There is no American cookie law, no mandatory legal notices page, and the accessibility rule everyone cites does not apply to private companies. There is also one genuinely mandatory page that applies to a two-person business with no revenue threshold whatsoever, and most European sites serving US visitors do not have it in the required form.

The result is a compliance profile that looks nothing like the European one. European companies expanding into the US tend to bring a banner they do not need and omit a policy they do.

One caution on how to read what follows. Some of this is proven by absence: no statute exists. That is a weaker form of evidence than a citation, and it is flagged where it applies.

This is the difference that surprises people most, and it is worth establishing carefully rather than asserting.

The FTC enumerates the federal privacy laws it enforces. Its own list names the Fair Credit Reporting Act, children’s online privacy law, the Gramm-Leach-Bliley Act, commercial email law, and debt collection law. Nothing about cookies. Nothing about prior consent to tracking.

It proposed to go further, and did not. A 2022 advance notice of proposed rulemaking on commercial surveillance opened the question. As of September 2026 no final rule has issued from it.

And the agency describes the landscape as fragmented. Federal privacy legislation “would give businesses much-needed clarity and certainty regarding the rules of the road in this important area, particularly given the patchwork of state laws that is emerging.”

What does apply federally is the general prohibition on deception. Which polices what you say about your practices, not whether you obtained permission. If your policy says you do not track and you track, that is the violation. Tracking with an accurate disclosure is not.

With a limit the FTC states about its own powers. The statute “generally does not allow the Commission to seek civil penalties for first-time violations of that provision.”

The one federal consent regime is for children. Children’s online privacy law requires “verifiable parental consent” before collecting personal information from a child under 13. That is the exception, and it proves the general rule.

A caution on this section. No official document states in terms that there is no federal cookie law. The conclusion rests on the agency’s own exhaustive enumeration plus the absence of a final rule. It is solid, and it is proof by absence.

Website obligations in the United States separated by whether they are mandatory and at what levelSeparation of website publication obligations in the United States according to whether they are mandatory, at which level of government they arise, and whether any size threshold applies. Not required at federal level are a cookie consent banner and any prior consent to tracking, since the trade commission’s own enumeration of the sector specific privacy laws it enforces contains no such provision and its 2022 advance notice of proposed rulemaking on commercial surveillance has produced no final rule. Also not found is any federal requirement to publish legal notices identifying the publisher, host or corporate registration details of the kind required in some European jurisdictions, this being established by absence of any located statute rather than by an official statement. Required at state level without any size threshold is a privacy policy under California online privacy law, which applies to any operator of a commercial website or online service collecting personally identifiable information through the internet about individual consumers residing in California, defines personally identifiable information to include a first and last name, a physical address, an email address, a telephone number, a social security number and any other identifier permitting contact, requires seven specified contents, and provides that the operator is in violation only if it fails to post its policy within thirty days of being notified of non compliance. Required at state level above thresholds are the fuller consumer privacy obligations, which apply where annual gross revenue exceeds twenty six million six hundred and twenty five thousand dollars as adjusted for inflation, or where the business buys sells or shares the personal information of one hundred thousand or more consumers or households, or where it derives fifty percent or more of annual revenue from selling or sharing personal information. Required federally in a different place entirely is a valid physical postal address in every commercial email sent.Mandatory, conditional, and not required at allNot requiredA cookie consent banner. Prior consent to tracking. A legal notices page naming the publisher and host.The first two rest on the FTC’s own enumeration plus the absence of a final rule. The third is proof by absence.Required, with no size threshold at allA privacy policy, under California online privacy law, for any commercial site collecting personally identifiableinformation from California residents. That definition includes an email address.A two-person company with a contact form is in scope.Required above thresholdsThe fuller consumer privacy obligations, where any one applies: revenue above $26,625,000, or 100,000 or moreconsumers or households, or 50 percent or more of revenue from selling or sharing personal information.Note the revenue figure. The statute still says $25 million; the indexed figure is higher.And one federal requirement in a different place: a valid physical postal address in every commercial email.
The banner is optional. The privacy policy is not, and it is the one obligation with no size threshold. Source : FTC 87 FR 51273; California Business and Professions Code 22575; California Civil Code 1798.140 (2026)

The one page that is genuinely mandatory

If you publish nothing else, publish this, because it is the only requirement here with no revenue threshold and no headcount test.

Who it applies to. “An operator of a commercial Web site or online service that collects personally identifiable information through the Internet about individual consumers residing in California who use or visit its commercial Web site or online service shall conspicuously post its privacy policy.”

And the definition of what triggers it is broad. Personally identifiable information includes a name, a physical address, “an e-mail address”, a telephone number, and “any other identifier that permits the physical or online contacting of a specific individual.”

