Real Results. Real Businesses.

We partner with businesses to build websites and growth systems designed to generate measurable results through strategy, design, optimization, and long-term marketing support.

Website Services Built Around Your Business

From custom websites and e-commerce to ongoing maintenance, we build fast, SEO-optimized websites that are easy to manage and designed to grow with your business.

Cookie Compliance for Websites: What Businesses Need to Know

Many businesses believe cookie compliance means installing a banner that says, “We use cookies,” and adding a privacy-policy link in the footer. That is not enough. A compliant setup may need to prevent certain tools from loading before consent, let visitors reject tracking as easily as they accept it, honor browser-based opt-out signals, accurately disclose…

The Strategic Foundation of a User Friendly Website

Download the Growth Playbook to build a clearer, more strategic website that attracts better clients.

Last Updated:

Published:

Collaborators

Many businesses believe cookie compliance means installing a banner that says, “We use cookies,” and adding a privacy-policy link in the footer.

That is not enough.

A compliant setup may need to prevent certain tools from loading before consent, let visitors reject tracking as easily as they accept it, honor browser-based opt-out signals, accurately disclose which companies receive data, and preserve a record of the visitor’s choice. This is why website privacy depends on what the website actually does, not simply whether the site displays a cookie banner or privacy policy.

The exact requirements depend on which laws apply to the business and its users. Those rules differ between countries and, within the United States, between states.

There is also an important misconception about location. A law does not necessarily apply simply because someone opens your website while physically located in that jurisdiction. Applicability may depend on where the person resides, whether your business targets that market, the type of information collected, and whether the business meets a law’s coverage thresholds.

For example, California says its privacy rights apply to California residents even when they are temporarily outside the state. The European Commission, however, provides an example where a company outside the EU is not automatically subject to the GDPR merely because existing customers can access its service while traveling in Europe. The company generally needs an EU establishment, to offer goods or services to people in the EU, or to monitor their behavior there. (Source: California Attorney General) (Source: European Commission)

The practical result is still complicated. If your website attracts customers from several states or countries, you may need a system capable of applying different rules or meeting a stricter common standard.

This article provides general information, not legal advice. A qualified privacy attorney should determine which laws apply to a specific business.

Cookie Compliance Covers More Than Cookies

The term “cookie compliance” is convenient, but the rules often cover more than traditional browser cookies.

Websites may store or access information through:

  • First-party cookies
  • Third-party cookies
  • Advertising pixels
  • Analytics tags
  • Local storage
  • Session storage
  • Embedded videos
  • Social-media widgets
  • Device identifiers
  • Software development kits
  • Browser fingerprinting
  • Session-replay tools

The UK Information Commissioner’s Office describes these more broadly as storage and access technologies. Its guidance states that the rules can apply whenever a technology stores information on, or accesses information from, a user’s device. (Source: UK Information Commissioner’s Office)

This matters because removing a visible cookie does not necessarily stop tracking.

A website may use Google Analytics, a Meta advertising pixel, embedded YouTube videos, HubSpot forms, call tracking, heatmaps, and an online scheduler. Each tool can collect or transmit different information.

The first step toward compliance is therefore not choosing a banner design. It is identifying what the website actually loads and where the collected information goes.

Not Every Cookie Is Treated the Same Way

Most compliance systems group website technologies into categories.

Strictly necessary cookies

These are required to provide a service the visitor explicitly requested. Examples may include authentication, shopping-cart functions, security, load balancing, and remembering information entered into a form.

European guidance states that cookies used solely to transmit communications or provide a specifically requested service can generally be used without prior consent. (Source: European Union)

Preference or functional cookies

These remember selections such as language, location, accessibility preferences, or display settings. Their legal treatment can depend on whether they are genuinely necessary to provide the requested experience.

Analytics cookies

These measure how people use a website, which pages they visit, and where problems occur. These tools can be valuable for understanding how visitors interact with a website, but their usefulness does not automatically exempt them from consent requirements. Businesses often assume analytics are automatically exempt because the data is used internally.

That is not universally true. European guidance lists analytics and market-research tracking among the technologies that may require prior consent. (Source: European Union)

Advertising and targeting cookies

These are typically used to create audiences, track visitors across sites, measure advertising, or personalize ads.

These technologies generally receive the most attention because they can involve multiple third parties, cross-site tracking, profiling, and the sharing or sale of personal information under certain laws.

Cookie Rules Differ Between Countries

There is no universal cookie law.

Different countries use different definitions, legal bases, exceptions, consent standards, and enforcement systems.

