Post a compliant privacy policy
Businesses must publish a comprehensive, up-to-date online privacy policy. It must detail the categories of personal information collected, their sources, and the purposes for collecting them, plus the categories sold or shared and the categories of third parties receiving them. It must explain the rights to know, delete, correct, and not be retaliated against, plus, where they apply, the right to opt out of sale/sharing (if you sell or share) and the right to limit the use of sensitive personal information (if you use it beyond the § 7027(m) purposes). Since January 1, 2026 the policy must also identify the categories of personal information disclosed to a service provider or contractor for a business purpose (§ 7011(e)(1)(H)) and be linked from the settings menu of any mobile application, and a business that uses ADMT as set forth in § 7200(a) must describe the right to access ADMT and, except as § 7221(b) provides, the right to opt out of it.