// Security
Privacy Policy for Websites in 2026: What to Include
A practical guide to what your website's privacy policy needs to cover in 2026, covering GDPR, CCPA, and best practices for small and medium businesses.
In this article
Who needs a privacy policy and why
If your website collects any personal data — including email addresses from a contact form, analytics via Google Analytics, or cookies that track user behavior — you need a privacy policy. This is true regardless of your company's size or jurisdiction. GDPR requires it for any site with EU visitors. CCPA requires it for California-based businesses above certain thresholds. Various US state laws are adding similar requirements.
Beyond legal compliance, privacy policies are a trust signal. Users who are concerned about their data increasingly check for a privacy policy before submitting a form or making a purchase. A missing or poorly written privacy policy is a conversion risk, not just a legal risk.
What GDPR requires in your privacy policy
GDPR Articles 13 and 14 specify what information must be provided when collecting personal data. Required disclosures include: the identity and contact details of the data controller (your company), contact details of your Data Protection Officer if you have one, the purposes and legal basis for processing data, the categories of data you collect, any third parties you share data with, international data transfers (if data leaves the EU), data retention periods, and the rights of data subjects.
Rights of data subjects that must be disclosed: the right to access their data, the right to correct inaccurate data, the right to erasure ('right to be forgotten'), the right to restrict processing, the right to data portability, and the right to object to processing. Each right needs a clear explanation of how users can exercise it.
Practical sections every privacy policy should include
Even for sites that don't technically fall under GDPR or CCPA, a policy covering these sections builds trust and anticipates future legal requirements as privacy laws spread to more jurisdictions.
- What information you collect (explicitly list forms, cookies, analytics, payment processors)
- How you use it (marketing communications, order fulfillment, analytics, improving the service)
- Who you share it with (analytics platforms, payment processors, email marketing tools, named third parties)
- How long you retain it (per category: active customers, inactive users, support records)
- How you protect it (HTTPS, access controls — at a high level, no technical specifics needed)
- How users can access, correct, or delete their data (contact email and expected response time)
- Effective date and how you'll notify users of changes