No federal cookie law and no legal notices page. One privacy policy is genuinely mandatory, with no size threshold, and it applies to a two-person firm.
There is no American cookie law, no mandatory legal notices page, and the accessibility rule everyone cites does not apply to private companies. There is also one genuinely mandatory page that applies to a two-person business with no revenue threshold whatsoever, and most European sites serving US visitors do not have it in the required form.
The result is a compliance profile that looks nothing like the European one. European companies expanding into the US tend to bring a banner they do not need and omit a policy they do.
One caution on how to read what follows. Some of this is proven by absence: no statute exists. That is a weaker form of evidence than a citation, and it is flagged where it applies.
The cookie banner nobody asked you for
This is the difference that surprises people most, and it is worth establishing carefully rather than asserting.
The FTC enumerates the federal privacy laws it enforces. Its own list names the Fair Credit Reporting Act, children’s online privacy law, the Gramm-Leach-Bliley Act, commercial email law, and debt collection law. Nothing about cookies. Nothing about prior consent to tracking.
It proposed to go further, and did not. A 2022 advance notice of proposed rulemaking on commercial surveillance opened the question. As of September 2026 no final rule has issued from it.
And the agency describes the landscape as fragmented. Federal privacy legislation “would give businesses much-needed clarity and certainty regarding the rules of the road in this important area, particularly given the patchwork of state laws that is emerging.”
What does apply federally is the general prohibition on deception. Which polices what you say about your practices, not whether you obtained permission. If your policy says you do not track and you track, that is the violation. Tracking with an accurate disclosure is not.
With a limit the FTC states about its own powers. The statute “generally does not allow the Commission to seek civil penalties for first-time violations of that provision.”
The one federal consent regime is for children. Children’s online privacy law requires “verifiable parental consent” before collecting personal information from a child under 13. That is the exception, and it proves the general rule.
A caution on this section. No official document states in terms that there is no federal cookie law. The conclusion rests on the agency’s own exhaustive enumeration plus the absence of a final rule. It is solid, and it is proof by absence.
If you publish nothing else, publish this, because it is the only requirement here with no revenue threshold and no headcount test.
Who it applies to. “An operator of a commercial Web site or online service that collects personally identifiable information through the Internet about individual consumers residing in California who use or visit its commercial Web site or online service shall conspicuously post its privacy policy.”
And the definition of what triggers it is broad. Personally identifiable information includes a name, a physical address, “an e-mail address”, a telephone number, and “any other identifier that permits the physical or online contacting of a specific individual.”
Which is to say a contact form does it. There is no minimum. A company with one landing page and an email field is an operator collecting personally identifiable information.
The seven required contents. The categories collected and the categories of third parties with whom they may be shared; a description of any process to review and request changes; how you notify people of material changes; “its effective date”; how you respond to browser do-not-track signals; whether other parties may collect information about a visitor’s activity across sites over time; and, optionally, a hyperlink satisfying the do-not-track element.
The effective date is the element most often missing. It is a named requirement, not a nicety.
And there is a cure period, which is unusually generous. An operator “shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance.”
With the standard for breach set at two states of mind. Failing to comply with the section or with your own posted policy, “knowingly and willfully” or “negligently and materially”. Writing a policy you do not follow is the second route.
The broader privacy obligations, the ones people mean when they say CCPA, do not apply to every company. Three tests, any one of which brings you in.
Revenue. Annual gross revenues above a figure the statute sets at $25 million and which is indexed. The applicable figure is $26,625,000, and quoting the statutory number rather than the adjusted one is a common error.
Volume. Buying, selling or sharing the personal information of 100,000 or more consumers or households, annually, “alone or in combination”.
Or dependence. Deriving 50 percent or more of annual revenue from selling or sharing personal information.
And the penalties are indexed too. $2,663 per violation, rising to $7,988 for an intentional violation or one involving a consumer under 16. A private action after a data breach carries statutory damages of $107 to $799 per consumer per incident, or actual damages if greater.
One threshold that catches B2B companies unexpectedly. The volume test counts information you share, and sharing includes disclosure for cross-context behavioural advertising. A site with heavy traffic and retargeting can reach 100,000 without ever selling anything.
