Guide
Cookie Consent Requirements by Country
Cookie laws differ dramatically from one jurisdiction to the next. Some demand explicit opt-in consent before a single tracking pixel fires. Others allow cookies by default and only require an opt-out mechanism. This guide breaks down the patchwork of global cookie and privacy laws so you know exactly what each region expects — and what happens when you get it wrong.
At a glance
Global Cookie Consent Comparison
A side-by-side comparison of cookie consent requirements across the jurisdictions that matter most. Use this table as a quick reference, then read the detailed sections below for implementation guidance.
| Region | Key Law | Consent Model | Enforcement Body | Max Penalty |
|---|---|---|---|---|
| European Union | GDPR + ePrivacy Directive | National DPAs (CNIL, BfDI, AEPD, etc.) | €20M or 4% global revenue | |
| United Kingdom | UK GDPR + PECR | ICO | £17.5M or 4% global revenue | |
| US — Federal | No comprehensive law | FTC (sectoral) | Varies by sector | |
| California | CCPA / CPRA | CA Privacy Protection Agency | $7,500 per intentional violation | |
| Colorado | CPA | CO Attorney General | $20,000 per violation | |
| Connecticut | CTDPA | CT Attorney General | $5,000 per violation | |
| Virginia | VCDPA | VA Attorney General | $7,500 per violation | |
| Texas | TDPSA | TX Attorney General | $7,500 per violation | |
| Oregon | OCPA | OR Attorney General | $7,500 per violation | |
| Other US States | 19+ state laws active | State Attorneys General | $5,000 – $20,000 per violation | |
| Brazil | LGPD | ANPD | 2% of BR revenue (R$50M cap) | |
| Canada — Federal | PIPEDA + CASL | OPC | $10M CAD (CASL) | |
| Canada — Quebec | Law 25 | CAI | $25M CAD or 4% global revenue |
European Union
GDPR + ePrivacy Directive
The European Union maintains the strictest cookie consent regime in the world. The ePrivacy Directive requires prior consent before any non-essential cookie or tracking technology is placed on a user's device, while the GDPR defines what valid consent looks like and sets the penalties for getting it wrong.
The Legal Framework
Cookie consent in the EU is governed by two interlocking pieces of legislation. The ePrivacy Directive (2002/58/EC, as amended in 2009) established the rule that storing information on a user's terminal equipment — which includes cookies, local storage, fingerprinting scripts, and tracking pixels — requires the user's prior informed consent, unless the cookie is strictly necessary for the service the user has explicitly requested. The GDPR (Regulation 2016/679), which came into force in May 2018, provides the definition of valid consent and the enforcement mechanisms. Together, these laws create the opt-in consent model that applies across all 27 EU member states.
The European Commission formally withdrew the long-awaited ePrivacy Regulation in February 2025, ending years of legislative uncertainty. This means the existing ePrivacy Directive remains the legal backbone for cookie consent rules in Europe. The withdrawal has had an important practical effect: national Data Protection Authorities are now enforcing the current rules more aggressively and uniformly, with no expectation that the framework is about to change.
What Valid Consent Requires
Under GDPR Article 7 and Recital 32, valid consent for cookies must meet all of the following criteria:
- Freely given — Users must have a genuine and free choice. Consent cannot be a precondition for accessing a service. Cookie walls that block access until a user clicks "Accept" are non-compliant in most EU jurisdictions.
- Specific — Consent must be granular. Users should be able to accept or reject cookies by purpose category (such as analytics, marketing, and preferences) rather than being presented with a single all-or-nothing choice.
- Informed — Before consenting, users must be told what cookies will be set, who sets them, what data is collected, and for what purposes. A vague statement like "we use cookies to improve your experience" is not sufficient.
- Unambiguous — Consent requires a clear affirmative action. Pre-ticked checkboxes, implied consent through continued browsing, and scroll-based consent mechanisms are all invalid under EU law.
- Withdrawable — Users must be able to withdraw consent as easily as they gave it. A "manage preferences" link should be accessible at all times, not just during the initial banner interaction.
Strictly Necessary Exemption
The only cookies exempt from the consent requirement are those that are strictly necessary for the functioning of the service the user has explicitly requested. This narrow exemption covers session identifiers for shopping carts, authentication tokens for logged-in users, load balancing cookies, and security cookies that detect fraud or authentication abuse. It does not cover analytics cookies, preference cookies (such as language selection), or any form of advertising or tracking cookies — all of these require consent.
