EnglishEspañol

US Cookie Laws: State-by-State Guide (2026)

Independently fact-checked against primary sources (last audited August 15, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 15, 2026. · 9 primary sources cited on this page. How we verify our legal content

US Cookie Laws: State-by-State Guide (2026)

Frequently Asked Questions

Does any US state require EU-style opt-in cookie consent?

No. As of August 2026, no US state requires affirmative opt-in consent before placing cookies on a user's device. All US state privacy laws use an opt-out model, where tracking begins by default and consumers can request it stop. The only opt-in requirements relate to specific categories: COPPA requires parental consent for children under 13 nationwide, and California requires opt-in consent before selling personal information of consumers aged 13 to 15.

What is the Global Privacy Control (GPC) and which states require it?

GPC is a browser signal that communicates a user's preference to opt out of the sale or sharing of personal information. Ten states require businesses to honor GPC: California, Colorado, Connecticut, Texas, Oregon, Montana, Delaware, New Hampshire, New Jersey, and Nebraska. GPC is built into Firefox, Brave, and DuckDuckGo browsers, and available as an extension for Chrome. When detected, websites must automatically suppress data sales and targeted advertising without requiring additional user action.

Which state privacy law is the strictest on cookies and tracking?

California's CCPA/CPRA remains the most comprehensive. It has the broadest definition of 'sale' (expanded by CPRA to include 'sharing' for advertising), mandatory GPC recognition, a dedicated enforcement agency (the CPPA), and penalties of $7,500 per intentional violation. Maryland's law (effective October 2025) is notably strict on data minimization and restricts targeted advertising to minors entirely, which may have significant implications for cookie-based tracking.

Do I need a 'Do Not Sell My Personal Information' link on my website?

If your business sells personal information or shares it for cross-context behavioral advertising and meets the applicability thresholds, California requires this link. Similar opt-out mechanisms are required by Colorado, Connecticut, Virginia, Texas, Oregon, and other states with comprehensive privacy laws. If you use advertising cookies that share data with ad networks or data brokers, you likely need this link. The safest approach is to display it for all visitors.

How does the CCPA define 'sale' of personal information through cookies?

The CCPA defines 'sale' broadly as transferring personal information to a third party for monetary or other valuable consideration. The CPRA amendment added 'sharing,' defined as transferring personal information for cross-context behavioral advertising, even without monetary exchange. This means that using advertising cookies from networks like Google Ads or Meta, where cookie data flows to the ad platform to serve targeted ads, constitutes 'sharing' under the CPRA even if no money directly changes hands for the data.

What happens if my business operates in a state without a privacy law?

In states without comprehensive privacy laws, there are no state-level requirements for cookie opt-out mechanisms. However, the federal FTC Act's prohibition on unfair or deceptive practices still applies. If your privacy policy makes promises about data practices or opt-out rights, the FTC can enforce those promises. Businesses should also prepare for new state laws, as the pace of state privacy legislation has accelerated significantly since 2023.

Are there different rules for sensitive personal data collected through cookies?

Several states distinguish between general personal data and sensitive personal data. California requires a 'Limit the Use of My Sensitive Personal Information' link if sensitive data is used beyond what is necessary. Precise geolocation data (collected through cookies or scripts) is classified as sensitive in California, Colorado, Connecticut, Virginia, and most other state privacy laws. Processing sensitive data through cookies may trigger heightened obligations including data protection impact assessments.

Can I just apply one state's rules nationwide instead of tracking each state?

Yes, and many privacy professionals recommend this approach. Applying California's CCPA/CPRA requirements (the strictest US standard) nationwide satisfies the requirements of all other state privacy laws. This means displaying opt-out links, honoring GPC, providing a privacy policy with required disclosures, and implementing processes for consumer rights requests. The simplicity of a single compliance standard often outweighs the marginal cost of providing opt-out mechanisms to residents of states that do not yet require them.

Updates

Added Florida and Rhode Island to the state guide and comparison table so the page now lists all 24 states it counts, and tightened the Connecticut applicability wording to match the enacted text of Public Act 25-113.

Updated the enacted-state count from 20 to 24 to include Oklahoma, Alabama, Louisiana, and Vermont (each noted as enacted-but-not-yet-effective with its effective date and cookie/opt-out provisions), corrected Connecticut's applicability threshold to the current 35,000-consumer / any-sensitive-data / any-sale test effective July 1, 2026, fixed a count error that said 'nine states' require GPC recognition while naming ten (added Texas consistently everywhere), and replaced two dead FTC citation links (COPPA rule and the Flo Health enforcement matter).

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Reviewed and approved by an editor

Sources and References

  1. California CCPA/CPRA(oag.ca.gov).gov
  2. CPPA Regulations(cppa.ca.gov).gov
  3. Colorado Privacy Act(coag.gov).gov
  4. Connecticut Data Privacy Act(portal.ct.gov).gov
  5. Virginia VCDPA(law.lis.virginia.gov).gov
  6. Texas HB 4 (TDPSA)(capitol.texas.gov).gov
  7. Oregon Consumer Privacy Act(oregonlegislature.gov).gov
  8. Global Privacy Control(globalprivacycontrol.org)
  9. FTC COPPA Rule(ftc.gov).gov
  10. FTC Flo Health Enforcement(ftc.gov).gov
  11. Connecticut Public Act 25-113, Sec. 6 (amending Conn. Gen. Stat. 42-516)(cga.ct.gov)
  12. Fla. Stat. 501.702 (Florida Digital Bill of Rights definitions)(flsenate.gov)
  13. Florida SB 262 (2023), ch. 2023-201, effective July 1, 2024(flsenate.gov)
  14. Rhode Island Data Transparency and Privacy Protection Act, R.I. Gen. Laws ch. 6-48.1(rilegislature.gov)
Share: