66% of company websites, two out of every three sampled, carried no privacy policy hyperlink on their landing page at all, according to a 2023 Pennsylvania State University study that crawled a dataset of more than 7.17 million companies. That figure comes from a hand-checked sample of 500 company domains, and it lines up closely with the study's broader machine-classified estimate that only 34% of company websites carry a discoverable privacy policy hyperlink irrespective of language.

Two thirds of company websites have no privacy policy link 66% of company websites carry noprivacy policy link at all

What percentage of small business websites lack a privacy policy?

Researchers Mukund Srinath, Soundarya Sundareswara, Pranav Venkit, C. Lee Giles, and Shomir Wilson built their dataset from the Free Company Dataset, a collection of over 7 million global companies with domain, industry, and size fields, sourced through LinkedIn. To ground their automated crawler results, the team manually reviewed a random sample of 500 successfully crawled company domain URLs and recorded exactly how each one handled its privacy policy link.

Manual sample outcomeSites (of 500)Share
No privacy policy hyperlink found33066.0%
Hyperlink using the word privacy, data, or protection10621.2%
Hyperlink using a translated version of those words428.4%
Policy shown through another HTML element, not a plain link224.4%

Two out of three sampled company sites gave a visitor no privacy policy link to click at all. Of the one-third that did, most used one of a handful of predictable keywords in the link text itself, which is also how the researchers' own automated crawler found candidate policies at scale.

How 500 sampled company domains handled a privacy policy link 66%21.2%8.4%4.4%No policy hyperlink found66%Policy link with privacy or data keyword21.2%Policy link with translated keyword8.4%Policy shown via other HTML element4.4%66%no policy link

Figure 1: How 500 manually reviewed company domains handled their privacy policy link. Source: Srinath et al., "Privacy Lost and Found," DocEng '23, Table 1.

How did researchers reach that 66% figure?

The 66% figure did not come from a casual scan. The team built a six-stage pipeline that started with 7,173,425 company records, extracted 5,474,764 unique domains, crawled each one, filtered out non-English and non-policy documents, then removed duplicates to arrive at a clean, citable corpus.

Figure 2: The pipeline that produced the CoLIPPs Corpus, from raw company records to a clean policy dataset. Source: Srinath et al., "Privacy Lost and Found," DocEng '23, Figure 1.

A random forest classifier separated genuine privacy policies from other legal documents with 0.96 precision and 0.97 recall after training on 1,600 manually labeled documents, and two independent human labelers agreed on 93% of a validation sample. That level of manual checking is why the 66% figure holds up better than a simple keyword search would.

Does this data actually represent small businesses?

Warning

The Free Company Dataset spans companies of every size, from single-founder shops to multinational firms, and the published study does not break its results out by employee count or revenue band. The 66% figure describes company websites broadly, not a small-business-only sample. Given that small businesses vastly outnumber large ones in any general company database, and that the study explicitly excludes personal blogs and non-commercial sites in favor of registered companies, this is a closer proxy for the small business web than a general internet crawl, but it is a proxy, not a direct measurement.

That caveat matters because a separate methodology reaches a compatible conclusion from a different angle. Our own analysis of how many websites have a privacy policy found that sites ranked below 1 million by traffic, the long tail where most small business and personal sites actually live, carried a detectable privacy policy link only 9.6% of the time, using a 2021 Princeton and KU Leuven dataset of 9.6 million archived homepages. Two independent research teams, using two different crawling methods on two different populations five years apart, both land on the same story: the smaller and less prominent a site is, the less likely it is to post a findable privacy policy.

Which business sectors are most likely to skip a privacy policy?

The researchers classified their 612,046-policy corpus into 11 sectors of commerce, using LinkedIn's own industry categorization scheme. Finance, marketing, and human resources businesses produced the largest single share of the corpus at 17%, followed by information technology and electronics companies at 14%.

Privacy policies found per sector of commerce 030k60k90k120k103.9kFinance,marketing, HR78.73kIT andelectronics75.61kConsumer andsupply chain68.79kCivil,mechanical,electrical47.9kMedical42.75kSports,media,entertainment34.29kEducation

Figure 3: Number of privacy policies identified per sector of commerce in the CoLIPPs Corpus (top 7 of 11 sectors). Source: Srinath et al., "Privacy Lost and Found," DocEng '23, Figure 4.

Raw policy counts track sector size as much as compliance behavior, so the researchers also compared the ratio of domains with a policy to domains without one within each sector. The medical sector had the highest ratio of any sector, and non-consumer-facing sectors such as civil, mechanical, and electrical engineering and government, defense, and legal work had among the lowest. The sports, media, and entertainment sector stood out as an exception: despite handling consumer data at a scale comparable to retail or hospitality, it had the lowest policy-to-no-policy ratio the researchers measured.

How has the case for a small business privacy policy built up over time?

Company-level privacy disclosure has been studied on and off since the late 1990s, and each study used a different sample and a different definition of what counts as a policy, so the numbers below are directional evidence of a trend rather than one continuous series.

Figure 4: Company and website privacy policy research findings across 25 years, using different samples and methods. Sources: FTC (1998); Liu and Arnett (2002) and Nokhbeh and Barber (2017), as cited in Amos et al., WWW '21; Amos et al., WWW '21; Srinath et al., DocEng '23.