Enforcement and Penalties
Enforcement is handled by national Data Protection Authorities across the EU's 27 member states. The maximum penalty for GDPR violations is the higher of 20 million euros or 4% of annual global turnover. Cookie-specific fines have escalated dramatically in recent years. France's CNIL has been the most aggressive enforcer: it fined Google 150 million euros in 2021 and then 325 million euros in September 2025 for making cookie rejection harder than acceptance, and it fined SHEIN 150 million euros in September 2025 for placing cookies before consent was obtained and for failing to provide a working "Reject all" button.
Key 2025–2026 developments: DPAs across Europe are now proactively scanning websites rather than waiting for complaints. The Dutch DPA monitors approximately 10,000 websites annually and plans to warn 500 organizations per year. Denmark's Datatilsynet has announced that cookie compliance is an enforcement priority for 2026. Sweden's DPA has ordered equal visual prominence for accept and reject buttons. Regulators are coordinating enforcement and using automated tools to detect violations at scale.
The EU Cookie Fatigue Reforms
The European Commission has acknowledged the problem of "cookie fatigue" — the phenomenon where users mindlessly click "Accept" on every banner without reading anything. In response, the Commission has proposed targeted reforms aimed at reducing the administrative burden on businesses and improving user experience while preserving strong data protection. These are not a reopening of the GDPR; the core consent requirements remain intact. The reforms focus on streamlining how consent is collected, potentially allowing browser-level consent signals to satisfy website-level requirements. These proposals are still under development as of early 2026.
United Kingdom
UK GDPR + PECR
After Brexit, the United Kingdom retained the substance of EU data protection law but now operates its own regulatory framework. Cookie consent is governed by the Privacy and Electronic Communications Regulations (PECR), which requires prior consent for non-essential cookies, while the UK GDPR provides the definition of consent and the enforcement powers.
Core Consent Requirements
Under PECR, consent is required before storing or accessing information on a user's terminal equipment via cookies or similar technologies. The requirements largely mirror the EU framework: consent must be freely given, specific, informed, and unambiguous. Pre-ticked checkboxes, implied consent through continued browsing, and preloading tracking technologies before obtaining consent all violate PECR. Users must be able to refuse tracking as easily as they can accept it, and cookie walls that force users to accept tracking in order to access essential services are non-compliant.
The Data (Use and Access) Act 2025
The most significant change to UK cookie law since Brexit is the Data (Use and Access) Act (DUAA), which received Royal Assent on 19 June 2025. The DUAA does not replace existing legislation but introduces important amendments to PECR. The most notable change is the introduction of new exceptions to the consent requirement for certain low-risk cookie uses. Consent is no longer required for cookies used solely for statistical analytics, website appearance or preference settings, security functions, fraud detection and fault prevention, or automatic authentication. However, organizations must still provide users with clear information about these cookies and offer a mechanism to opt out.
This divergence from EU law is significant. Under the EU's ePrivacy Directive, analytics cookies still require prior opt-in consent. Under the amended UK PECR, they no longer do, provided the organization is transparent about their use and offers an opt-out. Organizations subject to both UK and EU law will need to maintain different consent configurations for users in each jurisdiction.
ICO Enforcement
The Information Commissioner's Office is the UK's data protection regulator. Following a year-long review of the country's 1,000 most-visited websites, the ICO reports that more than 95% now meet its cookie compliance standards. In 2025, the ICO issued cookie compliance warnings to 134 UK websites for consent walls and insufficient transparency, imposing strict deadlines for remediation before opening formal investigations.
The DUAA has also dramatically increased the penalty exposure for PECR breaches. The previous cap of 500,000 pounds has been removed and replaced with a maximum of 17.5 million pounds or 4% of worldwide annual turnover, whichever is higher. This aligns PECR penalties with UK GDPR penalties, meaning that cookie violations now carry the same maximum fine as any other data protection breach.
Advertising cookies — a divergence to watch: The ICO has proposed relaxing its enforcement approach for certain lower-risk advertising cookies. The regulator plans to publish a statement in early 2026 specifying the advertising activities that are unlikely to trigger enforcement action under PECR, with the goal of enabling new approaches to online advertising to scale up. This represents a clear divergence from the EU's strict consent requirements for advertising technologies.