The homepage link, and when you can skip it. A “Do Not Sell or Share My Personal Information” link is required if you sell or share, but not “if the business allows consumers to opt out … through an opt-out preference signal”. Honouring the universal signal can replace the link.
The accessibility rule that does not say what it is quoted as saying
This is the correction most worth making, because the misreading is nearly universal and it points companies at the wrong obligation.
Who the 2024 rule covers. “Title II of the ADA requires state and local governments to make sure that their services, programs, and activities are accessible to people with disabilities.” The Department of Justice fact sheet adds that Title II “uses the term ‘public entities’ to describe who it applies to, but in this fact sheet, we call these ‘state and local governments.’”
So it is not about your company. A private business is a Title III entity. The 2024 rule is a Title II rule.
Its technical standard, for the entities it does cover. “The Web Content Accessibility Guidelines (WCAG) Version 2.1, Level AA is the technical standard for state and local governments’ web content and mobile apps.” Note 2.1, not 2.2.
And its deadlines moved. An interim final rule published on 20 April 2026 extended compliance to 26 April 2027 for entities with populations of 50,000 or more, and to 26 April 2028 for smaller entities and special district governments. The dates published in 2024 are no longer the applicable ones.
What applies to a private company instead. The DOJ’s position is that the ADA does reach commercial websites: it “has consistently taken the position that the ADA’s requirements apply to all the goods, services, privileges, or activities offered by public accommodations, including those offered on the web.”
But without a technical standard. “Businesses and state and local governments have flexibility in how they comply … The Department of Justice does not have a regulation setting out detailed standards, but the Department’s longstanding interpretation of the general nondiscrimination and effective communication provisions applies to web accessibility.”
Which is the accurate statement of the position. You are subject to a general obligation with no prescribed test. WCAG 2.1 AA is the de facto reference used in litigation and settlements, and it is a sensible target. It is not a regulatory requirement imposed on a private company by the 2024 rule, and saying otherwise misstates the law. Aiming at it is a build decision rather than a legal one, which is why it belongs in the specification when a B2B site is built to that standard from the start rather than retrofitted later.
State privacy laws are multiplying, and the count is harder to state than it looks. A coalition of state attorneys general wrote in June 2026 that “since 2018, twenty states have enacted comprehensive privacy laws.” That says enacted, not in effect, and some carry deferred dates. No official consolidated register of which are currently in force was located. Cite the figure with its wording and its source.
And children’s privacy rules changed recently. The amended rule took effect on 23 June 2025 with a compliance date of 22 April 2026, which has passed. Among the additions is a retention obligation: information “may not be retained indefinitely”, and the operator must maintain “a written data retention policy” published in its notice.
That last point generalises. Between the children’s rule and the California retention requirement, a written retention decision is now something a US-facing site is expected to have and to publish. It is the requirement most companies have never made a decision about.
Check whether you have a privacy policy that names its effective date and says how you respond to do-not-track signals. Those two elements are named requirements and they are the two most commonly absent.
Then decide whether the banner on your site is doing anything. If your audience is US-only, it may be answering a question nobody asked while the notice at your form, which is the real obligation, is missing.
Work out which side of the thresholds you are on, using the indexed revenue figure rather than the one printed in the statute, and remembering that retargeting counts toward the volume test.
And if accessibility is on your roadmap, keep it there, for the right reason. The general obligation is real, the technical standard is not prescribed for you, and WCAG 2.1 AA remains the sensible target regardless of what the 2024 rule does or does not require.
No federal law requires one. The FTC's own list of the privacy laws it enforces contains nothing on cookies or prior consent, and its 2022 rulemaking on commercial surveillance has produced no final rule.
Is a privacy policy mandatory?
Yes, and with no size threshold. California online privacy law applies to any operator of a commercial website collecting personally identifiable information, which it defines to include an email address, from California residents.
Does the 2024 DOJ accessibility rule apply to my company site?
Not if you are a private business. That rule covers state and local governments. Private businesses are still subject to the ADA, but the DOJ states it 'does not have a regulation setting out detailed standards' for them.
Do I need a legal notices page like in Europe?
No US federal equivalent was found. What is mandatory is a valid physical postal address in every commercial email you send, which is a different obligation in a different place.