Book a Demo

What Are Cookie Banner Requirements in US States in 2026?

Twenty US states now have comprehensive consumer privacy laws in force. Most use an opt-out model — notice plus Do Not Sell / targeted-ads controls and, in twelve states, Global Privacy Control — not EU-style opt-in consent. This guide maps the mid-2026 rules state by state.

Written by
Daniel
Published on
What Are Cookie Banner Requirements in US States in 2026?

If your US cookie banner still reads like a GDPR consent gate — "Accept All" required on first visit, cookies off until a click — you're solving the wrong problem for most American traffic.

As of mid-August 2026, twenty US states have comprehensive consumer privacy laws in force. Almost all of them are opt-out regimes: you may collect and use personal data for many purposes by default, but covered businesses must give clear notice, honor opt-outs of sale / sharing / targeted advertising, and — in twelve states — treat browser signals like Global Privacy Control (GPC) as a valid opt-out. There is still no federal privacy law.

Supportive: Once you stop copying EU banner UX into US law, the checklist gets shorter and more testable.

Cynical: The patchwork still means twenty effective dates, twelve GPC mandates, and a New York AG guide that will ding you for a broken "Decline" button even without a comprehensive statute.

This post replaces our stale 2025 write-up. It covers every in-force comprehensive state law, the firm 2026–2027 pipeline, and what that actually means for banners — without inventing GDPR-style "Accept All" duties that US statutes do not impose.

For the broader 2026 context, see what changed in cookie consent laws in 2026 and laws to watch before 2027. For the opt-in vs opt-out map, see where opt-in cookie consent is required and our CCPA vs GDPR comparison.


First principle: US state laws are mostly opt-out, not GDPR opt-in

US comprehensive state privacy laws regulate sale, sharing, and targeted advertising of personal data. They generally do not require opt-in consent before non-essential cookies fire the way the EU ePrivacy Directive and GDPR do.

What they typically do require of a website that sells or shares data or runs targeted ads:

  1. A privacy notice that discloses collection, purposes, and consumer rights.
  2. A clear way to opt out of sale / sharing and/or targeted advertising (often a "Do Not Sell or Share" link, preference center, or equivalent).
  3. No dark patterns that make the privacy-protective choice harder than the less protective one — California's CCPA regulations § 7004 is the most detailed version of this rule.
  4. In twelve states, honoring universal opt-out preference signals such as GPC.
  5. Opt-in (or stronger restrictions) for sensitive data and minors in many statutes.

A banner can be a useful delivery mechanism for notice and opt-out. It is not, under most US laws, a mandatory "Accept All / Reject All" consent gate. If you show an Accept/Decline UI for US visitors, California § 7004 and New York AG guidance still expect the choices to be symmetrical and the controls to actually work — but that is not the same as saying CCPA requires GDPR-style prior consent.


Which states have comprehensive privacy laws in force (August 2026)?

Twenty states. Indiana, Kentucky, and Rhode Island joined on January 1, 2026. Florida's Digital Bill of Rights is usually counted in that twenty even though its $1 billion+ applicability threshold means it reaches only a handful of very large companies.

State Law Effective Opt-out model Must honor GPC / UOOM?
California CCPA / CPRA Jan 1, 2020 (CPRA amendments Jan 1, 2023) Sale / sharing Yes (regs § 7025)
Virginia VCDPA Jan 1, 2023 Sale / targeted ads / certain profiling No
Colorado CPA Jul 1, 2023 Sale / targeted ads / certain profiling Yes (since Jul 1, 2024)
Connecticut CTDPA Jul 1, 2023 Sale / targeted ads / certain profiling Yes (since Jan 1, 2025)
Utah UCPA Dec 31, 2023 Sale / targeted ads No
Texas TDPSA Jul 1, 2024 Sale / targeted ads / certain profiling Yes (since Jan 1, 2025)
Oregon OCPA Jul 1, 2024 Sale / targeted ads / certain profiling Yes (since Jan 1, 2026)
Florida FDBR Jul 1, 2024 Sale / targeted ads (narrow scope) No
Montana Montana Consumer Data Privacy Act Oct 1, 2024 Sale / targeted ads / certain profiling Yes
Delaware DPDPA Jan 1, 2025 Sale / targeted ads / certain profiling Yes (since Jan 1, 2026)
Iowa ICDPA Jan 1, 2025 Sale (no standalone targeted-ads opt-out) No
Nebraska NDPA Jan 1, 2025 Sale / targeted ads / certain profiling Yes
New Hampshire NHDPA Jan 1, 2025 Sale / targeted ads / certain profiling Yes
New Jersey NJDPA Jan 15, 2025 Sale / targeted ads / certain profiling Yes
Tennessee TIPA Jul 1, 2025 Sale / targeted ads / certain profiling No
Minnesota Minnesota Consumer Data Privacy Act Jul 31, 2025 Sale / targeted ads / certain profiling Yes
Maryland MODPA Oct 1, 2025 Sale / targeted ads / certain profiling Yes
Indiana INCDPA Jan 1, 2026 Sale / targeted ads / certain profiling No
Kentucky KCDPA Jan 1, 2026 Sale / targeted ads / certain profiling No
Rhode Island RIDTPPA Jan 1, 2026 Sale / targeted ads No

