Skip to content
TagSentry
Blog

Answer · Rules and enforcement

Do US websites need a cookie banner?

Opt-in versus opt-out, what California and the privacy-signal states expect, what demand letters usually claim, and what a sensible US setup looks like.

The TagSentry team · September 18, 2026 · updated October 2, 2026 · 3 min read

The question, as people ask it

“My business is in the US and so are most of my customers. Do I actually need a cookie banner, and should US visitors default to tracking on?”

Asked in reddit.com, reddit.com

The short answer

Most US states don't require an EU-style "ask first" banner. They require that visitors can opt out of having their data sold or shared for advertising, and a growing number require you to honour the browser's privacy signal (GPC) automatically. In practice that means a visible "Your privacy choices" link, tracking that stops when someone opts out, and a record of it.

Opt-in versus opt-out

There are two families of rules.

  • Opt-in (the EU, UK, Brazil and others): you ask before setting non-essential cookies or running trackers, and nothing runs until the visitor says yes.
  • Opt-out (California and most US state laws): you may run trackers by default, but visitors must be able to say stop, and you must actually stop.

So the short answer for a US business with US visitors is: you probably don't need a wall that blocks the page, but you do need a working way to opt out. If you also get visitors from the EU or UK, they need the ask-first version.

What California expects

California's privacy law gives people the right to opt out of the "sale" or "sharing" of their personal information. Regulators treat many advertising pixels, like the Meta Pixel, as sharing. That means:

  • A clear link, usually labelled "Your Privacy Choices" or "Do Not Sell or Share My Personal Information".
  • Opt-outs that actually stop the relevant tags.
  • Honouring the Global Privacy Control signal a browser sends, as an opt-out.

That last point was the heart of California's first enforcement action. In 2022 Sephora paid $1.2 million, partly for ignoring GPC. In February 2026 Disney paid $2.75 million, a record, for not fully honouring opt-outs and preference signals.

Enforcement has also reached the tools themselves. In 2025 California's privacy agency fined Todd Snyder $345,178, partly because its opt-out tool was misconfigured for 40 days and the company hadn't been checking it.

The privacy-signal states

Global Privacy Control is a setting in some browsers and extensions that tells every site "don't sell or share my data". About a dozen states now require businesses to treat it as a valid opt-out, including California, Colorado, Connecticut, Texas, Oregon, New Jersey and others. The list keeps growing, so check the current statutes before relying on any list, including ours.

TagSentry currently honours GPC before anything fires for visitors in California and 11 other states: Colorado, Connecticut, Texas, Montana, New Hampshire, New Jersey, Minnesota, Oregon, Delaware, Nebraska and Maryland.

From January 2027, a new California law requires browsers to offer an opt-out signal, so expect many more visitors to arrive with it switched on.

What the demand letters usually claim

A separate wave of risk comes from lawsuits and demand letters under California's Invasion of Privacy Act, a law originally written for wiretaps. Plaintiffs argue that pixels and session recorders that send data to third parties before any consent amount to eavesdropping. Letters typically attach screenshots of trackers firing on page load.

A bill passed in August 2026, SB 690, narrows one type of these claims (the "pen register" theory), but it leaves the wiretap claims in place and was awaiting the Governor's signature at the time of writing. The practical takeaway many firms give: know exactly what your site sends before anyone agrees.

A sensible US setup

VisitorWhat they should get
California and GPC states, no signalTracking runs, with a visible privacy choices link that works
California and GPC states, GPC onTreated as opted out before anything runs
Other US statesTracking runs, with a way to opt out
EU, EEA, UKA banner that asks first, with Reject and Accept equally easy

And in every case, a record of what each visitor chose, kept long enough to show someone who asks.

Should US visitors default to tracking on?

For opt-out states, most practitioners set Google Consent Mode to granted by default for US visitors and switch it to denied when someone opts out. The caveat is the demand-letter risk above: some businesses choose stricter defaults in California regardless, especially for advertising pixels.

How TagSentry handles it

TagSentry applies opt-out rules to US visitors with a small privacy choices link instead of a wall, treats GPC as an opt-out before anything runs in California and the 11 GPC states, and shows EU and UK visitors a banner that asks first. Every answer is kept as a record for 24 months.

Sources

  1. California AG: Sephora settlement over Global Privacy Control
  2. CPPA: Todd Snyder enforcement announcement
  3. Hunton: California AG record settlement with Disney over opt-out rights
  4. CookieScript: Universal opt-out mechanisms by US state
  5. Sidley: California's SB 690 clears the Legislature
  6. Shumaker: The CIPA demand letters flooding businesses