US website privacy laws in 2026: CCPA, CIPA and state-by-state compliance guide

In 2026, navigating US website privacy laws is more challenging than ever. There’s no single federal privacy law that applies to every website. Instead, you have to navigate the minefield of complex state laws. Website compliance doesn’t stop at having a privacy policy – it now includes consent mechanisms, tracking controls, transparent disclosures, and state-specific privacy rights.
It’s no surprise that website owners are asking questions like, “Which US privacy laws apply to my website? Is complying with the California Consumer Privacy Act (CCPA) enough, or do I also need to worry about laws like the California Invasion of Privacy Act (CIPA) and privacy regulations in other states?” These are exactly the questions you should be asking, and they deserve clear answers.
In this guide, I cover important US website privacy requirements, explain which laws apply to your site, and show you simple steps to stay compliant. While the legal landscape can seem intimidating, I’ll keep things straightforward and leave the legal jargon to the lawyers.
Why US website privacy compliance is so fragmented in 2026
Trying to understand US privacy laws can feel like putting together a puzzle with pieces from 50 different boxes. There's no single federal law that applies to every website. Instead, each state creates its own privacy rules, enforcement standards, compliance thresholds, and technical requirements. That's a sharp contrast to the GDPR, which provides a clear framework for the whole EU.
There's another problem. You're actually dealing with two different compliance challenges. The first is about consumer privacy rights and transparency laws. An example is the CCPA, which requires businesses to inform users about the data they collect. It also grants users specific privacy rights. The second involves tech-related lawsuits under laws like CIPA. Because of that, businesses can get sued over how tools like analytics, chat widgets, or session recording software collect user data. Since these are distinct legal risks, websites need different compliance approaches.
CCPA and CPRA – compliance baseline most website operators know
CCPA compliance goes a little beyond publishing a privacy policy. You need to create processes and website features that allow your customers to use their privacy rights. At the same time, you must ensure that personal information is collected, used, and shared clearly. Regardless of what type of website you host, there are some of the key operational requirements:
- Providing a transparent privacy notice. Your privacy policy should clearly explain what personal information you collect, why you collect it, where it comes from, who you share it with, how long you retain it, and what rights consumers have.
- Honoring consumer privacy requests. You'll need a process for responding to requests to know what personal information has been collected, how to delete personal information, how to correct inaccurate data, and, where applicable, to provide a copy of the consumer's information.
- Offering opt-out rights for data sharing. If your website sells or shares personal information, like for advertising, you must give users an easy way to opt out. This process should be clear and easy to follow.
- Managing targeted advertising. Many advertising cookies, pixels, and third-party analytics tools may count as sharing personal information under the CCPA. As a result, you often need to let users choose how these technologies are used.
- Applying additional protections to sensitive personal information. If a website collects sensitive data like exact location, government IDs, bank details, or login info, consumers may be able to control how this information is used or shared.
What the CCPA means for cookies and tracking
Although the CCPA isn't technically a cookie law, it has a major impact on how websites use tracking technologies. It controls how companies share and handle third-party tracking, ad tools, and personal data. Since cookies can collect information like IP addresses, device identifiers, and browsing activity, they often fall within the CCPA's definition of personal information.
This means that you can't simply install advertising pixels and call it a day. If personal information is shared with third parties for targeted advertising, you must give users a way to opt out. That's why many websites are required to display a clear "Do Not Sell or Share My Personal Information" link. They must also automatically recognize and honor universal browser opt-out signals, allowing users to exercise their privacy rights without submitting a separate request.
What CPRA changed and why it matters
The California Privacy Rights Act (CPRA) is another law you'll often see mentioned in website compliance discussions. It took effect in 2023 and isn't a completely new law. Instead, it's an update to the CCPA that strengthens and expands its requirements.
The CPRA created a dedicated enforcement agency, the California Privacy Protection Agency (CPPA). It added stronger protections for sensitive personal information, reinforced data minimization principles, and clarified the rules for targeted advertising and data sharing. In other words, it raised the bar for privacy compliance in California.
