The short answer
There is no federal cookie consent law in the United States, and none of the 27 state privacy laws tracked on this page requires a cookie banner as such. That is the honest reading of every one of them, and it is the answer the regulators give too.
It is also the wrong question. These laws regulate what a tracker does with a visitor's data, not the banner. 25 of them run on an opt-out model: you may set analytics and advertising cookies by default, but you have to tell visitors that you do, give them a way to opt out of targeted advertising and of the sale or sharing of their data, and honor it when they use it. 12 of them, today, require you to treat a browser signal such as Global Privacy Control as that opt-out, automatically, with no click. 24 require opt-in consent before you handle sensitive data. And California's regulations say in so many words that a cookie banner is not, by itself, an acceptable way to take an opt-out request.
So the practical answer for a US site running Google Analytics, a Meta pixel or any advertising tag is: you need a privacy notice, an opt-out that actually stops the sharing, and a way to honor Global Privacy Control. A banner is the common way to deliver the first two. It is not the law, and a banner that does not stop the tracking is worse than none, because now the site is also making a false statement.
What US privacy laws require instead of a banner
Four obligations recur across the state laws. A banner is one way to meet the first two. The third cannot be met by a banner at all, and the fourth is where a banner comes back into the picture.
Cookie identifiers, device identifiers and pixel data count as personal information under these laws. Your privacy policy has to say which categories you collect, why, and which third parties receive them. California also requires a notice at or before the point of collection.
Visitors must be able to opt out of targeted advertising and of the sale or sharing of their data, and the opt-out has to actually stop it. In California that means at least two methods, one of which is a browser opt-out preference signal, and a Do Not Sell or Share My Personal Information link (or the Alternative Opt-out link) on the site. A banner or a Your Privacy Choices control is the usual place to put it.
12 laws in force today require you to treat Global Privacy Control as a valid opt-out, and 14 do once the scheduled ones take effect. The signal arrives with the first request, before any banner has rendered, so whatever runs your consent has to read it and apply the opt-out itself. This is the obligation most US sites miss, because nothing visible happens when it is ignored.
24 of the laws require affirmative consent before you process sensitive categories: health data, precise location, biometrics, and data about children. Washington's health data law and the federal COPPA rule for visitors under 13 sit on top of that. If a tracker can reveal any of those, the model flips from opt-out to opt-in for that data, and a banner is how sites usually collect the consent.
Which states require cookie consent, state by state
Every enacted US state privacy law, ordered by the date it took effect. Consent model tells you whether trackers may run before the visitor chooses. Must honor GPC and opt-in for sensitive data are the two obligations a banner alone cannot meet. Each row links to the full breakdown of that law, and the counts on this page are read from those records, not maintained by hand.
| State | Law | In force | Consent model | Must honor GPC | Opt-in for sensitive data | Consumers can sue |
|---|---|---|---|---|---|---|
| California | CIPA | Jan 1, 1967 | Opt-in | No | Not specified | Yes |
| California | CCPA | Jan 1, 2020 | Opt-out | No | No | Yes |
| California | CPRA | Jan 1, 2023 | Opt-out | Yes | Yes | Yes |
| Virginia | VCDPA | Jan 1, 2023 | Opt-out | No | Yes | No |
| Colorado | CPA | Jul 1, 2023 | Opt-out | Yes | Yes | No |
| Connecticut | CTDPA | Jul 1, 2023 | Opt-out | Yes | Yes | No |
| Utah | UCPA | Dec 31, 2023 | Opt-out | No | Yes | No |
| Washington | MHMDA | Mar 31, 2024 | Opt-in | No | Yes | Yes |
| Florida | FDBR | Jul 1, 2024 | Opt-out | No | Yes | No |
| Oregon | OCPA | Jul 1, 2024 | Opt-out | Yes | Yes | No |
| Texas | TDPSA | Jul 1, 2024 | Opt-out | Yes | Yes | No |
| Montana | Montana MCDPA | Oct 1, 2024 | Opt-out | Yes | Yes | No |
| Delaware | DPDPA | Jan 1, 2025 | Opt-out | Yes | Yes | No |
| Iowa | ICDPA | Jan 1, 2025 | Opt-out | No | No | No |
