Privacy & Compliance
What Small Businesses Need to Know About Website Privacy Laws
This post is for informational purposes only and does not constitute legal advice. Every business situation is different. If you have specific legal questions about your compliance obligations, talk to an attorney.
A few years ago, privacy compliance was mostly a concern for large companies. The laws were new, enforcement was inconsistent, and most small business owners figured they were too small to be on anyone’s radar.
That’s changed. The legal landscape has shifted significantly, the number of states with active privacy laws has grown, and enforcement is no longer limited to big tech. More importantly, the businesses getting caught flat-footed aren’t the ones intentionally ignoring the laws. They’re the ones who set up a website, added a privacy policy template they found online, and assumed that was enough.
It usually isn’t.
The short version of how we got here
Privacy law in the United States started in California. The California Consumer Privacy Act went into effect in 2020 and gave California residents specific rights over their personal data: the right to know what’s collected, the right to delete it, and the right to opt out of it being sold. It also required businesses to disclose what they collect and why.
That opened the door. In the years since, more than a dozen states have passed their own versions of similar laws. Colorado, Virginia, Connecticut, Texas, Oregon, Montana, and others. The details vary by state, but the core intent is consistent: consumers have rights over their data, and businesses that collect it have obligations.
Internationally, GDPR has been in effect since 2018 and applies to any business that handles data from EU residents, regardless of where the business is based. If someone in Germany fills out a contact form on your website, GDPR considerations apply.
None of this is going to slow down. More states are working on legislation. Federal legislation has been debated for years and will eventually pass in some form. The trajectory is clear.
What “collecting data” actually means for a typical small business website
Most business owners think of data collection as something that happens when someone fills out a form. Name, email, phone number. That part is obvious.
The part that catches people off guard is everything else.
When someone visits your website, you’re almost certainly collecting data on them before they do anything at all. Analytics tools like Google Analytics track which pages they visit, where they came from, how long they stayed, and what device they used. Meta’s pixel, if you run Facebook ads, fires and ties that visit back to their Facebook profile. Heatmap tools record their scroll behavior and clicks. Retargeting pixels follow them to other websites.
All of that is data collection. And most of it happens before the visitor has any idea, let alone given consent.
This is where most small business sites have real gaps, not because the owner did anything intentionally wrong, but because these tools were installed to do their jobs, and no one set up the guardrails required by law.
What the laws actually require
The specifics vary by jurisdiction, but for most small and mid-size businesses operating in the US with any national reach, the practical requirements look something like this:
Tell people what you collect and why. Your privacy policy needs to reflect what your site actually does, not what a generic template says. If you run Google Analytics and Meta pixel and a chat widget that stores conversations, your policy needs to say so.
Give people a way to opt out. Most US state laws require a clear opt-out mechanism for data sharing and sale. “Do Not Sell or Share My Personal Information” is a required link in many states. It needs to actually work, not just exist.
Get consent before tracking in some jurisdictions. GDPR and some other frameworks require affirmative consent before most tracking can happen. That means your analytics and pixels should not fire until the user has agreed. A cookie banner that shows up after the page has already loaded, after all your scripts have already fired, doesn’t meet that requirement.
Have a process for data requests. If someone asks what data you have on them, or asks you to delete it, the law in several states gives them that right. You need to have some way to respond.
Keep it current. Adding a new tool to your website means updating your disclosures. A privacy policy written in 2021 that doesn’t mention a chat tool you added in 2023 is already out of date.
The gaps we actually find on audit
When we review a business website for compliance, a few problems come up consistently.
The most common one is a consent banner that doesn’t actually do anything. The banner appears, which looks right, but the tracking scripts have already loaded. The user hasn’t consented to anything yet. This is one of the most widespread issues and one of the easiest to get wrong, because most cookie banner plugins don’t handle this correctly out of the box.
The second is a privacy policy that doesn’t match reality. Often pulled from a template or copied from another site, it lists data practices that don’t apply and omits the tools that are actually running. Courts and regulators look at whether your disclosures are accurate, not just whether they exist.
The third is missing opt-out mechanisms. Many sites have a privacy policy but no way for a California or other regulated-state visitor to actually exercise their rights. The mechanism needs to exist and needs to work.
The fourth is no process at all for handling a data request if one arrived. Most small businesses would have no idea what to do if someone submitted a data deletion request. Having a plan in advance is both a legal requirement in some jurisdictions and just good practice.
What responsible businesses are doing
The businesses that are handling this well aren’t necessarily doing anything complicated. They’ve taken a few concrete steps.
They’ve implemented a consent management platform correctly, one that actually holds scripts until consent is given and applies geo-based rules so the strictest requirements apply to visitors from regulated locations while unregulated visitors still get full tracking.
They’ve updated their privacy policy to reflect what their site actually does, and they review it when they add new tools.
They’ve added the required opt-out mechanisms and made sure they’re findable.
They’ve documented what data they collect and where it goes, so if a request comes in, they can respond.
None of this is a massive undertaking. It’s mostly a matter of setting things up correctly the first time and having someone watch for changes over time.
What’s worth paying attention to going forward
The state law patchwork is going to keep expanding. The practical implication is that if you serve customers nationally, you should be building toward the higher standard, because more states will eventually require it anyway.
AI and data are intersecting in ways regulators are starting to pay attention to. If your business uses AI tools that process customer data, that’s going to come under increasing scrutiny.
Children’s privacy has its own separate legal framework, and it’s getting stricter. If any part of your audience could be under 18, that’s a specific area to look into with an attorney.
Enforcement is getting more active at the state level, not just the federal level. California in particular has been increasingly willing to act.
How we can help
We do compliance audits on business websites: test from regulated states, document what’s actually firing and when, and identify the gaps. From there we implement consent management correctly, update policy pages, and set up the opt-out mechanisms that need to exist.
We also do quarterly monitoring, because the laws change and what was compliant last year may not be this year. That’s included in our ongoing retainer for compliance clients.
If you’re not sure where your site stands, the audit is the right place to start.
Learn more about our privacy and compliance work.
Again, this post is general information about the privacy landscape, not legal advice for your specific situation. Talk to an attorney about your specific obligations.