Cookie consent requirements come down to one question: where are your visitors. In the EU and UK, you need a visitor's opt-in before any non-essential cookie loads. In California and the other US states with privacy laws, you do not need opt-in, or even a banner, but you do need to tell people what you collect, give them a working way to opt out, and honor the privacy signal their browser sends. Almost every site serves both audiences, which means running both models at once.
Key Takeaways
- 01Cookie consent requirements depend on where your visitors are. The EU and UK use an opt-in model; California and other US states use an opt-out model. Most sites have to satisfy both.
- 02The EU requires opt-in before any non-essential cookie loads, with reject as easy as accept. No US law requires a banner, but California requires notice, a working opt-out, and honoring Global Privacy Control.
- 03No cookie law actually mandates the banner itself. What they mandate is the outcome: tracking held back until consent in the EU, and an opt-out that genuinely works in the US.
- 04The real exposure is not a missing banner but a tracker that fires when it should not. In our scan of 229 live sites, 78 to 83 percent tracked before consent, and 43 percent of Reject buttons let a tracker keep firing.
- 05ConsentStack runs both models from one install, honors GPC by default, ships Google Consent Mode v2 on by default, and records each decision. Plans start at $29 a month.
The two models behind every cookie law
Strip away the country names and there are really just two systems. The European model is opt-in: trackers stay off until the visitor agrees, and no answer counts as no. The American model is opt-out: trackers may run by default, but you have to say what you collect and give people a real way to switch off the sale or sharing of their data. The GDPR and the ePrivacy Directive drive the first. California's CCPA and CPRA, along with a growing list of other state laws, drive the second.
Most of the requirements you will read about are one of these two models wearing a local label. So the fastest way to know what your site needs is to sort your obligations by where your visitors actually are, then meet the stricter standard wherever the two overlap.
Cookie consent requirements by region
Here is what the two models ask for, side by side. If you serve visitors in both regions, you are on the hook for both columns.
| Requirement | EU and UK (GDPR + ePrivacy) | US states (CCPA/CPRA and similar) |
|---|---|---|
| Consent before loading | Required. Non-essential cookies must not load until the visitor opts in. | Not required. Cookies may load first, as long as you disclose them and allow opt-out. |
| Notice and transparency | Required. Say what each category does and who receives the data, before the choice. | Required. Give notice at collection of what you collect and why. |
| A real way to say no | Reject must be as easy as accept, at the same level, in one click. | A clear "Do Not Sell or Share My Personal Information" control that actually stops the sharing. |
| Honor universal opt-out signals | Not the core mechanism, though respecting signals is good practice. | Required in California and a growing list of states. Global Privacy Control must count as a valid opt-out, applied automatically. |
| Granular choice | Required. Consent is per purpose, so a single Accept All is not enough on its own. | Opt-out can be broad, but sensitive data and minors get extra protection: opt-in is required for users under 16. |
| Proof and records | Required. Keep a record of who consented, to what, and when. | Keep records that show opt-outs and rights requests were honored. |
| A way to change your mind | Required. A visible, always-available way to reopen preferences and withdraw. | Opt-outs have to stick, and consumers can submit rights requests at any time. |
What every regime asks for, whatever the flag
Underneath the differences, the two models want the same four things. Tell people what you are doing before you do it. Give them a genuine choice, not a fake one. Make saying no as easy as saying yes. And then, the part that trips up almost everyone, actually honor the choice they make. A banner that collects a preference and then ignores it fails under both systems. Different sections of different laws, but it fails.
The requirement almost everyone gets wrong
Read the guides that rank for this topic and you come away thinking the requirement is the banner. It is not. Under the GDPR the requirement is that non-essential trackers do not fire until the visitor opts in. Under California law the requirement is that the opt-out actually works and that Global Privacy Control is respected. In both cases the legal exposure is not a missing popup. It is a tracker that runs when it should not.
A cookie banner is how most sites deliver notice and choice, but no law mandates the popup itself. What the laws mandate is the outcome: non-essential tracking held back until consent in the EU, and a working opt-out that is honored in the US. A banner that looks right but lets tracking through is not partial compliance. It is the violation.
