Website Legal Requirements: What Actually Applies to Your Site
Website Legal Requirements: What Actually Applies to Your Site

Almost every article on this subject is a list of everything that could possibly apply to a website, which is useless in a specific way: it makes a restaurant in Ohio and a hospital system in California read the same page and come away with the same undifferentiated anxiety.
The useful question is not what website laws exist. It is which ones bind you, what each actually requires, and what happens if you ignore it. This page is organized that way. Work through the four sections, note what applies, and ignore the rest with a clear conscience.
One framing point first, because it reorders everything below.
Regulation and liability are not the same thing
People assume these move together: where there is a rule there is risk, and where there is no rule there is none. In website law the opposite is often true.
The clearest example is web accessibility. State and local government bodies are covered by a detailed federal regulation with a named standard and a deadline. Private businesses are covered by no web accessibility regulation at all — and private businesses are the ones being sued, thousands of times a year.
So as you read, keep two columns in your head. Compliance obligations have deadlines, named standards, and a regulator. Liability exposure has none of those and can still cost you a great deal. The second is easier to ignore and generally the more likely to actually happen to you.
1. Accessibility
The most active area of website law in the United States, and the one where the mismatch above is starkest.
If you are a state or local government body, the DOJ's ADA Title II rule applies: WCAG 2.1 Level AA, by 26 April 2027 if you serve 50,000 or more people, and 26 April 2028 for smaller entities and special districts. Both dates were extended by a year in April 2026, which is worth knowing because a lot of published guidance still cites the old ones. See our Title II guide, the WCAG 2.2 AA checklist for what actually fails on public-sector sites, and, if you serve a multilingual population, what language access requires beyond a translation plugin.
If you receive HHS funding — which reaches most providers taking Medicare, Medicaid or CHIP, plus community health centres and Head Start agencies — a rule under Section 504 requires WCAG 2.1 Level AA by 11 May 2027 for organizations with 15 or more employees, and 10 May 2028 below that. This one is widely unknown and is probably the most consequential deadline on this page. See the HHS rule explained.
If you are a federal agency or sell to one, Section 508 applies. Its technical standard still incorporates WCAG 2.0 Level AA, and you will be asked for a conformance report.
If you are a private business open to the public, there is no rule and no deadline — and this is the group facing the litigation. Roughly four in five accessibility claims are now filed in state rather than federal court, because state civil rights statutes often carry damages the ADA does not. California's Unruh Civil Rights Act, with statutory damages starting at $4,000 per violation, is the best-known and a large part of why California, New York and Florida dominate filings.
If you sell into the EU, the European Accessibility Act has applied since 28 June 2025, assessed against EN 301 549, and it follows your customers rather than your incorporation.
The engineering answer in every case is the same — build and test to WCAG 2.2 Level AA — but the version you write in a contract differs by rule. Our post on which standard binds you works through that, and what changed in 2.2 covers the delta if you were audited against 2.1. If you are being sold a widget as the solution, read why overlays do not work first.
2. Privacy and data
Twenty states now have comprehensive consumer privacy laws in effect: California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia and Washington. Indiana, Kentucky and Rhode Island were the most recent, all taking effect on 1 January 2026.
Two things matter more than the list.
First, they apply based on whose data you process, not where you are. A business in a state with no privacy law can be covered by several of these because it has customers in those states. Thresholds vary — commonly tens of thousands of consumers, with lower triggers where you sell personal data — and Rhode Island's are notably low.
Second, the obligations are broadly similar even though the statutes differ: a privacy notice saying what you collect and why, a way for consumers to access, correct and delete their data, an opt-out of sale and targeted advertising, and in several states an obligation to honour browser-level universal opt-out signals rather than only your own cookie banner.
If you operate at any scale across state lines, the practical approach is to build to the strictest requirement you are subject to rather than maintaining twenty variants.
Separately, a fast-growing area of litigation concerns tracking technologies — session replay tools, chat widgets and advertising pixels — under state wiretapping and privacy statutes. The theory is that data sharing with a third party without consent is an intercepted communication. This is most acute for healthcare sites, where a pixel on a page about a condition can transmit something close to a diagnosis. If you run analytics, chat or advertising pixels on a health, legal or financial site, this deserves attention now rather than after a demand letter.
We cover the fundamentals in website privacy and data protection.
3. Marketing, forms and commerce
Rules governing what you do with the contacts your website collects.
Email. CAN-SPAM requires accurate headers and subject lines, a physical postal address, a working unsubscribe mechanism, and honouring opt-outs promptly. It is not onerous and is widely breached by small operators using their own tooling.
Phone and SMS. The TCPA governs calls and texts, and this area has moved recently: the FCC's one-to-one consent rule, which would have significantly restricted lead-generation practices, was vacated by the Eleventh Circuit in January 2025 and the FCC has since removed it. Consent reverted to the prior standard. If you are reading guidance written in 2024 about one-to-one consent, it describes a rule that never took effect. Consent revocation obligations do apply, and the underlying prior-express-written-consent requirement is unchanged.
Subscriptions and auto-renewals. Also in flux. The FTC's click-to-cancel rule was vacated by the Eighth Circuit in July 2025, and the agency opened fresh rulemaking in March 2026. But the absence of that rule does not mean subscriptions are unregulated: ROSCA, Section 5 of the FTC Act, and state automatic-renewal statutes all still apply, and several states have their own specific cancellation requirements. Make cancellation as easy as signup regardless — that is where the law is heading and where enforcement already is.
Pricing and disclosure. If you sell online, expect scrutiny of drip pricing and undisclosed mandatory fees, an area of active state and federal attention. If you are scaling a store rather than simply running one, the obligations that get expensive with volume are worth reviewing before they do.
4. Sector rules
If any of these describe you, they are likely to matter more than everything above.
Healthcare: HIPAA governs protected health information, including what your forms collect and where it goes. Combined with the tracking-pixel exposure and the HHS accessibility deadline, healthcare has the heaviest website compliance load of any sector.
Law firms: state bar advertising rules govern claims, testimonials, comparative statements and disclaimers, and they vary by state. A phrase that is fine in one jurisdiction can be a violation in another.
Financial services and insurance: GLBA safeguards obligations, and for investment advisers the SEC marketing rule, which governs testimonials and performance claims on your site.
Education: FERPA for student records, and COPPA where you collect data from children under 13.
Nonprofits: state charitable solicitation registration is the requirement most often missed. A "Donate" button that can be used from any state may trigger registration obligations in many of them. Donor and beneficiary records are also unusually sensitive for organizations of this size, which is a separate problem from registration — see donor data privacy.
What to do with this
Three things, in order.
Work out which of the four sections actually bind you and write it down. Most organizations are subject to fewer requirements than they fear and are non-compliant with something specific they have never heard of — usually accessibility or a sector rule.
Fix accessibility first if you are subject to any of the deadlines, because it has the longest lead time. Document remediation in particular cannot be done quickly, and both the Title II and HHS rules reach documents rather than only pages. Start with an audit.
Then get your notices and consent flows in order, which is a smaller job than accessibility and can usually be done in weeks.
If a rebuild is on the table anyway, put the requirements into the procurement document rather than discovering them afterwards — our guide to accessibility requirements in an RFP and the RFP template pack cover the wording, and you can send us an RFP when yours is ready. The same document is where ownership, hosting and exit terms belong, for the same reason: they are cheap to set before the work starts and expensive to renegotiate afterwards.
Two caveats worth stating plainly. This page describes requirements in general terms and is not legal advice; whether a given rule applies to your organization is a question for your counsel. And this area moves — three of the rules described above changed within the eighteen months before this was written, two of them by being struck down in court. Anything you act on should be checked against a current primary source rather than against this page alone.
Put this into action with eSEOspace
We help businesses grow with website development that actually performs. Explore the services behind this guide:
Get a FREE Audit
We'll perform a comprehensive SEO, AEO, GEO & CRO audit of your website — completely free — and show you exactly how to outrank your competitors.
Don't have a site yet? Get in touch →
Get a FREE GEO/AEO/SEO Audit
We'll analyze your site's SEO, GEO, AEO & CRO — completely free — and show you exactly how to get found across Google and AI answers.
Don't have a site yet? Get in touch →
Great — your audit is on the way!
We'll send your free SEO/GEO/AEO/CRO audit within the next few hours. Where should we send it?
You're all set! ✓
Your free audit is being prepared — check your inbox in the next few hours. Talk soon!






