CCPA, CPRA and US state law

CCPA cookie banner requirements: notice, opt-out and GPC in 2026

A practical guide to California's notice and opt-out requirements, balanced privacy choices, Global Privacy Control, and testing what your tags do after a consumer opts out.

Published
Updated
Reading time
9 min

The CCPA does not impose a general requirement to obtain consent before placing every non-essential cookie. For a covered business, the starting points are notice at or before collecting personal information and an effective way to exercise applicable privacy rights, including opting out of sale or sharing.

A banner can help deliver those controls. Its presence does not establish compliance, and its absence does not, by itself, establish a violation. The important questions are what the business collects, how it uses and discloses that information, and whether the consumer's choice changes those activities.

This guide covers the CCPA as amended by the CPRA. It separates the California requirements from suggested implementation checks. Other laws and particular processing activities may impose additional obligations.

Establish whether the CCPA applies

The main business definition covers a for-profit entity doing business in California that determines the purposes and means of processing consumers' personal information and meets at least one threshold:

  • Annual gross revenue over $26,625,000 in the preceding calendar year, assessed as of 1 January.
  • Annually buying, selling or sharing the personal information of 100,000 or more consumers or households, alone or in combination.
  • Deriving 50% or more of annual revenue from selling or sharing consumers' personal information.

The revenue amount is the inflation-adjusted threshold effective from 1 January 2025, still applicable in 2026. Sources: Civil Code § 1798.140(d) and the Agency's monetary threshold notice.

100,000 website visits is not the statutory test. Assess the relevant California consumers or households and the buying, selling or sharing activity. The preceding-calendar-year wording above belongs to the revenue test; do not apply it indiscriminately to every threshold.

Related-entity rules and exemptions can affect the assessment. Being below the revenue threshold alone does not settle applicability.

Give notice before collection

The Attorney General's notice guidance explains that consumers must receive notice at or before collection. A conspicuous link can be used in the appropriate context; a mandatory pop-up is not the only format.

The notice should cover the categories of personal information, including sensitive information, the purposes, whether categories are sold or shared, and retention periods or criteria. It also needs the relevant opt-out notice link and privacy-policy link. A cookie inventory alone does not explain those practices.

Under 11 CCR § 7012, a link into a privacy policy must lead directly to the section containing the required notice, rather than making readers search the entire policy.

For implementation, map every collection point to its notice: the introductory page, checkout, account registration, embedded forms and app interfaces. Check the first network activity as well as the visible page. A notice that appears after collection begins does not solve the timing requirement.

Keep notice and consent distinct. A California configuration may use an opt-out model for relevant adult activity, but it must still honour existing opt-outs and GPC. Consent can be required in specific circumstances, including sale or sharing where the business knows the consumer is under 16, with parental authorisation for under-13s. See the Attorney General's explanation of children's sale/sharing protections.

Make the privacy choice clear and balanced

The CPPA's dark-patterns advisory emphasises understandable language and symmetrical choices. The effect of an interface matters, even where the designer did not intend to obstruct the consumer.

If a banner offers an acceptance path, do not make the more protective choice harder to find or complete. A useful design pattern is a direct refusal action beside acceptance, with optional settings for more detail. The labels must describe what those actions actually do.

Avoid treating a particular colour, pixel size or three-button layout as a universal legal template. Review prominence, meaning and the complete interaction. A visually balanced pair of buttons still fails the consumer if refusal opens a lengthy form while acceptance takes effect immediately.

Honda's order documents a two-step advertising-cookie opt-out and a one-step return to allowing cookies. Its remedy included a “Reject All” control. See the Honda order, paragraphs 53–65 and 77.

For the preference centre, our suggested review is:

  • Use labels that make the active choice explicit.
  • Count the steps for refusal and acceptance, including confirmation screens.
  • Test a return visit after an earlier opt-out.
  • Check keyboard focus, screen-reader labels, zoom and smaller screens.
  • Check the languages used for consumer-facing information.

Accessibility is part of the disclosure requirement. Section 7003 references recognised standards such as WCAG 2.1; it does not state the simple blanket “WCAG 2.1 AA” rule sometimes attributed to it.

Provide a working opt-out route

The standard link is “Do Not Sell or Share My Personal Information”. The alternative is “Your Privacy Choices” or “Your California Privacy Choices”, with the prescribed opt-out icon. Its colour may be adjusted for visibility. Sections 7013 and 7015 place these links in the header or footer of the business's internet homepages.

The exception for frictionless signal processing requires all conditions in § 7025(f)–(g), including disclosures and full effectuation. Installing GPC detection alone is insufficient. See the current CCPA regulations.

As an implementation choice, a shared footer is a useful way to keep the route available throughout a site. Test it from product pages, campaign pages and checkout, rather than only the homepage.

The destination should make the right understandable and actionable. “Manage cookies” should not lead consumers to believe they have stopped sale or sharing if it only changes a subset of browser cookies. Keep the rights route available after dismissing a banner.

For the form behind the link, collect only necessary information and avoid identity-verification gates. Ford's order illustrates the failure caused by making email confirmation a condition of processing. See the Ford order and our opt-out form guide.

Honour GPC and show the result

The California Attorney General confirms that covered businesses that sell or share personal information must honour Global Privacy Control as a valid sale/sharing opt-out request. A manual form does not replace signal handling.

The GPC specification describes the HTTP header Sec-GPC: 1 and the browser property navigator.globalPrivacyControl. These expose the preference to different parts of an implementation. The law does not prescribe a particular server framework or require a specific three-line code sample.

Our engineering recommendation is to inspect the signal wherever decisions about disclosure are made. Check that a CDN, cache, tag manager or server endpoint does not lose it, and that browser-side handling happens before an affected transfer.

