Nestor Logic
ADA Title III · AccessibilityState privacy lawsNew York & Michigan

The laws that touch your US website, written plainly.

Federal accessibility law, a fifty-state privacy patchwork, and New York and Michigan's own rules. What each one asks of a public-facing site, what it costs to ignore, and how the gap gets closed.

Rules for
Which states?any state — we read it off the site

One free scan. We keep the result for 12 months, along with the address and approximate location your request came from — read the Scanner Terms and our Privacy Policy.

// The scan reads what is publicly visible on your site. It is a starting point for review — not a legal opinion or a certification of compliance.

What the laws actually ask for

Four bodies of law reach a US business website.

Most owners have heard the names and never seen the requirements written plainly. These are the obligations that apply to a public-facing site — no legalese, and for most of them, no small-business exemption.

// Federal · In force in every state

Accessibility, email and texting

Three federal regimes apply everywhere regardless of local law: the Americans with Disabilities Act for your website, CAN-SPAM for your email, and the TCPA for your texts.

A website people with disabilities can use

Courts treat a public-facing site like a storefront. The working standard is WCAG 2.1 AA — readable contrast, labelled forms, text alternatives for images, keyboard navigation. No revenue threshold, no small-business exemption.

Menus in real HTML, not only PDF

PDF-only menus and third-party ordering or reservation widgets are the first things a plaintiff's lawyer looks for — and the widget's failures count as yours.

An accessibility statement with a plan

A published statement naming a remediation plan and a timeline, backed by a continuous, timestamped log of what was fixed and when.

Honest email with a way out

Every commercial email needs an accurate from-line and subject, a valid postal address and a working unsubscribe honoured within 10 business days.

Written consent before marketing texts

Marketing texts need prior express written consent, quiet hours of 8 a.m. to 9 p.m. in the recipient's time zone, STOP handling, and a registered sender — carriers block unregistered traffic.

No overlay widgets

An accessibility overlay layered over a site does not fix the code underneath, and marketing one as a compliance solution has drawn regulatory action against the vendor.

// New York · State and city

Data security, disclosures and pricing

New York adds its own duties on top of the federal ones, and they bind any business holding a New York resident's information — you don't have to be located there.

Reasonable safeguards for private information

The SHIELD Act requires administrative, technical and physical safeguards — in practice a written security program, encryption in transit and at rest, and access controls. No revenue or headcount threshold.

Breach notice within 30 days

Affected residents must be notified within 30 days of discovery, with the Attorney General and, since December 2024, the financial regulator on the list. A clock that short has to be a system timer.

Prices set from customer data are disclosed

Since November 2025, any price set by an algorithm using a customer's personal data must carry a fixed, conspicuous disclosure beside it — on every surface that shows the price.

Displayed price equals the total

The deceptive-acts and false-advertising sections are the catch-all for junk fees and misleading promotions. The price on the page, the total charged and every claim have to survive a literal reading.

Human rights laws stack on the ADA

The state and city Human Rights Laws add compensatory damages the federal ADA does not. New York leads every state in accessibility filings.

New York City: menu labels and biometrics

Chains with 15 or more locations must show calories, a sodium warning and an added-sugar label — online ordering included. Any face or fingerprint kiosk needs a posted notice, and biometric data may never be sold.

// Michigan · State

Security baseline and honest practice

Michigan asks for a security baseline, prompt breach notice and standard accessibility hygiene — less disclosure load than New York, but the federal rules apply in full.

Safeguard sensitive information

The Identity Theft Protection Act requires businesses to safeguard sensitive information and to notify promptly after a breach — Michigan's counterpart to New York's SHIELD Act.

No deceptive practices

The Consumer Protection Act is Michigan's catch-all, and the Attorney General uses it. Displayed prices, totals and promotional claims all have to hold up.

Accessibility, state and federal

The Persons with Disabilities Civil Rights Act is the state analog to the ADA, and the federal law applies in Michigan in full. Fewer filings than New York; the same standard.

