Privacy Policy in the US
The United States has no general federal privacy statute, so the obligation to publish a privacy policy comes from state law. California's online privacy law has required a conspicuously posted policy since 2004 and prescribes its minimum contents, while the California Consumer Privacy Act adds disclosures that must be refreshed at least every twelve months. Texas is stricter about wording: a controller selling sensitive or biometric data must post two prescribed sentences verbatim.
Governing law
State consumer privacy statutes impose the notice obligation and prescribe its contents. Federal law applies sectorally rather than generally.
What a privacy policy has to contain in the US
An operator of a commercial website or online service collecting personally identifiable information about individual consumers residing in California must conspicuously post its privacy policy, and is in violation only if it fails to post within 30 days after being notified of noncompliance.
That policy must identify the categories of personally identifiable information collected and the third-party categories it may be shared with, describe any review process and how material changes are notified, give its effective date, and disclose how the operator responds to browser do not track signals.
A business subject to the California Consumer Privacy Act must disclose in its online privacy policy a description of consumer rights, two or more request methods, the categories of personal information collected in the preceding 12 months, their sources, the business purpose, the third-party categories disclosed to, and separate lists of categories sold or shared and disclosed for a business purpose, updated at least once every 12 months.
That Act applies to a for-profit entity doing business in California that determines the purposes and means of processing and meets one of three thresholds: annual gross revenues above $25,000,000 as adjusted under § 1798.199.95(d), handling the personal information of 100,000 or more consumers or households, or deriving 50 percent or more of annual revenues from selling or sharing personal information.
A Texas controller must provide a reasonably accessible and clear privacy notice covering the categories of personal data processed including sensitive data, the purpose of processing, how consumers exercise and appeal their rights, the categories of data shared with third parties and of those third parties, and the request submission methods.
Form, notarisation and registration
A Texas controller that sells sensitive personal data must post the exact sentence "NOTICE: We may sell your sensitive personal data." and one that sells biometric data must post "NOTICE: We may sell your biometric personal data.", each in the same location and manner as the privacy notice.
What catches drafters out
The Texas act has no revenue threshold: it applies to any person that conducts business in Texas or produces a product or service consumed by Texas residents, processes or sells personal data, and is not a small business as defined by the US Small Business Administration.
An operator collecting personal information from children must obtain verifiable parental consent before collection, use or disclosure, and make reasonable efforts to give the parent direct notice of its practices, including any material change to practices previously consented to.
Privacy Policy in the US: common questions
- Does US law require a website to have a privacy policy?
- There is no general federal requirement, but California Business and Professions Code § 22575(a) requires an operator of a commercial website or online service collecting personally identifiable information about California residents to post a privacy policy conspicuously. Section 22575(b) prescribes its contents, including the categories of information collected, the categories of third parties it may be shared with, how material changes are notified, the effective date, and how the operator responds to do not track signals.
- How often must a US privacy policy be updated?
- Under California Civil Code § 1798.130(a)(5), a business subject to the California Consumer Privacy Act must update the required disclosures in its online privacy policy at least once every 12 months. Those disclosures include the categories of personal information collected in the preceding 12 months, the sources, the business or commercial purpose, the categories of third parties disclosed to, and separate lists of categories sold or shared and categories disclosed for a business purpose.
- Does a small US business need a privacy policy under the Texas law?
- Texas Business and Commerce Code § 541.002(a) applies the Texas Data Privacy and Security Act to a person that conducts business in Texas or produces a product or service consumed by Texas residents, processes or sells personal data, and is not a small business as defined by the US Small Business Administration. There is no revenue threshold. Section 541.102(b) and (c) also require exact prescribed sentences where sensitive or biometric personal data is sold.
Sources
Every statement on this page is drawn from one of these. All were fetched on .
- Cal. Bus. & Prof. Code § 22575
- Cal. Bus. & Prof. Code § 22575(a)
- Cal. Bus. & Prof. Code § 22575(b)(1) to (5)
- Cal. Civ. Code § 1798.130(a)(5)
- Cal. Civ. Code § 1798.140(d)(1)
- Tex. Bus. & Com. Code § 541.102(a)
- Tex. Bus. & Com. Code § 541.102(b) and (c)
- Tex. Bus. & Com. Code § 541.002(a)
- 16 CFR § 312.4(a) and (b)
The same document elsewhere
Other US documents
- Employment Contract
- Non-Compete Agreement
- Termination Letter
- Independent Contractor Agreement
- Non-Disclosure Agreement (NDA)
- Service Agreement
- Residential Lease Agreement
- Commercial Lease Agreement
- Eviction Notice
- Power of Attorney
- Last Will and Testament
- LLC Operating Agreement
- Shareholder Agreement
- Loan Agreement
Privacy Policy: the jurisdiction-neutral guideBack to Document Library