EnglishEspañol

Privacy Policy Requirements: What You Must Include (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 4 primary sources cited on this page. How we verify our legal content

Privacy Policy Requirements: What You Must Include (2026)

Frequently Asked Questions

Is a privacy policy legally required for all websites?

Not under federal law alone. However, CalOPPA requires any commercial website or app collecting personal information from California residents to post a privacy policy, which effectively covers most US-facing websites. If you process data from EU residents, the GDPR independently requires a privacy notice. Nearly 20 US states now have comprehensive privacy laws with notice requirements.

What is the penalty for not having a privacy policy?

CalOPPA carries no penalty of its own. The remedy runs through California's Unfair Competition Law, which allows civil penalties of up to $2,500 per violation in an action by the Attorney General, a district attorney, or certain city attorneys. Section 22575(a)'s 30-day window covers only the failure to post a policy at all, not a posted policy that omits required disclosures. Under the CCPA, penalties reach $2,663 per unintentional violation and $7,988 per intentional violation. The GDPR allows fines up to 20 million euros or 4% of global annual turnover. COPPA violations carry penalties of up to $53,088 per violation.

How often should a privacy policy be updated?

The CCPA requires annual review and update. There is no specific federal frequency requirement, but best practice calls for updating whenever data collection practices change, new third-party sharing begins, or a new privacy law takes effect in a jurisdiction where you operate. The policy must always accurately reflect current practices.

Does the GDPR require a privacy policy?

The GDPR requires a 'privacy notice' or 'transparency information' under Articles 13 and 14, which functions like a privacy policy. It must disclose the identity of the data controller, DPO contact details, purposes and legal bases for processing, retention periods, data subject rights, and information about international transfers. It must be written in clear, plain language.

What must a CCPA privacy policy include?

The CCPA requires disclosure of categories of personal information collected, purposes of collection, sources of data, third-party sharing and selling practices, retention periods for each category, and a description of all consumer rights with instructions for exercising them. Businesses that sell data must include a 'Do Not Sell or Share My Personal Information' link.

Do I need a separate privacy policy for my mobile app?

Both Apple's App Store and Google Play require apps to have a privacy policy, and the policy must be accessible both within the app and on the app store listing. If your app's data practices differ from your website, a separate or supplemental policy is recommended. CalOPPA and the CCPA apply to mobile apps the same way they apply to websites.

What are the COPPA privacy policy requirements for children's sites?

COPPA requires sites directed at children under 13 to disclose all categories of data collected, how data is used, third-party sharing, parental rights (review, delete, refuse further collection), and operator contact information. The policy must link from the homepage and every page where child data is collected. Verifiable parental consent is required before collection.

Can I use a privacy policy template or generator?

Templates can provide a starting point, but regulators have fined companies for using generic policies that do not accurately describe their actual data practices. Any template must be customized to reflect the specific categories of data collected, actual sharing practices, applicable laws, and real consumer rights. A misleading privacy policy is worse than a missing one from an enforcement perspective.

Updates

Corrected the California Age-Appropriate Design Code section (the data protection impact assessment is an internal document produced to the Attorney General on request, not a privacy policy disclosure) and updated its injunction status after the Ninth Circuit's March 12, 2026 ruling; corrected CalOPPA's penalty and cure-period description and the GDPR and CCPA multi-language attributions.

Updated the CCPA and COPPA penalty figures to the current inflation-adjusted amounts, corrected the CCPA privacy-policy content citation, noted the FAST Act annual-notice exception, and refreshed the state-law count.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. FTC Act Section 5 - Unfair or Deceptive Acts or Practices(ftc.gov).gov
  2. COPPA (15 USC 6501-6506)(law.cornell.edu)
  3. COPPA Rule (16 CFR Part 312)(law.cornell.edu)
  4. HIPAA Notice of Privacy Practices (45 CFR 164.520)(law.cornell.edu)
  5. CalOPPA (Cal. Bus. & Prof. Code 22575)(leginfo.legislature.ca.gov).gov
  6. CCPA Section 1798.100(leginfo.legislature.ca.gov).gov
  7. CPPA Regulations (11 CCR 7011)(cppa.ca.gov).gov
  8. GDPR Article 13 - Transparency Requirements(gdpr-info.eu)
  9. GDPR Article 12 - Transparent Information and Communication(gdpr-info.eu)
  10. GDPR Article 83 - Administrative Fines(gdpr-info.eu)
  11. GLBA Privacy Rule (Regulation P)(law.cornell.edu)
  12. CAADCA Data Protection Impact Assessment (Cal. Civ. Code 1798.99.31)(leginfo.legislature.ca.gov)
  13. NetChoice, LLC v. Bonta, No. 25-2366 (9th Cir. Mar. 12, 2026)(ca9.uscourts.gov)
  14. Unfair Competition Law civil penalties (Cal. Bus. & Prof. Code 17206)(leginfo.legislature.ca.gov)
  15. CalOPPA standard of noncompliance (Cal. Bus. & Prof. Code 22576)(leginfo.legislature.ca.gov)
  16. Article 29 Working Party Guidelines on Transparency under Regulation 2016/679 (WP260 rev.01)(ec.europa.eu)
  17. CCPA Regulations, 11 CCR 7003 (Requirements for Disclosures and Communications to Consumers)(cppa.ca.gov)
Share: