Twenty US states now have comprehensive privacy laws in effect as of 2026, according to state-by-state tracking from MultiState, and twelve of them require your site to honor Global Privacy Control as a valid opt-out signal. US state privacy regulators collected $3.425 billion in privacy-related fines in 2025, nearly double the $1.827 billion collected in 2024, per enforcement data compiled by Gartner and reported by Help Net Security.
If your compliance plan is "we handle CCPA," you're covering one state out of twenty, and possibly not even the parts of CCPA that changed this year. A cookie banner built for California doesn't automatically satisfy Virginia's opt-in requirements for sensitive data, or Colorado's universal opt-out mechanism rules, or Texas's law, which applies to businesses regardless of revenue or how much data they process. "Even if we had one state law that was the strictest one in the country, then it'd be fine," Gary Kibel, a partner at Davis+Gilbert, told Legal Dive. "But that's not the case … and it's making compliance for businesses an incredible burden." This guide compares the cookie consent platforms US businesses actually evaluate, not on generic feature checklists, but on the one question that determines whether a single banner covers a website legally across all twenty state laws at once: does the platform track the patchwork for you, or leave you tracking it yourself.
Key Takeaways
- Twenty US states have comprehensive privacy laws in effect as of 2026 (per MultiState), and each sets its own applicability thresholds, consumer rights, and opt-out mechanics, so "CCPA-compliant" and "US-compliant" are not the same claim.
- Twelve states, including California, Colorado, Connecticut, Texas, and Oregon, require sites to recognize Global Privacy Control or an equivalent universal opt-out signal, with Maryland and Minnesota adding the requirement in July 2026.
- Thresholds vary sharply by design: California's revenue floor is $26.625 million (inflation-adjusted for 2026), Virginia-model states use consumer-volume triggers instead of revenue, and Texas has no minimum at all, meaning a small site with no California customers can still be squarely inside Texas's law.
- US state privacy fines reached $3.425 billion in 2025, up from $1.827 billion in 2024, a trend regulators describe as the shift from awareness-building to sustained enforcement.
- A platform built for the full patchwork needs three things a CCPA-only tool doesn't: automatic detection of which state's rules apply to a given visitor, GPC recognition that holds across every state that mandates it, and consent logs that can prove compliance state by state, not just "US" as one undifferentiated bucket.
Why "CCPA-Compliant" Isn't the Same as "US-Compliant"
California was the first state with a comprehensive privacy law, and it's still the one most site owners think about first. That instinct is now the biggest gap in a lot of compliance programs. Virginia's Consumer Data Protection Act, Colorado's Privacy Act, and Connecticut's Data Privacy Act don't use California's revenue-based threshold at all; they trigger on consumer volume and how much of a business's revenue comes from selling personal data, per legal analysis from Clym. A business can clear California's $26.625 million revenue bar with room to spare and still fall squarely inside Colorado's or Connecticut's law because of how many state residents' data it processes, independent of revenue.
Texas takes a different approach again: the Texas Data Privacy and Security Act has no revenue floor and no minimum consumer-volume threshold at all, which means a small business with a handful of Texas visitors can be in scope even if it would never trigger California's or Virginia's law. Rhode Island set its threshold even lower than the Virginia model, at 35,000 consumers or 10,000 consumers plus 20% of revenue from data sales, a bar that a mid-traffic regional site can clear without noticing. Christina Gagnier, a partner at Jeffer Mangels Butler & Mitchell, has described this as especially hard on smaller companies: they generally don't have compliance teams built to track twenty separate rule sets, each with its own trigger.
Universal opt-out mechanism (UOOM): the general legal term for a browser- or extension-level signal, of which Global Privacy Control is the dominant real-world implementation, that communicates a visitor's opt-out preference automatically, without requiring a click on every individual site.
Twelve states require recognizing a UOOM as of 2026: California, Colorado, Connecticut, Montana, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Delaware, Oregon, and Texas. California, Colorado, and Connecticut have explicitly confirmed GPC itself satisfies that requirement, and in September 2025 those three states ran a coordinated enforcement sweep specifically targeting sites that weren't honoring the signal. A platform that detects GPC in California but treats it as optional everywhere else isn't offering partial coverage; it's leaving eleven other states' requirements unmet by default.