High-privacy defaults for minors

The Kids Code Act, in force since July 2026, requires data minimisation and high-privacy defaults on any service minors access — a kids' menu page can be enough to trigger it.

Recording privacy reaches tracking

An older statute on customer purchase records has no residency requirement and has been used against advertising pixels — live the moment you sell media or wire video to ad tags.

Age-restricted marketing lists

If any location sells a product minors cannot buy, marketing lists must be scrubbed against the state's Children's Protection Registry before a send.

// About 20 states · Law follows the customer

Privacy, cookies and tracking

Roughly twenty states now have comprehensive privacy laws, and they follow where your customers live rather than where you are. Two of them reach almost every US site.

A published privacy policy

California's posting rule is triggered by any California visitor — which in practice means every US-facing site. What you collect, why, who receives it, your customers' rights, a contact and an effective date.

Access, deletion, correction and opt-out

The comprehensive laws grant consumers rights over their data once a business crosses their thresholds — typically 100,000 consumers, or 25,000 plus revenue from selling data.

Honour the Global Privacy Control signal

A dozen states now require sites to treat a browser's GPC signal as an opt-out of sale and targeted advertising. Cure periods are expiring, so a first notice no longer comes with a chance to fix.

Pixels and session replay are lawsuit material

The fastest-growing exposure is private litigation under decades-old wiretapping statutes over advertising pixels and session-replay tools, filed as class actions.

Consent before tags fire

A tag inventory, a banner with a genuine reject, and no advertising or analytics tag firing before consent — advisable wherever pixels run, mandatory where a state law applies.

Children's data

Kids' menus, games and birthday-party signups can bring a site under the federal children's privacy rule: verified parental consent before collection, and no tracking on those pages.

Why we don't use compliance overlays

The quickest way to claim compliance is a third-party script that layers a banner and a widget over your existing site. It's also the quickest way to slow the site down, and overlays have a poor record of actually satisfying regulators or the people they're meant to help. Nestor changes the underlying code instead — slower to deploy, but it's the version that holds up when someone looks closely.

What's at stake

The numbers, from the statutes themselves.

Every figure below is taken from the law that sets it, and links to it — check us in one click.

$500–$1,500 per text

Text-message damages are counted per message

A recipient may recover $500 for each message sent without the consent the law requires, and a court may treble that to $1,500 where the violation was willful or knowing. The right to sue is the recipient's own, which is what makes a single non-compliant campaign a class action.

Source: 47 U.S.C. § 227(b)(3)

Up to $5,000 per violation

SHIELD Act — reasonable safeguards

Any business holding a New York resident's private information must keep reasonable administrative, technical and physical safeguards, wherever the business itself sits. No business is exempt, but one under 50 employees, $3M in revenue or $5M in assets may scale its safeguards to its own size and complexity. Enforced by the Attorney General, who recovers penalties of up to $5,000 per violation under § 350-d; there is no private right of action.

Source: NY General Business Law § 899-bb (penalties via § 350-d)

Up to $250,000 for botched notice

Failing to notify

A court may impose the greater of $5,000, or up to $20 for each failed notification — capped at $250,000. That sits on top of the safeguards exposure.

Source: NY General Business Law § 899-aa

$5,000 per violation, class-wide

Wiretapping suits over pixels and session replay

California's wiretap statute lets a plaintiff recover $5,000 per violation, or three times actual damages, whichever is greater — and says in terms that having suffered actual damages is not a prerequisite to suing. That is what turns one pixel firing on thousands of visitors into a class action.

Source: California Penal Code § 637.2

$50 floor, trebled to $1,000

Deceptive acts and false advertising

New York declares unfair, deceptive and abusive business practices unlawful in general terms. Anyone injured may sue for actual damages or $50, whichever is greater, and a court may treble the award up to $1,000 where the violation was willful, plus attorney's fees. The Attorney General may act separately for restitution and an injunction.

