Why the US Is Uniquely Dangerous
Unlike the European GDPR or Israel's Amendment 13, the United States has no comprehensive federal privacy law. Instead, there exists a regulatory patchwork of sectoral laws by industry and state laws by territory, supplemented by Federal Trade Commission enforcement.
The result: your privacy policy is not a legal shield. It is a legally binding contract with every visitor to your website. And if you cannot prove compliance, you will lose.
For the full enforcement picture across GDPR, US state law, and operational compliance, see the Privacy Enforcement and Operational Compliance guide.
A Privacy Policy in the US Is a Legally Enforceable Contract
In the United States, a privacy policy is a contractual promise to consumers. Every sentence written in it can serve as the basis for a lawsuit under Section 5 of the FTC Act — "Unfair or Deceptive Practices."
If your site's policy states "We do not share personal data" and the company actually shares information with Google Analytics or Meta Ads, that is a misleading statement that can be considered consumer fraud.
In 2023, the FTC reached a $7.8 million settlement with BetterHelp for sharing consumers' sensitive health data with Facebook, Snapchat, and other platforms for advertising purposes — despite promising in its privacy policy to keep such data private. The complaint alleged that BetterHelp repeatedly broke these privacy promises while continuing to profit from the shared data.
The Patchwork Problem: State Laws Are Now the Real Enforcement Risk
With no federal law, companies must navigate a growing set of state privacy statutes. California's CCPA and CPRA are the most comprehensive, but Virginia, Colorado, Connecticut, Texas, and a growing list of other states have enacted their own frameworks — each with different thresholds, rights, and enforcement mechanisms.
Key operational requirements under most state frameworks include:
- Clear disclosure of what data is collected and why
- Honoring opt-out requests for data sales or targeted advertising
- Responding to consumer data access and deletion requests within defined timeframes
- Maintaining Data Processing Agreements with service providers
- Annual privacy policy updates reflecting actual data practices
Related reading: Privacy Enforcement and Operational Compliance
The FTC: Enforcement Without a Federal Law
Even without comprehensive federal legislation, the FTC has broad authority to pursue companies for "unfair or deceptive" data practices under Section 5. In recent years, the FTC has pursued companies for misrepresenting their data practices, failing to secure sensitive data, violating their own stated privacy policies, and sharing health or financial data without adequate disclosure.
Critically, FTC enforcement does not require a specific violation of a privacy statute. A company can be pursued simply for doing something that contradicts what its policy says — or for engaging in practices that consumers would not reasonably expect.
What Your Privacy Policy Actually Needs to Do
A US privacy policy that works operationally must do four things:
- Accurately describe your actual data practices — not your intended practices, and not a generic template. What data you collect, from whom, for what purposes, and with whom you share it.
- Match your technical stack — if you use analytics, advertising pixels, CRM tools, or data brokers, those need to be disclosed. The gap between policy and reality is where enforcement happens.
- Provide functional consumer rights mechanisms — opt-out links for data sales and targeted advertising, verifiable deletion request processes, and reasonable response timelines.
- Be updated regularly — a policy that was accurate twelve months ago may no longer reflect current data practices. Privacy policies require active maintenance.
Related reading: The 7 Legal Timebombs Killing Startups Before Series A
The Class Action Risk
State privacy laws with private rights of action — most notably California's CPRA — create exposure to class action litigation that can dwarf regulatory fines. The legal theory is straightforward: if your policy says one thing and your practices do another, you have a misrepresentation claim.
In California, statutory damages under CCPA for security breaches can reach $100 to $750 per consumer per incident. For a company with 100,000 users, a single incident can create theoretical exposure in the tens of millions before a single case is litigated.
Your privacy policy is not a legal formality. In the US, it is a public commitment you will be held to. The gap between what it says and what you actually do is not a compliance risk. It is a litigation risk.
Related resource: Free resources for founders and operators
If your company has no establishment in the EU but you have users there, US privacy exposure is only half the picture. GDPR Article 27 requires you to appoint a representative inside the Union.