State Thresholds and Signal Requirements Compared
| Requirement | California | Virginia / Indiana / Kentucky | Colorado / Connecticut | Texas | Rhode Island |
|---|---|---|---|---|---|
| Applicability trigger | $26.625M revenue, OR 100,000+ residents/devices, OR 50%+ revenue from data sales | 100,000 consumers, OR 25,000 consumers + 50% revenue from data sales | Consumer-volume based; no revenue floor | No revenue or volume minimum | 35,000 consumers, OR 10,000 consumers + 20% revenue from data sales |
| Opt-out model | Opt-out (sale/sharing) | Opt-out for sale/targeted ads; opt-in for sensitive data | Opt-out; opt-in for sensitive data | Opt-out; opt-in for sensitive data | Opt-out; opt-in for sensitive data |
| GPC / UOOM required | Yes, confirmed | Not explicitly confirmed as of 2026 | Yes, confirmed (CO and CT) | Yes, required | Not explicitly confirmed as of 2026 |
| Enforcement posture | Coordinated multi-state sweeps; largest 2025 fines | Newly active (Jan. 1, 2026) | Joint CA/CO/CT GPC enforcement sweep, Sept. 2025 | Active, no minimum-size exemption | Newly active (Jan. 1, 2026) |
The practical read: a website that only configures for California's rules is unprotected in at least eleven other states that also require honoring an opt-out signal, and is potentially non-compliant with Virginia-style opt-in requirements for sensitive categories that California doesn't treat the same way.
What a Genuinely Multi-State Platform Needs to Do
Before comparing vendors, it's worth fixing what "handles US compliance" actually has to mean once you're past one state. A platform earns that claim by doing four things, not one:
Jurisdiction detection: identifying which state's (or country's) rules apply to a given visitor and adjusting the banner's legal behavior accordingly, rather than showing the same static consent flow to every visitor regardless of location.
Signal recognition across every mandating state: honoring GPC (or another UOOM) as a valid opt-out everywhere it's legally required, not just in California, and logging that it happened.
Threshold-aware configuration: letting a business apply the correct opt-in versus opt-out logic for sensitive data categories, since several state laws (Virginia, Colorado, Connecticut, Texas among them) require affirmative opt-in for sensitive personal data even though they use opt-out for ordinary sale/sharing.
State-attributable audit logs: consent records that can be filtered and exported by state, so a business facing a state-specific inquiry, like the coordinated CA/CO/CT GPC sweep, can produce exactly the evidence that state's regulator is asking for, rather than one undifferentiated global log.
That checklist, not a generic feature list, is what the comparison below is built around.
Cookie Consent Platforms for a US Website Compared
| Comparison Point | Secure Privacy | Clym | Osano | Usercentrics | OneTrust | Termly |
|---|---|---|---|---|---|---|
| Entry price | Free tier; paid from $15/month per domain | No free tier; $49/month (50,000 pageviews) | Free tier; self-serve Plus at $199/month (3 domains, 30K visitors) | Free tier; paid from ~$50-109/month, scales by session volume | ~$10,000/year minimum (self-serve tier retired) | Free tier; paid from ~$10-20/month |
| US comprehensive state laws covered | All 20, within 55+ laws worldwide | Markets specifically on US state-law breadth (150+ regulations claimed) | Configurable; strong CCPA/CPRA and Colorado/Virginia focus, fewer laws out of the box overall | CCPA/GDPR-focused; other US state laws not a built-in template set | Enterprise-configurable across all 20 | CCPA/GDPR templates only |
| Jurisdiction/geo-based auto-detection | Yes, auto-detects visitor location and serves region-specific consent flows | Yes, location-based detection is the product's core differentiator | Built-in, US state-focused | Limited; not a stated core feature | Yes, enterprise-configured | No |
| GPC / UOOM detection & enforcement | Yes, standard from the Small tier up | Yes | Yes, built-in | Yes | Yes, enterprise-configured | Limited on lower tiers |
| Consent logging exportable by state/jurisdiction | Yes, exportable from the dashboard | Not confirmed as a distinct filter | Yes | Yes | Yes, extensive | Basic (higher tiers only) |
| DSAR / data request handling | Built-in validated forms from the Business tier | Governance add-on from the Grow plan | Consumer + employee workflows | Add-on, not built in | Full workflow engine | Basic intake form |
