The short answer
Most US states don't require an EU-style "ask first" banner. They require that visitors can opt out of having their data sold or shared for advertising, and a growing number require you to honour the browser's privacy signal (GPC) automatically. In practice that means a visible "Your privacy choices" link, tracking that stops when someone opts out, and a record of it.
Opt-in versus opt-out
There are two families of rules.
- Opt-in (the EU, UK, Brazil and others): you ask before setting non-essential cookies or running trackers, and nothing runs until the visitor says yes.
- Opt-out (California and most US state laws): you may run trackers by default, but visitors must be able to say stop, and you must actually stop.
So the short answer for a US business with US visitors is: you probably don't need a wall that blocks the page, but you do need a working way to opt out. If you also get visitors from the EU or UK, they need the ask-first version.
What California expects
California's privacy law gives people the right to opt out of the "sale" or "sharing" of their personal information. Regulators treat many advertising pixels, like the Meta Pixel, as sharing. That means:
- A clear link, usually labelled "Your Privacy Choices" or "Do Not Sell or Share My Personal Information".
- Opt-outs that actually stop the relevant tags.
- Honouring the Global Privacy Control signal a browser sends, as an opt-out.
That last point was the heart of California's first enforcement action. In 2022 Sephora paid $1.2 million, partly for ignoring GPC. In February 2026 Disney paid $2.75 million, a record, for not fully honouring opt-outs and preference signals.
Enforcement has also reached the tools themselves. In 2025 California's privacy agency fined Todd Snyder $345,178, partly because its opt-out tool was misconfigured for 40 days and the company hadn't been checking it.
The privacy-signal states
Global Privacy Control is a setting in some browsers and extensions that tells every site "don't sell or share my data". About a dozen states now require businesses to treat it as a valid opt-out, including California, Colorado, Connecticut, Texas, Oregon, New Jersey and others. The list keeps growing, so check the current statutes before relying on any list, including ours.
TagSentry currently honours GPC before anything fires for visitors in California and 11 other states: Colorado, Connecticut, Texas, Montana, New Hampshire, New Jersey, Minnesota, Oregon, Delaware, Nebraska and Maryland.
From January 2027, a new California law requires browsers to offer an opt-out signal, so expect many more visitors to arrive with it switched on.
What the demand letters usually claim
A separate wave of risk comes from lawsuits and demand letters under California's Invasion of Privacy Act, a law originally written for wiretaps. Plaintiffs argue that pixels and session recorders that send data to third parties before any consent amount to eavesdropping. Letters typically attach screenshots of trackers firing on page load.
A bill passed in August 2026, SB 690, narrows one type of these claims (the "pen register" theory), but it leaves the wiretap claims in place and was awaiting the Governor's signature at the time of writing. The practical takeaway many firms give: know exactly what your site sends before anyone agrees.
A sensible US setup
| Visitor | What they should get |
|---|---|
| California and GPC states, no signal | Tracking runs, with a visible privacy choices link that works |
| California and GPC states, GPC on | Treated as opted out before anything runs |
| Other US states | Tracking runs, with a way to opt out |
| EU, EEA, UK | A banner that asks first, with Reject and Accept equally easy |
And in every case, a record of what each visitor chose, kept long enough to show someone who asks.
Should US visitors default to tracking on?
For opt-out states, most practitioners set Google Consent Mode to granted by default for US visitors and switch it to denied when someone opts out. The caveat is the demand-letter risk above: some businesses choose stricter defaults in California regardless, especially for advertising pixels.
How TagSentry handles it
TagSentry applies opt-out rules to US visitors with a small privacy choices link instead of a wall, treats GPC as an opt-out before anything runs in California and the 11 GPC states, and shows EU and UK visitors a banner that asks first. Every answer is kept as a record for 24 months.
Sources
- California AG: Sephora settlement over Global Privacy Control
- CPPA: Todd Snyder enforcement announcement
- Hunton: California AG record settlement with Disney over opt-out rights
- CookieScript: Universal opt-out mechanisms by US state
- Sidley: California's SB 690 clears the Legislature
- Shumaker: The CIPA demand letters flooding businesses