15.4 State Cookie and Online-Tracking Rules
Key Takeaways
- U.S. comprehensive state laws regulate sale, sharing, and targeted advertising of personal data; they do not copy the EU ePrivacy cookie-consent rule
- California consumers opt out of sale and of sharing for cross-context behavioral advertising; Colorado consumers opt out of sale and of targeted advertising — similar adtech results, different statutory hooks
- California, Colorado, and Connecticut require controllers to honor a universal opt-out mechanism or opt-out preference signal; Oregon’s UOOM duty became mandatory on 1 January 2026; Global Privacy Control is the common qualifying signal, and Colorado formally designated it
- A cookie banner is not a federal U.S. requirement; it is one interface for honoring opt-outs and collecting valid sensitive-data or sale consent
- Dark-pattern limits apply to consent and to opt-out flows: pre-checked boxes, bundled terms, and an “Accept all” path that is easier than refusal are not valid consent under CCPA regulations, MHMD, and VA-style consent definitions
There Is No Federal Cookie-Banner Statute
The United States does not have an ePrivacy Directive. There is no federal law that says “set a cookie, show a banner, obtain prior consent.” The Federal Trade Commission Act still reaches deception if a site says it does not track and then sells a behavioral profile. Sectoral rules (COPPA, HIPAA portal pixels, GLBA sharing) still apply. Domain V’s tracking question is different: state comprehensive privacy laws treat advertising cookies, mobile advertising IDs, pixels, and similar identifiers as personal data, and they give consumers a right to opt out of sale, sharing, and targeted advertising. A banner can be how the site honors those rights. The banner is not, itself, the legal requirement.
Teaching “U.S. sites need GDPR cookie consent” as if it were U.S. law is an exam fail. A U.S. company that offers goods to the European Union may owe General Data Protection Regulation (GDPR) and ePrivacy consent to EU visitors. That is a Domain I transfer and multinational problem. It is not California law, Colorado law, or a federal cookie rule.
Sale, Share, and Targeted Advertising
Two statutory vocabularies do most of the work.
California (CCPA / CPRA). A sale is disclosing personal information to a third party for monetary or other valuable consideration. Sharing is a CPRA term of art: disclosing personal information to a third party for cross-context behavioral advertising, whether or not money changes hands. Cross-context behavioral advertising is targeting advertising to a consumer based on personal information obtained from the consumer’s activity across businesses, distinctly-branded websites, applications, or services other than the business with which the consumer intentionally interacts. The consumer’s right is to opt out of sale or sharing. The homepage must offer a “Do Not Sell or Share My Personal Information” link, or an authorized alternative such as a cookie preference tool that actually stops the sale or share, plus processing of an opt-out preference signal. California also gives a limit the use of sensitive personal information right that is not the same as the sale/share opt-out.
Colorado (Colorado Privacy Act) and the Virginia-style majority. A sale is the exchange of personal data for monetary or other valuable consideration. Targeted advertising is displaying advertisements to a consumer where the advertisement is selected based on personal data obtained from that consumer’s activities over time and across nonaffiliated websites or applications to predict preferences or interests. Contextual ads on the site the consumer is currently visiting, first-party ads, and ads based on a consumer’s visit to the controller’s own properties are generally carved out. The consumer’s right is to opt out of sale, targeted advertising, and certain profiling. Colorado does not use California’s word “sharing.”
Functionally, a third-party advertising cookie that retargets a Colorado visitor on another company’s site is targeted advertising (and may also be a sale if the identifier is exchanged for value). The same cookie on a California visitor is sharing for cross-context behavioral advertising (and may also be a sale). CIPP/US wants the hook named correctly.
| Hook | California | Colorado (and most VA-style laws) |
|---|---|---|
| Money-or-value disclosure to a third party | Sale | Sale |
| Cross-site / cross-app behavioral ads, even without money | Share (cross-context behavioral advertising) | Targeted advertising |
| Consumer control | Opt out of sale and sharing; limit sensitive PI | Opt out of sale, targeted advertising, and covered profiling |
| Interface language | “Do Not Sell or Share My Personal Information” | Opt-out of targeted advertising / sale, often inside a privacy-choices page |
First-party analytics that never leave the controller, service-provider processing under a contract that forbids reuse, and true contextual ads are the usual “this is not a sale or share” defenses. They fail if the “analytics” vendor keeps the right to use the data for its own advertising graph.
Scenario. A news site drops a third-party demand-side-platform pixel that sends the visitor’s cookie ID and article section into a real-time bid. No cash changes hands at the moment of the bid; the site is paid later for the impression. In California that disclosure is at least a share, and likely a sale if the consideration analysis is met. In Colorado it is targeted advertising, and likely a sale. A “We do not sell data for money” footer does not finish the analysis in either state.