Sources for this table: IAPP / MultiState 2026 trackers cross-checked against statute effective dates; GPC column matches our verified twelve-state GPC list.

Not "emerging in 2025" anymore: Utah, Oregon, Indiana, Delaware, and New Jersey are all in force. Treating them as upcoming is how last year's guide went stale.


Global Privacy Control: twelve states require it

GPC is a browser-level opt-out signal (Sec-GPC: 1 header and navigator.globalPrivacyControl). As of mid-2026, twelve states require covered businesses to treat qualifying opt-out preference signals as valid requests to opt out of sale / sharing and/or targeted advertising:

California, Colorado, Connecticut, Texas, Montana, New Hampshire, Nebraska, New Jersey, Minnesota, Maryland, Delaware, and Oregon.

Full dates, detection code, and enforcement history are in our GPC guide. Operational takeaway for banners: detecting GPC is separate from showing a popup. A banner alone does not satisfy a UOOM duty.

Most teams honor GPC for all US visitors rather than geo-fencing twelve states.


California – CCPA / CPRA

California remains the strictest US banner jurisdiction — not because it requires EU-style prior consent, but because the California Privacy Protection Agency (CPPA) and Attorney General have turned opt-out UX and GPC into active enforcement themes (Sephora, Tractor Supply, Honda, Disney, PlayOn Sports, GM).

What the law actually requires for cookies / tracking

Requirement Status Legal basis / notes
Notice at collection + privacy policy disclosures Required Civ. Code § 1798.100, § 1798.130
"Do Not Sell or Share My Personal Information" link (or approved alternative) if you sell or share Required Civ. Code § 1798.135
Honor opt-out preference signals (GPC) Required 11 CCR § 7025
Display whether a visitor's opt-out preference signal was processed Required since Jan 1, 2026 11 CCR § 7025 (updated regs)
Symmetry in choice / no dark patterns when offering CCPA request methods or seeking consent Required 11 CCR § 7004
Closing / dismissing a banner ≠ consent Required (cannot treat dismissal as consent) 2026 CPPA regs; Enforcement Advisory 2024-02
Opt-in for sale/sharing of data about consumers under 16 Required Civ. Code § 1798.120
GDPR-style "Accept All" before cookies fire Not required CCPA is opt-out for sale/sharing

If you do use a banner that seeks consent to use personal information, § 7004 says "Accept All" paired only with "More Information" or "Preferences" is not symmetrical — an equal path such as "Decline All" is the regulation's own example. That is a rule about fair choice design when you seek consent, not a mandate to run an opt-in gate for every California visitor.

Updated CCPA regulations took effect January 1, 2026. ADMT (automated decision-making) notice/opt-out rules phase in January 1, 2027.


Colorado – CPA

Colorado's Privacy Act emphasizes opt-outs of targeted advertising, sale, and certain profiling, plus a formal AG process for approving universal opt-out mechanisms. GPC is currently the (only) approved UOOM on the Colorado AG's list.

Requirement Status Notes
Opt-out of sale / targeted advertising / covered profiling Required Colo. Rev. Stat. § 6-1-1306
Honor approved UOOMs (GPC) Required since Jul 1, 2024 Colorado AG UOOM rules
Opt-in for sensitive data Required § 6-1-1308
Privacy notice with purposes and rights Required § 6-1-1308
"Accept All" consent gate Not required Opt-out statute

A practical Colorado banner (or preference center) surfaces a clear targeted-advertising / sale opt-out and wires GPC into the same state. Granular cookie categories are good UX, not a CPA checkbox.