The European Union generally requires prior consent for nonessential tracking

Under the EU framework, certain cookies can be placed without consent when they are strictly necessary to provide a service requested by the user. Nonessential tools, including many advertising, social tracking, analytics, and market-research cookies, generally require consent before they load.

European guidance also says consent should be specific to different purposes and that withdrawing consent should be as easy as giving it. (Source: European Union)

This means a banner that loads advertising trackers immediately and only lets visitors “accept” what has already happened is not providing meaningful prior consent.

The EU ePrivacy Directive creates the broader cookie framework, while individual countries implement and enforce it through national law. This can produce differences in enforcement priorities, local guidance, and the exact treatment of particular technologies.

France’s privacy regulator, the CNIL, has taken repeated enforcement action over cookie practices, including whether cookies load before consent and whether rejecting or withdrawing consent actually works.

The United Kingdom uses PECR alongside the UK GDPR

UK cookie rules are primarily governed by the Privacy and Electronic Communications Regulations, commonly called PECR.

The ICO states that PECR can apply even when cookie information is anonymous. When the information is personal data, the UK GDPR can also apply. (Source: UK Information Commissioner’s Office)

The UK’s Data (Use and Access) Act 2025 introduced changes intended to allow some lower-risk uses without consent and increased the potential PECR fine to as much as £17.5 million or 4% of global turnover. Implementation has been phased, so businesses should use current ICO guidance rather than relying on an older cookie-banner template. (Source: UK Information Commissioner’s Office)

Canada may permit opt-out consent in limited situations

Canada’s approach to online behavioral advertising is not identical to the EU model.

The Office of the Privacy Commissioner of Canada says meaningful consent is required for behavioral advertising. It states that implied or opt-out consent may be acceptable when the practice is clearly explained, visitors can easily and persistently opt out, the information is not sensitive, and the data is limited and appropriately retained. (Source: Office of the Privacy Commissioner of Canada)

This illustrates why copying an EU banner and assuming it addresses every country is not a complete compliance strategy. The standards may overlap, but the legal reasoning and required controls can differ.

Brazil has its own LGPD cookie guidance

Brazil’s National Data Protection Authority has published specific guidance addressing cookies, personal-data protection, policies, and cookie banners under the LGPD. (Source: Brazil National Data Protection Authority)

The existence of country-specific guidance is another reason a universal banner cannot be assumed to resolve every obligation.

U.S. Cookie Rules Differ From State to State

The United States does not currently have one comprehensive federal privacy law governing every commercial website in the same way.

Instead, businesses must evaluate a combination of state privacy laws, federal consumer-protection rules, sector-specific laws, and laws governing sensitive information.

California focuses heavily on disclosure and opt-out rights

The California Consumer Privacy Act applies to for-profit businesses that do business in California and meet at least one statutory threshold:

  • More than $25 million in annual gross revenue
  • Buying, selling, or sharing personal information from 100,000 or more California residents or households
  • Receiving at least 50% of annual revenue from selling California residents’ personal information

Covered businesses must give required notices and let residents opt out of the sale or sharing of personal information, including sharing for cross-context behavioral advertising. (Source: California Attorney General)

California does not simply require every covered website to block all nonessential cookies until the user opts in. In many ordinary situations, the central requirement is disclosure and an effective right to opt out of sale or sharing.

Covered businesses must also process signals such as Global Privacy Control where applicable.

California reached a $1.2 million settlement with Sephora over allegations that the company failed to disclose the sale of personal information and failed to honor opt-out requests communicated through Global Privacy Control. (Source: California Attorney General)

Colorado requires covered businesses to honor Global Privacy Control

Colorado gives consumers the right to opt out of the sale of personal data and its use for targeted advertising.

Since July 1, 2024, businesses covered by the Colorado Privacy Act must allow consumers to exercise applicable opt-out rights through a recognized universal opt-out mechanism. Colorado currently recognizes Global Privacy Control for that purpose. (Source: Colorado Attorney General)

A cookie banner that appears compliant visually can still fail if it ignores the privacy signal already sent by the visitor’s browser.

Texas generally exempts small businesses, with an important exception

The Texas Data Privacy and Security Act generally exempts businesses that qualify as small businesses under the federal Small Business Administration’s standards.

However, a small business that sells sensitive consumer data must first obtain consent. Sensitive data includes precise geolocation and information about a child under 13. Texas can impose civil penalties of up to $7,500 per violation following the applicable cure process. (Source: Texas Attorney General)

This is a useful example of why “small businesses are exempt” is often an incomplete statement.

Washington expressly includes small businesses in its health-data law

Washington’s My Health My Data Act is particularly important for websites involving health, wellness, reproductive health, mental health, fitness, symptoms, medications, or location information associated with health services.

The law expressly defines and regulates small businesses. It can require a consumer-health-data privacy policy, affirmative consent for certain collection, separate consent for sharing, and processes for accessing or deleting data. (Source: Washington State Legislature)

Washington defines consumer health data broadly. It can include information identifying someone as seeking healthcare services, precise location near health services, and information inferred from other data. (Source: Washington State Legislature)

A violation is treated as an unfair or deceptive practice under Washington’s Consumer Protection Act, which creates more litigation exposure than many state privacy laws that reserve enforcement exclusively for the attorney general. (Source: Washington State Legislature)

The Visitor’s Current Location Is Only Part of the Analysis

Many cookie tools use IP geolocation to show different banners in different regions.

That can be useful, but it is not a complete legal analysis.

A person’s IP address may show where they are currently located, but applicable law may instead depend on:

  • Where the person resides
  • Whether the business targets that market
  • Where the company is established
  • Whether the business conducts business in the jurisdiction
  • How much data the company processes
  • Whether the data is sensitive
  • Whether the activity involves children
  • Whether the business sells or shares information
  • Whether an industry-specific law applies

A California resident traveling in Florida may still have California rights. A non-EU business does not necessarily become subject to the GDPR every time a traveler opens the site from Paris.

VPNs, mobile carriers, shared networks, travel, and inaccurate location databases also make geolocation imperfect.

A business therefore needs to decide whether it will:

  1. Apply one strict standard to most visitors
  2. Use regional configurations based on a documented legal analysis
  3. Restrict certain tracking tools in higher-risk locations
  4. Stop targeting or serving markets it is not prepared to support

Many smaller companies choose a relatively strict default because maintaining several regional configurations can create more technical and administrative complexity than using one well-designed system.

The Small-Business Question Is a Genuine Gray Area

Small businesses often assume privacy regulators are only interested in large technology companies.

Most high-profile fines do involve larger companies, but company size is not the only factor that determines risk.

The European Commission states that GDPR applicability depends on the nature of the organization’s activities, not simply its size. Some obligations may be reduced for certain small and medium-sized businesses, but an SME can still be fully subject to the regulation when its activities fall within scope. (Source: European Commission)

Small-business uncertainty usually comes from several issues.

Thresholds differ

A company may fall below the California thresholds but still be covered by another state law.

It may be exempt under the main Texas privacy act but subject to the sensitive-data exception.

It may be considered a small business under Washington’s health-data law, yet still have specific privacy-policy and consent obligations.

“We do not sell data” may not resolve the issue

Businesses often use the word “sell” in its ordinary sense. Privacy laws may define sale or sharing more broadly.

A company may never receive cash for customer information but may still transmit identifiers and browsing activity to advertising networks in exchange for advertising, analytics, audience matching, or other services.

Whether that qualifies as sale, sharing, targeted advertising, or another regulated activity depends on the law and the contracts involved.

Plugins can change the website’s data practices

A small business may install a chat widget, booking tool, video embed, heatmap, analytics service, or advertising pixel without realizing what information the tool collects. New plugins and integrations can also introduce hidden operational risks inside an otherwise functional website.

The privacy policy and banner may remain unchanged even though the site’s actual data flows are now different.

Low traffic does not always mean low risk

A small healthcare, legal, financial, fertility, therapy, or wellness website may receive relatively little traffic but process highly sensitive information.

The sensitivity of the data can matter more than the number of visitors.

Industry rules may apply outside comprehensive privacy statutes

A company that does not meet a state consumer-privacy threshold may still face obligations under health, financial, children’s privacy, consumer-protection, wiretapping, or data-breach laws.

Small businesses should therefore avoid relying on a single statement such as “the CCPA does not apply to us.” That may answer only one part of the analysis.

What Can Happen When a Website Is Not Compliant?

The consequences are not limited to receiving a fine.

