[ US states ]

    US state privacy laws and cookie consent

    Short answer: a growing number of US states have comprehensive consumer privacy laws, and the count keeps changing. Many states require businesses to recognize browser or device signals such as Global Privacy Control. Because the rules differ, check the statute for each state where you have customers.

    • Comprehensive state privacy laws
    • Global Privacy Control

    How many states have privacy laws?

    Sources disagree depending on when they were written. A MultiState article dated 4 February 2026 said twenty states then had comprehensive privacy laws, and that the Indiana, Kentucky and Rhode Island laws took effect on 1 January 2026. It said those three new laws largely follow Virginia's template. A later Byte Back article (its URL is dated June 2026; the copy reviewed showed no date or author) says 24 states now have comprehensive consumer privacy laws, and that Alabama, Louisiana, Oklahoma and Vermont were added in 2026 and are not yet in effect. The IAPP keeps a state legislation tracker; its details are for members.

    What most state laws have in common

    The sources above support only a few general points. For anything more specific — who is covered, which rights apply, effective dates — check the statute for that state.

    • Several newer laws follow an existing model: MultiState says the Indiana, Kentucky and Rhode Island laws largely follow Virginia's template.
    • Many states require businesses to recognize browser-based or device-level signals such as Global Privacy Control, according to Byte Back.
    • Some laws are passed but not yet in effect. Byte Back lists Alabama, Louisiana, Oklahoma and Vermont as added in 2026 and not yet in effect.
    • California is covered separately. See the CCPA / CPRA guide for California details.

    How CookieJar handles it

    CookieJar lets you vary the banner by state. CookieJar is software, not legal advice.

    • Detects the visitor's US state by location.
    • Serves a banner variant per state, so you can set different behaviour where a state's law requires it.
    • Honors the Global Privacy Control signal automatically.

    How to work through each state

    Because the facts available here are general, the practical approach is to list the states where you have customers and then work through each one. For every state, check the statute for that state to confirm whether it has a comprehensive privacy law, whether that law is in effect yet, and whether it requires you to recognize signals such as Global Privacy Control. Use the IAPP tracker as a starting point if you are a member, and keep a note of the date you checked, because counts and effective dates change. For California, use the CCPA / CPRA guide. Once you know which states need different treatment, set up a banner variant for each of them.

    Common mistakes

    These follow from the facts above.

    • Relying on a fixed number of states. Counts change, and sources written months apart give different totals.
    • Treating a passed law as already in effect, or the other way round. Check the effective date in the statute for that state.
    • Ignoring Global Privacy Control. Many states require businesses to recognize it.
    • Assuming every state copies California. Some newer laws largely follow Virginia's template instead.
    • Guessing at a state's rules. Where you are unsure, check the statute for that state.

    [ FAQ ]

    Common questions

    Counts change; last reviewed 3 October 2026 by CookieJar team.

    Need our DPA or security details?

    One email and you'll have everything your security and legal teams need.

    View DPA