Connecticut – CTDPA

Connecticut has been one of the more active AGs on opt-out and GPC. Mid-2026 amendments matter for coverage and minors:

  • SB 1295 amendments in force since July 1, 2026: applicability threshold dropped from 100,000 to 35,000 consumers (and can disappear entirely if you process sensitive data or sell personal data); targeted advertising and sales involving known (or wilfully disregarded) 13–17-year-olds are prohibited.
  • SB 4 / Public Act 26-64 (mostly Oct 1, 2026): ban on selling precise geolocation (within a 1,750-foot radius), with data-broker registration following January 1, 2027.
Requirement Status Notes
Opt-out of sale / targeted ads / covered profiling Required Conn. Gen. Stat. § 42-518 et seq.
Honor opt-out preference signals (GPC) Required since Jan 1, 2025 CT AG guidance + statute
Fair, non-deceptive choice design Required in practice AG enforcement posture
"Accept All" prior-consent gate Not required Opt-out model

Virginia – VCDPA

Virginia set the template many later states copied: notice, consumer rights, and opt-outs of sale / targeted advertising / certain profiling — without a statutory duty to read browser signals.

Requirement Status Notes
Privacy notice Required Va. Code § 59.1-578
Opt-out of sale / targeted ads / covered profiling Required § 59.1-577
Honor GPC Not required by statute Still a strong multi-state best practice
Equal-prominence Accept/Reject consent UI Not mandated as EU-style consent Avoid deceptive design anyway
July 1, 2026 amendments In force Tightened rules on specific sensitive / data categories

Virginia is the classic "clear notice + working opt-out path" state. Do not copy California's GPC display duty onto Virginia law.


Texas – TDPSA (yes, Texas has a privacy law)

The old claim that Texas "lacks comprehensive privacy legislation" is false. The Texas Data Privacy and Security Act (Tex. Bus. & Com. Code ch. 541) has been in force since July 1, 2024, with universal opt-out signal duties since January 1, 2025.

Notable design choices: no volume/revenue threshold for most for-profit controllers (small-business exemptions apply via SBA definitions), opt-out of sale and targeted advertising, opt-in for sensitive data, and authorized-agent / browser-signal mechanics in § 541.055(e).

Requirement Status Notes
Opt-out of sale / targeted advertising / covered profiling Required § 541.051
Honor universal opt-out mechanisms (GPC in practice) Required since Jan 1, 2025 § 541.055(e)–(f)
Opt-in for sensitive data Required § 541.101
Privacy notice Required § 541.102
"Accept All" consent gate Not required Opt-out model

If your footer still says "we comply with CCPA only," Texas traffic is a gap.


Florida – FDBR (law exists; almost nobody is in scope)

Florida's Digital Bill of Rights (Fla. Stat. § 501.701 et seq.) took effect July 1, 2024. It is comprehensive in structure but extremely narrow in reach: generally $1 billion+ global gross annual revenue and one of several additional criteria (for example, deriving a large share of revenue from online ads, operating certain consumer smart-speaker products, or operating a very large app store).

Requirement (if in scope) Status Notes
Opt-out of sale / targeted advertising Required FDBR consumer rights
Honor GPC Not required No UOOM mandate
Applies to typical SMBs / mid-market sites Usually no $1B+ threshold

So: Florida is not a "no privacy law" state — but for most CookieChimp-scale customers it is still a non-event compared with California or Texas.


Other in-force states (grouped)

States that require GPC / UOOM (beyond CA / CO / CT / TX)

Montana, New Hampshire, Nebraska, New Jersey, Minnesota, Maryland, Delaware, Oregon — all grant opt-outs of sale and (except where noted in statute) targeted advertising, and require controllers to honor opt-out preference signals. Oregon DOJ FAQs confirm controllers must accept universal opt-out mechanisms starting January 1, 2026 (ORS 646A.578). Delaware's parallel UOOM duty also landed January 1, 2026.

Oregon also prohibits selling personal data of consumers the controller knows (or wilfully disregards) are under 16, and restricts sale of precise geolocation in defined cases.

