US state privacy laws

Since California went first, around twenty states have passed their own privacy laws, and more arrive each legislative session. They are broadly similar to each other and quite unlike the GDPR: the model is opt out rather than opt in, thresholds mean many businesses fall outside them entirely, and several now require you to honour an opt-out signal sent by the browser.

  • No federal law
  • Opt out, not opt in
  • Thresholds decide who is covered

From €10 a month. No credit card, no per-visitor billing.

What these laws have in common

The details differ by state. The shape does not, and building for the shape covers most of them.

  • Disclose what you collect, why, and who you share it with
  • Offer an opt out of sale and of targeted advertising
  • Honour access, deletion and correction requests
  • Get consent before processing sensitive data
  • Respect a universal opt-out signal from the browser

This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.

What Consent Studio does about it

  • Serves the US model to US visitors

    An opt out of sale and sharing rather than a prior consent prompt, applied by the visitor’s region. One configuration covers the EU, the UK and the United States without your team maintaining a version per market.

    • By visitor region
    • One configuration
    • Opt in and opt out
  • Honours the universal opt-out signal

    Global Privacy Control is applied on the first page load rather than after a banner interaction, which is the only way to honour it: the signal arrives before anybody clicks anything. Several states now require this and more are adding it.

    • Global Privacy Control
    • Before any click
    • Applied per visitor
  • Records the request

    An opt out is a request under these laws, and requests have to be evidenced. Each is stored with a timestamp and is exportable by your own staff rather than through a ticket with us.

    • Timestamped
    • Self-service export
    • Per request

Where teams go wrong on the United States

  1. Shipping the EU banner to everybody

    It looks like the safe choice and it misses the point. A prior consent prompt does not provide the opt out of sale and sharing these laws actually require, so a site can block more than it needs to and still lack the required control.

  2. Solving it state by state

    Building a configuration per statute produces a maintenance burden that grows every legislative session and a matrix nobody can verify. The laws are similar enough that two mechanisms cover most of them, and the exceptions are worth advice rather than architecture.

  3. Ignoring the browser signal

    Universal opt-out mechanisms are required by several states and are sent by the browser, not clicked in your banner. A tool that only reacts to banner interactions never sees one, and the visitor has made a request that is going unanswered.

Essential

€10/month

For a single site that has to be compliant, and stay that way.

  • Unlimited pages and displays
  • 200,000 consent actions a month
  • The full stack, not a starter tier
Try Essential for FreeNo credit card required. 7 day free trial.
  • Professional

    €36/month

    For growing teams that run on data, and the agencies serving them.

    Try Professional for Free
  • Enterprise

    From €250/month

    For a volume, or an obligation, a standard plan cannot answer.

    Explore Enterprise
  • Agencies & Resellers

    Buy at a partner rate and resell client sites at your own price.

    Discover Partner Programme
  • Public Sector

    Government, healthcare and education run on Enterprise.

    See Enterprise

Running under rules like these, in more than one country


  • Philips, the Dutch electronics group, using Consent Studio for cookie consent
  • Erasmus Universiteit Rotterdam, managing cookie consent with Consent Studio
  • America Today, a fashion retailer using Consent Studio across its webshop
  • Van Vulpen, an infrastructure contractor using Consent Studio for cookie consent
  • EuroParcs, a European holiday park operator running Consent Studio on its booking sites
  • Optica, a Dutch opticians chain using Consent Studio for consent management
  • Jeans Centre, a Dutch fashion retailer using Consent Studio for cookie consent
  • Mondiaen, a Tilburg primary school foundation, running Consent Studio across its school websites
  • Fiterman Pharma, a pharmaceutical company using Consent Studio for cookie consent
  • Eddie Rockets, a hospitality group managing cookie consent with Consent Studio
  • Veneta, a kitchen retailer using Consent Studio for consent management
  • MS Mode, a fashion retailer running Consent Studio across its European webshops
  • Dynamis
  • SB Supply
  • The Chosen

Other rules that may apply to you

Common questions about US state laws

Is there a federal US privacy law?

No comprehensive one. There are sector-specific federal statutes covering health, financial and children’s data, and general consumer privacy is left to the states. Around twenty have now passed comprehensive laws and the number grows each legislative session.

Do these laws apply to my business?

Most set thresholds based on revenue or the number of residents whose data you process, so many smaller businesses fall outside them entirely. They also generally apply to for-profit entities, which puts many non-profits outside their scope. Check the states where you have real volume rather than assuming all twenty.

Do I need a cookie banner in the United States?

Not in the European sense. What these laws ask for is notice and a clear way to opt out of sale and targeted advertising, plus consent before processing sensitive data. Prior consent before anything loads is a European requirement, and applying it in the US does not substitute for the opt out.

What is a universal opt-out mechanism?

A signal sent by the browser or an extension, most commonly Global Privacy Control, that communicates an opt out without the visitor interacting with your site. Several states require it to be honoured, and because it arrives before any click, a tool that only listens to banner interactions cannot honour it.

Does Consent Studio make us compliant?

No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.

Where is our consent data stored?

In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.

Get Started with the Full Consent Stack

Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.

Read the documentation

Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.

Which privacy policy?

We publish two, and they cover different audiences. Pick the one that describes you.