The 30-second answer
You need a privacy policy if any of these are true:
- You collect an email, name, or any account info
- Your site uses Google Analytics, Meta Pixel, or any analytics
- Your site loads ads
- You sell anything online
- You publish a mobile app on the App Store or Google Play
- Anyone in the EU, UK, California, or Brazil could visit your site
For 99% of digital products, the answer is yes.
Who specifically requires it
| Requirement source | What triggers it |
|---|---|
| GDPR (EU/UK) | Any processing of EU/UK user data |
| CCPA (California) | $25M revenue or 100k+ CA consumers |
| LGPD (Brazil) | Any service offered to Brazilian users |
| Apple App Store | App Review Guideline 5.1.1 — required URL |
| Google Play | Data Safety section — required URL |
| Google AdSense / AdMob | Publisher policy — required disclosure |
| Meta Ads | Business Tools Terms — required disclosure |