Back to Blog
Compliance GuidesMarch 29, 202612 min readReviewed by the PrivacyLawMap editorial teamLast reviewed August 5, 2026

Cookie Consent Requirements Under US State Privacy Laws: What You Actually Need in 2026

Share:
Turn This Guide Into a Working Privacy SetupSponsored

Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.

Start Free with Termly

Do US State Privacy Laws Require Cookie Consent?

No US state privacy law requires a cookie consent banner. As of August 5, 2026, none of the 20 comprehensive state privacy laws in force mandates prior opt-in consent before non-essential cookies load — but 12 of them require you to detect and honor a universal opt-out signal such as Global Privacy Control automatically, with no banner and no user confirmation. That is the single distinction that decides what you actually have to build.

If you’ve spent time researching cookie consent compliance, you’ve probably encountered advice designed for GDPR — the European Union’s privacy regulation that requires explicit opt-in consent before placing any non-essential cookies on a user’s device. That approach has created a global expectation that every website needs a cookie consent banner.

US state privacy laws take a fundamentally different approach. Instead of asking permission first, they require you to give consumers the right to opt out of certain data practices — the sale of personal information, sharing for targeted advertising, and profiling. Cookies are relevant only insofar as they enable those activities. The obligation that trips businesses up is not the banner they built; it is the browser signal they never wired up.

This distinction matters because blindly applying a GDPR-style cookie consent framework to your US website can create a worse user experience without actually achieving compliance with the laws that apply to you. This guide explains what US state privacy laws actually require when it comes to cookies, consent, and tracking technologies.

How US Cookie Requirements Differ from GDPR

The fundamental difference between GDPR and US state privacy laws on cookies comes down to consent model:

Requirement GDPR (EU/EEA) CCPA/CPRA (California) Other US State Laws
Consent modelOpt-in (prior consent required)Opt-out (no prior consent, but must honor opt-out)Opt-out (similar to California)
Cookie banner required?Yes — must get consent before non-essential cookiesNo — but must provide opt-out mechanismNo — but must provide opt-out mechanism
Tracking cookies restricted?Yes — blocked until consent givenOnly if they enable "sale" or "sharing" of PIOnly if they enable sale/targeted advertising
GPC/universal opt-outNot specifically requiredRequired — must honor GPC signalRequired in CO, CT, MT, TX, DE, OR; varies elsewhere
Sensitive data via cookiesExplicit consent requiredOpt-out of sale; opt-in for some usesGenerally requires opt-in consent
Analytics cookiesConsent required (unless strictly necessary)Generally permitted (first-party analytics)Generally permitted (first-party analytics)
EnforcementData Protection AuthoritiesCA AG + CPPAState Attorneys General

The practical takeaway: if your business only operates in the United States and does not target EU consumers, you likely do not need a GDPR-style opt-in cookie banner. But you absolutely need robust opt-out mechanisms. See our state comparison tool for a detailed breakdown of each state’s requirements.

CCPA/CPRA Cookie Consent Requirements

California’s CCPA (as amended by the CPRA) does not explicitly regulate cookies as a technology. Instead, it regulates the activities that cookies often enable:

  • Sale of personal information — If third-party cookies on your site transmit personal information to an advertising network or data broker in exchange for monetary or other valuable consideration, that constitutes a "sale" under the CCPA.
  • Sharing for cross-context behavioral advertising — If cookies enable sharing personal information with third parties for targeted advertising (even without direct payment), that’s "sharing" under the CPRA.
  • Targeted advertising — Using cookies to build profiles for behavioral advertising falls under consumers’ right to opt out.

What California Actually Requires

Instead of a cookie consent banner, California requires:

  1. "Do Not Sell or Share My Personal Information" link — A clear, conspicuous link on your homepage (and in your privacy policy) that allows consumers to opt out of the sale and sharing of their personal information. See our guide on "Do Not Sell" link compliance.
  2. Honor Global Privacy Control (GPC) — You must treat GPC browser signals as a valid opt-out request. When a user’s browser sends a GPC signal, you must stop selling or sharing their personal information via cookies and other tracking technologies. Use our GPC Compliance Checker to determine your obligations.
  3. Disclose tracking in your privacy policy — Your privacy policy must describe the categories of personal information collected, the purposes, and whether you sell or share it. This includes data collected via cookies.
  4. Process opt-out requests within 15 business days — When a consumer opts out, you must stop selling/sharing their data within 15 business days and ensure third-party cookies that enable these activities are suppressed.

The Disney CCPA settlement ($2.75 million in February 2026) demonstrates why this matters: Disney offered multiple opt-out mechanisms, but they didn’t work consistently across all services and devices. Partial compliance is not compliance. See our analysis of the Disney settlement.