| Nebraska | NDPA | Jan 1, 2025 | Opt-out | Yes | Yes | No |
| New Hampshire | NHPA | Jan 1, 2025 | Opt-out | Yes | Yes | No |
| New Jersey | NJDPA | Jan 15, 2025 | Opt-out | Yes | Yes | No |
| Tennessee | TIPA | Jul 1, 2025 | Opt-out | No | Yes | No |
| Minnesota | Minnesota MCDPA | Jul 31, 2025 | Opt-out | Yes | Yes | No |
| Maryland | MODPA | Oct 1, 2025 | Opt-out | Yes | Yes | No |
| Indiana | INCDPA | Jan 1, 2026 | Opt-out | No | Yes | No |
| Rhode Island | RIDTPPA | Jan 1, 2026 | Opt-out | No | Yes | No |
| Kentucky | KCDPA | Jan 1, 2026 | Opt-out | No | Yes | No |
| Louisiana | LDPA | Jan 1, 2027Upcoming | Opt-out | Yes | Yes | No |
| Oklahoma | OKCDPA | Jan 1, 2027Upcoming | Opt-out | No | Yes | No |
| Alabama | APDPA | May 1, 2027Upcoming | Opt-out | No | Yes | No |
| Vermont | VDPOSA | Jan 1, 2028Upcoming | Opt-out | Yes | Yes | No |
23 of 27 laws are in force today. Law records last reviewed August 9, 2026. The two opt-in rows are not general privacy laws: Washington's MHMDA covers consumer health data, and California's CIPA is a wiretap statute that requires consent before a communication is recorded, which is how session replay and chat widgets end up needing consent. The full comparison, with cure periods, is on the US state privacy law tracker.
California is the special case
Three things make California the state where the banner question stops being theoretical. The first is that the CCPA's definition of sharing covers cross-context behavioral advertising, which is exactly what an advertising pixel does, so most sites running ads are sharing whether or not money changes hands.
The second is the regulation itself. Section 7026 of the CCPA regulations lists the methods a business must offer for opt-out requests, and subsection (a)(4) reads: “A notification or tool regarding cookies, such as a cookie banner or cookie controls, is not by itself an acceptable method for submitting requests to opt-out of sale/sharing because cookies concern the collection of personal information and not the sale or sharing of personal information.” An online business has to offer an opt-out preference signal plus at least one other method, such as a form or a link in the privacy policy. A banner can carry that link. It cannot be the whole answer.
The third is enforcement. California's largest CCPA settlement to date, $1.55 million against Healthline in July 2025, turned on a consent banner that, in the Attorney General's words, “did not disable tracking cookies, despite purporting to do so if a consumer unchecked a box.” Dozens of trackers kept sharing data with third parties after visitors opted out. The banner was not the violation. The banner that did nothing was.
And then there is CIPA, the 1967 wiretap law with a private right of action. It is the reason US sites receive demand letters over session replay, chat widgets and tracking pixels that ran before any choice was made. It does not mention cookies or banners either. It asks whether the visitor consented before the communication was recorded, and a banner that gates those tools until the visitor chooses is the least expensive answer to that question.
If you also have EU or UK visitors
The European model is the opposite of the US one. Under the GDPR and the ePrivacy rules, non-essential cookies and trackers may not be set until the visitor has given prior consent, rejecting has to be as easy as accepting, and scrolling or continuing to browse does not count. That applies to a US business the moment it serves visitors in the EU, EEA or UK.
The practical setup for a site with both audiences is geo-aware: an opt-in banner that blocks trackers until consent for European visitors, an opt-out model with Global Privacy Control handling for visitors in the US states above, and nothing at all for visitors nowhere covered. Our guide to consent models explains how the three modes differ, and the European regulations pages cover each country's rules.
What a compliant US setup looks like
Strip the banner question away and what remains is a short list. Detect where the visitor is and apply that state's model. Read the Global Privacy Control signal on the first request and apply the opt-out without asking. Give visitors without the signal a visible way to opt out, and keep it reachable after the banner is gone. Make the opt-out real, by gating the analytics and advertising tags rather than only recording a preference. Keep a record of each choice. And put the disclosure in the privacy policy.