That said, you don't need to comply with two separate California privacy laws. Think of the CPRA as the latest version of the CCPA. If your website falls under California's privacy rules, you must follow the updated CCPA requirements. This includes all of the stricter standards introduced by the CPRA.
CIPA – why California website compliance now goes beyond consumer rights
As you research US website privacy laws, you'll probably come across the CIPA. It's easy to confuse it with the CCPA, but they're completely different laws. The CIPA is a 1967 wiretapping law that has recently become a major concern for website owners. Originally, this law aimed to stop secret phone call recordings. Now, plaintiffs argue that some third-party tracking tools can “intercept” website visitors’ actions in real-time without consent.
This is a different legal theory from the CCPA. CCPA focuses on privacy disclosures and consumer rights, such as explaining data collection and allowing users to opt out. CIPA lawsuits focus on alleged real-time interception by tracking technologies.
That's an important point. Just having a privacy policy or a cookie banner doesn't guarantee protection from CIPA claims. If your website loads third-party analytics, ads, session replay tools, chat widgets, or similar tech before getting consent, plaintiffs may argue that those tools are illegally intercepting communications.
Which website technologies create the highest CIPA risk?
If you run a website, you probably rely on analytics, chat widgets, or marketing tools to understand visitors and improve conversions. While they help improve user experience and guide business decisions, some of these tools are now being mentioned in CIPA lawsuits.
Some think that specific tools like Meta Pixels or Hotjar are the problem, but that’s often not the case. The bigger question is what the tool collects, when it starts collecting it, and whether the user has given consent first.
| Tool category | Common examples | Why does it get attention in CIPA lawsuits | What website owners should look at |
| Advertising pixels | Meta Pixel, TikTok Pixel, LinkedIn Insight Tag | Plaintiffs argue these scripts may send browsing behavior, page visits, clicks, or other identifiers to third parties before a user agrees to tracking | Does the pixel load before consent? What data is being shared? Is it used for targeted advertising? |
| Session replay and heatmap tools | Hotjar, FullStory, Microsoft Clarity | These tools can record user interactions like clicks, scrolling, and form activity. Lawsuits often claim this creates a recording of user activity without permission | Are recordings anonymized? Are sensitive fields blocked? Does the tool start only after consent is given? |
| Chat widgets | Customer support chats, AI chat assistants, third-party messaging tools | Some complaints claim chat providers may receive conversation content or visitor information in real time | Does the chat vendor receive messages, metadata, or visitor details? Is the user informed before the conversation starts? |
| Analytics scripts | Google Analytics and similar tracking tools | The concern is usually that analytics scripts collect identifiers or browsing behavior before the visitor has made a privacy choice | Do analytics cookies or scripts fire before consent is given? Are non-essential trackers delayed until opt-in? |
CIPA compliance is less about removing every tracking tool from your website and more about making sure those tools are used transparently, with the right consent process in place.
Why a cookie banner alone doesn’t remove CIPA risk
Almost every website you visit has a cookie consent banner. But don't assume that simply adding a banner means you're compliant. Unfortunately, it’s not that simple.
The key difference is between telling users about cookies and getting real, prior consent before tracking begins. A banner that says “we use cookies” might just give notice. If analytics, advertising pixels, or other tracking tools run in the background, it doesn’t count as consent.
Laws like CIPA, where some plaintiffs argue that certain third-party tracking tools can act like real-time interception of user activity if they collect data before permission is given. While cookie banners are part of the solution, websites also need a good consent system that blocks non-essential cookies and tracking scripts before a user gives consent.
State-by-state picture – which other US privacy laws matter in 2026?
While CCPA, CPRA, and CIPA are all California laws, this isn’t to say you shouldn’t know them if your business is based in another state. What matters most isn't where your business is located – it's where your users are. So, a website with visitors from California may still have compliance obligations, even if the business itself is based in another state.
