
Federal accessibility law, a fifty-state privacy patchwork, and New York and Michigan's own rules. What each one asks of a public-facing site, what it costs to ignore, and how the gap gets closed.
// The scan reads what is publicly visible on your site. It is a starting point for review — not a legal opinion or a certification of compliance.
Most owners have heard the names and never seen the requirements written plainly. These are the obligations that apply to a public-facing site — no legalese, and for most of them, no small-business exemption.
// Federal · In force in every state
Accessibility, email and texting
Three federal regimes apply everywhere regardless of local law: the Americans with Disabilities Act for your website, CAN-SPAM for your email, and the TCPA for your texts.
A website people with disabilities can use
Courts treat a public-facing site like a storefront. The working standard is WCAG 2.1 AA — readable contrast, labelled forms, text alternatives for images, keyboard navigation. No revenue threshold, no small-business exemption.
Menus in real HTML, not only PDF
PDF-only menus and third-party ordering or reservation widgets are the first things a plaintiff's lawyer looks for — and the widget's failures count as yours.
An accessibility statement with a plan
A published statement naming a remediation plan and a timeline, backed by a continuous, timestamped log of what was fixed and when.
Honest email with a way out
Every commercial email needs an accurate from-line and subject, a valid postal address and a working unsubscribe honoured within 10 business days.
Written consent before marketing texts
Marketing texts need prior express written consent, quiet hours of 8 a.m. to 9 p.m. in the recipient's time zone, STOP handling, and a registered sender — carriers block unregistered traffic.
No overlay widgets
An accessibility overlay layered over a site does not fix the code underneath, and marketing one as a compliance solution has drawn regulatory action against the vendor.
// New York · State and city
Data security, disclosures and pricing
New York adds its own duties on top of the federal ones, and they bind any business holding a New York resident's information — you don't have to be located there.
Reasonable safeguards for private information
The SHIELD Act requires administrative, technical and physical safeguards — in practice a written security program, encryption in transit and at rest, and access controls. No revenue or headcount threshold.
Breach notice within 30 days
Affected residents must be notified within 30 days of discovery, with the Attorney General and, since December 2024, the financial regulator on the list. A clock that short has to be a system timer.
Prices set from customer data are disclosed
Since November 2025, any price set by an algorithm using a customer's personal data must carry a fixed, conspicuous disclosure beside it — on every surface that shows the price.
Displayed price equals the total
The deceptive-acts and false-advertising sections are the catch-all for junk fees and misleading promotions. The price on the page, the total charged and every claim have to survive a literal reading.
Human rights laws stack on the ADA
The state and city Human Rights Laws add compensatory damages the federal ADA does not. New York leads every state in accessibility filings.
New York City: menu labels and biometrics
Chains with 15 or more locations must show calories, a sodium warning and an added-sugar label — online ordering included. Any face or fingerprint kiosk needs a posted notice, and biometric data may never be sold.
// Michigan · State
Security baseline and honest practice
Michigan asks for a security baseline, prompt breach notice and standard accessibility hygiene — less disclosure load than New York, but the federal rules apply in full.
Safeguard sensitive information
The Identity Theft Protection Act requires businesses to safeguard sensitive information and to notify promptly after a breach — Michigan's counterpart to New York's SHIELD Act.
No deceptive practices
The Consumer Protection Act is Michigan's catch-all, and the Attorney General uses it. Displayed prices, totals and promotional claims all have to hold up.
Accessibility, state and federal
The Persons with Disabilities Civil Rights Act is the state analog to the ADA, and the federal law applies in Michigan in full. Fewer filings than New York; the same standard.
High-privacy defaults for minors
The Kids Code Act, in force since July 2026, requires data minimisation and high-privacy defaults on any service minors access — a kids' menu page can be enough to trigger it.
Recording privacy reaches tracking
An older statute on customer purchase records has no residency requirement and has been used against advertising pixels — live the moment you sell media or wire video to ad tags.
Age-restricted marketing lists
If any location sells a product minors cannot buy, marketing lists must be scrubbed against the state's Children's Protection Registry before a send.
// About 20 states · Law follows the customer
Privacy, cookies and tracking
Roughly twenty states now have comprehensive privacy laws, and they follow where your customers live rather than where you are. Two of them reach almost every US site.
A published privacy policy
California's posting rule is triggered by any California visitor — which in practice means every US-facing site. What you collect, why, who receives it, your customers' rights, a contact and an effective date.
Access, deletion, correction and opt-out
The comprehensive laws grant consumers rights over their data once a business crosses their thresholds — typically 100,000 consumers, or 25,000 plus revenue from selling data.
Honour the Global Privacy Control signal
A dozen states now require sites to treat a browser's GPC signal as an opt-out of sale and targeted advertising. Cure periods are expiring, so a first notice no longer comes with a chance to fix.
Pixels and session replay are lawsuit material
The fastest-growing exposure is private litigation under decades-old wiretapping statutes over advertising pixels and session-replay tools, filed as class actions.
Consent before tags fire
A tag inventory, a banner with a genuine reject, and no advertising or analytics tag firing before consent — advisable wherever pixels run, mandatory where a state law applies.
Children's data
Kids' menus, games and birthday-party signups can bring a site under the federal children's privacy rule: verified parental consent before collection, and no tracking on those pages.
Why we don't use compliance overlays
The quickest way to claim compliance is a third-party script that layers a banner and a widget over your existing site. It's also the quickest way to slow the site down, and overlays have a poor record of actually satisfying regulators or the people they're meant to help. Nestor changes the underlying code instead — slower to deploy, but it's the version that holds up when someone looks closely.