Where sites actually fail the requirement
The gap between having a banner and meeting the requirement is wide, and measurable. For our state of cookie compliance study we scanned 229 live websites from both a European and a California vantage point. Between 78 and 83 percent fired a third-party request before anyone agreed to anything, which breaks the EU model's central rule on the first page load. Then we clicked Reject on the 70 sites that offered a working Reject button and watched what still loaded. On 30 of them, 43 percent, a genuine third-party tracker kept firing after the click. That describes what those Reject buttons did, not a regional compliance rate, but it is the exact failure both models care about.
Every one of those sites looked fine from the outside. The banner was there, the button was there, and the tracking carried on underneath. That is why the requirement worth checking is not whether you have a banner, but whether your banner does what it claims.
How to actually meet the requirements
The practical version is short. For visitors under the EU opt-in model, block non-essential cookies until they opt in, offer reject as plainly as accept, and keep a record. For visitors under the California opt-out model, post your notice, give a real opt-out, and honor GPC automatically. Where your audiences overlap, meet the stricter of the two and you are covered for both.
ConsentStack runs both models from a single install, so a visitor in Berlin gets the opt-in experience and a visitor in Los Angeles gets the opt-out one, without you maintaining two setups. Non-essential trackers are held back until consent where opt-in applies, Global Privacy Control is honored by default on every plan, and Google Consent Mode v2 ships on by default so your analytics and ads respect the choice too. Each decision is recorded so you can prove it. Plans start at $29 a month, and if you would rather not touch the setup, we do it for you.
Those are the requirements. Whether your site meets them today is a separate question, and an answerable one. This is a plain-language summary rather than legal advice, so check anything load-bearing with your counsel.
Cookie consent requirements FAQ
It depends on where your visitors are. In the EU and UK, you need opt-in consent before any non-essential cookie loads, and reject has to be as easy as accept. In the US, you need a notice of what you collect, a working way to opt out of the sale or sharing of data, and automatic honoring of Global Privacy Control. Most sites serve both regions and have to satisfy both.
Not opt-in consent, and no US law requires a cookie banner. What California and a growing number of states require is transparency about what you collect, a genuine opt-out from targeted advertising and data sales, and honoring universal opt-out signals like GPC. You can run cookies before a visitor chooses, as long as the opt-out actually works when they use it.
The banner itself is not required by any law. In the EU the requirement is that non-essential trackers stay off until the visitor opts in, and a banner is simply the usual way to collect that. In the US the requirement is a working opt-out. A banner is a convenient delivery mechanism, not the legal obligation.
Opt-in, the EU model, means trackers stay off until the visitor actively agrees, and no answer counts as no. Opt-out, the US model, means trackers can run by default but the visitor must be able to switch off the sale or sharing of their data, and that choice has to be honored. The EU standard is stricter, so meeting it usually covers the US requirements on the same site.
In California, yes, and in a growing list of other states. GPC has to be treated as a valid opt-out request and applied automatically, with nothing for the visitor to click. It is the requirement sites miss most, because there is no visible interface for it. The GDPR does not center on GPC, but respecting the signal is good practice everywhere.
In the EU, fines reach 20 million euros or 4 percent of global turnover. France's regulator fined Google 150 million euros and Facebook 60 million in 2022 over banners where rejecting was harder than accepting. In California, penalties run up to $2,663 per violation and $7,988 for intentional ones or those involving minors, and because they are per violation they scale with the number of affected visitors. Honda was fined $632,500 in the state's first enforcement decision, partly for an opt-out that took more clicks than opting in.
See whether your site meets the requirements
Run a free compliance scan and see which trackers fire before anyone consents, and which keep going after Reject, checked from both the EU and the US. About a minute, no signup.
Related Posts
GDPR Cookie Consent Requirements: What the Law Actually Requires (2026)
Yes, the GDPR requires opt-in consent before non-essential cookies load. Here is what valid consent actually requires, what regulators enforce, and where most sites fail it.
CCPA Cookie Consent Requirements: What California Actually Requires (2026)
No, the CCPA does not require a cookie banner. It requires a notice, a working opt-out, and honoring Global Privacy Control. Here is what California actually enforces, and where sites fail it.
How Cookie Consent Script Blocking Works (And What Every CMP's Blocking Attribute Does)
Every consent platform blocks scripts the same basic way: it neutralizes the tag, then labels it with a category. Here is the exact syntax for each major CMP, and why hand-marking scripts keeps leaking.