Privacy Policy Template for the United States
Create a privacy policy compliant with US federal and state privacy laws. Covers CCPA/CPRA (California), VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), and sector-specific regulations like COPPA and HIPAA.
AI-generated draft for review. Not legal advice. Starting at $29.
Legal Requirements in United States
Must comply with CCPA/CPRA if serving California consumers (businesses over $25M revenue, 100K+ consumers, or 50%+ revenue from data sales)
Should address state-specific laws: VCDPA (Virginia), CPA (Colorado), CTDPA (Connecticut), UCPA (Utah)
Must comply with COPPA if collecting data from children under 13
Should address FTC Act Section 5 requirements for unfair or deceptive practices
Must comply with sector-specific laws if applicable: HIPAA (health), GLBA (finance), FERPA (education)
Key Statutes & Regulations
- California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
- Children Online Privacy Protection Act (COPPA)
- FTC Act Section 5
- Virginia Consumer Data Protection Act (VCDPA)
Common Pitfalls
- •Not including "Do Not Sell or Share My Personal Information" link for CCPA compliance
- •Failing to address children privacy under COPPA if the site could attract users under 13
- •Not monitoring new state privacy laws — several states pass new legislation each year
- •Using vague language about data sharing that does not meet FTC standards for transparency
Local Terminology
- CCPA/CPRA
- California Consumer Privacy Act / California Privacy Rights Act — California comprehensive privacy law
- COPPA
- Children Online Privacy Protection Act — federal law protecting children under 13
- FTC Act Section 5
- Federal Trade Commission authority over unfair or deceptive business practices
How United States Differs
The US has no single comprehensive federal privacy law — it is a patchwork of federal and state regulations
California (CCPA/CPRA) has the most comprehensive state privacy law with GDPR-like rights
US privacy law is enforcement-driven through the FTC rather than regulatory-driven like GDPR
Sector-specific laws (HIPAA, COPPA, GLBA) have their own specific requirements
Frequently Asked Questions
Does my business need to comply with CCPA?
▾
CCPA applies if your business has annual gross revenue over $25 million, buys/sells/shares personal information of 100,000+ California consumers, or derives 50% or more revenue from selling personal information. If you serve California consumers and meet any threshold, compliance is required.
What is the difference between CCPA and GDPR?
▾
Key differences: CCPA focuses on the right to opt-out of data sales; GDPR requires affirmative consent for most processing. CCPA applies to businesses meeting specific thresholds; GDPR applies to any organization processing EU residents data. GDPR fines are higher, but CCPA allows private right of action for data breaches.
Do I need to comply with multiple state privacy laws?
▾
If you serve consumers in multiple states with privacy laws (California, Virginia, Colorado, Connecticut, Utah, and others), you should comply with each applicable law. Many businesses create a single comprehensive privacy policy that addresses all applicable state requirements.
What happens if I violate US privacy laws?
▾
Consequences vary by law. CCPA: $2,500 per unintentional violation, $7,500 per intentional violation, plus private lawsuits for data breaches ($100-$750 per consumer). FTC: consent decrees, fines, and 20-year monitoring. HIPAA: up to $1.9 million per violation category per year.
Available in Other Jurisdictions
Related Contract Types
Ready to Create Your Privacy Policy?
Describe your deal in plain English. Three AI agents draft, review, and refine your privacy policy for United States.
Get StartedAI-generated draft for review. Not legal advice.