A privacy policy is required under California law (CCPA) and European law (GDPR) to disclose how a website collects and manages its user data. Even a website that uses Google Analytics is required to have a privacy policy since it tracks users on the website.