01List what the site collects
Note every form, analytics tag, ad pixel, chat widget, embedded map or video, booking tool, and call-tracking number. For each, record what it collects, where the data goes, and who can see it. Your provider can check the page code for tags you have forgotten.
02Write the policy to match
Say what you collect, why, which outside services receive it, how long you keep it, and how people can contact you about their information. Use plain language. Google Analytics' terms require a privacy policy that discloses its use and its cookies. Update the policy whenever you add or remove a tool.
03Know when a consent banner is expected
In the EU and UK, non-essential cookies, such as advertising cookies, generally need consent before they are set. Cookies strictly needed to run the site are exempt. UK rules are being updated, so check the ICO's current guidance. The US has no single federal cookie rule. Keep any banner honest: rejecting should be as easy as accepting, and should actually stop the tags.
04Check US state privacy thresholds
California's privacy law (the CCPA, as amended by the CPRA) applies to for-profit businesses that meet any one of three tests. The first is annual gross revenue above an inflation-adjusted threshold, $26,625,000 as of January 2025. The second is buying, selling, or sharing personal information of 100,000 or more California residents or households. The third is earning half or more of revenue from selling or sharing it. Other states set their own tests. Many small businesses fall below them, but ad pixels that share data can change the picture.
05Follow the platforms' own consent rules
Google's EU user consent policy applies to sites using its ad and analytics products. It requires consent from visitors in the European Economic Area, the UK, and Switzerland for cookies where legally required and for ad personalization. If you have visitors there, use a consent banner with Google Consent Mode. Other ad platforms have similar terms.