But that doesn’t mean you’ll have to tailor your website for each state separately. California is often the starting point for US privacy compliance. Many other states, including Colorado, Connecticut, and Virginia, have introduced their own privacy laws with somewhat similar requirements. Let’s break down the key US website privacy laws state by state.
Colorado, Connecticut, Virginia, Utah, and Texas
27 US states now have comprehensive privacy laws, and while they share many similarities, the details can vary. That said, if your website is already considering privacy notices, user rights, cookies, and vendor management, you’re already laying a solid foundation.
| State | What website owners should know | Threshold |
| Colorado (CPA) | Adds opt-out rights for targeted advertising and profiling, requires universal opt-out mechanisms (GPC), and has stricter consent expectations for sensitive data. | Businesses processing data of 100,000+ consumers/year, or 25,000+ consumers and deriving revenue or discounts from selling personal data |
| Connecticut (CTDPA) | Similar to Colorado, with strong protections around sensitive data, targeted advertising opt-outs, and children’s data. | Businesses processing data of 35,000+ consumers per year |
| Virginia (VCDPA) | Requires privacy notices, consumer rights (access, delete, correct, opt out), consent for certain sensitive data, and contracts with processors. No private right of action. | Businesses that process data of 100,000+ consumers/year, or 25,000+ consumers, and earn over 50% of revenue from selling personal data |
| Utah (UCPA) | Generally considered more business-friendly, with higher thresholds and fewer consumer rights obligations than many other states. | Businesses that process data of 100,000+ consumers/year and exceed $25M annual revenue, or process data of 25,000+ consumers and earn over 50% of revenue from selling personal data |
| Texas (TDPSA) | Applies broadly because it has no revenue threshold, but still includes familiar requirements like disclosures, rights requests, and processor agreements. | No specified threshold |
As of mid-2026, 12 states require businesses to recognize Global Privacy Control (GPC), including California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. GPC is a browser setting that lets users opt out of the sale or sharing of their personal information and targeted advertising with a single click. Instead of asking visitors to submit a separate opt-out request on every website, businesses must automatically honor the GPC signal where required by state law.
What these laws typically have in common
Although the details change from state to state, most privacy laws ask you to do the same core things:
- Be transparent about what personal data you collect, why you collect it, and who you share it with
- Respect user privacy rights, including requests to access, correct, delete, or receive a copy of personal data
- Provide opt-out options for targeted advertising and, where required, the sale or sharing of personal information
- Handle sensitive personal information with extra care, ensuring strong protections
- Keep personal data secure by using reasonable safeguards to protect it from unauthorized access or misuse
If your website is subject to multiple privacy laws, you may not need to build a different compliance process for every state. While there are important differences between laws, they overlap much more than they differ. A good consent management platform (CMP), along with a clear privacy policy, can help you meet shared requirements. This way, you won’t have to start from scratch every time a new law is introduced.
Where the most important differences show up
While each state has its own privacy law, most of the differences boil down to a few key compliance tasks. If you're making privacy updates, these are the areas worth paying the most attention to.
| Situation | What you may need to change |
| Your business meets a state's coverage threshold | Determine whether that state's privacy law now applies to you |
| You collect sensitive personal information | Update your consent flow if the state requires opt-in consent |
| You use targeted advertising or third-party tracking tools | Make sure users can opt out and that your site honors universal opt-out signals (GPC) where required |
| You receive consumer privacy requests | Review your response process, deadlines, and verification steps |
| You're documenting compliance | Keep records of consent and privacy requests, especially in states with stricter enforcement |
What website operators actually need to do to stay compliant
Knowing the rules is only half the job. You also need to put them into practice on your website. Below is an overview of concrete steps you should take to ensure your website stays compliant.
Step 1. Audit every cookie, pixel, script, and embedded tool
Start by finding out exactly what's running on your website. Many compliance issues start with poor understanding, as teams often don’t have a complete picture of every third-party script, cookie, and tracker loading on their site. Over time, plugins, campaign tags, marketing tools, and embedded vendors can add new trackers that are easy to miss.