What has changed underneath these inconsistent numbers is the legal landscape, not just researcher curiosity. GDPR took effect in the EU in May 2018, California's CCPA followed in January 2020, and a wave of additional US state laws has arrived since, which is the part of this story that matters most for a small business deciding whether it actually needs to act.

Do small businesses legally need a privacy policy?

Size alone does not exempt a business from state privacy law. Under the CCPA, a business must post a compliant privacy policy if it meets any one of three thresholds set by the California Privacy Protection Agency: 26.625 million dollars or more in annual gross revenue, buying, selling, or sharing the personal information of 100,000 or more California consumers or households a year, or deriving 50% or more of annual revenue from selling personal information.

Figure 5: The CCPA's three independent applicability thresholds. Meeting any one is enough. Source: California Privacy Protection Agency FAQ, 2026.

A ten-employee company that buys ad-targeting data on 150,000 local shoppers a year clears the second threshold easily, regardless of its revenue. That is the scenario the California Privacy Protection Agency specifically warns about: "size alone does not create an exemption." For any small business unsure where it lands, the fastest way to close the gap is to generate a privacy policy that maps your actual data practices to the disclosures a regulator or a customer would expect to find.

How fast are state privacy laws spreading to more small businesses?

California was the only US state with a comprehensive consumer privacy law in effect as recently as 2020. That number has grown nearly twentyfold in six years.

US states with a comprehensive privacy law in effect 051015202020202320242025202619

Figure 6: Cumulative US states with a comprehensive consumer privacy law in effect, 2020 to 2026. Source: Privacy Law Map state legislation tracker, updated March 2026.

Virginia, Colorado, Connecticut, and Utah brought the total to 5 states by 2023. Texas, Oregon, and Montana pushed it to 8 by 2024. Eight more states, including Iowa, Delaware, New Hampshire, New Jersey, Nebraska, Minnesota, Maryland, and Tennessee, took effect through 2025, and Indiana, Kentucky, and Rhode Island brought the count to 19 states in effect as of January 2026, with a 20th, Oklahoma, set to take effect January 1, 2027. Each new law carries its own applicability thresholds, and several set them lower than California's, which means a small business that clears no CCPA threshold today may still fall under a neighboring state's law depending on where its customers live.

The Bottom Line

The most carefully checked number available says two out of three company websites, 66% of a manually verified 500-site sample, have no privacy policy hyperlink a visitor could click. The broader machine-classified estimate across the full crawl lands in the same range, at 34% coverage overall. Neither figure is a small-business-only measurement in the strict sense, since the underlying dataset spans companies of every size, but a general company database is dominated by small businesses by simple count, and a second, independent study using website-traffic rank instead of company records reached a compatible conclusion for the lowest-traffic tier of sites. What has changed since these gaps were first documented is not the technology, it is the law: 20 US states now require some businesses, regardless of size, to post a privacy policy once they cross a revenue or data-volume threshold that a growing share of small businesses will eventually meet.

Frequently Asked Questions

What percentage of small business websites lack a privacy policy? 66% of company websites sampled, 330 of 500, had no privacy policy hyperlink on their landing page, and only 34% plus or minus 4.15% of company websites overall carried one, according to Pennsylvania State University's 2023 Privacy Lost and Found study of a dataset built from more than 7.17 million companies.

Do small businesses have to post a privacy policy under CCPA? Only if the business crosses one of three thresholds: 26.625 million dollars or more in annual gross revenue, buying, selling, or sharing the personal information of 100,000 or more California consumers or households annually, or deriving 50% or more of revenue from selling personal information, per the California Privacy Protection Agency. Revenue size alone does not create an exemption.

Which business sectors are most likely to have a privacy policy? Finance, marketing, and human resources businesses accounted for 17% of all privacy policies found in the research corpus, the largest share of any sector, while the medical sector had the highest ratio of domains with a policy to domains without one, per the Penn State research team's sector analysis.

How many US states now require some businesses to post a privacy policy? 20 states had enacted a comprehensive consumer privacy law as of March 2026, with 19 already in effect and Oklahoma's law set to take effect on January 1, 2027, according to Privacy Law Map's state legislation tracker.

Where the Numbers Come From

  1. Srinath, M., Sundareswara, S., Venkit, P., Giles, C.L., and Wilson, S. (2023). "Privacy Lost and Found: An Investigation at Scale of Web Privacy Policy Availability." Proceedings of DocEng '23. Best Student Paper award. 500-site manual sample, 330 without a policy hyperlink, 34% plus or minus 4.15% overall estimate, 612,046-document CoLIPPs Corpus, 2,981,047 estimated lower bound on English-language privacy policies.
  2. Pennsylvania State University. (2023, October 25). "Most websites do not publish privacy policies, researchers say." Press coverage of the DocEng '23 study, quoting lead author Mukund Srinath.
  3. California Privacy Protection Agency. "Frequently Asked Questions." CCPA applicability thresholds: 26.625 million dollars annual gross revenue (effective January 1, 2025), 100,000 consumers or households, 50% of revenue from data sales.
  4. Privacy Law Map. (2026, March 28). "How Many States Have Data Privacy Laws." 20 states enacted, 19 in effect as of January 2026, effective-date table by state.

Note: All figures verified as of July 2026. The state privacy law count is a live, rolling tracker and may have added states since Privacy Law Map's March 2026 update; CCPA's revenue threshold is adjusted annually for inflation and should be reconfirmed against the California Privacy Protection Agency's current FAQ before relying on the exact dollar figure. Figures are refreshed at least twice a year.