Structural Changes Ahead
The ICO itself is being restructured. The DUAA provides for the replacement of the Information Commissioner's Office with a new "Information Commission" (IC), expected to be in place by 2027. The IC will adopt a corporate governance model with a chief executive and a board, similar to Ofcom. For businesses, the practical implication is that UK cookie enforcement will continue and likely intensify under the new structure, even as certain consent requirements become less strict.
United States
A Patchwork of State Privacy Laws
The United States has no federal cookie law. Instead, a rapidly expanding patchwork of state privacy legislation governs how businesses must handle cookies, consent, and personal data. These laws predominantly follow an opt-out model rather than the opt-in model used in Europe, but they still carry real compliance obligations and growing enforcement activity.
No Federal Cookie Law
As of February 2026, there is no comprehensive federal privacy or cookie law in the United States. Various federal proposals have been introduced over the years, including the American Data Privacy and Protection Act (ADPPA), but none have been enacted. The FTC has sectoral authority over deceptive and unfair business practices, which can include misleading cookie disclosures or privacy policy misrepresentations, but it does not have a general mandate to regulate cookie consent in the way that European DPAs do. Without a federal framework, the regulatory burden falls entirely on individual states.
The Opt-Out Model
US state privacy laws take a fundamentally different approach from European law. Rather than requiring opt-in consent before cookies are set, most state laws allow businesses to use cookies by default but require them to give users the ability to opt out of certain processing activities — specifically the sale of personal data, targeted advertising, and profiling. This means that technically, no US state law requires you to show a cookie consent banner in the European sense. However, if your website uses cookies for targeted advertising, cross-site tracking, or data sales, you must provide transparency about this data collection, offer a clear opt-out mechanism (such as a "Do Not Sell or Share My Personal Information" link), and honor universal opt-out signals like Global Privacy Control (GPC). For sensitive data processing, 16 of the 19 active state laws now require opt-in consent, though each state's definition of "sensitive personal information" differs slightly.
California — CCPA / CPRA
California's Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), remains the most significant state privacy law in the country and the de facto national standard for US privacy compliance. The law applies to for-profit businesses that meet revenue or data volume thresholds and serve California residents. Key cookie-related requirements include providing a conspicuous "Do Not Sell or Share My Personal Information" link on the website, disclosing in the privacy policy what cookies are used and for what purposes, honoring browser-based opt-out signals such as Global Privacy Control automatically, and obtaining opt-in consent before selling the personal information of consumers under 16 years of age. The California Privacy Protection Agency enforces the law, with penalties of up to 2,500 dollars per unintentional violation and 7,500 dollars per intentional violation. Starting August 1, 2026, every registered data broker in California must also connect to a state-operated deletion platform, retrieve consumer deletion requests every 45 days, and process them automatically, with penalties of 200 dollars per request per day for missed deadlines.
Key State Laws Active in 2026
By early 2026, comprehensive privacy laws are active in more than 19 states, with three new laws taking effect on January 1, 2026. The regulatory landscape continues to expand rapidly.
Colorado (CPA)
Active since July 2023. Requires opt-out for targeted advertising and sale of personal data. Universal opt-out mechanism must be honored. Fines up to $20,000 per violation.
Connecticut (CTDPA)
Active since July 2023. Requires opt-out for targeted advertising, data sales, and profiling. GPC signals must be recognized. Amendments in 2026 expand obligations.
Virginia (VCDPA)
Active since January 2023. Consumers can opt out of targeted advertising, sale of data, and profiling. Requires prior consent for processing sensitive data.
Texas (TDPSA)
Active since July 2024. Broad applicability with no revenue threshold. Opt-out for targeted advertising and data sales. Expected aggressive enforcement in 2026.
Oregon (OCPA)
Active since July 2024. Covers a broad definition of personal data. Requires opt-out mechanisms and consent for sensitive data processing. Amendments expand scope in 2026.
Montana (MCDPA)
Active since October 2024. Consumer opt-out rights for targeted advertising and data sales. Requires data protection assessments for high-risk processing.
Maryland (MODPA)
Active from October 2025, with full enforcement from April 2026. Stricter data minimization requirements and explicit consent obligations for sensitive data.
