Blog

Cookie Consent Requirements: What You Actually Need, by Region (2026)

Cookie consent requirements come down to one question: where are your visitors. In the EU and UK, you need a visitor's opt-in before any non-essential cookie loads. In California and the other US states with privacy laws, you do not need opt-in, or even a banner, but you do need to tell people what you collect, give them a working way to opt out, and honor the privacy signal their browser sends. Almost every site serves both audiences, which means running both models at once.

Key Takeaways

  • 01Cookie consent requirements depend on where your visitors are. The EU and UK use an opt-in model; California and other US states use an opt-out model. Most sites have to satisfy both.
  • 02The EU requires opt-in before any non-essential cookie loads, with reject as easy as accept. No US law requires a banner, but California requires notice, a working opt-out, and honoring Global Privacy Control.
  • 03No cookie law actually mandates the banner itself. What they mandate is the outcome: tracking held back until consent in the EU, and an opt-out that genuinely works in the US.
  • 04The real exposure is not a missing banner but a tracker that fires when it should not. In our scan of 229 live sites, 78 to 83 percent tracked before consent, and 43 percent of Reject buttons let a tracker keep firing.
  • 05ConsentStack runs both models from one install, honors GPC by default, ships Google Consent Mode v2 on by default, and records each decision. Plans start at $29 a month.

Strip away the country names and there are really just two systems. The European model is opt-in: trackers stay off until the visitor agrees, and no answer counts as no. The American model is opt-out: trackers may run by default, but you have to say what you collect and give people a real way to switch off the sale or sharing of their data. The GDPR and the ePrivacy Directive drive the first. California's CCPA and CPRA, along with a growing list of other state laws, drive the second.

Most of the requirements you will read about are one of these two models wearing a local label. So the fastest way to know what your site needs is to sort your obligations by where your visitors actually are, then meet the stricter standard wherever the two overlap.

Here is what the two models ask for, side by side. If you serve visitors in both regions, you are on the hook for both columns.

What the EU and US models require for cookie consent.
RequirementEU and UK (GDPR + ePrivacy)US states (CCPA/CPRA and similar)
Consent before loadingRequired. Non-essential cookies must not load until the visitor opts in.Not required. Cookies may load first, as long as you disclose them and allow opt-out.
Notice and transparencyRequired. Say what each category does and who receives the data, before the choice.Required. Give notice at collection of what you collect and why.
A real way to say noReject must be as easy as accept, at the same level, in one click.A clear "Do Not Sell or Share My Personal Information" control that actually stops the sharing.
Honor universal opt-out signalsNot the core mechanism, though respecting signals is good practice.Required in California and a growing list of states. Global Privacy Control must count as a valid opt-out, applied automatically.
Granular choiceRequired. Consent is per purpose, so a single Accept All is not enough on its own.Opt-out can be broad, but sensitive data and minors get extra protection: opt-in is required for users under 16.
Proof and recordsRequired. Keep a record of who consented, to what, and when.Keep records that show opt-outs and rights requests were honored.
A way to change your mindRequired. A visible, always-available way to reopen preferences and withdraw.Opt-outs have to stick, and consumers can submit rights requests at any time.

What every regime asks for, whatever the flag

Underneath the differences, the two models want the same four things. Tell people what you are doing before you do it. Give them a genuine choice, not a fake one. Make saying no as easy as saying yes. And then, the part that trips up almost everyone, actually honor the choice they make. A banner that collects a preference and then ignores it fails under both systems. Different sections of different laws, but it fails.

The requirement almost everyone gets wrong

Read the guides that rank for this topic and you come away thinking the requirement is the banner. It is not. Under the GDPR the requirement is that non-essential trackers do not fire until the visitor opts in. Under California law the requirement is that the opt-out actually works and that Global Privacy Control is respected. In both cases the legal exposure is not a missing popup. It is a tracker that runs when it should not.

The banner is not the requirement

A cookie banner is how most sites deliver notice and choice, but no law mandates the popup itself. What the laws mandate is the outcome: non-essential tracking held back until consent in the EU, and a working opt-out that is honored in the US. A banner that looks right but lets tracking through is not partial compliance. It is the violation.

Where sites actually fail the requirement

The gap between having a banner and meeting the requirement is wide, and measurable. For our state of cookie compliance study we scanned 229 live websites from both a European and a California vantage point. Between 78 and 83 percent fired a third-party request before anyone agreed to anything, which breaks the EU model's central rule on the first page load. Then we clicked Reject on the 70 sites that offered a working Reject button and watched what still loaded. On 30 of them, 43 percent, a genuine third-party tracker kept firing after the click. That describes what those Reject buttons did, not a regional compliance rate, but it is the exact failure both models care about.

Every one of those sites looked fine from the outside. The banner was there, the button was there, and the tracking carried on underneath. That is why the requirement worth checking is not whether you have a banner, but whether your banner does what it claims.

How to actually meet the requirements

The practical version is short. For visitors under the EU opt-in model, block non-essential cookies until they opt in, offer reject as plainly as accept, and keep a record. For visitors under the California opt-out model, post your notice, give a real opt-out, and honor GPC automatically. Where your audiences overlap, meet the stricter of the two and you are covered for both.

ConsentStack runs both models from a single install, so a visitor in Berlin gets the opt-in experience and a visitor in Los Angeles gets the opt-out one, without you maintaining two setups. Non-essential trackers are held back until consent where opt-in applies, Global Privacy Control is honored by default on every plan, and Google Consent Mode v2 ships on by default so your analytics and ads respect the choice too. Each decision is recorded so you can prove it. Plans start at $29 a month, and if you would rather not touch the setup, we do it for you.

Those are the requirements. Whether your site meets them today is a separate question, and an answerable one. This is a plain-language summary rather than legal advice, so check anything load-bearing with your counsel.

Cookie consent requirements FAQ

See whether your site meets the requirements

Run a free compliance scan and see which trackers fire before anyone consents, and which keep going after Reject, checked from both the EU and the US. About a minute, no signup.

Related Posts