A quick way to get started is by running a cookie scan. Cookiebot offers a free cookie scan that automatically detects cookies and trackers on your website, categorizes them, and gives you a clear overview of what's being collected before you begin your compliance review.
Before you make any compliance decisions, create a complete inventory of your cookies and scripts. This provides the foundation for understanding what data is being collected and where potential risks may exist.
Step 2. Separate essential from non-essential tracking
Not every cookie requires users' consent. So, it’s important to know the difference between essential and non-essential tracking. Essential tracking tools help keep website functions running smoothly. Non-essential tools gather extra data for analytics, advertising, personalization, or user behavior tracking.
Review each cookie, script, and tracking tool to determine its purpose and consent requirements. This step is especially important for managing CIPA risk, as certain tracking tools may expose the company to legal liability if they collect user data before consent is obtained.
Step 3. Configure consent before non-essential scripts fire
A consent banner alone isn’t enough to prevent compliance issues. One of the most common mistakes is allowing non-essential scripts to load in the background while only asking for consent afterward. To meet consent requirements, these trackers must be blocked at a technical level until a user makes an active choice.
Check your consent setup to make sure analytics, advertising, and other non-essential scripts don’t run before permission is given. A properly configured consent management platform can automate this process by blocking trackers until consent is collected, helping reduce privacy risks and potential CIPA exposure.
Step 4. Keep privacy and cookie disclosures accurate and up to date
Review your privacy disclosures regularly and update them whenever you add, remove, or change tracking tools. Make sure your cookie notice clearly explains what technologies are used, what data they collect, and why they are used. Keeping your disclosures aligned with your website’s actual setup helps reduce compliance gaps and builds greater trust with users.
Ensure that your privacy policy and cookie disclosure accurately reflect the tools and trackers your website actually uses. Generic statements about cookies or third-party tracking may not provide enough transparency if your site uses specific tools like Meta Pixel, Google Analytics, Hotjar, or similar tools.
Step 5. Build a repeatable process for rights requests and re-audits
Privacy compliance isn’t a one-time banner installation project. It needs regular revisions, which can be achieved through setting up repeatable processes for handling consumer rights requests, reviewing consent configurations after martech changes, reassessing vendor integrations, and conducting regular cookie re-audits.
Any new campaign, plugin, or third-party tool can introduce new trackers or change how data is collected. By scheduling regular reviews and updating consent configurations when changes occur, teams can identify new risks early and keep their privacy practices aligned with their website operations.
Managing multi-state compliance more simply – Cookiebot by Usercentrics
Managing privacy compliance across multiple US states can feel overwhelming, especially for smaller teams without dedicated privacy specialists. The challenge is not only understanding laws like CCPA and CIPA, but also keeping website tracking under control, updating consent settings, and maintaining proof that user choices are respected.
Instead of building a full privacy operations team, you can use tools that automate key compliance tasks and create repeatable processes. Cookiebot by Usercentrics helps simplify this work by combining cookie scanning, consent enforcement, and documentation into one workflow, including:
- Keeping track of every cookie and tracker. Automatic cookie scanning helps identify and categorize cookies, pixels, and other trackers, including tools added through tag managers, plugins, or third-party services. This gives teams a clearer view of what is collecting data on their website and helps keep privacy disclosures accurate.
- Enforcing consent before tracking begins. Cookiebot by Usercentrics helps automate script blocking, so tracking tools follow users' choices rather than collecting data immediately.
- Adapting content settings by location. Geo-targeted consent flows allow websites to apply stricter opt-in rules where needed while using different consent models for users in other jurisdictions.
- Maintaining records of user choices. Timestamped consent logs create a documented record of when and how users made their choices. These records can help you show your compliance efforts and respond more effectively to complaints or legal requests.
- Creating a manageable compliance workflow. Cookiebot by Usercentrics combines scanning, consent enforcement, location-based controls, and documentation to help you maintain a more reliable privacy process over time, allowing you to avoid complex systems needed to manage ever-changing privacy requirements.