Kentucky (KCDPA)
Active from January 1, 2026. Applies to entities processing data of 100,000+ consumers. Fines up to $7,500 per incident. Standard opt-out model.
Rhode Island (RIDTPPA)
Active from January 1, 2026. Notable for having no cure period — violations result in immediate fines with no grace period to fix the issue.
Other states with active comprehensive privacy laws include Utah, Florida, Delaware, Iowa, New Hampshire, Nebraska, New Jersey, Tennessee, and Indiana (effective January 1, 2026). The IAPP's Westin Research Center tracks all proposed and enacted state privacy bills and was last updated in February 2026.
Trend to watch: US state privacy enforcement is shifting from checking whether a consent notice exists to evaluating whether it actually works. California and Texas are expected to remain the most aggressive enforcers in 2026. Federal and state privacy enforcers have signaled throughout 2025 that they will be active in 2026, with particular focus on universal opt-out signal compliance (GPC), data broker obligations, and children's data.
Brazil
LGPD — Lei Geral de Proteção de Dados
Brazil's General Data Protection Law (LGPD), in force since September 2020, establishes a comprehensive data protection framework that applies to cookies collecting personal data. While the LGPD does not contain cookie-specific provisions like the EU's ePrivacy Directive, the national authority (ANPD) has issued guidance making clear that consent is the appropriate legal basis for non-essential cookies.
Cookie Consent Under the LGPD
The LGPD requires a lawful basis for any processing of personal data, and cookies that collect personal data are no exception. In October 2022, the ANPD published its official guidance document, "Cookies and Protection of Personal Data," which clarifies the framework. For non-essential cookies — including analytics, marketing, profiling, and cross-site tracking cookies — the ANPD identifies consent as the appropriate lawful basis. For strictly necessary cookies that are essential for the functioning of the website, the legitimate interest basis may be used.
Under the LGPD, consent must be affirmative, specific, and unambiguous. Organizations must clearly state the identity of the data controller, the specific purposes of processing, details of any data recipients, and notification of any profiling activities. The consent mechanism must be presented in Portuguese (the official language of Brazil), and users must be provided with a free and easily accessible procedure to withdraw consent at any time. Organizations must also maintain adequate records and documentation of consent to demonstrate compliance.
Cookie Banner Requirements
The ANPD encourages a layered information format for cookie consent banners. The first layer should present a concise summary with options to accept, reject, or manage cookies. A "Manage Cookies" button should direct users to a second layer with detailed information about each category of cookies, including their specific purposes, retention periods, and instructions for blocking them. This layered approach is similar to the best practices recommended by European DPAs and reflects the global trend toward transparent, granular consent interfaces.
Key Data Protection Principles for Cookies
- Transparency — Data subjects must be informed clearly, precisely, and in easily accessible language about what data is collected, how it is used, and who receives it.
- Necessity and purpose limitation — Data collection must be relevant and limited to what is necessary for the stated purposes. Setting more cookies than needed for the disclosed purposes violates this principle.
- Storage limitation — Cookie retention periods must be proportionate to the processing purpose. Indefinite cookie lifetimes or excessively long retention periods are non-compliant.
- Data minimization — Only the minimum amount of personal data required for each stated purpose should be collected through cookies.
Enforcement and Penalties
The ANPD is Brazil's federal-level regulator for LGPD matters. Since January 2023, it has been associated with the Ministry of Justice and has full authority to enforce the LGPD and impose penalties. Non-compliance can result in fines of up to 2% of revenue in Brazil, capped at R$50 million (approximately 10 million USD) per violation. The ANPD can also require data processing activities to be halted until compliance is achieved, order deletion of improperly collected data, and issue public warnings.
While the ANPD has not yet taken enforcement action specifically targeting cookie practices, its regulatory agenda for 2025–2026 includes regulation of data subject rights, data protection impact assessments, security measures, and high-risk processing — all of which have direct implications for cookie compliance. Enforcement is also not limited to the ANPD: consumer protection authorities and individual data subjects can bring claims under the LGPD, creating multiple enforcement channels.
Practical note: The LGPD's similarities to the GDPR mean that organizations already compliant with EU cookie requirements will need only minor adjustments for Brazil — primarily ensuring that consent banners and privacy notices are available in Portuguese and that the ANPD's layered information approach is followed. The key risk is underestimating LGPD requirements by treating Brazil as a lower-priority market.