How ConsentStack handles it. The US state laws region resolves the consent model per state at the edge, so a visitor in California and a visitor in a state with no privacy law get the treatment their own law calls for, from one install. Global Privacy Control is honored everywhere by default: a visitor sending the signal sees no banner, every non-essential category is set to denied, a small confirmation appears with a link to preferences, and the downstream signals (Google Consent Mode v2, Meta Limited Data Use and the equivalents for TikTok and Pinterest) go out automatically. Visitors without the signal get an opt-out banner and a persistent preferences control, catalogued trackers are held back when a visitor opts out rather than merely logged, and the resolved consent model is exposed to your own code so you can render a Your Privacy Choices link where California expects one. Every choice is recorded as proof.
Whichever platform you use, the fastest way to know whether your banner is doing anything is to look. The scanner below loads your site as a US visitor and shows which trackers fire before any choice and which keep firing after an opt-out.
A banner is a promise. A scan tells you if yours is kept.
See which trackers fire before consent and after a visitor opts out, on the platform you already have.
Questions
No US law makes the absence of a cookie banner illegal. What can be unlawful is what the banner usually covers: setting analytics or advertising trackers without the notice and opt-out that 25 state privacy laws require, ignoring a Global Privacy Control signal in the 12 states that require honoring it, or recording a visitor's session or chat without consent under California's CIPA. A banner that promises an opt-out and does not deliver it is a separate problem: California treated that as a deceptive practice in its 2025 Healthline settlement.
No. The CCPA requires a notice at collection, a way to opt out of the sale or sharing of personal information (the Do Not Sell or Share My Personal Information link, or the Alternative Opt-out link), at least two opt-out methods including an opt-out preference signal such as Global Privacy Control, and for the opt-out to be honored. Its regulations say in so many words that a cookie banner or cookie controls are not by themselves an acceptable method for submitting an opt-out request (Cal. Code Regs. tit. 11, section 7026(a)(4)). A banner is one way to present the notice and the link; it does not satisfy the law on its own.
None of the 27 state privacy laws tracked here requires opt-in consent for ordinary cookies. 25 of them use an opt-out model: trackers may run by default, but the visitor must be told and must be able to opt out of targeted advertising and of the sale or sharing of their data. 24 require opt-in consent before sensitive data is processed. The two opt-in laws in the table are not general privacy laws: Washington's MHMDA covers consumer health data, and California's CIPA is a wiretap statute that requires consent before a communication is recorded, which is how session replay and chat widgets end up needing consent in California.
12 laws in force today require a business to treat a browser opt-out signal such as Global Privacy Control as a valid opt-out, with no click from the visitor: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. Also scheduled: Louisiana (Jan 1, 2027) and Vermont (Jan 1, 2028). The signal arrives before the page has rendered anything, so a banner cannot catch it. Whatever handles consent on your site has to read the header or the browser property and apply the opt-out itself.
Not a banner as such, but Google Analytics is not exempt either. It sets identifiers that count as personal information under the state laws, and its advertising features can amount to sharing for cross-context behavioral advertising, which is the thing visitors have a right to opt out of. So a US site running GA4 needs the notice, a working opt-out, and Global Privacy Control handling, and a banner or preferences control is the usual way to deliver the first two. If the same site has visitors in the EU or UK, GA needs their prior consent before it loads at all.
A privacy policy that discloses your cookies and trackers, what they collect and who receives the data is required by every state privacy law in the table, and California has required a conspicuously posted privacy policy from any commercial site collecting personal information from its residents since 2004 (CalOPPA). A separate document titled cookie policy is not required by name. Most US sites fold the cookie disclosure into the privacy policy and link the opt-out from there.
Under the state privacy laws, enforcement runs through the state attorney general or, in California, the privacy agency, with a cure period in many states (the tracker one level up lists each one) and civil penalties after it. California's largest CCPA settlement to date, $1.55 million against Healthline in July 2025, was about a consent banner that did not actually disable tracking. Separately, California's CIPA carries a private right of action, which is why session replay, chat widgets and pixels that run before any choice produce demand letters from plaintiffs' firms rather than regulator inquiries.
Reviewed September 14, 2026. The California regulation is quoted from Cal. Code Regs. tit. 11, section 7026(a)(4), and the Healthline figures are from the California Attorney General's July 1, 2025 announcement. None of this is legal advice; the law pages linked from the table carry each statute's specifics.