Website compliance rules by business
Privacy, consent, and accessibility rules vary by visitor location, business size, industry, and org type. See which website compliance rules apply to you.
Privacy, consent, and accessibility rules vary by visitor location, business size, industry, and org type. See which website compliance rules apply to you.
Website compliance can feel overwhelming because there is no single set of rules that applies to every organization. Privacy, consent, and accessibility obligations can change depending on your customers, business model, industry, and even the amount of personal data you process.
Instead of starting with a massive website compliance checklist, start with a more useful question: Which requirements actually apply to my organization? This article walks through the factors, location, size, industry, and organization type, that shape your obligations. For the full picture of privacy, consent, and accessibility requirements in one place, see our website compliance guide.
Your obligations depend on where your website visitors live, not just where your business is based.
Business size and data volume both affect which privacy laws apply to you.
Some states apply privacy law thresholds to nonprofits; California's CCPA generally does not.
Website accessibility rules can apply separately from privacy and consent requirements.
A structured applicability review comes before buying software or rebuilding your site.
One of the biggest sources of confusion is geography. A business doesn't necessarily need to be physically located in a state for that state's privacy requirements to become relevant.
Where your website visitors live can matter.
For example, a company operating in Texas may still have obligations related to consumers in Indiana. With states continuing to introduce and update comprehensive privacy laws, businesses serving customers across the country may need to account for multiple regulatory frameworks.
That makes understanding your digital audience an important first step in evaluating website privacy compliance.
Location is only one part of the equation. Privacy laws can establish thresholds based on factors such as:
Annual gross revenue
Number of consumers whose data is processed
How personal information is used or shared
Other business activities
Those thresholds aren't necessarily static, either. The Connecticut Data Privacy Act (CTDPA), for example, lowered one of its consumer thresholds from 100,000 to 35,000 residents, effective July 1, 2026, according to the Connecticut Attorney General's office.
The takeaway: assumptions based on an old compliance review may no longer reflect current requirements.
State privacy law | Who it can apply to | Data or revenue threshold |
|---|---|---|
For-profit businesses doing business in California | 100,000+ CA consumers, households, or devices; or $26,625,000+ annual gross revenue; or 50%+ of revenue from selling or sharing personal information | |
Entities conducting business in or targeting Colorado residents | 100,000+ CO residents; or 25,000+ CO residents if the business sells personal data | |
Entities conducting business in or targeting Connecticut residents | 35,000+ CT residents as of July 1, 2026 (previously 100,000); a lower, no-threshold trigger can apply if the business sells data or processes sensitive data |
These examples show how a single factor, like a state threshold, can shift over time. For a closer look at California's rules, see our CCPA applicability guide.
Different industries can face different obligations.
Publishers, advertisers, and businesses involved in data sharing, for instance, may need to account for privacy preference signals such as Global Privacy Control (GPC) where required.
Healthcare organizations may have additional responsibilities involving protected health information under HIPAA.
The technologies a business uses can matter as well. Emerging rules surrounding automated decision-making and AI add another layer for some organizations.
Organization type can also determine which privacy laws apply.
California's CCPA generally does not apply to nonprofits, while Colorado's Privacy Act can. A nonprofit operating across multiple states therefore shouldn't assume its organizational structure provides a universal exemption. Our guide on how nonprofits can meet Colorado's requirements walks through what qualifying organizations need to know.
The relevant requirements need to be evaluated individually.
Website compliance extends beyond privacy.
Organizations open to the public may have accessibility responsibilities under Title III of the Americans with Disabilities Act. Depending on the organization and services involved, Section 508 and WCAG technical standards may also need to be considered.
That makes accessibility an important part of the broader compliance conversation rather than a separate afterthought. Clym's accessibility widget can help address common accessibility gaps once you know which standards apply to your site.
Buying software or changing your website before understanding your obligations can lead to wasted effort or overlooked requirements.
A better sequence is:
Identify where your customers and website visitors are located.
Review relevant business and data-processing thresholds.
Account for industry and organization-specific requirements.
Determine applicable privacy and accessibility obligations.
Build your implementation plan around those findings.
Tools such as Clym Compass can help organizations create a tailored overview of potentially applicable requirements before investing resources in implementation.
Understanding what applies gives you a much clearer starting point for deciding what to do next.
Website compliance isn't one-size-fits-all. Your obligations take shape based on where your visitors live, how much data you process, your industry, your organization type, and whether your site needs to meet accessibility standards. Treating these as separate questions, rather than assuming one rule covers everything, is what keeps a compliance review accurate.
Once you know which factors apply to you, the rest of the process gets much more manageable. You're no longer guessing your way through a generic checklist. You're building a plan around your organization's actual requirements. If you want the step-by-step version of that plan, see our guide on how to get started with website compliance.
Not necessarily. Many state privacy laws apply based on where your website visitors or customers live, not where your business is headquartered. A company based in one state can still have obligations tied to consumers in another.
It depends on the law. Some states count residents whose personal data your business processes or controls, while others also factor in revenue from selling that data. Thresholds can also change over time, as Connecticut's did in 2026.
No. Exemptions are state-specific. California's CCPA generally excludes nonprofits, but Colorado's Privacy Act can still apply to qualifying nonprofits operating there, so a multi-state nonprofit needs to check each law it may be subject to.
No, accessibility and privacy are generally governed by separate rules. Accessibility can involve the ADA, Section 508, and WCAG standards, while privacy and consent are governed by state and federal privacy laws.