Blog

CCPA Cookie Consent Requirements: What California Actually Requires (2026)

No, the CCPA does not require a cookie banner, at least not the kind you see on European sites. California runs on an opt-out model: you are allowed to load tracking by default, but you have to tell people it is happening and give them a real way to stop it. That sounds easier than the GDPR, and in one sense it is. The catch is that the thing California actually enforces is not whether you have a banner. It is whether the opt-out behind it works. That is what California's cookie enforcement has actually been about.

Key Takeaways

  • 01No. The CCPA does not require a cookie banner, and it does not require opt-in consent. Cookies are allowed to load before a visitor chooses anything.
  • 02What it does require: a notice at collection, a clear way to opt out of the sale or sharing of personal information, and automatic honoring of Global Privacy Control signals.
  • 03Opting out has to be as easy as opting in. California's first enforcement decision fined Honda $632,500 in part because its banner took two clicks to reject advertising cookies and one to accept them.
  • 04The enforcement risk is not a missing banner. It is an opt-out that does not work. On 43% of the sites we scanned that had a Reject button, a third-party tracker kept firing after someone clicked it.
  • 05ConsentStack applies the opt-out model for California visitors and honors GPC by default, so the signal is respected before the page finishes loading.

No. There is no line in the CCPA or the CPRA that says "display a cookie banner," and nothing requires you to hold cookies until a visitor agrees. Cookies are allowed to load on the first page view.

What the law does require is that if you sell or share personal information, and that includes the ordinary case of letting advertising trackers collect data for targeted advertising across sites, you have to disclose it and let people opt out. Most sites end up using a banner for that, because a banner is a convenient place to put both the notice and the opt-out control. So the honest answer is that a banner is not required, but something has to carry the notice and the opt-out, and a banner is usually the easiest something.

What California actually requires

Four things have to be true. None of them is "show a banner," but a banner is how most sites satisfy the middle two.

What the CCPA and CPRA require for cookies and trackers.
RequirementWhat it means in practice
Notice at collectionTell people what categories of personal information you collect and why, at or before the moment you collect it. A privacy policy link in the footer and on the banner usually covers it.
A "Do Not Sell or Share My Personal Information" linkIf advertising trackers on your site share data for targeted advertising, you need a clearly labeled, easy to find way to switch that off. A footer link, a banner control, or both.
Honoring Global Privacy ControlIf a visitor's browser sends a GPC signal, you have to treat it as a valid opt-out request automatically. There is nothing for them to click.
Symmetry of choiceOpting out has to be as easy as opting in. If Accept All is one click, rejecting cannot take three.

The part California actually enforces

In 2022 the California Attorney General settled with Sephora for $1.2 million. In March 2025 the California Privacy Protection Agency issued its first enforcement decision, fining American Honda $632,500. The Honda finding is the one worth reading twice: the banner took two clicks to turn advertising cookies off and one click to turn them on. That asymmetry on its own was a violation, and the agency required Honda to add a Reject All button alongside its Allow All button.

Notice what those cases have in common. Neither company was penalized for failing to show a banner. They were penalized because the opt-out was harder than the opt-in, or because it did not do what it said.

Your banner is a rights request tool

In the Honda decision the agency treated the cookie banner as a mechanism for submitting a consumer rights request, which means it inherits the CCPA's rules about how those requests have to work. That reframes the whole thing. A banner that collects a choice and then quietly ignores it is not a cosmetic problem. It is the violation.

That is worth checking rather than assuming, because Reject buttons fail quietly and often. For our state of cookie compliance study we scanned 229 live websites and clicked Reject on the 70 that offered a working Reject button, then watched what still loaded. On 30 of those 70 sites, 43%, a genuine third-party tracker kept firing after the click. Every one of them looked fine from the outside. The banner was there, the button was there, and the tracking carried on. We measured that from both a European and a California vantage point, and it describes what the Reject button did, not a California compliance rate.

Global Privacy Control, the opt-out nobody clicks

GPC is the requirement sites miss most, partly because there is nothing to look at. It is a signal the browser sends automatically on every request, switched on in browsers like Firefox and Brave or through an extension, and California requires you to treat it as a valid opt-out. A visitor arriving with GPC turned on has already opted out before your banner renders. If your site sits there waiting for them to click something, you have already missed it.

This is also the one requirement our free scanner does not currently test, so it is worth verifying yourself or asking your consent tool directly. The quick version: open your site in a browser with GPC enabled and confirm that advertising and analytics trackers stay off without you touching the banner.

California and the GDPR are not the same job

Most of the confusion here comes from applying European habits to a Californian law. They ask for genuinely different things, and a banner built for one is usually wrong for the other.

How the GDPR and the CCPA differ on cookies.
QuestionGDPR (EU)CCPA and CPRA (California)
Can trackers load before the visitor chooses?NoYes
What does the visitor do?Opts inOpts out
Is a banner required?In practice, yesNo, but a notice and an opt-out are
Must browser signals be honored?Not requiredYes, GPC must be honored
Penalty ceilingUp to 4% of global annual turnover$2,663 per violation, $7,988 if intentional

Those California penalty figures are the current inflation-adjusted amounts, effective January 2025, and they are per violation rather than per incident, which is what makes them add up. Consumers can also claim between $107 and $799 each in a data breach case. If you serve visitors on both sides of the Atlantic you need both models running side by side, which is the subject of our GDPR cookie consent requirements guide. This is a plain-language summary rather than legal advice, so check anything load-bearing with your counsel.

How ConsentStack handles California visitors

ConsentStack applies the right model per region from a single install, so a visitor in Berlin gets an opt-in experience and a visitor in Los Angeles gets an opt-out one, without you maintaining two setups. GPC is honored by default on every plan: we read the signal from both the browser and the request header, and when it is present everything except strictly necessary cookies is switched off before the page finishes loading, with a small notice telling the visitor their signal was respected. And when someone does click Reject, the scripts actually stay off, which is the part the 43% above were getting wrong. Plans start at $29 a month, and if you would rather not touch the configuration, we set it up for you.

See what your site does for a California visitor

Before changing anything, find out where you actually stand. Run your domain through our free compliance scanner and it will show you which trackers fire on page load and which keep going after someone clicks Reject, checked from both a US and an EU vantage point. It takes about a minute and does not ask for an email. If your Reject button is one of the ones that does not hold, this is the fastest way to find out.

CCPA cookie consent FAQ

Find out whether your opt-out actually works

Run a free compliance scan and see exactly which trackers keep firing after someone clicks Reject. No signup.

Related Posts