Cookie Consent Requirements Explained
The United States has no single federal cookie law. Instead, a growing list of state privacy laws, starting with California's, require businesses that meet certain size thresholds to let website visitors opt out of having their data sold or shared through cookies, post a clear opt-out link, and honor automated opt-out preference signals such as Global Privacy Control. Whether your site needs a cookie banner depends on which states' thresholds your business meets, not a single nationwide rule.
By LLC Register · Last reviewed October 1, 2026
Comprehensive Guide
Why This Isn't a Single Rule
Unlike some other countries, the United States doesn't have one federal law requiring a cookie consent banner. What exists instead is a growing number of state consumer privacy laws, starting with the California Consumer Privacy Act (CCPA) and its amendment the California Privacy Rights Act (CPRA), that regulate how businesses use cookies and similar tracking technology to collect, sell or share personal information. Each state law has its own applicability thresholds, so the honest answer to "do I need a cookie banner" depends on which states' residents visit your site and whether your business meets that state's size or data-volume thresholds.
What California's Law Requires
The CCPA applies to a for-profit business that does business in California and meets at least one of these thresholds, per the California Privacy Protection Agency: more than $26.625 million in annual gross revenue, effective January 1, 2025; buying, selling or sharing the personal information of 100,000 or more California residents or households; or deriving 50% or more of annual revenue from selling or sharing personal information. A covered business must post a clear and conspicuous link, labeled "Do Not Sell or Share My Personal Information," "Your Privacy Choices," or "Your California Privacy Choices," and must process an opt-out request within 15 business days.
Opt-Out Preference Signals
Several state laws go further than requiring a link: they require a business to treat an automated browser-level signal, most commonly Global Privacy Control, the same as if the visitor had clicked the opt-out link directly, with no further action from the visitor. California, Colorado and Connecticut are among the states that require honoring this kind of signal. This matters for how your cookie or consent management tool is configured, since a tool that only responds to an on-page click will miss these automated requests.
Other State Laws Differ in What They Require
Virginia's Consumer Data Protection Act gives consumers the right to opt out of targeted advertising and the sale of personal data and requires consent before processing sensitive data, but it doesn't specifically require recognizing a universal opt-out signal the way California and Colorado do. Connecticut's Data Privacy Act requires a clear opt-out link and support for preference signals, and its attorney general's 2025 enforcement report noted that a banner offering "accept all" should give a "reject all" option similarly prominent placement. Because these requirements vary by state, check the specific law in any state where your business meets the applicability threshold rather than assuming one state's rule covers you everywhere.
What a Typical Compliance Approach Looks Like
Most businesses that are covered by one or more of these laws use a consent or preference management tool on their site that does three things: categorizes cookies by type (necessary, analytics, advertising), posts the required opt-out link or banner, and is configured to detect and honor an opt-out preference signal automatically. If your business doesn't meet any state's applicability threshold, these laws don't require you to do this at all, though posting a basic cookie disclosure in your privacy policy is still a reasonable practice.
Children's Data Is Handled Separately
If your site is directed at children under 13, or you have actual knowledge that you're collecting data from children under 13, the federal Children's Online Privacy Protection Act (COPPA), enforced by the FTC, applies regardless of your revenue or state, and requires verifiable parental consent before collecting personal information. This is a separate, stricter federal requirement layered on top of whatever state law applies to your general audience.
Practical Considerations
Check Your Own Numbers Against Each State's Threshold
Because thresholds are set in revenue or number of residents affected, a small business with a low-traffic site often isn't covered by any of these laws yet. Don't install a cookie banner reflexively; check whether you actually meet a specific state's threshold first.
Thresholds Change
Connecticut's applicability threshold dropped from 100,000 to 35,000 consumers effective July 1, 2026, and other states adjust their thresholds periodically. Recheck the current threshold in any state where you're close to the line, rather than relying on a number you read previously.
A Consent Tool Doesn't Replace a Privacy Policy
Cookie consent and your website's privacy policy are related but separate obligations. A visitor opting out of cookies through a banner doesn't substitute for disclosing, in your privacy policy, what data you collect and why.
This Is Not Legal Advice
Whether your specific business meets a given state's applicability threshold, and which signals or banner design satisfy that state's requirement, are legal questions that depend on your actual data practices and revenue. Talk to an attorney experienced in state privacy law before launching a site that collects data from residents of these states at scale.
Sources
The official sources used for this article.
California Privacy Protection Agency: CCPA FAQ | cppa.ca.gov/faq.html |
|---|---|
Colorado Attorney General: Colorado Privacy Act | coag.gov/resources/colorado-privacy-act |
Connecticut Attorney General: Connecticut Data Privacy Act | portal.ct.gov/ag/sections/privacy/the-connecticut-data-privacy-act |
Virginia Attorney General: Virginia Consumer Data Protection Act | oag.state.va.us/consumer-protection/index.php/programs/privacy/virginia-consumer-data-protection-act |
FTC: Children's Online Privacy Protection Rule (COPPA) | ftc.gov/business-guidance/privacy-security/childrens-privacy |
Created by: LLC RegisterLast reviewed October 1, 2026
Updated: October 1, 2026
Frequently Asked Questions
Do all businesses need a cookie consent banner?
No. Cookie and tracking rules in the U.S. come from state privacy laws that apply only to businesses meeting specific size or data-volume thresholds, such as California's $26.625 million revenue threshold. A business below every applicable state's threshold isn't required to post one.
What is Global Privacy Control and why does it matter?
It's a browser-level signal that tells a website a visitor wants to opt out of having their data sold or shared. States including California, Colorado and Connecticut require covered businesses to honor this signal automatically, without the visitor clicking anything on the site.
Is a cookie banner the same thing as a privacy policy?
No. A cookie banner or opt-out link addresses tracking technology and data sale or sharing choices specifically. Your privacy policy is a separate, broader disclosure of what personal information you collect and how you use it.
Does COPPA affect cookie consent for a children's website?
Yes. If your site is directed at children under 13, the Children's Online Privacy Protection Act requires verifiable parental consent before collecting personal information, regardless of your revenue or which state privacy law would otherwise apply.
Form your business with LLC Register
$99 a year for a registered agent, with LLC formation in year one and annual report filing included. State fees are passed through at cost.