Which is to say a contact form does it. There is no minimum. A company with one landing page and an email field is an operator collecting personally identifiable information.

The seven required contents. The categories collected and the categories of third parties with whom they may be shared; a description of any process to review and request changes; how you notify people of material changes; “its effective date”; how you respond to browser do-not-track signals; whether other parties may collect information about a visitor’s activity across sites over time; and, optionally, a hyperlink satisfying the do-not-track element.

The effective date is the element most often missing. It is a named requirement, not a nicety.

And there is a cure period, which is unusually generous. An operator “shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance.”

With the standard for breach set at two states of mind. Failing to comply with the section or with your own posted policy, “knowingly and willfully” or “negligently and materially”. Writing a policy you do not follow is the second route.

Required contents of the mandatory website privacy policy and the conditions of violationThe contents required in the privacy policy that must be conspicuously posted by any operator of a commercial website or online service collecting personally identifiable information about individual consumers residing in California, together with the conditions under which a violation arises. Seven contents are specified. First, identification of the categories of personally identifiable information the operator collects about individual consumers who use or visit the site, and the categories of third party persons or entities with whom the operator may share that information. Second, where the operator maintains a process for an individual consumer to review and request changes to their personally identifiable information, a description of that process. Third, a description of the process by which the operator notifies consumers of material changes to the privacy policy. Fourth, identification of the policy’s effective date. Fifth, disclosure of how the operator responds to web browser do not track signals or other mechanisms providing consumers the ability to exercise choice regarding collection of personally identifiable information about their online activities over time and across third party sites, where the operator engages in such collection. Sixth, disclosure of whether other parties may collect personally identifiable information about an individual consumer’s online activities over time and across different websites when a consumer uses the operator’s site. Seventh, an operator may satisfy the fifth element by providing a clear and conspicuous hyperlink to an online location containing a description, including the effects, of any program or protocol the operator follows offering that choice. Personally identifiable information is defined to include a first and last name, a home or other physical address, an email address, a telephone number, a social security number, and any other identifier permitting the physical or online contacting of a specific individual. The operator is in violation only where it fails to post its policy within thirty days after being notified of non compliance, and violation of the section requires failure to comply either knowingly and willfully or negligently and materially.The seven things it has to contain1. Categories collected, and the categories of third parties you may share them with2. Any process to review and request changes to that information3. How you notify people of material changes to the policy4. “Its effective date”most often missing5. How you respond to browser do-not-track signals6. Whether other parties collect activity data across sites when people use yours7. Optionally, a hyperlink satisfying item fiveA generous cure periodIn violation “only if the operator fails to post itspolicy within 30 days after being notified”.And a second route to breachFailing to comply with your own posted policy,“knowingly and willfully” or “negligently and materially”.
No threshold, a thirty day cure period, and an effective date that counts as a named requirement. Source : California Business and Professions Code 22575 to 22577 (2014)

Where the thresholds actually sit

The broader privacy obligations, the ones people mean when they say CCPA, do not apply to every company. Three tests, any one of which brings you in.

Revenue. Annual gross revenues above a figure the statute sets at $25 million and which is indexed. The applicable figure is $26,625,000, and quoting the statutory number rather than the adjusted one is a common error.

Volume. Buying, selling or sharing the personal information of 100,000 or more consumers or households, annually, “alone or in combination”.

Or dependence. Deriving 50 percent or more of annual revenue from selling or sharing personal information.

And the penalties are indexed too. $2,663 per violation, rising to $7,988 for an intentional violation or one involving a consumer under 16. A private action after a data breach carries statutory damages of $107 to $799 per consumer per incident, or actual damages if greater.

One threshold that catches B2B companies unexpectedly. The volume test counts information you share, and sharing includes disclosure for cross-context behavioural advertising. A site with heavy traffic and retargeting can reach 100,000 without ever selling anything.

The homepage link, and when you can skip it. A “Do Not Sell or Share My Personal Information” link is required if you sell or share, but not “if the business allows consumers to opt out … through an opt-out preference signal”. Honouring the universal signal can replace the link.

