A Description of What the Site Actually Does
A website privacy policy is a public, factual account of what personal information the site collects, why, who receives it, how long it is kept, and what rights the people described in it can exercise. It is not a terms of use document, which is a contract with the visitor; not a cookie banner, which is a consent mechanism; and not a data processing agreement, which is a contract between organisations.
Copying a policy from a competitor produces a document describing their vendors, their retention periods and their tag stack. It is inaccurate as to your site, and the inaccuracy is published under your own name. A policy that omits third-party trackers actually present on the site is a misrepresentation, reachable under state consumer-protection statutes and general prohibitions on deceptive practices, independently of any privacy statute.
It is also evidence of not having looked, which is the first thing an investigator establishes.
Why B2B Firms Are in Scope More Often Than They Assume
The belief that privacy law is a consumer problem is wrong in three ways.
California no longer carves out business contacts. The CCPA's exemptions for business-to-business and HR data expired on 1 January 2023 and were not renewed by the CPRA. A California resident's name, work email, job title and work phone are ordinary personal information, fully within the statute (notice at collection is owed on lead-generation forms). The framing matters: a temporary carve-out lapsed, rather than California creating a new B2B rule.
Two states have no volume threshold. Twenty states have comprehensive consumer privacy laws in force as of mid-2026, with Indiana, Kentucky and Rhode Island the most recent, all effective 1 January 2026. Texas and Nebraska apply to any business that is not a small business under the SBA definition, does business in the state, and processes or sells personal data.
Advertising tags can constitute a sale. Regulators have treated cookies and pixels that transmit identifiers to third parties for cross-context behavioural advertising as sale or sharing, which is how a site with a remarketing pixel acquires opt-out obligations.
One caution: the Virginia-model states generally define consumer to exclude individuals acting in a commercial or employment context, but the language varies, and there is no safe rule that B2B data is exempt outside California.
Take the Inventory Before Drafting a Word
Before a sentence is written, produce a register.
- Every tag and script actually loading. Compare the tag manager container against a network capture of a real page load. They diverge, because tags get hard-coded into templates by developers and agencies and never removed.
- Every form, and what each field collects, including hidden ones.
- Every third party that receives data: analytics, advertising, chat, session replay, heat mapping, A/B testing, CDN, form processors, CRM, marketing automation, webinar and email platforms.
- Where data goes after submission — which systems, in which countries, under which transfer mechanism.
- Retention per system in practice, rather than as written in a policy nobody implemented.
The output is a table with one row per recipient: the recipient, the purpose, the categories of data, the mechanism relied on, and the contract in place. That register makes drafting mechanical, exposes the trackers nobody can justify, and is the document a regulator asks for first.
What a Defensible Policy Contains
California puts the requirements in regulation. Under 11 CCR section 7011, the policy must set out:
- the categories of personal information collected, their sources, and the purposes for each;
- the categories sold or shared and to whom, or an express statement that none were, and the categories disclosed for a business purpose;
- whether sensitive personal information is used beyond permitted purposes;
- the rights to know, delete, correct, opt out of sale or sharing, limit the use of sensitive personal information, and non-discrimination;
- how to exercise each right, including the verification process, authorised-agent instructions, contact details, and how the business processes opt-out preference signals;
- the date the policy was last updated.
Where the GDPR or UK GDPR applies, Articles 13 and 14 add the controller's identity, the purposes and lawful basis for each, the legitimate interests where relied on, recipients or categories of recipients, third-country transfers and the mechanism relied on, retention or the criteria for setting it, the data-subject rights including the right to complain to a supervisory authority, and — under Article 14 — the source of the data.
One caveat: section 7011 has been amended, including for automated decision-making technology. Treat any checklist as a drafting aid to confirm against the current regulation with counsel.
Cookie Consent Comes From ePrivacy, Not the GDPR
Two separate regimes operate on the same page. The GDPR governs the processing of personal data and requires a lawful basis under Article 6. The ePrivacy Directive, Article 5(3) — implemented in the UK as PECR regulation 6 — governs storing information on, or gaining access to information stored on, a user's terminal equipment, and requires consent unless that storage or access is strictly necessary for a service the user explicitly requested.
The consequence most often missed: legitimate interests is not available for non-essential cookies. The cookie requirement is not a GDPR lawful-basis question, so a balancing test does not remove it for analytics or advertising tags.
Article 5(3) is technology-neutral and not limited to cookies. The EDPB adopted the final version of its Guidelines 2/2023 on the technical scope of Article 5(3) on 16 October 2024, applying the storage-and-access analysis to URL and pixel tracking, tracking based on IP address alone, and unique identifiers, and confirming that information under Article 5(3) is not limited to personal data.