Canada
PIPEDA, CASL, and Quebec's Law 25
Canada's cookie consent landscape is defined by a stark split between federal law and Quebec's provincial legislation. Federally, PIPEDA allows implied consent for some cookie use, while Quebec's Law 25 demands explicit opt-in consent on par with the EU's GDPR. The long-anticipated federal reform (Bill C-27) died in Parliament in January 2025, leaving this divided regulatory landscape intact for the foreseeable future.
PIPEDA — The Federal Baseline
The Personal Information Protection and Electronic Documents Act (PIPEDA) has governed federal privacy law in Canada since 2000. Under PIPEDA, consent is required for the collection, use, and disclosure of personal data, but the form of consent can vary based on context. For routine, low-risk data collection where the purpose is obvious and well-explained, implied consent may be sufficient. For sensitive data or unexpected uses, express consent is required.
In practice, this means that websites using cookies for basic analytics and functionality may rely on implied consent under PIPEDA, provided the privacy policy clearly discloses what cookies are used and for what purposes. However, cookies used for targeted advertising, behavioral profiling, or cross-site tracking typically require express consent because these uses go beyond what a reasonable user would expect when visiting a website.
It is also important to note that Canadian regulators classify most cookies as "computer programs" under the Canadian Anti-Spam Law (CASL), which requires user consent before software is installed on a user's device. CASL's penalties are significant — up to 10 million CAD for individuals and 10 million CAD for organizations per violation — and create an additional legal basis for cookie consent obligations at the federal level.
The Death of Bill C-27
Bill C-27, the Digital Charter Implementation Act, was intended to modernize Canada's federal privacy law by introducing the Consumer Privacy Protection Act (CPPA), the Personal Information and Data Protection Tribunal Act (PIDPTA), and the Artificial Intelligence and Data Act (AIDA). Together, these would have replaced PIPEDA, strengthened consent requirements, introduced significant new penalties, and created Canada's first federal AI law.
In January 2025, Prime Minister Trudeau prorogued Parliament, automatically killing all pending bills including C-27. A snap federal election followed in April 2025, and after the election, re-tabling C-27 in its original form was no longer a political priority. As a result, Canada remains operating under PIPEDA — a law written in 2000 — with no federal AI law in place and the Office of the Privacy Commissioner lacking the enforcement powers that C-27 would have provided.
Quebec's Law 25 — The Strictest Standard in Canada
With federal reform stalled, Quebec's Law 25 (an Act to modernize legislative provisions as regards the protection of personal information) stands as the strictest privacy regime in Canada. Fully in force since September 2024, Law 25 requires explicit opt-in consent for all cookies and tracking technologies — making it the only legislation in North America that matches the GDPR's opt-in approach.
Key features of Law 25 include:
- Confidentiality by default — All public-facing systems must have privacy settings configured to the highest level of confidentiality by default, without any action required by the user. No tracking technologies can be activated unless the user expressly consents.
- Explicit opt-in consent — Before deploying any cookie or tracking technology that collects personal information, businesses must obtain the user's explicit and affirmative consent. This is not opt-out; it is a full GDPR-style opt-in requirement.
- Private right of action — Unlike most privacy laws globally, including PIPEDA and the GDPR, Law 25 allows individuals to bring legal action (including class actions) against businesses that breach their rights. Damages start at 1,000 CAD per individual.
- Significant penalties — Fines can reach 25 million CAD or 4% of global revenue, whichever is greater.
- Broad scope — Law 25 protects the personal data of anyone whose data is managed under its jurisdiction, including Quebec residents, Canadians from other provinces, and individuals outside Canada. It even protects the data of deceased individuals for up to 20 years.
What this means for businesses: Companies serving Canadian users now face a split regime. For visitors from Quebec, you need GDPR-style opt-in consent with privacy-by-default settings. For visitors from the rest of Canada, PIPEDA's more flexible implied consent standard applies. Most compliance advisors now recommend defaulting to the Quebec/Law 25 standard for all Canadian visitors, since it automatically satisfies PIPEDA requirements as well.