| Best fit | Growing and mid-size US businesses needing all 20 state laws enforced correctly from one banner, without enterprise pricing | US-focused businesses wanting jurisdiction detection as the headline feature, on pageview-based pricing | Mid-market wanting deep US state-law focus with a compliance guarantee | Businesses wanting a CCPA/GDPR banner without needing the other 18 state laws built in | Large enterprises running a full multi-framework governance program alongside consent | Solo sites needing only the legal floor in one or two states |
Platform Overview
Secure Privacy is a cookie and consent management platform used on more than 100,000 websites, built to enforce all 20 US comprehensive state laws, alongside GDPR, LGPD, and 55+ privacy laws worldwide, from the same banner a marketing or ops team configures directly. It auto-detects a visitor's location and serves the corresponding consent flow, so a site doesn't need separate configurations for California, Texas, and Colorado visitors landing on the same page. GPC detection ships standard, exportable consent logs cover every domain, and validated DSAR intake forms are built in from the Business tier at $59/month per domain, well under the enterprise price floor the largest suites charge for the same underlying coverage.
Clym built its entire pitch around US jurisdiction detection: its consent platform identifies a visitor's location and adjusts consent behavior automatically, and third-party reviews consistently name multi-state breadth as its strongest differentiator. That focus is real, but it comes with tradeoffs for a typical business site: no free tier, page-view-based pricing that starts at $49/month for just 50,000 monthly page views, and governance features like HIPAA support gated behind the $149/month Grow plan.
Osano positions itself as one of the stronger dedicated US-state players among the mid-market platforms, with built-in GPC detection and a "No Fines, No Penalties" guarantee covering up to $500,000 in penalties for eligible plans. It's a genuine option for a business whose whole compliance need is CCPA-adjacent US coverage, though its self-serve Plus tier caps out at 30,000 monthly visitors before forcing a custom Enterprise quote, and its law coverage outside the US is thinner than a global multi-law platform's.
Usercentrics is a capable CCPA/GDPR consent management platform with a large legal-template library and pricing that scales with session volume rather than a flat per-domain fee. It covers the two laws most businesses think of first, but the other eighteen US state laws aren't part of its built-in template set, and DSAR handling is an add-on rather than a native workflow, which matters once a business needs to prove compliance state by state rather than just "US" in general.
OneTrust is the largest privacy platform on the market, and its enterprise configuration teams can build out coverage for all 20 state laws alongside GDPR, vendor risk, and ESG reporting in one governance program. That breadth is real, but OneTrust retired its self-serve pricing tier in 2026, pushing its effective floor to roughly $10,000 a year before implementation, a cost structure built around dedicated privacy counsel managing a multi-framework program, not a marketing team configuring a banner directly.
Termly covers the legal minimum cheaply for a single small site: a cookie banner, a handful of policy templates, and a basic DSAR intake form. Its templates are built around CCPA and GDPR specifically, so a business that starts triggering, say, Colorado's or Connecticut's thresholds as it grows has to verify manually whether Termly's default settings actually satisfy those states' different opt-in rules for sensitive data, since the platform doesn't build that distinction in.
Why Signal Recognition Has to Hold Across Every State, Not Just California
The most common failure mode isn't a missing banner. It's a banner that displays correctly and still doesn't stop the underlying trackers from firing before, or regardless of, a visitor's opt-out choice. That's exactly the mechanism behind the $1.35 million Tractor Supply settlement: the company's opt-out control was visible, but it didn't propagate to every downstream vendor and ad tag actually processing the data.