What Regulators Have Actually Enforced Against
California's enforcement record is conduct-specific.
| Matter | Date, enforcer | Amount | Conduct at issue |
|---|---|---|---|
| American Honda | March 2025, CPPA | $632,500 | Over-verification of opt-outs; asymmetrical cookie interface; GPC not applied to known users; missing ad-vendor contract terms |
| Healthline Media | 1 July 2025, CA AG | $1.55m | Sharing continued after opt-outs and GPC signals; banner that did not disable advertising cookies |
| PlayOn Sports | Order 27 Feb 2026, CalPrivacy | $1.1m | Opt-out routes that could not disable tracking; obstructive banner; policy not updated annually |
| Ford Motor | 5 Mar 2026, CalPrivacy | $375,703 | Email verification required before an opt-out would be processed |
Four patterns recur: opt-outs that exist in the interface but do not stop the data flow; failure to honour Global Privacy Control, including honouring it only per-device rather than across a known account; friction on the opt-out path, particularly identity verification, when under the CCPA an opt-out of sale or sharing is not a verifiable request; and missing contractual terms with advertising vendors.
On the signal itself, 11 CCR section 7025 requires a business that sells or shares personal information to process a conforming opt-out preference signal as a valid opt-out request. Global Privacy Control is the only mechanism on the Colorado Attorney General's recognised universal opt-out list, and Colorado controllers have had to honour it since 1 July 2024.
Keeping It True When Someone Adds a Tag, and a Necessary Disclaimer
Policies fail through drift rather than through drafting. A marketer adds a heat-mapping tool during a redesign; an agency adds a conversion pixel to prove its campaign worked. Nobody tells the person who owns the policy.
- One named owner, accountable for the policy matching the site — not a committee that meets quarterly.
- Change control with teeth. No tag reaches production without an entry in the register, enforceable by limiting tag manager publish rights to two people.
- Scheduled scanning. An automated check of representative pages for third-party requests, compared against the register, quarterly and after every release.
- An annual review at minimum, with the last-updated date changed. California requires the policy to be updated at least every 12 months and to state that date, and failure to update annually was expressly cited in the PlayOn Sports order.
- Vendor contract review, since missing CCPA service-provider and third-party terms featured in several actions above.
Test the mechanisms, not only the words. Submit an opt-out request through your own form, send a Global Privacy Control signal, and confirm with a network capture that the data flow actually stops. A described control that does not work is worse than no description.
This page is general information about how privacy policies work on business websites. It is not legal advice, does not create an attorney-client relationship, and should not be relied on in place of advice from qualified counsel admitted in the relevant jurisdiction. Statutes and regulatory guidance here change frequently; verify anything against the current primary source before acting on it.
Frequently Asked Questions
Does the CCPA apply to B2B companies?
Yes, where the business meets one of the CCPA's applicability thresholds. The statute's original exemption for business-to-business contact data expired on 1 January 2023 and was not renewed, so the name, work email, job title and work phone number of a California-resident business contact are ordinary personal information within the Act.
A California contact in the CRM can exercise the rights to know, delete, correct and opt out of sale or sharing, and notice at collection is owed on lead-generation forms.
Do we need a cookie banner on a B2B website?
If the site is used by visitors in the EEA or the UK and sets any non-essential cookie or similar technology, consent is required, and that requirement comes from ePrivacy Article 5(3) — PECR regulation 6 in the UK — rather than from the GDPR. Legitimate interests is not available as a basis for setting non-essential cookies.
US state laws generally approach the same tags through opt-out rights and preference signals rather than through a banner.
How often should a privacy policy be updated?
At least every 12 months, and additionally whenever the site's data practices change. California requires the policy to be updated at least every 12 months and to state the date it was last updated; failure to do so was cited in the CalPrivacy order against PlayOn Sports.
What makes a policy inaccurate is adding a tag, changing a vendor or migrating a CRM, none of which waits for the review date, so tie the update to a change-control rule.
What is Global Privacy Control and do we have to honour it?
Global Privacy Control is a browser-level signal indicating that the user opts out of the sale or sharing of their personal information. California's 11 CCR section 7025 requires a business that sells or shares personal information to process a conforming opt-out preference signal as a valid opt-out request, and specifies that a frictionless implementation must not charge a fee, alter the user's experience, or display notifications in response.
GPC is the only mechanism on the Colorado Attorney General's recognised universal opt-out list, and Colorado controllers have had to honour it since 1 July 2024.