Practical advice
If Your Site Serves Visitors from Multiple Regions
Most websites serve visitors from more than one jurisdiction, which means multiple cookie consent regimes apply simultaneously. Here is how to handle this without building a separate consent flow for every country.
Default to the Strictest Standard
The simplest approach is to apply the EU's opt-in consent model globally. If your consent mechanism is compliant with the GDPR and ePrivacy Directive, it automatically satisfies the requirements of the UK (PECR), Brazil (LGPD), Quebec (Law 25), and every US state privacy law. No visitor from any jurisdiction will be under-protected. This eliminates the need for geo-detection on the consent layer and reduces the risk of misclassifying a visitor's location. The trade-off is that US visitors, who are accustomed to less friction, will see a European-style consent banner. For many businesses, particularly small and mid-sized ones, this trade-off is well worth the simplicity.
Use Geo-Targeting to Adjust Banner Behavior
For organizations that want a tailored experience, geo-targeting allows the consent banner to adapt based on the visitor's location. EU and Quebec visitors see a full opt-in banner where no non-essential cookies are loaded until consent is granted. UK visitors see a similar banner, but with the new DUAA analytics exception applied where applicable. US visitors see a lighter opt-out mechanism with a "Do Not Sell or Share" link rather than a full consent modal. Brazilian visitors see an opt-in banner with Portuguese-language support. Visitors from jurisdictions with no specific cookie law see a simplified notice. Geo-targeting is more complex to implement and maintain, but it provides the best balance between compliance and user experience across regions. It also requires reliable IP-based geolocation and ongoing updates as new laws take effect.
Block Before Consent
The most critical technical requirement across all opt-in jurisdictions is that non-essential cookies and tracking scripts must not fire until consent is obtained. This means implementing a tag management system or consent-aware script loader that holds all marketing, analytics, and profiling tags until the visitor makes a choice. Loading scripts and then retroactively blocking them based on consent is not compliant.
Honor Universal Signals
Global Privacy Control (GPC) is now legally recognized by multiple US state laws, including California, Colorado, Connecticut, and Texas. When a browser sends a GPC signal, your site must treat it as a valid opt-out of the sale or sharing of personal data. Some businesses also honor GPC as a full opt-out of non-essential cookies, which provides a consistent experience regardless of jurisdiction.
Keep Proof of Consent
Under GDPR, LGPD, and Quebec's Law 25, you must be able to demonstrate that valid consent was obtained. This requires logging the timestamp of each consent decision, the version of the consent banner and privacy policy shown, the specific categories the user accepted or rejected, and a unique identifier for the consent record. These logs should be retained for at least as long as the data processing continues.
How FixGDPR Handles Multi-Region Compliance
FixGDPR's consent banner is built for multi-jurisdictional compliance out of the box. When you install the FixGDPR script on your website, the consent banner automatically detects the visitor's jurisdiction using IP-based geolocation and applies the appropriate consent model: full opt-in for EU, UK, Quebec, and Brazil visitors, and an opt-out mechanism for US visitors. The banner supports all major languages and adjusts its legal text and cookie categories based on the applicable law. All consent decisions are logged with timestamps, banner versions, and granular category choices, providing the documentation you need to demonstrate compliance to any regulator. The banner also recognizes GPC signals and automatically applies the appropriate opt-out for US visitors sending that signal. Every cookie and script on your site is held until the consent conditions for the visitor's jurisdiction are met.
If you are unsure whether your current setup meets the requirements for all the jurisdictions where you have visitors, the fastest way to find out is to run a free FixGDPR scan. The scanner evaluates your consent mechanism against the requirements of every major jurisdiction and tells you exactly where the gaps are.
Get started
Comply with cookie laws worldwide
FixGDPR's consent banner adapts to every visitor's jurisdiction automatically. Set up once, stay compliant everywhere — from the EU to California to Quebec.
Related Resources
Continue learning about cookie compliance.
A detailed comparison of the two most influential privacy laws in the world, covering scope, consent models, penalties, and practical compliance differences.
Everything you need to know about implementing cookie consent that meets GDPR requirements, including banner design, consent storage, and valid consent criteria.
How to build or choose a consent banner that meets GDPR and ePrivacy requirements without frustrating visitors or harming conversion rates.
A step-by-step checklist for making your website GDPR compliant, covering cookies, consent, privacy policies, data subject rights, and more.