Guide
Do I need a privacy policy or a cookie banner?
Facts checked Oct 9, 2026
A privacy policy: yes, if your website collects names or email addresses, and a contact form counts. A cookie banner: mostly for visitors in Europe or the UK.
Check the official rules. Privacy laws differ from state to state and change often, so check them with the official sources before you rely on them: the Federal Trade Commission, the California Attorney General, the California Privacy Protection Agency and your own state's attorney general. This page is general information for small websites. It isn't legal advice, and we can't take responsibility for decisions made from it. If you sell personal data, collect it from children or handle a lot of it, talk to a lawyer.
Which one is you?
- A contact form, sign-up, booking or shop
- You collect personal information (a name, an email address, a phone number). Post a privacy policy.
- Visitor statistics, ads or "pixels"
- Those services' terms usually make you post a privacy policy that mentions cookies and says you use them.
- Aimed at children under 13
- A federal law, COPPA, has its own rules, including parents' consent. Start with the FTC's children's privacy pages.
- Visitors or customers in Europe or the UK
- You probably need a cookie banner that asks first, and a fuller privacy notice.
- A bigger business, or you sell personal data
- A state privacy law may cover you, with more to say and do.
- Words and pictures only: no forms, no shop, no statistics
- The law may not ask for a policy. A short one still helps visitors, and your website builder may add statistics or cookies you didn't choose, so check.
When US law expects a privacy policy
There's no single US law that says every website needs one. But these reach most small business websites:
- California's Online Privacy Protection Act (CalOPPA). A business website that collects personal information (such as a name, email address, phone number or street address) from people who live in California must post a privacy policy where people can find it. There's no size limit, and most websites can't stop Californians filling in their forms.
- The Federal Trade Commission (FTC). Whatever your policy says, you must do. The FTC says that if a company makes privacy promises, the law requires it to live up to them. A copied policy that promises things you don't do is a risk, not a shield.
- Children's privacy (COPPA). If your site is aimed at children under 13, or you know you're collecting their details, you need a policy written for parents and, in most cases, parents' consent first.
- The services you use. Visitor statistics and advertising services usually make a privacy policy part of their terms.
Towns, schools and nonprofits often fall under different rules. Ask your attorney, or check with your state.
What to put in it
CalOPPA's list is a good plain starting point for a small website. Say:
- What personal information you collect (names, emails, phone numbers, order details) and how (forms, orders, sign-ups).
- Who you share it with: your email list service, payment company, booking system, visitor statistics.
- How people can see or correct their information, if you offer that.
- How you'll tell people when the policy changes.
- The date it took effect.
- How your site responds to a browser's "Do Not Track" signal.
- Whether other companies (statistics, ads, social media buttons, embedded maps or videos) can collect information about visitors across websites.
- How to contact you with a question.
Then:
- Link it from the footer of every page, and next to every form.
- Write it about your own website. A template or a generator is a starting point; check every line is true for you.
- Read it again whenever you add a form, a shop, a mailing list or a new service.
- Keep it in plain English. Readability tells you if it reads like a contract.
Do I need a cookie banner?
A cookie is a small file a website saves in your browser, to remember a shopping cart, a log-in or a visit. A cookie banner is the box that asks visitors about them.
- Europe and the UK: websites must ask before they save cookies that aren't needed for the site to work, such as statistics and advertising cookies. Cookies for a shopping cart or a log-in don't need consent. The choice must be real: people must be able to say no, and it must be as easy to change their mind as to agree. If you sell to people there, or aim your site at them, this may apply to you.
- The US: no federal law requires a cookie banner. Some state privacy laws make the businesses they cover let people opt out of targeted ads, and honor the opt-out signal some browsers send (Global Privacy Control).
- The services you use: some statistics services' terms make you ask for consent wherever the law requires it.
If your builder has a cookie banner setting, turning it on does no harm. Just know that a banner that only says "We use cookies" with an OK button isn't the real choice Europe and the UK ask for.
State privacy laws
About 20 states now have broad consumer privacy laws. Most small websites aren't covered, because most of these laws only reach a business that:
- handles the personal information of a large number of that state's residents in a year (often 100,000, lower in some states), or
- makes money from selling personal information, or
- in California, has yearly revenue over $26,625,000 (the figure set for 2025 and 2026).
A few states use different tests, so check your own state's attorney general page. If one covers you, your policy has to say more (what you collect and why, how long you keep it, and how people can see, correct or delete it), and you may need a link that lets people opt out of their data being sold or shared.
Send this to your web person
Not sure what to say? Copy this into an email, add your website's address, and send it.
Hi, I'm checking our website's privacy policy is true and up to date. Could you send me a list of: 1. Every form on the site, and where the details people type end up (email, a spreadsheet, a mailing list, a booking system). 2. Every outside service the site loads: visitor statistics, ads or pixels, maps, videos, fonts, chat, payment. 3. Every cookie the site sets, and what each one is for. Could you also add a link to the privacy policy in the footer of every page and next to each form? If we have visitors or customers in Europe or the UK, can the cookie banner hold back optional cookies until people agree? Thanks
What PageKiwi can check
None of our checks read your privacy policy or your cookies, and we can't tell you whether your site meets the law. Readability tells you whether your policy is plain enough for visitors to follow. Our own privacy page shows one way to write it.