Applicability thresholds and penalty amounts under California consumer privacy law after inflation adjustmentThe three alternative thresholds determining whether the fuller California consumer privacy obligations apply to a business, together with the penalty amounts, all stated at their inflation adjusted values rather than the values printed in the statute. A business is within scope if it satisfies any one of three tests. The first is annual gross revenue in the preceding calendar year exceeding a figure set in the statute at twenty five million dollars but adjusted to twenty six million six hundred and twenty five thousand dollars effective January 2025 and applicable through 2026, the next adjustment falling due in January 2027. The second is buying, selling or sharing, alone or in combination, the personal information of one hundred thousand or more consumers or households annually. The third is deriving fifty percent or more of annual revenue from selling or sharing consumers’ personal information. The volume test can be reached unexpectedly by business to business companies because sharing includes disclosure for cross context behavioral advertising, so a site with substantial traffic running retargeting can pass one hundred thousand without ever selling anything. Administrative penalties are two thousand six hundred and sixty three dollars per violation, rising to seven thousand nine hundred and eighty eight dollars for an intentional violation or one involving a consumer under sixteen years of age, both figures likewise adjusted from the statutory two thousand five hundred and seven thousand five hundred. Statutory damages available in a private action following a data breach are one hundred and seven to seven hundred and ninety nine dollars per consumer per incident, or actual damages if greater, adjusted from one hundred to seven hundred and fifty. Separately, the homepage opt out link is required only where the business sells or shares, and is not required where the business allows consumers to opt out through an opt out preference signal.Three thresholds, any one of which countsRevenue$26,625,000The statute says $25M. This is theindexed figure, and it is the one that applies.Volume100,000Consumers or households whose datayou buy, sell or share annually.Dependence50%Or more of annual revenue fromselling or sharing personal information.The one that catches B2B companies unexpectedlyVolume counts what you share, and retargeting is sharing. Heavy traffic plus pixels can reach 100,000 without a sale.Penalties, also indexed$2,663 per violation. $7,988 if intentional orinvolving a consumer under 16.And after a breach$107 to $799 per consumer per incident in aprivate action, or actual damages if greater.The homepage opt-out link is required only if you sell or share, and honouring the universal signal replaces it.
Any one threshold brings you in. Two of the numbers below differ from the ones printed in the statute. Source : California Civil Code 1798.140(d), 1798.155 and 1798.150, with the agency's CPI adjustment (2025)

The accessibility rule that does not say what it is quoted as saying

This is the correction most worth making, because the misreading is nearly universal and it points companies at the wrong obligation.

Who the 2024 rule covers. “Title II of the ADA requires state and local governments to make sure that their services, programs, and activities are accessible to people with disabilities.” The Department of Justice fact sheet adds that Title II “uses the term ‘public entities’ to describe who it applies to, but in this fact sheet, we call these ‘state and local governments.’”

So it is not about your company. A private business is a Title III entity. The 2024 rule is a Title II rule.

Its technical standard, for the entities it does cover. “The Web Content Accessibility Guidelines (WCAG) Version 2.1, Level AA is the technical standard for state and local governments’ web content and mobile apps.” Note 2.1, not 2.2.

And its deadlines moved. An interim final rule published on 20 April 2026 extended compliance to 26 April 2027 for entities with populations of 50,000 or more, and to 26 April 2028 for smaller entities and special district governments. The dates published in 2024 are no longer the applicable ones.

What applies to a private company instead. The DOJ’s position is that the ADA does reach commercial websites: it “has consistently taken the position that the ADA’s requirements apply to all the goods, services, privileges, or activities offered by public accommodations, including those offered on the web.”

But without a technical standard. “Businesses and state and local governments have flexibility in how they comply … The Department of Justice does not have a regulation setting out detailed standards, but the Department’s longstanding interpretation of the general nondiscrimination and effective communication provisions applies to web accessibility.”

Which is the accurate statement of the position. You are subject to a general obligation with no prescribed test. WCAG 2.1 AA is the de facto reference used in litigation and settlements, and it is a sensible target. It is not a regulatory requirement imposed on a private company by the 2024 rule, and saying otherwise misstates the law. Aiming at it is a build decision rather than a legal one, which is why it belongs in the specification when a B2B site is built to that standard from the start rather than retrofitted later.

