Compliance guide

Cookie Consent for US Websites: What State Privacy Laws Actually Require

US privacy law is opt-out, not opt-in. No US state or federal law requires a prior-consent cookie banner like GDPR does. What 13 states require instead is an opt-out link — and only when you run advertising pixels. Here’s what actually applies to your site.

The key distinction: EU law (GDPR + ePrivacy) says “don’t set non-essential cookies until the user says yes.” US state law says “you can set cookies, but give users a way to say no to data sharing for advertising.” These are fundamentally different mechanisms.
Not legal advice. This guide accurately covers US state privacy law requirements as of September 2026, but it is educational — not a legal opinion. Consult a qualified attorney for your specific situation.

US websites don’t need a prior-consent cookie banner

As of September 2026, there is no US federal cookie consent law, and no US state law requires a prior-consent cookie banner. The 13 states that have enacted comprehensive privacy legislation — California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, and North Carolina — all use an opt-out model, not an opt-in model.

Under the opt-out model:

  • You may load cookies and collect personal data without asking first
  • You must disclose what you collect in a privacy policy
  • If you share that data with third parties for advertising, you must provide an opt-out mechanism
  • You honor opt-outs going forward — you don’t need to delete data already collected

This is the opposite of GDPR’s prior-consent requirement. Under EU law, non-essential cookies cannot fire until the user actively accepts. Under US law, cookies can fire freely — the obligation only arises when you share the resulting data for cross-context behavioral advertising.

When US opt-out IS required: advertising pixels

The US opt-out obligation is triggered by “selling” or “sharing” personal data for cross-context behavioral advertising. In practice, this means running advertising pixels — code that sends visitor identifiers to ad networks so they can show those visitors targeted ads on other websites.

These integrations typically trigger the opt-out requirement:

  • Facebook Pixel / Meta Pixel — sends visitor identifiers to Meta for retargeting
  • Google Ads remarketing tags — adds visitors to Google retargeting lists
  • TikTok Pixel, LinkedIn Insight Tag — cross-site retargeting
  • Google AdSense — serves behavioral ads based on cross-site tracking
  • Any ad network code that syncs visitor data with an ad platform

These integrations typically do not trigger the opt-out requirement:

  • Google Analytics 4 (analytics-only mode) — measures traffic without advertising features
  • Plausible Analytics, Fathom — cookieless, privacy-first analytics
  • Hotjar, Microsoft Clarity — session recording not tied to ad networks
  • Stripe, PayPal payment widgets — payment processing, not behavioral advertising
  • First-party functional cookies — session, auth, cart, preferences

The key test: does the code pass visitor identifiers to a third party to enable serving that visitor targeted ads on other sites? If yes, that’s “sharing” under CPRA and equivalent state laws.

Global Privacy Control (GPC): automatic opt-out signal

Global Privacy Control is a browser-level signal (navigator.globalPrivacyControl === true) that users can set to indicate they want to opt out of data selling and sharing. California (CPRA), Colorado (CPA), Connecticut (CTDPA), and Oregon (OCPA) explicitly require businesses to recognize GPC as a valid opt-out — equivalent to clicking the “Do Not Sell or Share” link.

If your site serves visitors from these four states and you run advertising pixels, you must check for the GPC signal and honor it automatically:

if (!navigator.globalPrivacyControl) {
  // GPC not set — user has not opted out via browser signal
  loadFacebookPixel();
  loadGoogleAdsTag();
}
// If navigator.globalPrivacyControl === true, skip advertising pixels

The remaining states with privacy laws (Virginia, Utah, Texas, Montana, Iowa, Delaware, New Hampshire, New Jersey, North Carolina) do not currently require GPC recognition. Implementing GPC support universally is best practice regardless.

US state privacy law table

All 13 US state privacy laws with comprehensive coverage as of September 2026. All use opt-out models — none require prior consent for cookies.

