California
CPRA / CCPA
California treats most cross-context behavioural advertising as a "sale" or "share." Offer a clear opt-out and honour Global Privacy Control as a valid opt-out signal.
Find the services collecting data and turn them into a governed vendor inventory.
Use regional guidance to deliver the right consent experience to every visitor.
Keep the rest of your stack aligned and understand how consent performs.
Solutions
Start building
Explore
Detect each visitor's state and serve the right opt-out — honour Global Privacy Control where it's required and offer a Do Not Sell or Share choice where the law asks for it.
Create a fully customisable banner for each US state with a privacy law, then apply the opt-out model — and the universal-opt-out signals — that state expects.
CPRA / CCPA
California treats most cross-context behavioural advertising as a "sale" or "share." Offer a clear opt-out and honour Global Privacy Control as a valid opt-out signal.
GPC / UOOM required
These states require you to recognise a universal opt-out mechanism such as Global Privacy Control and to give a clear way to opt out of targeted advertising and the sale of personal data.
Opt-out, no UOOM mandate
These states follow an opt-out model but don't mandate honouring universal signals. Provide a clear opt-out of targeted advertising and sale through your banner or preference center.
No manual routing tables. Target a banner at each state and US visitors are automatically served the one you set for theirs.
One platform for the growing patchwork of US state privacy laws, from California's CPRA to the universal-opt-out states — with the signals and controls each one expects.
20+
State privacy laws
GPC
Universal opt-out
Let us do the heavy lifting. Automated cookie & vendor scanning, smart categorisation, intelligent recommendations and time saving automation.
Review detailed checks and actionable fixes for every region in your Regional Compliance Report .
Powered by a
global network
of 310+ data centers in
Seamless
pre-built integrations,
extensive documentation,
Keep detailed consent records with audit trails while ensuring no personally identifiable information is stored, prioritising user privacy and compliance.
Target by country, state, province, or territory, then serve the right consent model and language automatically.
European Union
GDPR + ePrivacy
California
CCPA/CPRA · GPC honoured
Québec
Law 25
Keep Google, Microsoft, Meta, HubSpot, and browser-level consent signals aligned with every visitor choice.
Schedule recurring website scans to surface new cookies and trackers for review.
Embed a detailed cookie declaration that stays aligned with your latest scan.
Google Analytics
Analytics
HubSpot
Marketing
Stripe
Payments
Run a US-wide baseline banner, layer state-specific opt-out banners where the law requires them, and honour Global Privacy Control automatically — all from one CookieChimp account.
Per-state control
Opt-out + GPC
“CookieChimp's intuitive UI made the integration process a breeze and far easier than we've experienced with other platforms. The platform provides valuable insights into user consent, making it our top choice for cookie management.”
“I love the developer experience with CookieChimp — it was very straightforward to set up, and the scan tools help you implement it correctly. The regional banners were exactly what I was looking for, letting me choose different banner types for each region, so some places can opt in and others opt out by default. The platform integrated right into our full stack, making it a great fit for our needs.”
“The CookieChimp team has been very helpful in getting us set up and ensuring that we are following the best practice. They've helped us to achieve what we needed, and respond quickly and thoughtfully. I've used a couple of other platforms and CookieChimp is by far the most intuitive platform I've used.”
“Great product with equally great support. Dan from support has been so helpful throughout the implementation, even helping with areas which are not necessarily within his support remit. Highly recommended product and company!”
“Outstanding, such great customer service. Dan looked into, debugged and solved my problems with the plugin.”
“I have to say I've tried several cookie bar solutions before, and CookieChimp is the first one that actually let me set everything up correctly.”
“Setting up the cookie banner was really easy. I didn't have to do it alone, the CookieChimp team helped me through the whole process. They also explained the technical setup and showed me how I could use it on my website and later on a mobile app.”
“Very easy and uncomplicated setup on Next.js compared to other cookie banners like Usercentrics. Works great and pricing is very affordable.”
“The CookieChimp platform is easy to use and the customer service support has always been tremendously helpful and prompt in helping me understand the ever-changing landscape of legal requirements and keeping our site compliant. I really appreciate their expertise.”
“CookieChimp has been incredibly useful for our company. It's exactly the tool we were looking for: easy to install and works perfectly. We've been using it for two months without any issues. Their development team is also excellent, responding quickly with helpful answers whenever we need support. The documentation is excellent too: clear, concise, and with just the right amount of information, without overwhelming you with unnecessary content.”
No. The US has no comprehensive federal privacy law for cookies. Instead there's a patchwork of state laws — led by California's CPRA — plus federal rules for specific sectors like health (HIPAA) and children (COPPA). Most state requirements follow an opt-out model.
You create a banner and target it at specific US states. CookieChimp geolocates each visitor, resolves their state, and serves the banner you set for it — with a US-wide banner as a fallback for anyone whose state can't be detected.
A growing number of states — including California, Colorado, Connecticut, Texas and Oregon — require you to recognise a universal opt-out mechanism such as GPC. Enable CookieChimp's GPC integration and a visitor's opt-out signal is treated as a valid opt-out automatically.
California and several other states treat cross-context behavioural advertising as a "sale" or "share" and require a clear way to opt out. Configure your banner and preference center to present that opt-out to visitors in those states.
Sector rules add stricter requirements: HIPAA covers protected health information and COPPA covers children under 13. On child-directed or health contexts, use an opt-in banner, disable personalised advertising, and minimise third-party trackers.
Around twenty states have passed comprehensive laws so far, and more take effect each year. CookieChimp lets you run a baseline US banner everywhere and add state-specific opt-out banners as new laws come into force.