State-by-State Cookie Consent Comparison

This table covers every one of the 20 comprehensive state privacy laws currently in force — not just the large states. States that require you to honor a universal opt-out signal are listed first, in the order their mandates took effect, because that date is your real deadline. Each row is generated from the same statutory dataset behind our state law pages and GPC checker, so it cannot drift out of step with them.

State (law) Cookie banner required? Must honor universal opt-out signal (GPC)? Sensitive-data cookies need opt-in?
California (CCPA/CPRA)NoYes — since March 29, 2024Yes — opt-in consent
Colorado (CPA)NoYes — since July 1, 2024Yes — opt-in consent
Connecticut (CTDPA)NoYes — since January 1, 2025Yes — opt-in consent
Montana (MCDPA)NoYes — since January 1, 2025Yes — opt-in consent
New Hampshire (NHPA)NoYes — since January 1, 2025Yes — opt-in consent
Texas (TDPSA)NoYes — since January 1, 2025Yes — opt-in consent
New Jersey (NJDPA)NoYes — since January 15, 2025Yes — opt-in consent
Minnesota (MCDPA)NoYes — since July 31, 2025Yes — opt-in consent
Maryland (MODPA)NoYes — since October 1, 2025Yes — opt-in consent
Delaware (DPDPA)NoYes — since January 1, 2026Yes — opt-in consent
Nebraska (NDPA)NoYes — since January 1, 2026Yes — opt-in consent
Oregon (OCPA)NoYes — since January 1, 2026Yes — opt-in consent
Florida (FDBR)NoNo universal opt-out mandateYes — opt-in consent
Indiana (INCDPA)NoNo universal opt-out mandateYes — opt-in consent
Iowa (ICDPA)NoNo universal opt-out mandateNo — opt-out only
Kentucky (KCDPA)NoNo universal opt-out mandateYes — opt-in consent
Rhode Island (RIDTPPA)NoNo universal opt-out mandateYes — opt-in consent
Tennessee (TIPA)NoNo universal opt-out mandateYes — opt-in consent
Utah (UCPA)NoNo universal opt-out mandateYes — opt-in consent
Virginia (VCDPA)NoNo universal opt-out mandateYes — opt-in consent

Notice the pattern: the “cookie banner required?” column is “No” in every single row. The requirement is always about providing opt-out mechanisms for data sale, sharing, and targeted advertising. The cookie itself is not regulated — the data practice it enables is. Where states genuinely diverge is the middle column: 12 of the 20 in-force laws now oblige you to detect a browser-level opt-out signal, and 8 do not.

Source check: universal opt-out and sensitive-data columns verified August 5, 2026 against the statutory text tracked per state on this site. Minnesota’s mandate was re-verified directly against Minn. Stat. § 325M.14, subd. 3 (“Universal opt-out mechanisms”), which requires controllers to let consumers opt out of targeted advertising and sale “through an opt-out preference signal” (date_retrieved: 2026-08-05). Maryland’s primary statute host (mgaleg.maryland.gov) was unreachable from our network on that date, so the MODPA row reflects our tracked reading of Md. Code Ann., Com. Law § 14-4607 rather than a same-day retrieval of the official text.

When DO You Need Cookie Consent Under US Law?

While US state privacy laws generally follow an opt-out model, there are specific situations where prior consent (opt-in) IS required:

1. Sensitive Data Processing

If cookies collect or process sensitive personal information — such as precise geolocation, health data, biometric data, or data revealing racial or ethnic origin — most state laws require opt-in consent before processing. This means if your website uses cookies that collect sensitive categories, you may need consent before those specific cookies activate. See our guide on sensitive data under state privacy laws.

2. Children’s Data (COPPA)

The federal Children’s Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal information from children under 13, including through cookies and tracking technologies. This applies regardless of state law. See our COPPA compliance guide.

3. Known Minors (Ages 13-15 in California)

Under the CCPA, businesses that have actual knowledge that a consumer is between 13 and 16 years old must obtain opt-in consent before selling or sharing their personal information. Cookies that enable sale/sharing of a known minor’s data require prior consent.

4. Maryland’s Stricter Approach

Maryland’s MODPA (effective with enforcement starting April 1, 2026) goes further than other states by prohibiting the sale of sensitive data entirely and imposing stricter data minimization requirements. If your cookies collect data beyond what is "reasonably necessary" for the service the consumer requested, Maryland’s law may require you to stop that collection. See our Maryland MODPA enforcement guide.

Global Privacy Control: The US Alternative to Cookie Banners

Instead of cookie consent banners, the US privacy landscape has converged on Global Privacy Control (GPC) as the primary mechanism for consumers to exercise their opt-out rights. GPC is a browser-level signal (sent as an HTTP header: Sec-GPC: 1) that communicates a user’s preference to opt out of data sale and sharing.