Scope of the 2024 web accessibility rule compared with the obligation applying to private businessesThe scope of the web accessibility rule published by the Department of Justice in 2024 compared with the separate and less specific obligation applying to private businesses, a distinction frequently misstated. The 2024 rule implements Title II of the Americans with Disabilities Act, which requires state and local governments to ensure their services, programs and activities are accessible to people with disabilities, including those offered online and through mobile applications, and which uses the term public entities to describe who it applies to. The rule adopts the Web Content Accessibility Guidelines version two point one, level double A, as the technical standard for state and local government web content and mobile applications, noting that this version rather than a later one is the standard adopted. The rule’s compliance dates were extended by an interim final rule published on the twentieth of April 2026, moving the deadline for entities with a total population of fifty thousand or more to the twenty sixth of April 2027 and for entities with a total population below fifty thousand or any special district government to the twenty sixth of April 2028, so that the dates published in 2024 are no longer applicable. Private businesses are Title III entities and are not covered by the 2024 rule. They remain subject to the Act itself, the Department having consistently taken the position that its requirements apply to all goods, services, privileges or activities offered by public accommodations including those offered on the web, but no technical standard is prescribed for them, the Department stating that businesses have flexibility in how they comply and that it does not have a regulation setting out detailed standards, relying instead on its longstanding interpretation of the general non discrimination and effective communication provisions. The accurate position is therefore a general obligation without a prescribed test, with the accessibility guidelines functioning as a de facto reference in litigation and settlements rather than as a regulatory requirement imposed on private companies by the 2024 rule.Who the 2024 rule actually coversTitle II: state and local governmentCovered by the 2024 rule.Technical standard: WCAG 2.1 Level AA.Deadlines extended in April 2026 to26 April 2027 and 26 April 2028.The 2024 dates are no longer applicable.Title III: private businessesNot covered by the 2024 rule.Still subject to the ADA: its requirementsapply to activities “offered on the web”.But no technical standard is prescribed.The sentence that settles it”The Department of Justice does not have a regulation setting out detailed standards, but the Department’s longstandinginterpretation of the general nondiscrimination and effective communication provisions applies to web accessibility.”So aim at WCAG for the right reasonIt is the reference used in litigation and settlements, and it is sensible. It is not what the 2024 rule imposes on you.
A Title II rule for public entities, with deadlines that moved in 2026. Private companies face a general duty and no prescribed standard. Source : Department of Justice, 2024 web rule fact sheet, and 2022 guidance on web accessibility and the ADA (2026)

Two more things worth knowing

State privacy laws are multiplying, and the count is harder to state than it looks. A coalition of state attorneys general wrote in June 2026 that “since 2018, twenty states have enacted comprehensive privacy laws.” That says enacted, not in effect, and some carry deferred dates. No official consolidated register of which are currently in force was located. Cite the figure with its wording and its source.

And children’s privacy rules changed recently. The amended rule took effect on 23 June 2025 with a compliance date of 22 April 2026, which has passed. Among the additions is a retention obligation: information “may not be retained indefinitely”, and the operator must maintain “a written data retention policy” published in its notice.

That last point generalises. Between the children’s rule and the California retention requirement, a written retention decision is now something a US-facing site is expected to have and to publish. It is the requirement most companies have never made a decision about.

Convergent data retention requirements across two United States privacy regimesThe convergence of data retention requirements across two separate United States privacy regimes, both of which now expect a business to have made and published an explicit decision about how long it keeps personal information. Under the amended children’s online privacy rule, which took effect on the twenty third of June 2025 with a compliance date of the twenty second of April 2026 that has now passed, an operator must retain personal information collected online from a child only for as long as is reasonably necessary to fulfil the specific purposes for which it was collected, must delete the information using reasonable measures once it is no longer reasonably necessary, may not retain such information indefinitely, must at minimum establish implement and maintain a written data retention policy setting out the purposes for which children’s personal information is collected, the business need for retaining it and a timeframe for its deletion, and must provide that written policy in the notice on the website or online service. Under California consumer privacy law as amended, a business must inform consumers at or before the point of collection of the length of time it intends to retain each category of personal information, or where that is not possible the criteria used to determine that period, and may not retain personal information for a disclosed purpose for longer than is reasonably necessary for that purpose, while its collection, use, retention and sharing must be reasonably necessary and proportionate to achieve the purposes for which the information was collected. The practical consequence for a business facing United States visitors is that a written retention decision has become an expected artefact rather than an optional internal policy, and it is the element most companies have never actually decided, since a statement such as until the person asks us to delete it expresses no period at all.Two regimes, one converging requirementChildren’s rule, as amendedInformation “may not be retainedindefinitely.”Requires “a written data retentionpolicy”, published in the notice.California privacy lawState the retention period per category,or the criteria that determine it.And keep nothing “longer than isreasonably necessary”.The element almost nobody has decided”Until you ask us to delete it” is not a period. Both regimes want a number or a rule that produces one.Which makes it an artefact, not an intentionA written retention decision, published. It is the cheapest of these obligations and the one most often absent.
A written retention answer is no longer optional. It appears in the children's rule and in the notice at collection. Source : 16 CFR 312.10 and California Civil Code 1798.100(a)(3) and (c) (2025)

What to do with this

Check whether you have a privacy policy that names its effective date and says how you respond to do-not-track signals. Those two elements are named requirements and they are the two most commonly absent.

Then decide whether the banner on your site is doing anything. If your audience is US-only, it may be answering a question nobody asked while the notice at your form, which is the real obligation, is missing.

Work out which side of the thresholds you are on, using the indexed revenue figure rather than the one printed in the statute, and remembering that retargeting counts toward the volume test.

And if accessibility is on your roadmap, keep it there, for the right reason. The general obligation is real, the technical standard is not prescribed for you, and WCAG 2.1 AA remains the sensible target regardless of what the 2024 rule does or does not require.

The adjacent pieces are consent on lead capture forms and customer data before you have a CRM.