States with opt-out rights but no GPC mandate

Utah, Virginia, Iowa, Tennessee, Indiana, Kentucky, Rhode Island, Florida (if in scope) — provide notice and opt-out rights (Iowa is narrower: sale-focused, without a standalone targeted-advertising opt-out), but do not require reading browser signals. Honoring GPC anyway remains the clean multi-state engineering choice.

Indiana, Kentucky, and Rhode Island are the January 1, 2026 cohort — already live, not "coming soon."


New York – no comprehensive law, real AG expectations

New York still lacks a comprehensive consumer privacy statute. The Attorney General's Website Privacy Controls business guide (updated July 15, 2024) nevertheless applies New York's deceptive-practices laws to tracking disclosures and controls:

  • Privacy controls must work as described (miscategorized tags and hardcoded pixels were the AG's top findings).
  • Do not imply opt-in ("Accept All means you agree") if tracking already fired on page load.
  • If you offer Accept and Decline, give them equal weight; do not hide refusal behind an "X" or extra steps.
  • Choices must cover cookieless sharing too, not just cookies.

Treat New York as a truth-in-controls jurisdiction even without a CCPA clone.


What's next: firm 2026–2027 dates

Align this calendar with our August 2026 watchlist refresh — and treat the March 2026 what changed post as history, not a live tracker. Indiana, Kentucky, and Rhode Island (the January 1, 2026 cohort that post announced) are already in force, as are Connecticut SB 1295 and Virginia's July 1, 2026 amendments.

Date Jurisdiction What happens Status (Aug 2026)
Oct 1, 2026 Connecticut Precise-geolocation sale ban (SB 4 / PA 26-64) Upcoming
Jan 1, 2027 Oklahoma Oklahoma Consumer Data Privacy Act takes effect Upcoming
Jan 1, 2027 Louisiana Louisiana Data Privacy Act takes effect Upcoming (enacted May 2026; not yet on the watchlist table)
Jan 1, 2027 California CCPA ADMT compliance date Upcoming
Jan 1, 2027 Vermont Age-Appropriate Design Code (Act 63) — minors-focused, not a full adult privacy law Upcoming
Jan 1, 2027 Connecticut Data-broker registration to sell/license brokered data Upcoming
May 1, 2027 Alabama Alabama Personal Data Protection Act takes effect Upcoming
Jul 1, 2027 Kentucky KCDPA amendments (HB 692) Upcoming

Triage priorities and non-US dates: cookie consent laws to watch before 2027.


Build to the strictest overlapping duties you face, not to a fictional federal "Accept All" rule:

  1. Notice — what you collect, why, and where the privacy policy lives.
  2. A working sale / share / targeted-ads opt-out — link, preference center, or both; test that tags actually stop.
  3. GPC detection and honor — at least for the twelve mandated states; simplest to do for all US traffic.
  4. California extras if you have CA traffic — Do Not Sell or Share, GPC processed-status display, § 7004 symmetry if you present consent choices, no consent-by-dismissal.
  5. Sensitive-data and minors rules where you actually process those categories (Colorado, Connecticut, Oregon, California, Texas, and others).
  6. No dark patterns — especially if New York or California users see your UI.

EU / UK traffic still needs a separate opt-in ruleset. One global "Accept All" banner is either illegal in the EU or overbuilt (and often misleading) in the US. Geo-aware configuration is the durable approach — see can one cookie banner cover every country?.


Where CookieChimp fits

CookieChimp is built for this split: geo-targeted banners that apply the right ruleset per region, native GPC support, Google Consent Mode v2, and consent logs that record what each visitor was shown. When the next state effective date arrives, it should be a settings change — not a rewrite.


FAQ

Do US state privacy laws require an "Accept All" cookie button?

No. Comprehensive US state laws are generally opt-out. California's § 7004 says that if you seek consent via a banner, "Accept All" alone next to "More Information" / "Preferences" is not symmetrical — but CCPA does not impose GDPR-style prior consent for non-essential cookies.

Which US states require Global Privacy Control?

Twelve, all in force as of mid-2026: California, Colorado, Connecticut, Texas, Montana, New Hampshire, Nebraska, New Jersey, Minnesota, Maryland, Delaware, and Oregon. See the GPC guide.

Does Texas or Florida have a comprehensive privacy law?

Yes for both, with very different reach. Texas's TDPSA has applied since July 1, 2024 (GPC since January 1, 2025). Florida's FDBR has applied since July 1, 2024 but only to a tiny set of $1B+ companies meeting extra criteria.