Which States Require Honoring GPC?

As of August 5, 2026, 12 states require businesses to honor universal opt-out mechanisms like GPC:

  • California (CCPA/CPRA) — required since March 29, 2024
  • Colorado (CPA) — required since July 1, 2024
  • Connecticut (CTDPA) — required since January 1, 2025
  • Montana (MCDPA) — required since January 1, 2025
  • New Hampshire (NHPA) — required since January 1, 2025
  • Texas (TDPSA) — required since January 1, 2025
  • New Jersey (NJDPA) — required since January 15, 2025
  • Minnesota (MCDPA) — required since July 31, 2025
  • Maryland (MODPA) — required since October 1, 2025
  • Delaware (DPDPA) — required since January 1, 2026
  • Nebraska (NDPA) — required since January 1, 2026
  • Oregon (OCPA) — required since January 1, 2026

The dates matter more than the count. If you built your opt-out handling around the first wave (California and Colorado) and have not revisited it since, you are missing the 10 mandates that took effect from 2025 onward. For a complete breakdown, see our Universal Opt-Out Mechanism Compliance Guide.

How GPC Affects Cookies

When your website detects a GPC signal, you must suppress any cookies that enable data sale or sharing. In practice, this means:

  • Third-party advertising cookies should not load or should be restricted
  • Cross-site tracking pixels should be suppressed
  • Data shared with advertising partners via cookies should stop
  • First-party analytics cookies are generally still permitted (they don’t typically constitute "sale" or "sharing")

Use our GPC Compliance Checker to determine whether your business needs to honor GPC based on the states where you operate.

5 Common Cookie Consent Mistakes Under US Privacy Laws

1. Copying a GDPR Cookie Banner for US Users

Many businesses deploy the same cookie consent banner they use for EU visitors to US visitors. While this isn’t illegal, it creates unnecessary friction without achieving compliance. US users are not required to consent before cookies load — they need the ability to opt out. A GDPR-style "Accept/Reject" banner is not a substitute for a proper "Do Not Sell or Share" mechanism and GPC detection.

2. Ignoring Global Privacy Control

GPC is not optional in states that require it. The $2.75 million Disney settlement and the multi-state GPC enforcement sweep in 2024-2025 demonstrate that regulators actively check for GPC compliance. If you honor "Do Not Sell" clicks but ignore GPC browser signals, you are not fully compliant.

3. Assuming "Cookie Banner = Compliant"

A cookie consent management platform (CMP) alone does not make you compliant with US state privacy laws. The CMP handles cookie loading, but US laws require broader opt-out mechanisms that extend beyond cookies — including opt-out of data sale through any mechanism, not just cookie-based tracking.

4. Not Applying Opt-Outs Across All Services

If a consumer opts out on one part of your platform, that opt-out must apply to all of your services connected to their account. The Disney settlement specifically targeted the practice of siloing opt-out requests to individual apps or devices rather than applying them account-wide.

5. Failing to Disclose Cookie Practices in Your Privacy Policy

Every state privacy law requires you to disclose what personal information you collect and how you use it. This includes data collected via cookies. Many businesses have detailed cookie policies for GDPR but fail to adequately describe cookie-based data collection in the privacy policy section that addresses state law requirements. See our privacy policy requirements guide.

Cookie Consent Compliance Checklist for US Businesses

Use this checklist to ensure your cookie practices comply with US state privacy laws:

  1. Audit your cookies — Identify all first-party and third-party cookies on your site. Classify which ones enable data sale, sharing, or targeted advertising.
  2. Implement GPC detection — Add JavaScript to detect the navigator.globalPrivacyControl signal and suppress sale/sharing cookies when detected.
  3. Add a "Do Not Sell or Share" link — Place a clear, conspicuous link on your homepage footer that allows consumers to opt out (required in California and recommended everywhere).
  4. Apply opt-outs universally — When a consumer opts out (via GPC, toggle, or form), ensure the opt-out applies across all services, devices, and third-party data-sharing arrangements linked to their account.
  5. Update your privacy policy — Disclose the categories of personal information collected via cookies, the purposes of collection, and any third parties with whom data is shared.
  6. Handle sensitive data cookies separately — If any cookies collect sensitive personal information, implement opt-in consent for those specific cookies.
  7. Document your compliance — Maintain records of your cookie audit, opt-out mechanism implementation, and GPC testing results.
  8. Test regularly — Verify that opt-out mechanisms and GPC detection work correctly across browsers, devices, and all parts of your website. Use our Privacy Law Calculator to confirm which state laws apply to your business.

Frequently Asked Questions

Is cookie consent required in the USA?

