Cookie Consent Banner Requirements: What US State Law Actually Says
Key Takeaways
- Neither the California Consumer Privacy Act nor the Colorado Privacy Act contains a provision requiring a website to present a cookie banner
- California requires a Notice at Collection at or before the point of collection under Cal. Code Regs. tit. 11, § 7012, and Civil Code § 1798.135 offers a choice between posting opt-out links and processing an opt-out preference signal
- Section 7004(a)(2)(C) names a banner offering only "Accept All" and "More Information" as an asymmetrical choice, regulating the banner rather than requiring it
- Colorado requires consent before processing sensitive data under C.R.S. § 6-1-1308(7), which is the clearest case in either state where an affirmative interface does legal work
- Colorado's definition of consent at C.R.S. § 6-1-1303(5) excludes acceptance of broad terms of use, closing a banner, and anything obtained through dark patterns
No State Privacy Statute Requires a Cookie Banner
The overlay asking a visitor to accept or manage cookies is the most visible artifact of privacy law on the American web, and it is not required by any American privacy statute. It arrived here from the European Union, where Article 5(3) of the ePrivacy Directive conditions the storing of information on a subscriber's terminal equipment on consent, and where the interface became the standard way of obtaining it. The two most-cited state privacy regimes in the United States are built on a different premise.
California's is an opt-out regime for the conduct that tracking technology usually supports. Civil Code section 1798.120, subdivision (a)(1), gives a consumer "the right, at any time, to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer's personal information." The right is exercised by direction from the consumer, and nothing in the section conditions collection on prior agreement. Colorado runs on the same axis: section 6-1-1306(1)(a)(I) of the Colorado Revised Statutes gives a consumer the right to opt out of processing for targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects.
That difference in premise is why the question "what are the cookie consent banner requirements" has no direct answer in either statute. What both have are requirements about notice and about the availability of an opt-out path. A banner is one way a business might discharge those, and in California's regulations it appears mainly as an object of constraint.
What California Requires at the Point of Collection
The operative obligation is the Notice at Collection. Section 7012 of title 11 of the California Code of Regulations states its purpose as providing consumers "with timely notice, at or before the point of collection, about the categories of personal information to be collected from them, the purposes for which the personal information is collected or used, and whether that information is sold or shared." Subsection (d) supplies the consequence: "If a business does not give the Notice at Collection to the consumer at or before the point of collection of their personal information, the business shall not collect personal information from the consumer."
What the notice has to contain is set out in subsection (e): the categories of personal information to be collected, including sensitive personal information, each written "in a manner that provides consumers a meaningful understanding of the information being collected"; the purposes for which those categories are collected and used; whether each category is sold or shared; the retention period for each category or the criteria used to set it; the "Do Not Sell or Share My Personal Information" link where the business sells or shares; and a link to the privacy policy.
Subsection (c) then lists how the notice may be delivered, and the list is permissive rather than prescriptive. Where a business collects personal information online, "it may post a conspicuous link to the notice on the introductory page of the business's website and on all webpages where personal information is collected." Other illustrative examples cover webforms, mobile application download pages, printed forms, signage and oral notice by telephone. A link satisfies the regulation; an interstitial overlay is nowhere named as the required form.
One case in section 7012 does call for something that surfaces on its own. Subsection (c)(4) provides that where a business collects personal information from a mobile device "for a purpose that the consumer would not reasonably expect," it must give a just-in-time notice summarising the categories collected and linking to the full notice, and the regulation's own example is a flashlight application that collects geolocation, with the notice given "such as through a pop-up window when the consumer opens the application."
A Link, or a Signal: the Choice Section 1798.135 Offers
Civil Code section 1798.135, subdivision (a), directs a business that sells or shares personal information to post a link titled "Do Not Sell or Share My Personal Information," and, where it uses or discloses sensitive personal information beyond the permitted purposes, a second titled "Limit the Use of My Sensitive Personal Information." Subdivision (b) makes that route optional. A business "shall not be required to comply with subdivision (a)" if it instead allows consumers to opt out through an opt-out preference signal sent with the consumer's consent by a platform, technology or mechanism meeting the regulatory standard.
