Wire / GDPR & Privacy Law / Article
┌── POST 07.21 · GDPR & Privacy Law · 4 min read

US State Privacy Laws 2026: Cookie Banner Cheat Sheet

US state privacy laws 2026 now cover more than half the US population, yet most cookie banners are still configured as if only California exists. Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Indiana, Iowa — and several newcomers — each carry distinct scope thresholds, opt-out signal requirements, and sensitive-data rules. This cheat sheet maps the key variables so you know exactly what your consent UI needs to do in each jurisdiction.

Why US State Privacy Laws 2026 Demand a Multi-State Approach

Unlike the GDPR, there is no single federal US privacy law in force. Instead, a patchwork of state statutes has emerged — each with its own revenue or volume threshold for applicability, its own definition of sensitive data, and its own stance on whether you must honour the Global Privacy Control (GPC) browser signal. Treating them as interchangeable is the fastest route to enforcement exposure. For context on how aggressive enforcement is becoming, see Cookie Compliance Lawsuits: Is Your Site a Target?.

The 2026 State-by-State Comparison Table

The table below covers the eleven active state laws plus Florida’s SB 262 (limited scope) and New Jersey’s P.L. 2023 (effective January 2025). “GPC Required” means the law explicitly mandates honouring the opt-out preference signal as a valid opt-out of sale or targeted advertising.

State / Law In Force Threshold (consumers) GPC Required Sensitive Data Opt-In Banner Config Needed
California CPRA Jan 2023 100k / $25M revenue Yes (AG confirmed) Yes Opt-out of sale/sharing + Do Not Sell link + sensitive opt-in
Virginia VCDPA Jan 2023 100k / 25k if 50% revenue from data No statutory mandate Yes Opt-out of targeted ads; sensitive opt-in consent
Colorado CPA Jul 2023 100k / 25k if 50% revenue from data Yes (rules effective Jul 2024) Yes Universal opt-out mechanism + GPC pass-through + sensitive opt-in
Connecticut CTDPA Jul 2023 100k / 25k if 25% revenue from data Yes (Jan 2025 onwards) Yes Opt-out of targeted ads; GPC honoured; sensitive opt-in
Utah UCPA Dec 2023 100k / $25M revenue No No (opt-out only) Opt-out of sale and targeted ads; no GPC obligation
Texas TDPSA Jul 2024 Processes data of TX residents; small-biz exemption Yes (recognised signal) Yes GPC-compliant opt-out; sensitive consent; privacy notice
Oregon OCPA Jul 2024 100k / 25k if 25% revenue from data Yes Yes GPC honoured; sensitive opt-in; broad sensitive-data definition
Montana MCDPA Oct 2024 50k (lower threshold) Yes Yes GPC mandatory; sensitive opt-in; lower scope threshold to watch
Tennessee TIPA Jul 2025 175k / 25k if 50% revenue from data No Yes Opt-out of targeted ads; sensitive opt-in; no GPC obligation
Indiana INCDPA Jan 2026 100k / 25k if 50% revenue from data No Yes Opt-out UI; sensitive consent; no universal signal mandate
Iowa ICDPA Jan 2025 100k / 25k if 50% revenue from data No No (opt-out only) Opt-out of sale and targeted ads; lightest obligations of the group
New Jersey NJDPA Jan 2025 100k / 25k if 50% revenue from data Yes Yes GPC honoured; sensitive opt-in; closely mirrors Colorado model

What Each Cookie Banner Configuration Must Actually Do

The table above distils to three practical banner tiers for 2026.

  • Tier 1 — GPC + sensitive opt-in required (California, Colorado, Connecticut, Texas, Oregon, Montana, New Jersey): Your CMP must detect the GPC header and suppress sale and targeted-ad cookies automatically, without a user clicking anything. Sensitive-data processing needs a separate affirmative consent path.
  • Tier 2 — Opt-out UI required, no GPC mandate (Virginia, Tennessee, Indiana): A visible opt-out link or toggle for targeted advertising is sufficient. GPC compliance is best practice but not legally compelled.
  • Tier 3 — Lightest obligations (Utah, Iowa): An opt-out mechanism for sale and targeted ads covers you. No sensitive opt-in required; no GPC obligation.

Configuring Your CMP for Multi-State Compliance

Most enterprise CMPs support geo-targeted rule sets. In practice, the safest default is to apply the Tier 1 configuration to all US visitors, then relax rules for Tier 3 states if your legal counsel approves. This avoids under-serving Colorado or Oregon residents who happen to browse without a geo-detectable IP. For teams evaluating platforms, the CCPA vs CPRA comparison at CCPA vs CPRA 2026 covers California-specific configuration in more depth.

Three Things to Audit Before End of 2026

  1. GPC detection: Confirm your CMP reads the Sec-GPC: 1 header and fires an opt-out signal before any ad or analytics tag loads.
  2. Sensitive-data flows: Map every cookie or pixel that could infer health, location, race, or sexual orientation data. States with sensitive opt-in requirements treat these differently from standard targeting cookies.
  3. Privacy notice alignment: Several 2026 laws require the notice to list the categories of third parties receiving data. A generic “we use cookies” statement no longer meets the bar in most of these states.

US state privacy laws 2026 are no longer edge-case compliance. If your site processes data for 100,000 or more US residents annually, you almost certainly fall under multiple state regimes simultaneously. Aligning your cookie banner configuration to the Tier 1 standard — GPC detection, sensitive opt-in, and geo-aware rule sets — gives you the most defensible position across the whole map.

Worried your site (or a client’s) is exposed? Run a free cookie compliance scan with CookieInspector to see every tracker firing before consent — the #1 trigger for privacy demand letters. Law firm? See how firms audit client sites for cookie risk.

C
About the author
Consent Mode HQ
Editorial team at Consent Mode HQ
Read more by author ↗