Extend that same failure across twelve states that now mandate honoring GPC, and the exposure multiplies. A platform that detects the signal only when a visitor is geolocated to California, and treats it as a soft preference everywhere else, is compliant in exactly one of the twelve states that require it. The joint September 2025 enforcement sweep run by California, Colorado, and Connecticut existed specifically because regulators expected to find sites doing exactly that: honoring the signal where they assumed it mattered most, and skipping it elsewhere.
This is also where consent logging earns its place as a compliance requirement rather than a nice-to-have dashboard feature. A log that shows "GPC honored: yes" as a single global flag doesn't answer the question a Colorado or Connecticut regulator would actually ask, which is whether it was honored for visitors physically in that state, on that date, under that state's specific rule. Consent records need to be filterable and exportable by jurisdiction, not just by domain, for a business to actually demonstrate state-by-state compliance rather than assert it.
Need to know whether your current setup is enforcing GPC correctly everywhere it's required, not just in California? Secure Privacy's compliance scanner checks cookies, trackers, and consent-mode implementation on a recurring basis and flags exactly which ones fire before consent, so this isn't a guess.
Pricing and ROI Across the Patchwork
The cost of "US compliance" depends entirely on how many of the twenty states a platform actually enforces by default versus how many require manual configuration. OneTrust's roughly $10,000/year floor buys full enterprise configurability across every state, but most of that spend is going toward governance modules like vendor risk registers and ESG scoring that a website-focused compliance need doesn't touch. Clym's jurisdiction-detection strength comes at page-view-based pricing that can outpace a growing site's traffic faster than a flat per-domain fee would, and its no-free-tier structure means there's no on-ramp below $49/month.
Osano and Usercentrics sit in a comparable mid-tier price band to each other, but neither builds all 20 state laws into its base template set the way a dedicated multi-law platform does; a business using either one for full US coverage is doing more manual verification per state than the price tag suggests. Termly's free and $10-20/month tiers are the right call for exactly one scenario: a single small site with no near-term plan to cross into Colorado, Connecticut, or Virginia's stricter opt-in territory.
Secure Privacy's Business tier puts all 20 state laws, GPC detection, jurisdiction-based auto-configuration, and DSAR handling into the same $59/month per-domain plan, below Clym's comparable tier and an order of magnitude below OneTrust's minimum, without asking a business to verify law-by-law coverage manually as it scales into new states.
Key Differentiators
Coverage that doesn't stop at California, without enterprise pricing: Secure Privacy's core advantage in this comparison is enforcing all 20 US state laws, plus GPC recognition in every state that mandates it, from a plan priced for a growing business rather than an enterprise governance budget. None of the mid-market platforms in this comparison match that combination at this price point.
Jurisdiction detection is real at Clym, but it's the whole product: Clym's location-based detection genuinely works as advertised, and it's a fair option for a business that wants that single capability above everything else. The tradeoff is a pricing model tied to page views rather than domains, and no free entry point, which makes it a narrower fit for a business still figuring out its traffic and compliance footprint.
Enterprise governance breadth, without an enterprise contract: OneTrust's ability to bundle vendor risk, data mapping, and multi-framework governance alongside consent is genuine, and worth naming honestly rather than pretending it doesn't exist. It isn't unique to OneTrust, though: Secure Privacy covers the same governance ground, including AI governance, vendor management, and DPIAs, through its separate Privacy & AI Governance Platform, available once a business actually needs it instead of bundled into a five- or six-figure contract from day one.
CCPA/GDPR-only tools carry a state-law blind spot, not a lesser version of the same coverage: Usercentrics and Termly are both capable at what they're built for, but "CCPA and GDPR" isn't a subset of "US compliance," it's a different, narrower claim. A business relying on either for full US coverage is implicitly self-certifying the other eighteen states itself.
Common Issues & Fixes
"We're CCPA-compliant, so we assumed we were covered everywhere else." CCPA compliance covers exactly one state's rules. Confirm your platform separately enforces Virginia's, Colorado's, or Connecticut's opt-in requirements for sensitive data, and Texas's law that applies regardless of revenue, rather than assuming California's rules travel.
"We don't know if GPC is actually being honored outside California." Test with GPC enabled from a browser session, then check whether your consent log records the opt-out as enforced for that session specifically, and confirm the platform's default configuration applies the same enforcement in every state that requires it, not only the one you originally set up for.
"Our banner looks the same for every visitor, everywhere." That's often a sign the platform isn't doing jurisdiction detection at all. A single static consent flow can't apply Virginia's opt-in rule for sensitive data to a Virginia visitor while applying California's opt-out rule to a California visitor on the same page.
"We can't tell which state's requirements our current tool is actually satisfying." If your consent logs can't be filtered by visitor location, you can't produce state-specific evidence if a regulator asks for it. That's a logging gap, not a paperwork inconvenience, and it's exactly what the 2025 coordinated enforcement sweep was built to catch.
Not sure how many of the twenty state laws your current setup actually enforces? Secure Privacy's free domain scan checks jurisdiction detection, GPC enforcement, and cookie blocking against current US state requirements before you commit to a plan.
Choose Your Platform
Choose Secure Privacy if you're the typical US business reading this guide: you need all 20 state laws enforced from one banner, want GPC recognized everywhere it's legally required rather than just in California, and don't want enterprise pricing or a page-view-metered bill to get there. This is the default recommendation for most single-site and multi-domain US businesses.
Choose Clym if jurisdiction-based auto-detection is your single highest priority and page-view-based pricing without a free tier is an acceptable tradeoff for that specific strength.
Choose Osano if deep CCPA/CPRA and Colorado/Virginia-adjacent coverage with a fines guarantee matters more to you than broad coverage of all twenty state laws out of the box.
Choose Usercentrics if your business genuinely only needs CCPA and GDPR covered, with no near-term exposure to the other eighteen state laws.
Choose OneTrust only if you're running a full multi-framework governance program with dedicated privacy counsel, where consent is one module inside a much larger enterprise contract.
Choose Termly only if you run one small site with no near-term plan to trigger a stricter state's opt-in requirements as you grow.
FAQ
What is the best cookie consent platform for a US website in 2026?
For most single-site and multi-domain US businesses, Secure Privacy covers the most ground: all 20 US state privacy laws, GPC recognition in every state that requires it, and jurisdiction-based auto-detection, from a $59/month Business tier, without an enterprise price floor.
How many US states have comprehensive privacy laws in 2026?
Twenty states have comprehensive privacy laws in effect as of 2026, according to MultiState's tracking: California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, Virginia, and Washington.
Does my website have to comply with every state's privacy law?
Only the ones where you meet that state's specific applicability threshold, and those thresholds vary widely. California's is revenue- or volume-based, several states use consumer-volume triggers with no revenue floor at all, and Texas has no minimum size requirement, so a small site with no California customers can still be squarely inside Texas's law.
Do I need to honor Global Privacy Control outside California?
Yes, if your visitors are in any of the twelve states that currently require recognizing a universal opt-out signal: California, Colorado, Connecticut, Montana, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Delaware, Oregon, and Texas. Maryland and Minnesota's requirements take effect in July 2026.
Is a CCPA-compliant cookie banner automatically compliant in other states?
No. CCPA is an opt-out model for sale and sharing of personal information, while several other states, including Virginia, Colorado, and Connecticut, require affirmative opt-in consent for sensitive personal data categories, a stricter standard that a CCPA-only configuration won't automatically satisfy.
How much does multi-state US privacy compliance software cost?
It ranges from free, single-domain tiers on platforms like Secure Privacy, Osano, and Usercentrics, up to enterprise contracts averaging $10,000 or more per year for OneTrust. Platforms genuinely built for all twenty state laws, like Secure Privacy's Business tier at $59/month per domain, sit well below that enterprise floor.
Manually tracking twenty different states' thresholds, opt-out signals, and sensitive-data rules across every visitor doesn't scale past a handful of states, let alone all of them. Secure Privacy's cookie and consent platform auto-detects each visitor's jurisdiction, enforces GPC everywhere it's legally required, and logs every consent decision by state for export, covering all 20 US state laws alongside GDPR and 55+ other privacy laws worldwide in one dashboard. Book a demo to see how it maps to your own state-by-state exposure.