Section 7025 sets that standard. Subsection (b) requires a business that sells or shares personal information to process any signal that is "in a format commonly used and recognized by businesses" — the regulation offers an HTTP header field or a JavaScript object as examples — and whose sender makes clear to the consumer that using it is meant to opt them out. Subsection (c)(1) then requires the business to treat a conforming signal "as a valid request to opt-out of sale/sharing submitted pursuant to Civil Code section 1798.120 for that browser or device and any consumer profile associated with that browser or device, including pseudonymous profiles."
Neither branch of that choice is a banner. One is a link on a page; the other is a header the browser sends before any interface renders.
The Rules Describe Banners Only to Constrain Them
Where the California regulations do address the banner directly, it is to describe a design that fails. Section 7004, subsection (a), requires methods for submitting requests and obtaining consent to be easy to understand and to incorporate "symmetry in choice," defined so that "[t]he path for a consumer to exercise a more privacy-protective option shall not be longer or more difficult or time-consuming than the path to exercise a less privacy-protective option because that would impair or interfere with the consumer's ability to make a choice."
Subsection (a)(2)(C) applies that to the banner by name: "A website banner that provides only the two options, 'Accept All' and 'More Information,' or, 'Accept All' and 'Preferences,' when seeking the consumer's consent to use their personal information is not equal or symmetrical because the method allows the consumer to 'Accept All' in one step, but requires the consumer to take additional steps to exercise their rights over their personal information." The regulation closes with an alternative rather than a mandate: "An equal or symmetrical choice could be between 'Accept All' and 'Decline All.'"
The surrounding examples run the same way. Subsection (a)(2)(B) treats a choice between "Yes" and "Ask me later" as unequal because there is no option to decline; subsection (a)(2)(D) treats a design where the "yes" button is "more prominent (e.g., larger in size or in a more eye-catching color) than the 'no' button" as neither equal nor symmetrical. Section 7004 is drafted as a rule about how a choice is presented once a business decides to present one, which is a different instrument from a rule requiring the presentation.
Where an Interface Does Legal Work in Colorado
Colorado's opt-out provisions describe placement without describing form. Section 6-1-1306(1)(a)(III) requires a controller that processes personal data for targeted advertising or sale to "provide a clear and conspicuous method to exercise the right to opt out," and to provide that method "clearly and conspicuously in any privacy notice required to be provided to consumers under this part 13, and in a clear, conspicuous, and readily accessible location outside the privacy notice." Since July 1, 2024, section 6-1-1306(1)(a)(IV)(B) has also required controllers to let consumers exercise the targeted-advertising and sale opt-outs "through a user-selected universal opt-out mechanism that meets the technical specifications established by the attorney general." The Colorado Department of Law's published list of recognised mechanisms contains one entry, the Global Privacy Control, and the Department states that the list "does not exclude additional UOOMs from meeting the requirements of the CPA and its regulations now or in the future."
The provision that gives an interface a defined legal role sits immediately after. Section 6-1-1306(1)(a)(IV)(C) provides that notwithstanding a consumer's decision to opt out through a universal mechanism, "a controller may enable the consumer to consent, through a web page, application, or a similar method, to the processing of the consumer's personal data for purposes of targeted advertising or the sale of personal data, and the consent takes precedence." That is a permission, not a duty, and it is the one place in either state's law where a web page asking for agreement is named as a mechanism with a stated effect on an existing signal.
The stronger case is sensitive data. Section 6-1-1308(7) provides that "[a] controller shall not process a consumer's sensitive data without first obtaining the consumer's consent or, in the case of the processing of personal data concerning a known child, without first obtaining consent from the child's parent or lawful guardian." That is an affirmative-agreement requirement stated as a precondition to processing, and it does not depend on a consumer asserting anything first. Section 6-1-1308.5, effective October 1, 2025, adds a further consent condition for controllers offering an online service to a consumer they know or willfully disregard to be a minor, covering targeted advertising, sale, and profiling in furtherance of decisions with legal or similarly significant effects.