State / Law Effective Applicability threshold Opt-out GPC
CA — CPRA Jan 2023 $25M revenue or 100k consumers or 50% rev from selling Yes Yes
VA — VCDPA Jan 2023 100k+ VA consumers or 25k+ from data sales Yes No
CO — CPA Jul 2023 100k+ CO consumers or 25k+ from data sales Yes Yes
CT — CTDPA Jul 2023 100k+ CT consumers or 25k+ from data sales Yes Yes
UT — UCPA Dec 2023 100k+ UT consumers or $25k rev from 25k+ Yes No
TX — TDPSA Jul 2024 100k+ TX consumers (small biz exempt) Yes No
OR — OCPA Jul 2024 100k+ OR consumers or 25k+ from data sales Yes Yes
MT — MTCPA Oct 2024 50k+ MT consumers or 25k+ from data sales Yes No
IA — ICDPA Jan 2025 100k+ IA consumers or 25k+ from data sales Yes No
DE — DPDPA Jan 2025 35k+ DE consumers or 10k+ from data sales Yes No
NH — NHPA Jan 2025 35k+ NH consumers or 10k+ from data sales Yes No
NJ — NJDPA Jan 2025 100k+ NJ consumers or 25k+ from data sales Yes No
NC — NCDPA Oct 2025 100k+ NC consumers or 25k+ from data sales Yes No

Practical scenarios: what your site actually needs

1
No action required

Analytics-only site (no advertising)

Your site uses Google Analytics 4 without advertising features, or Plausible/Fathom. No advertising pixels. US-only audience. Result: No opt-out link needed. Disclose cookie use in your privacy policy. No consent banner required.

2
Opt-out required

E-commerce with Facebook Pixel + Google Ads, CPRA-scale traffic

$30M revenue, runs Facebook Pixel and Google Ads remarketing. California visitors included. Result: Add “Do Not Sell or Share My Personal Information” footer link. Implement GPC signal detection. Block advertising pixels for opted-out users.

3
No action required

SaaS with under 100k users

B2B SaaS, 15,000 users, Stripe + Postmark + Mixpanel (analytics-only). No advertising pixels. Result: Below all US state thresholds. No opt-out link required. Privacy policy disclosure of data collected is sufficient.

4
Best practice to add

Content site monetizing with Google AdSense

Blog or content site with AdSense behavioral ads. Primarily US audience. May or may not meet CPRA thresholds. Result: If under thresholds, no strict legal requirement — but Google’s own AdSense policies increasingly require user consent disclosures. Adding an opt-out link is best practice and may be required by AdSense terms.

Common misconceptions about US cookie law

  • “I need a cookie banner because I read about GDPR” — GDPR only applies if you have EU or UK visitors. A US-only site with US-only traffic has no GDPR obligations. If you do have EU visitors, a consent banner is required for EU traffic — but not for US traffic specifically.
  • “Google Analytics requires consent in the US” — Standard GA4 (no advertising features, no Google Signals) does not trigger any US opt-out requirement. You collect data, but you’re not sharing it for cross-context behavioral advertising. Disclose it in your privacy policy; no opt-out link required.
  • “CPRA applies to every US business” — CPRA applies to for-profit businesses meeting one of three thresholds ($25M revenue, 100k consumers, or 50% revenue from data sales). Most indie apps and small businesses fall below all thresholds. No US privacy law applies to every website regardless of size.
  • “An opt-out link means I need a consent management platform” — A CMP is one way to implement opt-out, but it’s not required. A simple footer link pointing to an opt-out page, combined with a cookie to remember the preference, satisfies the requirement for many sites.
  • “Once I add the opt-out link, I’m fully compliant” — The link must actually work. An opt-out that records a preference but still loads advertising pixels for opted-out users is non-compliant. Opt-outs must be honored within 15 business days under CPRA, and advertising pixels must not fire for opted-out users.

What to actually add to your US-facing site

If you run no advertising pixels: No opt-out link required. Ensure your privacy policy discloses the cookies you use and what data they collect. That’s the complete US compliance requirement.

If you run advertising pixels and meet a state threshold:

  1. Add a “Do Not Sell or Share My Personal Information” link to your site footer on every page
  2. That link should lead to an opt-out mechanism — a page with a button, or a consent management tool
  3. Implement GPC signal detection in your page JavaScript to automatically honor browser-level opt-outs
  4. When a user opts out, block advertising pixels from loading for that visitor’s current and future sessions
  5. Update your privacy policy to describe the opt-out right and how to exercise it

If you have both US and EU visitors: You need both mechanisms — an opt-out footer link for US visitors, and a prior-consent banner for EU/UK visitors. Most consent management platforms handle both by geo-detecting visitor location and showing the appropriate experience. ComplyKit generates a cookie banner that satisfies the EU consent standard; add the US opt-out footer link separately.

