The US still has no federal privacy law like the GDPR. What it has instead is a growing list of state laws, and they reach further into your tracking than most setups allow for.

Twenty states had comprehensive consumer privacy laws in effect at the start of 2026, and more have been passed since, with later start dates. California's was first. Virginia, Colorado, Connecticut, Texas, Oregon, New Jersey and others followed. If you have customers in several states, assume several of these apply.

Opt-out, not opt-in.

The biggest difference from Europe is the model. In the EU, tracking waits for agreement. Under most US state laws, many kinds of processing can start straight away, but people have the right to say no, and you have to make that easy and respect it.

The rights that matter most for analytics and advertising are the right to opt out of:

  • the "sale" of personal information, which state laws define broadly, well beyond an exchange of money
  • "sharing" for cross-context behavioural advertising, California's term for ads based on activity across other sites
  • targeted advertising, as most of the other state laws put it

Some states go further for sensitive data, such as health or precise location, and require consent before it's processed.

Where GA4 and ad pixels fit.

Analytics used only to understand your own site is generally treated as lower risk. Advertising pixels are different. When the Meta pixel, TikTok or Google Ads remarketing tags send visitor data to a platform that uses it to target ads, that can count as a sale, sharing or targeted advertising under these laws.

So an opt-out has to reach your tags. A "Do not sell or share my personal information" link that records a preference but leaves every pixel running doesn't do what the law asks.

Google's tools for US states.

  • Restricted data processing. Google Ads and Google's other ad products can be told to process data only for limited purposes for a given visitor, for example after they opt out. It's set with a parameter on Google's tags, or through a consent platform.
  • Consent Mode by region. Consent Mode accepts regions down to state level, such as US-CA, so California visitors can get different defaults from the rest of the country.

Neither decides what your policy is. They're how a decision gets carried out in the tags.

The browser signal you have to honour.

A growing number of states require businesses to treat Global Privacy Control, a setting in some browsers, as an opt-out. A visitor who has switched it on shouldn't have to find your link at all. That's covered in how to honour Global Privacy Control in Tag Manager.

What to check on your site.

  1. List every tag that sends visitor data to a third party. Advertising pixels, chat widgets, session recording and embedded video all count.
  2. Decide, with your lawyer, which of those count as sale, sharing or targeted advertising in the states where you have customers.
  3. Make the opt-out work. When someone opts out, those tags should stop sending, or send in a restricted form, from that moment on.
  4. Honour Global Privacy Control in the same way, automatically.
  5. Keep sensitive data out of tags. Health, finance and location details in page URLs or event parameters are a common finding.
  6. Test it. Opt out, reload, and check that the network requests to ad platforms have stopped or changed.

And your UK and EU visitors.

A US site with visitors from Europe has a second set of rules to meet, stricter than any state's. That's covered in does your US website need a cookie banner for UK and EU visitors?, and the setup that handles both in one container is in region-specific consent in Tag Manager.

Which laws apply to your business, and how to read them, is for your lawyers. Marc Alexander makes GA4 and Tag Manager do what they decide, for US businesses with visitors on both sides of the Atlantic. The GA4 mini audit shows what your tags send today.