A regulator may require the business to:

  • Stop using certain tracking tools
  • Redesign its consent process
  • Honor opt-out signals
  • Correct its privacy disclosures
  • Delete previously collected data
  • Contact third parties that received the data
  • Implement a formal privacy program
  • Complete audits or reports
  • Pay penalties or consumer refunds

California’s enforcement list includes a $1.55 million settlement with Healthline over allegations involving tracking technology, targeted-advertising opt-outs, and the sharing of information suggesting that a visitor may have a serious health condition. (Source: California Attorney General)

France’s CNIL fined the publisher of VanityFair.fr €750,000 in 2025 after finding that consent-required cookies loaded before a choice was made and that refusal and withdrawal mechanisms were ineffective. (Source: CNIL)

The FTC required GoodRx to pay a $1.5 million civil penalty after alleging it disclosed sensitive health information to companies including Facebook and Google without providing the required notification. (Source: Federal Trade Commission)

BetterHelp was required to pay $7.8 million after the FTC alleged it disclosed email addresses, IP addresses, and health-questionnaire information to advertising platforms despite privacy promises made to consumers. (Source: Federal Trade Commission)

These are larger companies, and their penalties should not be treated as predictions for a small local business. They show that pixels, advertising platforms, and website tracking can create real privacy consequences.

A small business may be more likely to face a complaint, demand letter, investigation, cure notice, vendor dispute, or expensive remediation project than a multimillion-dollar fine. Those outcomes can still be disruptive. Privacy failures can also affect website security, business continuity, compliance, and customer trust.

A Cookie Banner Does Not Create Compliance by Itself

A banner is only the visible control layer.

The underlying system needs to work.

A practical compliance setup may need to:

  1. Scan and inventory cookies, pixels, scripts, and embedded tools
  2. Categorize each technology based on its actual purpose
  3. Prevent nonessential tools from loading where prior consent is required
  4. Provide equally clear accept and reject choices
  5. Allow category-specific choices where required
  6. Honor Global Privacy Control and other applicable signals
  7. Store evidence of consent or opt-out choices
  8. Make changing or withdrawing a choice easy
  9. Keep the cookie and privacy policies accurate
  10. Review vendors, contracts, and data-sharing terms
  11. Retest the site after plugin, advertising, or analytics changes

A common failure occurs when the banner says tracking is disabled, but the Meta pixel or analytics script has already loaded.

Another occurs when “Reject All” changes the banner interface but does not stop existing trackers from being read.

The CNIL’s Vanity Fair enforcement specifically cited cookies loading before consent and continued tracking after visitors rejected or withdrew consent. (Source: CNIL)

Compliance therefore requires technical testing, not just reviewing the text shown to users.

A Practical Cookie-Compliance Process

Businesses can begin with five questions.

1. Which tools are installed?

Create an inventory of analytics, advertising pixels, embedded media, forms, CRM tools, chat, schedulers, heatmaps, and third-party scripts.

2. What information does each tool collect?

Determine whether the tool receives IP addresses, device identifiers, page URLs, form information, health-related data, location information, or other personal information.

3. Who receives the information?

Identify the service provider, advertising platform, CRM, analytics company, and any additional third parties.

4. Which users and markets does the business serve?

Consider where customers reside, which markets the business targets, and whether sensitive categories such as children or health information are involved. The business should already have a clear understanding of who the website is trying to attract, including the customer types, locations, and markets it actively serves.

5. What choices must the website provide?

Depending on the applicable rules, the site may need prior opt-in consent, an opt-out mechanism, Global Privacy Control support, separate sensitive-data consent, or a combination of these controls.

Cookie Compliance Is an Ongoing Website Responsibility

Cookie compliance is not completed once and then forgotten. It should be treated as part of ongoing website maintenance, because websites, plugins, tracking scripts, vendors, and privacy requirements change over time.

Websites change.

A marketing team adds a new advertising pixel. A scheduling tool updates its scripts. A plugin introduces analytics. A video platform changes its data practices. A new state privacy law becomes effective. The company begins advertising in another country.

Any of those changes can make the existing banner and policy inaccurate.

A useful compliance program should include:

  • Regular cookie and script scans
  • Testing before and after website changes
  • Review of new vendors
  • Updates to disclosures
  • Confirmation that reject and withdrawal controls work
  • Testing of Global Privacy Control
  • Periodic legal review
  • Documentation of decisions and configurations

The goal is not to create the largest possible banner or frighten every visitor with legal language.

The goal is to understand what the website collects, explain it accurately, provide the choices required by applicable law, and make sure those choices work.

A cookie banner is part of that system.

It is not the system itself.

The Strategic Foundation of a User Friendly Website

Download the Growth Playbook to build a clearer, more strategic website that attracts better clients.

Latest From Our Resources

Stay Ahead in Professional Services

Get practical insights on winning higher-value clients, improving lead quality, and building a more predictable pipeline delivered to your inbox.

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form