Already generated a policy? If your ComplyKit policy was generated with California (CCPA) selected, it already includes the “Do Not Sell or Share” disclosure. Verify it accurately reflects whether you run advertising pixels — and add the footer opt-out link if you do. See cookie consent banner requirements for the EU consent standard.

Frequently asked questions

Do US websites need a cookie consent banner?

No. There is no US federal or state law that requires a prior-consent cookie banner like GDPR or the EU ePrivacy Directive. US state privacy laws use an opt-out model: you may run cookies and collect data by default, and users have the right to opt out of having their data shared for advertising. The opt-out mechanism is a footer link — not a banner that blocks page access until the user responds. If your site has no EU visitors and uses no advertising pixels, you need no cookie mechanism beyond a privacy policy disclosure.

What triggers the CCPA/CPRA cookie opt-out requirement?

“Sharing” personal data for cross-context behavioral advertising. In practice: Facebook Pixel, Google Ads remarketing tags, TikTok Pixel, LinkedIn Insight Tag, Google AdSense, and similar ad-network scripts that pass visitor identifiers to advertising platforms. Standard analytics (GA4 in analytics-only mode, Plausible, Fathom, Hotjar) without advertising features does not trigger the opt-out requirement. The test is whether a third party receives visitor identifiers from your site to serve those visitors targeted ads elsewhere.

Which states require honoring the Global Privacy Control (GPC) signal?

As of 2026: California (CPRA), Colorado (CPA), Connecticut (CTDPA), and Oregon (OCPA). If a visitor’s browser sends navigator.globalPrivacyControl === true, you must treat it as an opt-out and skip advertising pixels — without requiring them to click any link. Texas, Virginia, Utah, Montana, Iowa, Delaware, New Hampshire, New Jersey, and North Carolina do not currently require GPC recognition, though implementing it universally is best practice.

Does Google Analytics require cookie consent in the US?

Not in most cases. GA4 in standard analytics mode doesn’t trigger any US state opt-out requirement — you’re measuring your own traffic, not sharing data for cross-context advertising. Disclose analytics cookies in your privacy policy. The trigger for US opt-out obligations is enabling Google Signals, Audience features, or linking GA4 to a Google Ads remarketing audience — that constitutes “sharing” under CPRA for California visitors above the threshold.

What is the “Do Not Sell or Share My Personal Information” link?

A footer link required by US state privacy laws when you share personal data for advertising. Clicking it provides the visitor a way to opt out of data sharing for advertising — typically by setting a preference that blocks advertising pixels from loading for that visitor’s browser going forward. Unlike a GDPR banner, it doesn’t need to appear before the page loads. A simple text link in every page’s footer pointing to an opt-out page or mechanism is sufficient.

If I have both US and EU visitors, which cookie rules apply?

Both simultaneously. EU/UK visitors require prior consent before non-essential cookies fire (GDPR + ePrivacy). US visitors require an opt-out mechanism if you share data for advertising. The practical solution is a consent management platform that geo-detects visitor location: consent banner for EU/UK users, opt-out footer link for US users. ComplyKit generates the EU-standard cookie banner. Add the “Do Not Sell or Share” footer link separately for US compliance when you run advertising pixels.

Does CPRA apply to my small website?

CPRA applies to for-profit businesses meeting at least one threshold: $25M+ annual revenue, personal data on 100k+ California consumers/households, or 50%+ revenue from selling or sharing data. Most indie apps don’t qualify. Other states have lower thresholds — Delaware’s DPDPA covers 35k+ residents, Montana’s MTCPA covers 50k+ consumers — but all have thresholds. If you’re below all of them and have no EU visitors, analytics-only tools with no advertising pixels require no cookie banner or opt-out link beyond a privacy policy disclosure.

Also in the Copper Bay Labs ship-safety suite

Cookie compliance is one part of launching safely. These free tools cover the other gaps — security headers, exposed secrets, and accessibility: