Website compliance guide
Explains what website compliance means for US businesses: how privacy, accessibility, and consent rules vary by state, industry, and size, plus where to start.
Explains what website compliance means for US businesses: how privacy, accessibility, and consent rules vary by state, industry, and size, plus where to start.
If you’ve just been asked to figure out what your company needs to do to make its website compliant, after searching for answers online, you can quickly find yourself buried in state privacy laws, consent requirements, accessibility standards, acronyms, and conflicting advice about what your website actually needs.
If you’re wondering, “Where do I even start?” there's a reason the answer isn’t obvious.
Website compliance from data privacy compliance to accessibility isn’t governed by one law or a universal checklist. The requirements that apply to your website can depend on where your visitors live, how much consumer data your business processes, your industry, your organization type, and other factors. That means the best place to start isn’t by trying to comply with everything. It’s by determining which requirements actually apply to your business.
Understandably, businesses tasked with making their website compliant with privacy laws expect a simple checklist of items that, once installed, bring their website into compliance. The reality is that every company has a different set of requirements, based on its organization’s type, industry, revenue, and the amount of consumer data it processes.
Businesses must also take into account the location of their website users. That is because privacy requirements vary from state to state. Every state defines consumer privacy rights differently, and they are increasingly adopting laws to reflect this. In 2026 alone, comprehensive privacy laws took effect in Indiana, Kentucky, and Rhode Island. So even if a business is located in Texas, for example, they may be obligated to process the data of Indiana consumers according to Indiana’s laws.
As if keeping up with state privacy laws weren’t enough, the advent of AI muddies the waters even further. For example, Colorado’s amended AI law, which takes effect January 1, 2027, outlines new standards for some businesses using automated technology on their website when it influences consequential decisions. It requires them to provide consumers with notices of the use of AI technology, keep records of consumer preferences for three years, and provide human oversight of some decisions.
The important point to keep in mind is that there isn’t one version of website compliance that applies to every business.
Where your website visitors live is an important piece of the compliance puzzle, but it isn’t the only one. Whether a particular privacy law applies can also depend on how much revenue your business generates, how much consumers’ personal data it processes, the industry it operates in, and even whether the organization is for–profit or nonprofit. That’s why two businesses serving customers in the same state may have different compliance obligations.
Whether a privacy law applies to your business may depend on your company’s size and activities. California, for example, sets one applicability threshold at more than $26 million in annual gross revenue, while other states use different tests, including how much consumer data a business processes. Increasingly, these figures are changing. On July 1, 2026, Connecticut lowered its threshold from 100,000 to just 35,000 consumers. It is incumbent on the business to operate with up-to-date information for each state.
Compliance requirements are not the same for every industry. Each sector may have its own specific regulatory requirements. For example, publishers and other businesses that engage in online advertising or data sharing may need to recognize Global Privacy Control requirements where required by state law, while a healthcare provider may have additional obligations under HIPAA governing protected health information. Your industry can change the compliance framework you need to consider.
Even your organization's legal structure can change your approach. California’s CCPA generally doesn’t apply to nonprofits, while Colorado’s Privacy Act can. A nonprofit serving residents in multiple states, therefore, can’t assume that its nonprofit status automatically exempts it from state privacy laws.
Website accessibility requirements can also depend on the type of organization you operate and the services you provide. Under Title III of the Americans with Disabilities Act (ADA), businesses and nonprofits that are open to the public must provide people with disabilities equal access to their goods and services, including those offered online.
Determining your ADA website compliance and other accessibility obligations starts with understanding what type of organization you operate, the services you provide, and which accessibility laws apply to it. Many organizations also need to consider Section 508 and WCAG technical standards, which define specific accessibility requirements for websites.
When you’re trying to make sense of website compliance for the first time, simple solutions can sound especially appealing.
Install a cookie banner.
Buy privacy compliance software.
Check a box and move on.
Unfortunately, website compliance rarely works that way. Two common misconceptions can give businesses a false sense of security and leave important requirements unaddressed.
A cookie banner alone is not enough to make your website compliant. It is the visible element of website compliance, but it’s only one component of a larger solution.
Businesses may also need:
Depending on applicable privacy laws, businesses may need a process for handling a data subject access request (DSAR), which allows consumers to request access to personal information a business holds about them.
The reality is that no vendor can responsibly guarantee ongoing compliance with a one-time installation. Compliance involves many moving parts, so it’s an issue that needs continued attention.
That’s because compliance doesn’t stand still:
Trying to piece together a compliance solution through online advice can create gaps, leaving your business vulnerable.
Potential consequences include:
If your business has received a complaint from a consumer or a demand letter from an attorney, the pressure to resolve the issue is likely top of mind. Depending on the applicable law and circumstances, a business may have a limited opportunity to cure a violation. During this time period, it’s important to identify and resolve the underlying issues.
Businesses tasked with understanding how to make their website comply must begin with a detailed list of the regulations that apply to their business.
The idea of researching dozens of regulations individually is overwhelming, at best, for those who don’t specialize in this area. Rather than building your own website compliance checklist from scratch, it helps to first understand which regulations apply to your organization. Clym’s Compass tool provides a free starting point for doing just that.
Clym Compass allows users to:
→ Enter company information
→ Select their industry
→ Receive a tailored overview of applicable requirements
→ Build a clear roadmap before investing time or resources into implementation
Website compliance can quickly become like a massive undertaking when you start by asking, “How do I make my website compliant?” That question can send you down countless paths involving state laws, consumer location, industry requirements, business thresholds, and more.
A better place to begin is by asking, “Which compliance requirements may apply to my business?” Once you know that, you can focus your efforts on the requirements that matter instead of trying to make sense of every regulation you encounter.
If you're ready to find out which privacy, accessibility, and compliance requirements apply to your business, start with Clym’s Compass tool. This free assessment tool helps identify the regulations most relevant to your organization.
Website compliance means meeting the privacy, consent, and accessibility requirements that apply to your website based on factors like where your visitors live, your industry, your revenue, and how much personal data you collect. There's no single universal checklist, the requirements that apply to one business can differ from what applies to another.
No. A cookie banner is only the visible piece of compliance. Depending on which laws apply to your business, you may also need consent management software, script blocking in opt-in states, opt-out functionality, support for privacy signals like Global Privacy Control (GPC), and a process for handling data subject access requests (DSARs).
It depends on where your website visitors live (not just where your business is based), your annual revenue, how much consumer data you process, your industry, and your organization type. Free tools like Clym's Compass can generate a tailored overview of the requirements that apply to your specific business.
Not necessarily. Some laws, like California's CCPA, generally exclude nonprofits, but others, like the Colorado Privacy Act, can still apply. Nonprofits serving residents in multiple states should check each applicable state law individually rather than assume a blanket exemption.
If your business or nonprofit is open to the public, Title III of the ADA generally requires you to provide people with disabilities equal access to your goods and services, including online. Your specific accessibility obligations depend on your organization type and the services you provide.
Non-compliance can lead to consumer complaints, demand letters, and regulatory scrutiny. Depending on the applicable law, you may have a limited window to cure a violation, so it's important to identify and fix the underlying gaps quickly.