EnglishEspañol

Cookie Banner Requirements: US & EU Rules (2026)

Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 7 primary sources cited on this page. How we verify our legal content

Cookie Banner Requirements: US & EU Rules (2026)

Frequently Asked Questions

Does my website need a cookie banner in the US?

There is no federal US law requiring a cookie consent banner. However, if your website sells personal information or shares it for targeted advertising, California's CCPA/CPRA requires a 'Do Not Sell or Share My Personal Information' link. Other states (Colorado, Connecticut, Virginia, Texas, Oregon) have similar opt-out requirements. You may also need to display a banner to honor Global Privacy Control signals in states that mandate universal opt-out recognition.

Can I use a single cookie banner for both EU and US visitors?

Yes, but the banner should adapt based on the visitor's location. An EU visitor should see a full opt-in consent interface with accept and reject buttons of equal prominence. A US visitor should see a simpler notice with opt-out options. Most consent management platforms support geolocation-based banner display. Alternatively, you can apply the EU standard globally, which satisfies both sets of requirements but may reduce analytics and advertising data from US visitors.

What is the Global Privacy Control (GPC) and do I have to honor it?

GPC is a browser-level signal that communicates a user's opt-out preference. In California, businesses must honor GPC as a valid opt-out of the sale or sharing of personal information under the CCPA/CPRA. Colorado, Connecticut, Oregon, Texas, Montana, New Jersey, Minnesota, and Delaware also require recognition of universal opt-out mechanisms, while Maryland treats honoring the signal as one of two permitted ways to offer an opt-out. More states are adding this requirement as their own privacy laws take effect. If your website uses advertising cookies that share data with third parties, you must detect and honor GPC signals from visitors in these states.

Are pre-ticked cookie consent checkboxes legal?

Pre-ticked checkboxes are illegal for cookie consent in the EU. The Court of Justice of the EU ruled in Planet49 (Case C-673/17, October 2019) that consent must involve a clear affirmative action by the user, and a pre-ticked checkbox does not meet this standard. In the US, there is no specific prohibition on pre-ticked boxes, but manipulative consent interfaces could raise issues under FTC deceptive practices enforcement.

What counts as a dark pattern in a cookie banner?

Regulators identify several dark patterns: making the accept button visually dominant (larger, brighter) while minimizing the reject option; requiring multiple clicks to reject but only one click to accept; using confusing language or double negatives; hiding the reject option behind a 'Manage Preferences' link when 'Accept All' is displayed on the first layer; and continuously re-displaying the banner to users who previously rejected cookies. The EDPB and national DPAs like the CNIL have specifically sanctioned these practices.

Can I run Google Analytics without cookie consent in the EU?

No. Google Analytics 4 places cookies that transfer data to Google servers. EU data protection authorities (Austria, France, Italy) have specifically ruled that Google Analytics requires user consent under the ePrivacy Directive for cookie placement and the GDPR for the international data transfer. Privacy-preserving alternatives like Plausible, Fathom, or self-hosted Matomo in cookieless mode may operate without consent under some national implementations, particularly France's CNIL exemption for first-party audience measurement.

How often should I re-ask for cookie consent?

The ePrivacy Directive does not specify a re-consent interval. The French CNIL recommends re-requesting cookie consent every 6 months. Other national authorities suggest 12 months. You should also re-request consent whenever you add new cookie categories, change processing purposes, or update third-party data recipients. In the US, opt-out choices under the CCPA are generally persistent and do not need to be re-confirmed.

What penalties can I face for a non-compliant cookie banner?

In the EU, penalties can reach 20 million euros or 4% of global annual turnover under the GDPR, or lower amounts under national ePrivacy transpositions. France fined Google 150 million euros for cookie consent violations in 2021. In the US, the CCPA provides for penalties of up to $2,663 per unintentional violation and $7,988 per intentional violation, CPI-adjusted figures in effect since January 1, 2025 under Cal. Civ. Code Sec. 1798.155(a). California's AG and the CPPA have brought enforcement actions against businesses that failed to honor GPC or provide adequate opt-out mechanisms.

Updates

Corrected the multi-state opt-out details: only California requires a link titled 'Do Not Sell or Share My Personal Information,' the universal opt-out dates are now labeled as either signal-recognition deadlines or law effective dates, Maryland is described as allowing an opt-out link or a preference signal rather than mandating the signal, and the Texas signal duty now states the statutory conditions that limit it.

Added Texas and five more states (Montana, New Jersey, Minnesota, Delaware, Maryland) to this page's lists of states that require honoring the Global Privacy Control universal opt-out signal, updated the CCPA's penalty figures to the current CPI-adjusted amounts ($2,663 / $7,988, effective January 1, 2025), and replaced two dead CNIL links and one dead EDPB link with their current live URLs.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. Directive 2002/58/EC - ePrivacy Directive(eur-lex.europa.eu).gov
  2. CJEU Case C-673/17 (Planet49)(curia.europa.eu).gov
  3. CNIL Cookie Guidelines(cnil.fr)
  4. Italy Garante Cookie Guidelines(garanteprivacy.it).gov
  5. EDPB Dark Patterns Guidelines(edpb.europa.eu).gov
  6. EDPB Consent Guidelines(edpb.europa.eu)
  7. California CCPA/CPRA(oag.ca.gov).gov
  8. CPPA Regulations(cppa.ca.gov).gov
  9. GDPR Regulation 2016/679(eur-lex.europa.eu).gov
  10. Cal. Civ. Code Sec. 1798.135(a): the only US provision mandating a homepage link titled 'Do Not Sell or Share My Personal Information'(leginfo.legislature.ca.gov)
  11. Va. Code Sec. 59.1-578(D): controllers must clearly and conspicuously disclose the processing and the manner of opting out, with no link title required(law.lis.virginia.gov)
  12. Tex. Bus. & Com. Code Secs. 541.055 and 541.103: authorized-agent opt-out signal conditions, the default-setting bar, and the opt-out disclosure duty(statutes.capitol.texas.gov)
  13. 6 Del. C. Sec. 12D-106(e)(1): opt-out link and, not later than January 1, 2026, recognition of an opt-out preference signal(delcode.delaware.gov)
  14. Mont. Code Ann. Sec. 30-14-2809: opt-out preference signal required no later than January 1, 2025(mca.legmt.gov)
  15. Minn. Stat. Sec. 325M.14, subd. 3: opt-out preference signal duty; chapter 325M effective July 31, 2025(revisor.mn.gov)
  16. Maryland SB 541 (Ch. 455, 2024) as enrolled, Maryland Online Data Privacy Act: opt-out link or preference signal as alternative methods, effective October 1, 2025(mgaleg.maryland.gov)
  17. Conn. Gen. Stat. Sec. 42-520(e)(1)(A): clear and conspicuous opt-out link plus opt-out preference signal recognition not later than January 1, 2025(cga.ct.gov)
Share: