Does Your Website Need a Privacy Policy, Cookie Banner, or Terms and Conditions?

Consent management

Most websites collect more visitor information than their owners realize. Services like Google Analytics, advertising pixels, and WordPress plugins can place cookies or transmit visitor data in the background.

If your website has a contact form, embedded video, online booking, email signup, payment processing, advertising, or even Google Maps, it may be sharing information even if you never access that data yourself.

That is where privacy policies, cookie consent, and terms and conditions come in. In California, finding out that these protections are missing after receiving a demand letter can be considerably more expensive than addressing them now.

What does each one do?

A Privacy Policy explains what information your website collects, why it is collected, how it is used, and which third parties receive it.

Privacy policies are often legally required. California’s CalOPPA generally requires commercial websites collecting personally identifiable information from California visitors to conspicuously post and follow a Privacy Policy.

Larger businesses covered by the CCPA can face administrative fines of up to $2,663 per violation or $7,988 for intentional violations and certain violations involving children under 16. These penalties do not apply automatically to every small business, but they show how quickly repeated violations can add up. See the current California penalty amounts.

A Cookie Policy explains which cookies, pixels, and tracking technologies your website uses. A properly configured cookie banner lets visitors accept, reject, or customize nonessential tracking. Importantly, it should also prevent applicable trackers from loading until the visitor makes a choice.

A banner that appears after Google Analytics or the Meta Pixel has already started collecting information may provide little protection.

Terms and Conditions establish the rules for using your website or purchasing from your business. They can cover payments, cancellations, refunds, subscriptions, acceptable use, ownership of content, and dispute resolution.

Terms are not generally required by privacy laws, but they can help reduce disputes and clarify the relationship between your business and its customers.

Why California businesses are paying attention

Since late 2025, businesses around the country have received demand letters alleging that tools such as Google Analytics, Meta Pixel, chat widgets, and session-recording software violate the California Invasion of Privacy Act, or CIPA, when they transmit visitor information without prior consent.

A demand letter is a formal notice sent before a lawsuit. It normally explains the alleged violation, demands payment or corrective action by a deadline, and threatens a lawsuit or arbitration if the matter is not resolved.

A demand letter is not a lawsuit, government fine, court judgment, or proof that a business owes anything. It should still be taken seriously because responding may require an attorney and a technical investigation of the website.

CIPA allows a private claimant to seek the greater of $5,000 per violation or three times their actual damages. Some demand letters attempt to count individual visits, transmissions, or third-party services as separate violations, resulting in claimed exposure reaching six or even seven figures. Read the applicable California statute.

Because these matters frequently settle privately, there is no reliable official average. Industry sources have reported demand and settlement amounts ranging from approximately $5,000 into six figures per claim, depending on the claimant, number of alleged violations, website traffic, information involved, and whether a lawsuit has already been filed.

A 2026 legal analysis reports that thousands of businesses have received these letters, including small service businesses and companies located outside California. Read more about the reported demand-letter activity.

These legal theories remain unsettled, and courts have reached different conclusions about whether ordinary website tools violate CIPA. Receiving a demand letter does not mean a business has broken the law or owes the amount being requested.

It can still be costly. A business may need to hire an attorney, preserve its website configuration, complete a technical investigation, notify its insurer, and respond before a deadline. Those costs can begin before a lawsuit is ever filed.

A cookie banner has to work

A decorative banner is not enough if trackers continue operating after a visitor selects “Reject.”

In 2025, the California Attorney General announced a $1.55 million settlement with Healthline involving online tracking and other alleged CCPA violations. The state specifically alleged that Healthline displayed a consent banner that did not disable tracking cookies when visitors opted out.

Healthline is a major publisher and the settlement is not a typical small-business outcome, but it demonstrates that regulators examine what a banner actually does, not just whether one appears on the screen. Read the California Attorney General’s announcement.

Can you manage it yourself?

Absolutely.

You can inventory every form, cookie, script, plugin, and third-party service on your website, write the appropriate policies, install a consent system, and test whether trackers are properly blocked.

You can also subscribe to a platform such as Termly and configure it yourself. Businesses handling sensitive health, financial, or children’s information should consider working with a qualified privacy attorney.

The challenge is keeping everything accurate. A new plugin, advertising campaign, chat tool, or website integration can introduce additional tracking without it being obvious.

Or let us handle it for you

Peak Digital Studio offers a free website privacy scan to identify cookies, analytics, advertising pixels, embeds, forms, and other services that may collect or share visitor information.

If your website needs additional protection, we can set everything up for a one-time fee of $99, followed by $14.99 per month for ongoing management.

The $99 setup includes:

  • Reviewing your website scan
  • Setting up and configuring Termly
  • Creating your Privacy Policy, Cookie Policy, and Terms and Conditions
  • Installing your cookie consent banner and preference controls
  • Completing an initial cookie and tracker scan
  • Testing the consent controls after installation

Your $14.99 monthly plan includes:

  • Ongoing cookie and tracker scans
  • Policy and cookie-disclosure updates through Termly
  • Continued access to your consent banner and preference controls
  • Consent records and privacy-request tools where applicable
  • Ongoing management of the system

We will handle the initial setup and keep the system running, so you do not have to continually monitor policies, cookies, plugins, and changing privacy requirements yourself.

No tool can guarantee that a business will never receive a complaint or demand letter. However, accurate policies, working consent controls, and ongoing monitoring can help address many of the avoidable gaps these claims target.

Start with a free website scan

Not sure what your website is collecting or which policies you need?

We will scan your website, explain what we find, and identify anything that may need attention. There is no obligation and no scare tactics.

Get My Free Website Scan

Or, if you're ready to get your site protected, sign up for our Website Privacy & Consent plan and we'll get you set up.

Peak Digital Studio provides technical and self-help compliance tools, not legal advice. Complex or highly regulated businesses may require review from a qualified attorney.

Author:
Matthew Johnson
Founder
Date:
September 23, 2026