Most small to mid-size businesses think website privacy laws are only “big company” problems. But unfortunately, that’s not true.
All businesses can be on the hook to follow GDPR, CCPA and other emerging state-level legislation. Nearly two dozen US states now have data privacy laws on the books, and that number has grown every year. Indiana joined that list on January 1, 2026. So if you weren’t paying attention before, you should be now.
This isn’t about following legal compliance (although any good attorney would tell you that is always a good idea – I’m no legal expert, but I can just imagine they would say that), it’s about your visitors rights. When you are on someone else’s website you’d want them to protect, honor and abide by your rights. Your site visitors deserve the same.
What Data Your Website Is Probably Collecting Right Now
Every website we build includes some amount of tracking, at minimum that’s Google Analytics. But if you are running ads there could be more invisible pixels collecting information about site visitors. As a business, this is great. You can be more targeted with your ads, you learn about the people searching on your site. But the site visitor is unaware this is happening.
What the Law Says
Each law is different and as I already mentioned, I’m not a legal expert. But in general, the laws share a common thread … they exist to give people more control over what happens to their personal data. Laws like GDPR (which covers European visitors), CCPA in California, and now Indiana’s own Consumer Data Protection Act all establish baseline expectations around transparency and consent. These laws don’t care where your business is located. They care about where your visitors are. If someone in California or the EU lands on your website, those regulations can apply to you. With dozens of regulations across states, the odds are your site is touching regulated visitors without you even thinking about it.
What Visitors Have the Right to Do
Visitors have the right to know what is being collected and opt out of tracking their data. You wouldn’t want your data sold to some unknown entity so a request for deletion or prohibition of sale of data is also within the visitor’s rights.
What a Compliant Website Needs
There are a few ways to ensure your website is compliant. You’ve likely encountered hundreds of consent banners while visiting websites. This is the easiest way to notify users with details about the collection of information. Banner add-ons from trusted sources like SecurePrivacy can handle the display and ever-changing policies for states and countries so you remain in compliance without having to become a legal expert. Your privacy policy should also be updated. That copy-paste template you found online in 2019 is probably not going to cut it. These banners can also handle the opt-out and deletion request functionality all in one. Read more about JH’s partnership with SecurePrivacy here.
The Risk of Getting Privacy Wrong
The lawsuit chasers abound in this space. It likely won’t be long before you are met with a “I’m a California resident who visited your site and you violated my rights” filing. It’s happening to companies just like yours every day. Not only are these fines and legal fees costly, but they take time out of your business to address properly. Growing consumer awareness around online privacy means you could be sending signals that you don’t care and are harming trust with your future customers by not complying.

How To Handle Website Privacy Compliance
Feeling a little overwhelmed? You aren’t alone. The bar is rising and will keep rising as more states pass their own laws. Tackling this issue now is your best bet. Reach out to discuss how JH can help protect your site visitors and your business follows today’s best practices.