No — not in the GDPR sense. There is no US federal cookie law, and none of the 20 comprehensive state privacy laws in force as of August 5, 2026 requires you to obtain consent before non-essential cookies load. What US law requires instead is that you let consumers opt out after the fact: a “Do Not Sell or Share My Personal Information” mechanism, and — in 12 states — automatic recognition of a universal opt-out signal like Global Privacy Control. Two narrow exceptions do require prior opt-in consent: processing sensitive personal data, and processing the data of known minors.

Which US states require website cookie opt-outs?

Every state with a comprehensive privacy law in force requires an opt-out of sale and targeted advertising, which is what governs advertising cookies. The stricter obligation — honoring a browser-level universal opt-out signal automatically, without a banner or any user confirmation — applies in 12 states: California (since March 29, 2024), Colorado (since July 1, 2024), Connecticut (since January 1, 2025), Montana (since January 1, 2025), New Hampshire (since January 1, 2025), Texas (since January 1, 2025), New Jersey (since January 15, 2025), Minnesota (since July 31, 2025), Maryland (since October 1, 2025), Delaware (since January 1, 2026), Nebraska (since January 1, 2026), and Oregon (since January 1, 2026). The remaining in-force laws (Florida, Indiana, Iowa, Kentucky, Rhode Island, Tennessee, Utah, Virginia) require an opt-out mechanism but do not mandate recognition of a universal signal.

Does Minnesota require companies to show a cookie consent banner?

No. Minnesota’s Consumer Data Privacy Act, in force since July 31, 2025, contains no banner requirement. It does contain something many businesses miss: Minn. Stat. § 325M.14, subd. 3 obliges controllers to let a consumer opt out of targeted advertising and the sale of personal data “through an opt-out preference signal” — and it explicitly bars such a mechanism from using a default setting, so the signal must reflect an affirmative choice by the consumer. In practice that means detecting GPC server-side and suppressing advertising cookies for Minnesota visitors who send it, rather than showing them a consent dialog. (Statute text retrieved 2026-08-05.)

Do I need a cookie consent banner for CCPA compliance?

No. The CCPA does not require a cookie consent banner. Instead, you need a "Do Not Sell or Share My Personal Information" link that allows consumers to opt out, and you must honor Global Privacy Control (GPC) browser signals. The focus is on providing opt-out mechanisms, not obtaining prior consent for cookies. However, if you also serve EU customers, you may still need a GDPR-compliant cookie banner for those users.

Does the CCPA require opt-in consent for cookies?

Generally, no. The CCPA follows an opt-out model, not an opt-in model. However, there are exceptions: opt-in consent is required before selling or sharing the personal information of consumers you know to be under 16, and stricter rules apply to sensitive personal information. For most business-to-adult-consumer interactions, the CCPA only requires that you provide the ability to opt out.

What is Global Privacy Control and do I have to honor it?

Global Privacy Control (GPC) is a browser-level signal that communicates a consumer’s intent to opt out of data sale and sharing. It is sent as an HTTP header (Sec-GPC: 1) with every web request. As of August 5, 2026, 12 states require businesses to honor it: California (since March 29, 2024), Colorado (since July 1, 2024), Connecticut (since January 1, 2025), Montana (since January 1, 2025), New Hampshire (since January 1, 2025), Texas (since January 1, 2025), New Jersey (since January 15, 2025), Minnesota (since July 31, 2025), Maryland (since October 1, 2025), Delaware (since January 1, 2026), Nebraska (since January 1, 2026), and Oregon (since January 1, 2026). Failing to do so can result in significant fines — as demonstrated by California’s $2.75 million settlement with Disney.

Are tracking cookies considered personal information under state privacy laws?

Yes, in most cases. State privacy laws define personal information broadly to include online identifiers, device identifiers, IP addresses, and browsing activity — all of which are commonly collected via cookies. If a cookie can be linked to an identified or identifiable individual (directly or indirectly), the data it collects is personal information under these laws.

How does CPRA differ from CCPA on cookie consent?

The CPRA (which amended the CCPA in 2023) added several requirements relevant to cookies: it introduced the concept of "sharing" personal information for cross-context behavioral advertising (separate from "sale"), required businesses to honor opt-out preference signals like GPC, created the CPPA as a dedicated enforcement agency, and added new requirements around sensitive personal information. For cookie practices, the most significant change is the mandatory GPC compliance and the expanded definition of "sharing" that covers many advertising cookie use cases that were ambiguous under the original CCPA. See our CCPA compliance checklist for the full list of requirements.

This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 29, 2026. Last verified: August 5, 2026 against Minn. Stat. § 325M.14 and the per-state universal opt-out and sensitive-data records tracked on this site (date_retrieved: 2026-08-05).

Put This Guide Into PracticeSponsored

Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.

Start Free with Termly