# Do US websites need a cookie banner?

Opt-in versus opt-out, what California and the privacy-signal states expect, what demand letters usually claim, and what a sensible US setup looks like.

_The TagSentry team · September 18, 2026 · https://tagsentry.ai/blog/do-i-need-a-cookie-banner-us_

> **The short answer:** Most US states don't require an EU-style "ask first" banner. They require that visitors can opt out of having their data sold or shared for advertising, and more of them now say you must honour the browser's privacy signal (GPC) automatically. In practice you need a visible "Your privacy choices" link, tracking that stops when someone opts out, and a record that they did.

> **Not legal advice** This is a plain-language summary of how the rules generally work, as of September 2026. Your situation depends on your business, your visitors and what your tags do. Talk to a lawyer before relying on it.

## Opt-in versus opt-out

The rules come in two kinds.

- **Opt-in** (the EU, UK, Brazil and others): you ask before setting non-essential cookies or running trackers, and nothing runs until the visitor says yes.
- **Opt-out** (California and most US state laws): you may run trackers by default, but visitors must be able to say stop, and you must actually stop.

For a US business with US visitors, then, you probably don't need a wall that blocks the page. You do need an opt-out that works. Visitors from the EU or UK still need the ask-first version.

## What California expects

California's privacy law gives people the right to opt out of the "sale" or "sharing" of their personal information, and regulators treat many advertising pixels, the Meta Pixel among them, as sharing. So you need:

- A clear link, usually labelled "Your Privacy Choices" or "Do Not Sell or Share My Personal Information".
- Opt-outs that actually stop the relevant tags.
- The Global Privacy Control signal a browser sends, honoured as an opt-out.

California's first enforcement action was largely about that last point. In 2022 Sephora paid $1.2 million, partly for ignoring GPC. In February 2026 Disney paid $2.75 million, a record, for not fully honouring opt-outs and preference signals.

Regulators have gone after broken tools too. In 2025 California's privacy agency fined Todd Snyder $345,178, partly because its opt-out tool was misconfigured for 40 days and the company hadn't been checking it.

## The privacy-signal states

[Global Privacy Control](/blog/global-privacy-control-explained) is a setting in some browsers and extensions that tells every site "don't sell or share my data". About a dozen states now require businesses to treat it as a valid opt-out, among them California, Colorado, Connecticut, Texas, Oregon and New Jersey.

States keep being added, so check the current statutes before you rely on any list, ours included.

TagSentry currently honours GPC before anything fires for visitors in California and 11 other states: Colorado, Connecticut, Texas, Montana, New Hampshire, New Jersey, Minnesota, Oregon, Delaware, Nebraska and Maryland.

From January 2027, a new California law requires browsers to offer an opt-out signal, so expect many more visitors to arrive with it switched on.

## What the demand letters usually claim

The other risk is lawsuits and [demand letters](/blog/got-a-cookie-demand-letter) under California's Invasion of Privacy Act, a law first written for wiretaps. Plaintiffs argue that pixels and session recorders sending data to third parties before any consent amount to eavesdropping. The letters usually attach screenshots of trackers firing on page load.

A bill passed in August 2026, SB 690, narrows one type of these claims (the "pen register" theory), but it leaves the wiretap claims in place and was awaiting the Governor's signature at the time of writing. The advice many firms give is to know exactly what your site sends before anyone agrees.

## A sensible US setup

| Visitor | What they should get |
|---|---|
| California and GPC states, no signal | Tracking runs, with a visible privacy choices link that works |
| California and GPC states, GPC on | Treated as opted out before anything runs |
| Other US states | Tracking runs, with a way to opt out |
| EU, EEA, UK | A banner that asks first, with Reject and Accept equally easy |

Whichever row a visitor falls in, keep a record of what they chose, for long enough that you can show it to someone who asks.

## Should US visitors default to tracking on?

In opt-out states, most people who set these up give US visitors Google Consent Mode `granted` by default and switch it to `denied` when someone opts out. The catch is the demand-letter risk above. Some businesses pick stricter defaults in California anyway, especially for advertising pixels.

## How TagSentry handles it

TagSentry [applies opt-out rules](/docs/how-consent-works) to US visitors, with a small privacy choices link instead of a wall. In California and the 11 GPC states it treats GPC as an opt-out before anything runs. EU and UK visitors get a banner that asks first. We keep every answer as a record for 24 months.

## Sources

- [California AG: Sephora settlement over Global Privacy Control](https://oag.ca.gov/news/press-releases/attorney-general-bonta-announces-settlement-sephora-part-ongoing-enforcement)
- [CPPA: Todd Snyder enforcement announcement](https://cppa.ca.gov/announcements/2025/20250506.html)
- [Hunton: California AG record settlement with Disney over opt-out rights](https://www.hunton.com/privacy-and-cybersecurity-law-blog/california-ag-reaches-record-2-75-million-settlement-with-disney-for-violating-ccpas-opt-out-rights)
- [CookieScript: Universal opt-out mechanisms by US state](https://cookie-script.com/privacy-laws/universal-opt-out-mechanisms-in-us-privacy-laws-gpc-requirements-by-state)
- [Sidley: California's SB 690 clears the Legislature](https://www.sidley.com/en/insights/newsupdates/2026/09/californias-sb-690-clears-the-legislature-what-it-means-for-cipa-website-tracking-claims)
- [Shumaker: The CIPA demand letters flooding businesses](https://www.shumaker.com/insight/client-alert-your-website-may-be-a-lawsuit-waiting-to-happen-the-cipa-demand-letters-flooding-businesses/)