Under § 7025, processing covers the browser/device and associated profiles, including pseudonymous profiles, and the consumer if known. The website must display whether it processed the signal. The absence of a later signal is not a known consumer's consent to opt back in. See the 2026 regulations, § 7025(c).

Show an accurate status, such as “Your sale and sharing opt-out is active”, only when it is true. A message saying “GPC detected” describes an input, not the result of processing it.

Disney's settlement illustrates why account associations matter: a choice confined to one service or device did not fully stop sale or sharing for recognised consumers. Test the associated account as well as the original browser. See the Attorney General's Disney announcement.

Under Civil Code § 1798.140, sale involves monetary or other valuable consideration. Sharing concerns cross-context behavioural advertising, regardless of payment. Qualifying service-provider and contractor processing may fall outside those definitions, subject to the applicable conditions.

A tag name alone cannot resolve the classification. Assess its configuration, payload, destination, purpose and recipient's permitted and actual use. Avoid blanket claims that every GA4 installation is a sale or every advertising request has the same legal treatment.

Use a transfer inventory alongside the cookie scan:

LayerSuggested inspectionUseful evidence
BrowserRequests before and after opting out, including embedded contentNetwork captures and tag configuration
ServerForwarding, conversion APIs and scheduled exportsDestination settings and processing logs
Accounts and appsWhether associated clients read the updated preferenceTest-account results across clients
RecipientsHow restrictions reach the recipient and affect useApplicable agreements and configuration

Deleting a cookie does not by itself stop server-side exports. Conversely, a continuing network request is not automatically proof of prohibited sale or sharing. Determine what the request does.

Google Consent Mode controls how Google's tags respond to storage and data-use choices. Its values are granted and denied, not JavaScript booleans. The four commonly used types are ad_storage, analytics_storage, ad_user_data and ad_personalization. Google documents their meanings and the order of default and update calls in its implementation guide.

Consent Mode does not provide the notice, decide whether processing is sale or sharing, or control every non-Google destination. In advanced mode, Google tags can send cookieless measurements while storage consent is denied. A denied state therefore does not mean no data is transmitted. See Google's Consent Mode overview.

Document how each privacy choice maps to vendor settings. Inspect actual requests after the update. Do not use a generic “Accept All” handler that silently overwrites an active sale/sharing opt-out.

Detailed configuration belongs in our Consent Mode implementation guide and basic versus advanced comparison.

A practical pre-release review

Use these checks as an engineering review, not a guarantee of compliance:

  1. Scope: record the applicability assessment and which transfers constitute sale or sharing.
  2. Notice: compare the deployed collection with the notice's categories, purposes, retention and links.
  3. Choice: follow acceptance and refusal through completion on desktop and mobile.
  4. Access: reopen the privacy controls after dismissal, using a keyboard as well as a pointer.
  5. Manual opt-out: submit without creating an account or completing an identity-verification challenge.
  6. GPC: use a fresh profile with the signal enabled; compare the displayed status with actual transfers.
  7. Persistence: revisit the site and test an associated account on another client.
  8. Integrations: check browser tags, server forwarding and advertising exports separately.
  9. Failures: interrupt an integration and confirm that monitoring catches the incomplete update.
  10. Ownership: keep the configuration version, expected result, observed result and responsible owner with the test record.

The Attorney General's guidance states that opt-outs must be fulfilled as soon as feasibly possible, within a maximum of 15 business days. Treat that as an outer limit, not a routine waiting period.

Penalties and enforcement context

For 2026, the Agency's published administrative fine limits are up to $2,663 per violation, or $7,988 for an intentional violation or one involving a consumer actually known to be under 16. These are maximum amounts, not an automatic price per banner error. See the current monetary threshold notice.

An opportunity to cure in Agency enforcement is discretionary under § 1798.199.45. Do not assume a guaranteed 30-day repair window. This is distinct from the provisions governing certain private data-breach claims.

For concrete findings and remedies, use our Honda, Ford and Disney case review. A settlement's specific reporting or audit obligation should not be presented as an automatic requirement for every other business.

FAQ

Do all sites need an Accept All and Reject All banner?

No. Determine the applicable notice and rights requirements first. If acceptance and refusal controls are offered, make the choices clear and balanced. A banner layout is one part of the implementation.

Can one platform support California and other regions?

Yes, but the configuration and notices need to reflect the applicable rules. A global prior-consent approach still needs California rights handling, including GPC and appropriate opt-out scope. Separate state laws also require their own assessment; California compliance is not a nationwide certification.

No. It helps identify browser storage, but can miss server transfers, account-level preferences and scheduled exports. Combine it with the transfer and journey checks above.

Not automatically. Review the full frictionless-processing exception discussed above before changing the available rights routes.

Further reading

For a transfer-by-transfer decision framework, see CCPA sale vs. sharing: analytics and advertising explained.

Continue with the CCPA audit framework, CCPA and CPRA comparison, or Global Privacy Control guide.

For help reviewing your current banner and integrations, request a free consent audit or discuss your CCPA and GPC setup.

Portrait of Doğancan Doğan
Written bySolution Engineer, Privacy Engineering

Solution engineer who has implemented consent management on 200+ corporate websites globally. Specialises in CCPA and GDPR operational compliance.

Keep reading

Related guides.

All of CCPA, CPRA and US state law →
  1. 01Honda, Ford and Disney: CCPA lessons for cookie banners and opt-outsCCPA, CPRA and US state law · May 2026
  2. 02CCPA opt-out forms: collect only what you need, without identity verificationCCPA, CPRA and US state law · May 2026
  3. 03CCPA vs. CPRA: what changed and what businesses need to reviewCCPA, CPRA and US state law · May 2025

See what fires before consent on your own site.

A free audit of your current banner and tags across regions, with the findings in writing and a 30-minute call to go through them.