Universal Opt-Out Mechanisms and Global Privacy Control
A universal opt-out mechanism (UOOM) or opt-out preference signal (OOPS) is a browser or extension setting that says, once, “do not sell or share / do not use for targeted advertising.” Global Privacy Control (GPC) is the signal the industry actually ships.
As of August 2026, the verified core is:
- California. CCPA regulations require businesses to process opt-out preference signals that meet specified criteria. GPC is the common qualifying signal. The business must treat the signal as a valid request to opt out of sale and sharing for that browser or device, and it may not require extra steps that sabotage the signal.
- Colorado. The Colorado Privacy Act requires controllers to honor a UOOM. The Colorado Attorney General formally designated GPC as a valid UOOM. Colorado is the jurisdiction with an official designation process; do not invent a similar designation in every other state.
- Connecticut. The Connecticut Data Privacy Act requires controllers to recognize a UOOM for sale and targeted-advertising opt-outs.
- Oregon. IAPP’s official 5 January 2026 news item states that, as of 1 January 2026, Oregon covered entities must now recognize UOOM signals (alongside the HB 2008 children’s and geolocation amendments). Official IAPP: https://iapp.org/news/a/new-year-new-rules-us-state-privacy-requirements-coming-online-as-2026-begins.
Other comprehensive-law states have also enacted UOOM-recognition duties, including Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, and Texas. Do not treat a consulting-firm “12-state” graphic as an official census; name the statute you mean. The usual no-UOOM-mandate cluster includes Virginia, Utah, Iowa, and — per the same IAPP 2026 article — Rhode Island, which omitted UOOM recognition from its statute.
A qualifying signal is not a GDPR consent withdrawal and not a “delete everything” request. It is an opt-out of the sale / share / targeted-advertising uses the statute names. Authenticated-account rules can differ from browser-level rules; California’s regulations address how a business applies a signal when the consumer is logged in. Do not invent a single national protocol beyond what each statute and regulation actually require.
Banners, Consent, and Dark Patterns
If a banner is used, it has to do a real legal job:
- Honor opt-outs — stop sale, sharing, and targeted advertising for consumers who refuse or who send GPC, including before the advertising cookies fire.
- Collect valid consent where the statute requires opt-in: sale of sensitive data in Virginia-style laws, sale of a known child’s data, MHMD collection or sharing of consumer health data, or any processing the business has chosen to put on a consent footing.
Consent in these statutes is a clear affirmative act. It is not a pre-checked box, not silence, not scrolling, and not hovering. Dark patterns (deceptive design) that impair user choice spoil consent and can independently violate CCPA regulations, Colorado, Connecticut, Oregon’s consent definition, and MHMD’s ban on deceptive design. An “Accept all” button in a high-contrast primary color next to a grey “Manage” maze, with advertising cookies already writing on page load, is the textbook fail. Symmetric “Accept all” / “Reject all” choices, a GPC listener that actually suppresses the pixels, and a residual first-party cookie that is not a sale are the textbook pass.
Sensitive-data processing is the other reason a U.S. site might ask for a click. Virginia-style laws generally require consent before processing sensitive data (health, precise geolocation, racial or ethnic origin, genetic or biometric data used to identify, children’s data, and similar categories). That consent is not “we showed a cookie wall.” It is purpose-specific opt-in. MHMD is stricter still for consumer health data.
Scenario. A national retailer serves the same homepage to everyone. A California visitor’s browser sends GPC. A Colorado visitor clicks “Reject targeted ads.” A Virginia visitor never sees a banner; the site just writes a third-party retargeting cookie. The California and Colorado choices must be honored as sale/share or targeted-advertising opt-outs. The Virginia cookie is lawful only if the retailer either does not sell / target or has provided the required notice and opt-out and, if any cookie field is sensitive data (for example precise geolocation), has consent. None of the three visitors is owed a GDPR-style prior-consent banner as a matter of U.S. state law.
Exam traps
- Cookie banners are not a federal U.S. requirement.
- Do not teach GDPR/ePrivacy cookie consent as if it were California or Colorado law.
- California sharing ≠ Colorado targeted advertising as words, even when the pixel is the same.
- GPC is a UOOM implementation. Colorado designated it; other UOOM states require a mechanism that meets their criteria.
- Oregon’s UOOM duty is a 1 January 2026 fact; Rhode Island’s statute, per IAPP, does not include UOOM recognition.
- Dark patterns invalidate consent; they are not a clever way to keep the advertising cookie.
A U.S.-only retailer that does not target the European Union wants to know whether federal law requires a GDPR-style cookie-consent banner before any advertising cookie is set. Which statement is correct?
A news site sends a visitor’s cookie ID to a demand-side platform that retargets the visitor on unrelated websites. No cash moves at the moment of the bid. How should a CIPP/US candidate classify that disclosure?
As of August 2026, which statement about universal opt-out mechanisms is accurate?