Go to main content
Certyneo

US Website Privacy Policy template

Free
Customizable
Electronic signature

Overview

The United States has no single, general federal privacy law comparable to the EU's GDPR. Instead, website privacy obligations arise from a patchwork of sources: the FTC Act Section 5 prohibition on unfair or deceptive practices, which the Federal Trade Commission uses to police privacy policies that misstate or fail to honor their own data practices; the CAN-SPAM Act, which governs commercial email and requires an unsubscribe mechanism and accurate sender information; sector-specific federal statutes such as COPPA (children under 13), HIPAA (health information handled by covered entities), and GLBA (financial institutions), which apply only where the relevant sector or data type is involved; and a rapidly growing set of state comprehensive privacy laws that now form the practical baseline for most commercial websites. California's CCPA, as substantially amended and expanded by the CPRA, is the most detailed and most litigated of these state laws, and is treated as the de facto national baseline by most US businesses given California's market size. It grants consumers rights to know, delete, correct, and opt out of the sale or sharing of personal information, and requires specific disclosures in the privacy policy itself. Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, Utah's UCPA, and a growing list of other states have each enacted their own comprehensive privacy statutes, with materially different thresholds, exemptions, and consumer rights — this is a genuinely fragmented, state-by-state landscape, not a single "US privacy law," and a privacy policy intended for national use should be drafted to satisfy the most protective applicable requirements while noting where a specific state's rights differ. Also relevant: most states have separate data breach notification statutes (all 50 states now have one), which are not part of the privacy policy itself but inform the security and incident response commitments a policy typically references. When to use it: for any commercial website or app that collects personal information from visitors — through forms, cookies, analytics, or account creation — particularly one with any California traffic or customers, given the size and reach of CCPA/CPRA. Key clauses: categories of personal information collected and sources; purposes of processing; categories of third parties personal information is disclosed to, and whether the business "sells" or "shares" data as those terms are defined under CCPA/CPRA (a routine ad-tech integration can trigger this definition even without a literal sale); consumer rights (access, deletion, correction, opt-out of sale/sharing, and non-discrimination for exercising rights), and how to submit a request; cookie and tracking technology disclosures; data retention; children's privacy statement (COPPA, if the site may be used by under-13s); security measures; and contact information for privacy inquiries. Pitfalls to avoid: describing the site as not "selling" data while using third-party advertising or analytics tools that meet CCPA/CPRA's broad definition of sale or sharing; omitting a "Do Not Sell or Share My Personal Information" mechanism where required; and treating this as a single national policy without flagging that specific states (and the EU, if applicable) may grant additional or different rights.

Information to customize

  • Company's legal name

  • Company's principal place of business

  • Website URL

  • Categories of personal information collected

  • Purposes of processing

  • Categories of third parties data is disclosed to

  • Does the business sell or share personal information (CCPA/CPRA definition)?

  • Data retention period

  • Is the site directed to or likely used by children under 13?

  • Privacy inquiries contact email

  • Effective date of this policy

Customize your template

Signature recipient

Frequently asked questions

Is there a single federal privacy law we need to comply with, like GDPR?
No. The United States has no general federal privacy law. Compliance obligations come from the FTC Act's ban on unfair or deceptive practices, sector-specific federal laws (COPPA, HIPAA, GLBA where applicable), and a growing patchwork of state comprehensive privacy laws.
Do we have to comply with California's CCPA/CPRA even if we're not based in California?
Often yes, if you meet CCPA/CPRA's applicability thresholds (which are based on revenue, volume of California consumers' data, or a percentage of revenue from selling personal information) and have any California website visitors or customers. Many national businesses treat CCPA/CPRA as their practical compliance baseline.
What counts as "selling" or "sharing" personal information under CCPA/CPRA?
The definitions are broad and can be triggered by routine advertising and analytics integrations that exchange data with third parties for valuable consideration or cross-context behavioral advertising, even without a literal cash sale. Review your third-party tools carefully before stating you do not sell or share data.
Do other states have different privacy rights than California?
Yes. Virginia, Colorado, Connecticut, Utah, and other states each have their own comprehensive privacy statute with different thresholds, exemptions, and consumer rights. There is no single uniform "US privacy law" — this is a genuinely state-by-state patchwork.
Does COPPA apply to our site?
COPPA applies if your site is directed to children under 13 or you have actual knowledge you're collecting personal information from children under 13, requiring verifiable parental consent and additional protections.
What happens if our privacy policy misstates our actual data practices?
The FTC can pursue enforcement action under Section 5 of the FTC Act for unfair or deceptive practices if a privacy policy misrepresents how personal information is actually collected, used, or disclosed — accuracy between stated and actual practices is essential.

Related templates

Information about this template

Last updated
31 August 2026
Country
US
Legal notice
This template is provided for general informational purposes and must be adapted to your specific situation and governing state law. It does not constitute legal advice.