Are Utah, Oregon, Indiana, Delaware, and New Jersey still "emerging"?

No. All five are in force (Oregon and Delaware's UOOM duties specifically since January 1, 2026; Indiana since January 1, 2026; New Jersey since January 15, 2025; Utah since December 31, 2023).

Do I need a different banner for every state?

Usually not a different design — but you do need jurisdiction-aware logic: opt-out + GPC for US states that require it, and a true opt-in experience for EU/UK visitors. Many teams use one US opt-out experience that meets California's bar and honors GPC everywhere.

What about New York?

No comprehensive privacy statute yet. The NY AG still expects accurate disclosures and working, non-deceptive privacy controls under existing consumer-protection law.

Which US privacy laws take effect in 2027?

Oklahoma's Consumer Data Privacy Act and Louisiana's Data Privacy Act take effect January 1, 2027; Alabama's Personal Data Protection Act follows May 1, 2027. California ADMT rules, Vermont's Age-Appropriate Design Code, and Connecticut data-broker registration also land January 1, 2027; Kentucky's HB 692 amendments follow July 1, 2027. (Our August 2026 watchlist highlights Oklahoma and Alabama as the headline new comprehensive statutes; Louisiana is included here because it is also enacted with a firm January 1, 2027 date.)


References

  1. IAPP, "US State Privacy Legislation Tracker" (20 comprehensive laws in effect as of January 2026): iapp.org
  2. MultiState, "20 State Privacy Laws in Effect in 2026: Key Dates & Changes": multistate.us
  3. California Privacy Protection Agency, CCPA regulations (including 11 CCR §§ 7004, 7025): cppa.ca.gov
  4. Cornell LII, "Cal. Code Regs. Tit. 11, § 7004 – Requirements for Methods for Submitting CCPA Requests and Obtaining Consumer Consent": law.cornell.edu
  5. Cornell LII, "Cal. Code Regs. Tit. 11, § 7025 – Opt-Out Preference Signals": law.cornell.edu
  6. CPPA, Enforcement Advisory No. 2024-02 (symmetry / dark patterns / consent): cppa.ca.gov
  7. Tex. Bus. & Com. Code § 541.055 (TDPSA authorized agent / universal opt-out technology): texas.public.law
  8. Oregon Department of Justice, "Privacy Law FAQs for Businesses" (universal opt-out required as of January 1, 2026): doj.state.or.us
  9. New York Attorney General, "Website Privacy Controls" (business guide): ag.ny.gov
  10. Florida Legislature, Fla. Stat. § 501.701 et seq. (Digital Bill of Rights): leg.state.fl.us
  11. Colorado Attorney General, Colorado Privacy Act resources (including universal opt-out mechanism materials): coag.gov
  12. Wiley, "Major Changes to Connecticut's Consumer Privacy Law Will Take Effect July 1, 2026" (SB 1295): wiley.law
  13. Foley & Lardner, "Connecticut Dramatically Expands Its Data Privacy Act" (July 2026): foley.com
  14. Proskauer, "From Data Brokers to DNA: Connecticut Enacts Sweeping Privacy Amendments" (SB 4 / PA 26-64): privacylaw.proskauer.com
  15. Indiana General Assembly, Senate Enrolled Act No. 5 (Indiana Consumer Data Protection Act, IC 24-15; effective January 1, 2026): iga.in.gov
  16. Indiana Attorney General, "Indiana Consumer Data Protection — Consumer Bill of Rights": in.gov
  17. Perkins Coie, "Oklahoma and Alabama Headline a Busy Spring for Privacy Legislation" (OCDPA January 1, 2027; APDPA May 1, 2027): perkinscoie.com
  18. Davis Wright Tremaine, "Louisiana Joins the State Privacy Law Party" (LDPA effective January 1, 2027): dwt.com
  19. California Privacy Protection Agency, "California Finalizes Regulations to Strengthen Consumers' Privacy" (ADMT / 2027 compliance dates): cppa.ca.gov
  20. CookieChimp, "Global Privacy Control (GPC): Which Laws Require It, With Code": cookiechimp.com

The US map will keep adding effective dates; your banner logic does not have to be rewritten each time. Get started with CookieChimp.

The content of this article is provided for information purposes only and does not constitute legal or other advice.