What Counts as Consent, and What Does Not
Where consent is required, Colorado defines it narrowly. Section 6-1-1303(5) defines consent as "a clear, affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement," and then excludes three things by name: "[a]cceptance of a general or broad terms of use or similar document that contains descriptions of personal data processing along with other, unrelated information"; "[h]overing over, muting, pausing, or closing a given piece of content"; and "[a]greement obtained through dark patterns."
Two of those exclusions describe common banner behaviour directly. A design that treats dismissal of an overlay as agreement falls within the second, and a design that buries processing terms in a general acceptance falls within the first. California reaches the same point from the other direction in section 7004, subsection (a)(3), which provides that "[a] consumer's silence or failure to act affirmatively does not constitute consent."
California requires affirmative authorisation in one clearly marked case. Civil Code section 1798.120, subdivision (c), provides that a business shall not sell or share the personal information of a consumer it has actual knowledge is under 16 unless the consumer, if at least 13, or a parent or guardian, if under 13, "has affirmatively authorized the sale or sharing." The subdivision adds that a business "that willfully disregards the consumer's age shall be deemed to have had actual knowledge of the consumer's age."
Where the Two States Diverge
| Question | California | Colorado |
|---|---|---|
| Is a banner required by the statute | No provision requires one | No provision requires one |
| Notice at or before collection | Cal. Code Regs. tit. 11, § 7012(a), (d) | Privacy notice under C.R.S. § 6-1-1308(1)(a) |
| Opt-out route | Links under Civ. Code § 1798.135(a), or a signal under § 1798.135(b) | Clear and conspicuous method under § 6-1-1306(1)(a)(III), plus a universal mechanism since July 1, 2024 |
| Consent required before processing sensitive data | Right to limit use, exercised by the consumer | Yes, as a precondition under § 6-1-1308(7) |
| Named rule on banner design | § 7004(a)(2)(C), symmetry in choice | Dark-pattern exclusion in the consent definition, § 6-1-1303(5)(c) |
| Interface that overrides an opt-out signal | Business-specific setting conflict handled by § 7025(c)(3) | Consent through a web page takes precedence, § 6-1-1306(1)(a)(IV)(C) |
The divergence that matters is structural rather than cosmetic. California's regime treats the interface as a regulated surface: section 7004 constrains how a choice is framed, and section 7025(c)(3) tells a business what to do when a signal conflicts with a business-specific setting, providing that the business "shall process the opt-out preference signal as a valid request to opt-out of sale/sharing, but may notify the consumer of the conflict and provide the consumer with an opportunity to consent." Colorado's regime instead identifies a category of data — sensitive data, and the data of known children and minors — where processing does not begin without agreement.
Neither approach produces a general banner obligation, and the reasons a given site displays one are frequently unrelated to either statute: the operator may be within the scope of the ePrivacy Directive and the General Data Protection Regulation for European visitors, may be applying one global interface rather than branching by jurisdiction, or may be relying on a consent management platform configured to a European default. Whether a particular site's arrangement satisfies a particular state's provisions turns on facts specific to that site.
Background
For the underlying law rather than this development: California privacy law, Colorado privacy law.
Frequently Asked Questions
Does the CCPA require a cookie consent banner?
What does section 7004 say is wrong with an "Accept All" and "More Information" banner?
When does Colorado law actually require consent rather than an opt-out?
Can closing a banner count as agreement under the Colorado Privacy Act?
If a website honors the Global Privacy Control, does it still need an opt-out link in California?
Sources
Everything above is reported from these documents. Follow them to verify.
- California Privacy Protection Agency — approved text of the CCPA regulations, Cal. Code Regs. tit. 11, div. 6 (including §§ 7004, 7012 and 7025) (September 22, 2025) regulation
- California Civil Code § 1798.135 — notice and opt-out links, and the opt-out preference signal alternative statute
- California Civil Code § 1798.120 — right to opt out of sale or sharing, and affirmative authorization for consumers under 16 statute
- Colorado Revised Statutes 2024, Title 6 — Colorado Privacy Act, C.R.S. §§ 6-1-1303, 6-1-1306, 6-1-1308 and 6-1-1308.5 (December 31, 2024) statute
- Colorado Attorney General — Universal Opt-Out and the Colorado Privacy Act, the published list of recognized mechanisms registry
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.