Every figure below is taken from the law that sets it, and links to it — check us in one click.
$500–$1,500 per text
Text-message damages are counted per message
A recipient may recover $500 for each message sent without the consent the law requires, and a court may treble that to $1,500 where the violation was willful or knowing. The right to sue is the recipient's own, which is what makes a single non-compliant campaign a class action.
Source: 47 U.S.C. § 227(b)(3)Up to $5,000 per violation
SHIELD Act — reasonable safeguards
Any business holding a New York resident's private information must keep reasonable administrative, technical and physical safeguards, wherever the business itself sits. No business is exempt, but one under 50 employees, $3M in revenue or $5M in assets may scale its safeguards to its own size and complexity. Enforced by the Attorney General, who recovers penalties of up to $5,000 per violation under § 350-d; there is no private right of action.
Source: NY General Business Law § 899-bb (penalties via § 350-d)Up to $250,000 for botched notice
Failing to notify
A court may impose the greater of $5,000, or up to $20 for each failed notification — capped at $250,000. That sits on top of the safeguards exposure.
Source: NY General Business Law § 899-aa$5,000 per violation, class-wide
Wiretapping suits over pixels and session replay
California's wiretap statute lets a plaintiff recover $5,000 per violation, or three times actual damages, whichever is greater — and says in terms that having suffered actual damages is not a prerequisite to suing. That is what turns one pixel firing on thousands of visitors into a class action.
Source: California Penal Code § 637.2$50 floor, trebled to $1,000
Deceptive acts and false advertising
New York declares unfair, deceptive and abusive business practices unlawful in general terms. Anyone injured may sue for actual damages or $50, whichever is greater, and a court may treble the award up to $1,000 where the violation was willful, plus attorney's fees. The Attorney General may act separately for restitution and an injunction.
Source: NY General Business Law § 349(h)Up to $1,000 per violation
Prices set from customer data carry a fixed sentence
Since 10 November 2025, a price set using a customer's personal data has to carry one exact sentence, clearly and conspicuously, near and at the same time as the price itself. The wording is prescribed, so an edited version is a defect rather than a variation.
Source: NY General Business Law § 349-aAddress, opt-out, 10 business days
Commercial email needs an address and a way out
Every commercial message must carry a valid physical postal address and an opt-out that still works for at least 30 days after sending, and an opt-out must be honoured within 10 business days. Materially misleading headers and subject lines are separately unlawful. Enforced by the FTC and state attorneys general; the per-message penalty is set by the FTC Act and adjusted for inflation each year.
Source: 15 U.S.C. § 7704No exemption, no safe harbour
The ADA reaches every public-facing site
The Justice Department's position is that the ADA reaches everything a business open to the public offers, including on the web, and it names no size threshold. Businesses are given flexibility in HOW they comply rather than a single mandated technical standard — WCAG is cited as helpful guidance, and it is the benchmark settlements and courts have converged on in practice.
Source: US Department of Justice — ADA guidance on web accessibilityA second law, with its own duties
New York's own laws stack on the federal one
New York's Human Rights Law separately bars disability discrimination by places of public accommodation, and requires reasonable modifications, removal of communication barriers where readily achievable, and auxiliary aids short of undue burden. It applies alongside the federal rule rather than instead of it.
Source: NY Executive Law § 296(2)30 days from discovery
New York breach notice
Affected New Yorkers must be notified within thirty days after a breach is discovered. The Attorney General, the Department of State and the State Police must be told as well; the Department of Financial Services only when the business is a DFS-covered entity, which a restaurant is not.
Source: NY General Business Law § 899-aaAny site with California visitors
California's posting rule reaches your site
Any commercial site collecting personal information from a California resident must post a privacy policy — which in practice means every US-facing site. It must name the categories collected and who they are shared with, describe how changes are announced, carry an effective date, and state how the site responds to browser Do-Not-Track signals. A missing policy becomes a violation only if it is still missing 30 days after notice.
Source: Cal. Business & Professions Code § 22575Parental consent before you collect
The federal rule reaches any surface built for under-13s
Where a site is directed at children under 13 — a kids' menu, a game, a birthday-party signup can be enough — verifiable parental consent must come before any collection, use or disclosure of a child's personal information, not after.
Source: 16 CFR § 312.5 (COPPA Rule)// Statutory maximums and per-violation amounts, not predictions about any business. What a court or regulator does in a given case depends on the facts. This is a starting point for review, not legal advice.
Compliance isn't a one-time fix — the law follows every content change you make. Nestor handles the first pass and then keeps it from drifting.
// 01 · Scan
We read your public site
Every page, form, tracker and embedded widget. You get a plain-language readout of what's in place, what's missing, and what a scan can't confirm from the outside.
// 02 · Rebuild
Fixes go into real code
Alt text, contrast, labelled forms, consent gating, a privacy policy that matches what the site collects — built into the site itself, never a widget layered over the top.
// 03 · Approve
Nothing ships without you
Every change is staged and previewed. You approve by SMS or in the panel — one tap to publish, one tap to send it back.
// 04 · Maintain
The record keeps itself
A timestamped remediation log, consent records with the wording shown, and a mail log that proves an unsubscribe was honoured. Ongoing checks catch drift before a demand letter does.
// Handled for you
When a customer asks what data you hold — or wants it deleted — it gets done, and old data clears out on schedule. You don't have to remember any of it.
// Stays put
Your customers' information lives on servers in the region you choose, with immutable audit logs showing where it's been the whole time.
// One snippet
Nothing to rebuild, nothing to migrate. One snippet on your site and the compliance layer is running.