Source: NY General Business Law § 349(h)

Up to $1,000 per violation

Prices set from customer data carry a fixed sentence

Since 10 November 2025, a price set using a customer's personal data has to carry one exact sentence, clearly and conspicuously, near and at the same time as the price itself. The wording is prescribed, so an edited version is a defect rather than a variation.

Source: NY General Business Law § 349-a

Address, opt-out, 10 business days

Commercial email needs an address and a way out

Every commercial message must carry a valid physical postal address and an opt-out that still works for at least 30 days after sending, and an opt-out must be honoured within 10 business days. Materially misleading headers and subject lines are separately unlawful. Enforced by the FTC and state attorneys general; the per-message penalty is set by the FTC Act and adjusted for inflation each year.

Source: 15 U.S.C. § 7704

No exemption, no safe harbour

The ADA reaches every public-facing site

The Justice Department's position is that the ADA reaches everything a business open to the public offers, including on the web, and it names no size threshold. Businesses are given flexibility in HOW they comply rather than a single mandated technical standard — WCAG is cited as helpful guidance, and it is the benchmark settlements and courts have converged on in practice.

Source: US Department of Justice — ADA guidance on web accessibility

A second law, with its own duties

New York's own laws stack on the federal one

New York's Human Rights Law separately bars disability discrimination by places of public accommodation, and requires reasonable modifications, removal of communication barriers where readily achievable, and auxiliary aids short of undue burden. It applies alongside the federal rule rather than instead of it.

Source: NY Executive Law § 296(2)

30 days from discovery

New York breach notice

Affected New Yorkers must be notified within thirty days after a breach is discovered. The Attorney General, the Department of State and the State Police must be told as well; the Department of Financial Services only when the business is a DFS-covered entity, which a restaurant is not.

Source: NY General Business Law § 899-aa

Any site with California visitors

California's posting rule reaches your site

Any commercial site collecting personal information from a California resident must post a privacy policy — which in practice means every US-facing site. It must name the categories collected and who they are shared with, describe how changes are announced, carry an effective date, and state how the site responds to browser Do-Not-Track signals. A missing policy becomes a violation only if it is still missing 30 days after notice.

Source: Cal. Business & Professions Code § 22575

Parental consent before you collect

The federal rule reaches any surface built for under-13s

Where a site is directed at children under 13 — a kids' menu, a game, a birthday-party signup can be enough — verifiable parental consent must come before any collection, use or disclosure of a child's personal information, not after.

Source: 16 CFR § 312.5 (COPPA Rule)

// Statutory maximums and per-violation amounts, not predictions about any business. What a court or regulator does in a given case depends on the facts. This is a starting point for review, not legal advice.

How we close the gaps

Scan, rebuild, approve, stay on top of it.

Compliance isn't a one-time fix — the law follows every content change you make. Nestor handles the first pass and then keeps it from drifting.

// 01 · Scan

We read your public site

Every page, form, tracker and embedded widget. You get a plain-language readout of what's in place, what's missing, and what a scan can't confirm from the outside.

// 02 · Rebuild

Fixes go into real code

Alt text, contrast, labelled forms, consent gating, a privacy policy that matches what the site collects — built into the site itself, never a widget layered over the top.

// 03 · Approve

Nothing ships without you

Every change is staged and previewed. You approve by SMS or in the panel — one tap to publish, one tap to send it back.

// 04 · Maintain

The record keeps itself

A timestamped remediation log, consent records with the wording shown, and a mail log that proves an unsubscribe was honoured. Ongoing checks catch drift before a demand letter does.

The sovereign vault

Your customer data, kept where it belongs.

// Handled for you

Requests, done

When a customer asks what data you hold — or wants it deleted — it gets done, and old data clears out on schedule. You don't have to remember any of it.

// Stays put

In-region hosting

Your customers' information lives on servers in the region you choose, with immutable audit logs showing where it's been the whole time.

// One snippet

One line of code

Nothing to rebuild, nothing to migrate. One snippet on your site and the compliance layer is running.

See it work on your business.