link to include the word “privacy.” A few instruments prescribe the label, so follow the form rule of the regime you are writing under.
What happens if my privacy policy is wrong?
The policy becomes the evidence against you. The FTC treats a false policy as a deceptive practice under Section 5 (BetterHelp, $7.8M, and Avast, $16.5M). California’s AG and the CPPA fine disclosure failures directly (Sephora, $1.2M, Tractor Supply, $1.35M, and GM, $12.75M). GDPR transparency breaches sit in the top fine tier, up to €20M or 4 percent of global turnover. And plaintiff firms quote the policy verbatim in class complaints as the promise you broke.
Does a template or generator make me compliant?
It gives you compliant structure, not compliant content. A template cannot know which trackers fire on your checkout page, which vendors receive your form data, or whether your opt-out actually works, and those are precisely the facts regulators check first. Use templates for skeleton and wording. Verify the substance against what your site observably does.
DISCLAIMER: This guide is for general informational purposes only and does not constitute legal advice. While we strive for accuracy, we make no warranties about the completeness or reliability of this information, and are not liable for any errors, omissions, or actions taken based on its contents. Consult a licensed attorney for guidance specific to your business.
