Website privacy policies and CCPA: what US small businesses actually need to have in 2026.
Whether CCPA applies to your business, what a real privacy policy needs to say, and the cookie consent and data-request mechanics most small business sites still get wrong.
PinexaDigital
September 6, 2026

Most small business websites should have a real, accurate privacy policy whether or not California's CCPA technically applies to them, because the practical standard customers and competitors now expect is higher than the legal minimum. CCPA itself only binds businesses that meet specific size or data-volume thresholds, but a generic, copy-pasted policy that doesn't match what your site actually does is arguably worse than having none: it's a documented, dated claim you can be held to.
Does CCPA actually apply to your business?
CCPA, as amended by CPRA, applies to a for-profit business doing business in California that meets at least one of three thresholds: annual gross revenue over $25 million, buying/selling/sharing the personal information of 100,000 or more California consumers or households a year, or deriving 50% or more of annual revenue from selling or sharing personal information. Most small, single-location businesses fall under all three thresholds and aren't technically covered. The catch: if you sell online, run retargeting ads, or use analytics and marketing pixels, you may be collecting and sharing more consumer data than you realize, and other states (Virginia, Colorado, Connecticut, Utah and more) now have similar laws with their own thresholds.
What a real privacy policy needs to say
- ▸What personal information you actually collect, name, email, phone, IP address, cookies, form submissions, not a vague "information you provide us"
- ▸Why you collect it and how it's used, matching your actual practices, not boilerplate marketing language
- ▸Whether you sell or share it with third parties (ad networks and analytics tools often count), and a "Do Not Sell or Share My Personal Information" link if CCPA applies to you
- ▸How long you retain data and how someone can request deletion or a copy of what you hold
- ▸A working contact method for privacy requests, not just a generic info@ inbox nobody monitors
- ▸The policy's last-updated date, so visitors and regulators can see it isn't stale
Cookie consent: what's actually required vs. optional
CCPA runs on an opt-out model: you can set cookies by default but must honor a clear opt-out request and the browser-level "Global Privacy Control" signal. GDPR, which only applies if you're actively targeting EU residents, runs on a stricter opt-in model requiring consent before non-essential cookies load at all. Most US small-business sites only need to handle the CCPA opt-out case, but if your contact form or checkout collects data from any EU visitors, treat that traffic under the stricter opt-in standard rather than guessing.
Handling a data request when one actually comes in
- 1Verify the requester's identity using information you already have on file, don't hand over data to anyone who simply emails asking for it
- 2Confirm what categories of data you actually hold on that person, pulling from your CRM, email platform, and website analytics, not just guessing
- 3Respond within the required window, CCPA gives businesses 45 days, extendable once by another 45 with notice
- 4Document the request and your response, a dated record is your protection if the same request is ever disputed
Where most small business sites get this wrong
- ▸Publishing a generic template policy that references data practices (like selling data to named third-party categories) the site doesn't actually engage in
- ▸Collecting data through forms with no visible link to the privacy policy anywhere near the submit button
- ▸Never updating the policy after adding a new tool, like a chat widget or new analytics platform, that changes what's actually being collected
- ▸Treating privacy like a one-time launch task instead of something that gets reviewed the same way the rest of the site does
Never publish a privacy policy you copy-pasted from a template without editing it to match your actual data practices. A policy that promises something you don't do, or omits something you do, is a liability specifically because it's dated and in writing.
Privacy compliance isn't a one-time checkbox, it changes every time you add a new tool, form, or integration to the site, which is exactly why it belongs in any redesign or migration checklist rather than being treated as separate legal paperwork. If you want this built in correctly from the start rather than bolted on later, tell us what your site collects and we'll make sure the policy actually matches what you're running.
More articles

E-commerce holiday readiness checklist: what to fix on your site before Black Friday.

Google Ads vs. SEO: where should a small business put its first marketing dollar in 2026?

Web design for law firms: what actually builds trust and converts visitors into consultations.

Web design for restaurants: the pages and features that actually drive reservations and orders.
PinexaDigital
Web design and SEO agency helping US businesses grow online. We write about web design, SEO, e-commerce, and digital growth for business owners who want honest, actionable information.
Keep reading
Related articles.

E-commerce holiday readiness checklist: what to fix on your site before Black Friday.
Most holiday traffic failures come from the same handful of preventable issues: slow checkout, broken mobile cart flows, and unclear shipping cutoffs. A pre-launch checklist that covers them.
October 1, 2026

Google Ads vs. SEO: where should a small business put its first marketing dollar in 2026?
Ads buys instant visibility you pay for every click. SEO earns visibility you keep without paying per click, but takes months to build. A practical framework for choosing, or running both.
September 26, 2026

Web design for law firms: what actually builds trust and converts visitors into consultations.
Law firm website visitors are deciding who to trust during a stressful, high-stakes moment. What actually earns that trust in the first few seconds, and what advertising rules you can't ignore.
September 21, 2026