Most common US privacy compliance mistakes websites still make
It's surprisingly easy to make privacy mistakes, even if you already have a cookie banner. These issues often happen when businesses focus on legal requirements and overlook technical steps needed to enforce privacy compliance.
| Common mistake | Why it creates risk |
| Treating CCPA as the only relevant law | Focusing only on California privacy rules can cause businesses to miss CIPA risks, new state privacy laws, or requirements specific to their industry and user base. |
| Assuming a banner equals compliance | A banner that allows tracking scripts to load before consent only provides notice, not true prior consent. |
| Failing to re-audit after website changes | New marketing campaigns, plugins, or third-party tools can add trackers without being noticed. |
| Leaving session replay tools ungated | Session replay and heatmap tools can capture detailed user behavior and are often linked to higher CIPA litigation risk. |
| Using outdated or vague disclosures | General descriptions of tracking practices may not meet modern expectations for transparency under state privacy laws. |
| Relying on legal text without technical enforcement | A privacy policy alone doesn’t prevent unauthorized data collection if tracking tools still operate without consent |
Conclusion – US privacy compliance in 2026 requires governance, not just disclosure
US privacy compliance has changed significantly. In 2026, it’s no longer just about adding a cookie notice and posting a privacy policy.
This means you need more than a privacy policy – you need clear disclosures, proper consent controls, and a repeatable process. As a result, US privacy compliance requires much more than disclosure – it requires active governance.
CCPA and CPRA set the California standard, while CIPA creates additional risks related to tracking scripts and user consent. Other state laws continue to expand these responsibilities. This doesn’t mean you must remove analytics or advertising tools to comply; you need to manage them properly. A simple step you can take today is to run a cookie scan of your site to evaluate your current consent configuration and identify areas for improvement before they become bigger issues.
FAQ
Does CCPA apply to every US website?
No, CCPA doesn’t apply to every website. Its application depends on factors like business size, revenue, the amount of personal data collected, and connections with California users. However, many websites follow CCPA-style privacy practices as a standard because US privacy laws are becoming increasingly stricter.
What is the difference between CCPA and CIPA?
CCPA is a privacy law that requires businesses to explain how they collect and use personal data and gives users rights over their information. CIPA is a wiretapping law that some plaintiffs have argued applies to certain website tracking technologies, such as third-party scripts and session replay tools, when they allegedly collect user interactions without consent. These laws create different privacy risks for businesses.
If I already have a cookie banner, am I compliant?
No, a cookie banner alone doesn't guarantee compliance. It must stop non-essential tracking tools from running until the user chooses to accept them. If the banner only shows a message but allows trackers to collect data immediately, it may not meet privacy requirements.
Which US states have privacy laws that affect websites in 2026?
California has the most website privacy requirements, including CCPA/CPRA and CIPA rules, which apply to all businesses that get traffic from the state. Other states with active privacy laws include Colorado, Connecticut, Virginia, Utah, and Texas. More states are passing or considering new privacy laws, making US website compliance requirements increasingly complex in 2026.
Why are session replay tools and ad pixels considered especially risky?
Session replay tools and ad pixels are considered especially risky because they collect and transmit behavioral data in real time. Session replay tools can capture detailed website activity, which some courts have compared to intercepting private communications, making them a common focus in CIPA lawsuits.
How can Cookiebot by Usercentrics help with multi-state compliance?
Cookiebot by Usercentrics helps websites automatically scan and classify cookies, block scripts until users give consent, support location-based consent flows for different legal regions, and keep timestamped records of user consent. This makes it easier for businesses to manage complex privacy compliance requirements across different jurisdictions.
Do smaller businesses need to worry about these laws?
Yes, in many cases, these laws also affect smaller businesses. Unlike other statutes that have thresholds for the smallest businesses, CIPA doesn’t have them, meaning it applies to any website accessible to California residents.