US state privacy laws
Since California went first, around twenty states have passed their own privacy laws, and more arrive each legislative session. They are broadly similar to each other and quite unlike the GDPR: the model is opt out rather than opt in, thresholds mean many businesses fall outside them entirely, and several now require you to honour an opt-out signal sent by the browser.
- No federal law
- Opt out, not opt in
- Thresholds decide who is covered
From €10 a month. No credit card, no per-visitor billing.
What these laws have in common
The details differ by state. The shape does not, and building for the shape covers most of them.
- Disclose what you collect, why, and who you share it with
- Offer an opt out of sale and of targeted advertising
- Honour access, deletion and correction requests
- Get consent before processing sensitive data
- Respect a universal opt-out signal from the browser
This page explains what the law asks for and what our software does about it. It is not legal advice, and it cannot tell you whether your organisation is compliant, because that depends on everything else you process.
What Consent Studio does about it
Serves the US model to US visitors
An opt out of sale and sharing rather than a prior consent prompt, applied by the visitor’s region. One configuration covers the EU, the UK and the United States without your team maintaining a version per market.
- By visitor region
- One configuration
- Opt in and opt out
Honours the universal opt-out signal
Global Privacy Control is applied on the first page load rather than after a banner interaction, which is the only way to honour it: the signal arrives before anybody clicks anything. Several states now require this and more are adding it.
- Global Privacy Control
- Before any click
- Applied per visitor
Records the request
An opt out is a request under these laws, and requests have to be evidenced. Each is stored with a timestamp and is exportable by your own staff rather than through a ticket with us.
- Timestamped
- Self-service export
- Per request
Where teams go wrong on the United States
Shipping the EU banner to everybody
It looks like the safe choice and it misses the point. A prior consent prompt does not provide the opt out of sale and sharing these laws actually require, so a site can block more than it needs to and still lack the required control.
Solving it state by state
Building a configuration per statute produces a maintenance burden that grows every legislative session and a matrix nobody can verify. The laws are similar enough that two mechanisms cover most of them, and the exceptions are worth advice rather than architecture.
Ignoring the browser signal
Universal opt-out mechanisms are required by several states and are sent by the browser, not clicked in your banner. A tool that only reacts to banner interactions never sees one, and the visitor has made a request that is going unanswered.
Essential
€10/month
For a single site that has to be compliant, and stay that way.
- Unlimited pages and displays
- 200,000 consent actions a month
- The full stack, not a starter tier
Professional
€36/month
For growing teams that run on data, and the agencies serving them.
Try Professional for FreeEnterprise
From €250/month
For a volume, or an obligation, a standard plan cannot answer.
Explore EnterpriseAgencies & Resellers
Buy at a partner rate and resell client sites at your own price.
Discover Partner ProgrammePublic Sector
Government, healthcare and education run on Enterprise.
See Enterprise
Running under rules like these, in more than one country
Other rules that may apply to you
Common questions about US state laws
Is there a federal US privacy law?
No comprehensive one. There are sector-specific federal statutes covering health, financial and children’s data, and general consumer privacy is left to the states. Around twenty have now passed comprehensive laws and the number grows each legislative session.
Do these laws apply to my business?
Most set thresholds based on revenue or the number of residents whose data you process, so many smaller businesses fall outside them entirely. They also generally apply to for-profit entities, which puts many non-profits outside their scope. Check the states where you have real volume rather than assuming all twenty.
Do I need a cookie banner in the United States?
Not in the European sense. What these laws ask for is notice and a clear way to opt out of sale and targeted advertising, plus consent before processing sensitive data. Prior consent before anything loads is a European requirement, and applying it in the US does not substitute for the opt out.
What is a universal opt-out mechanism?
A signal sent by the browser or an extension, most commonly Global Privacy Control, that communicates an opt out without the visitor interacting with your site. Several states require it to be honoured, and because it arrives before any click, a tool that only listens to banner interactions cannot honour it.
Does Consent Studio make us compliant?
No single tool can, and any vendor saying otherwise is selling you something. Consent Studio handles the part a consent platform can handle: asking properly, holding every tag to the answer, keeping the record, and telling you when the site changes. What you process elsewhere is yours.
Where is our consent data stored?
In Amsterdam, on infrastructure owned and operated by Scaleway, a French company. Ownership matters more than location here: Scaleway is independently French rather than a European subsidiary of a US parent, so neither they nor we fall under the US CLOUD Act. Consent Studio itself is built and owned in the Netherlands.
Get Started with the Full Consent Stack
Everything you need in one bundle. Consent Studio provides you with a consent banner, scanner and client-side tag manager that guarantees no data ever gets transferred overseas.
Read the documentation
Our help center walks through every integration, plugin and template step by step, with screenshots. It is written and kept current by the people who build Consent Studio.






