
You see a cookie pop-up on nearly every site you visit, and now you are wondering whether your own site is missing one. Maybe you added Google Analytics last year, a Meta Pixel for your ads, or a booking widget that loads from another company. On one side sits the worry about a fine. On the other sits the worry about greeting every visitor with a box they have to click away. When you ask "does my small business website need a cookie banner," the plain answer is that no general US federal law requires every commercial website to show one. What decides your case is what your site actually tracks, where your visitors are, and whether a state privacy law with a coverage threshold applies to your business. Those three facts can be checked, and you can check most of them yourself in about fifteen minutes. Everything below is general information, not legal advice, and it can help you work out which of those facts matter for your site.
Key Takeaways
No general US federal law requires a cookie banner; state laws such as California's CCPA apply only to businesses that cross set thresholds, like $25 million in annual revenue or 100,000 California residents or households.
Google Analytics requires you to disclose that you use it and how it collects data, and Meta puts notice and consent duties for its Pixel on the business using it, whether or not you show a banner.
A fifteen-minute look at what your site loads, compared with your privacy notice, tells you whether you need a better notice, an opt-out, a real consent tool, or legal advice.
Find Out Whether Your Own Site Needs One
For a typical US small business, the answer turns on coverage, not on the mere presence of cookies. There is no general federal rule saying a website must show a cookie banner. What does exist is a set of state privacy laws that give covered businesses duties around notice and opt-out when cookie, pixel or other tracking data counts as personal information and is sold, shared, used for targeted advertising, or processed in ways the law regulates.
That means three questions decide your answer:
- What does your site load? Analytics, ad pixels, embedded booking, chat, maps and video can all send visitor data to other companies.
- Who visits, and from where? A business that markets to people in the EU or UK faces different rules than one that serves customers down the road.
- Does a state law cover your business? Each broad state privacy law has its own revenue or volume test, and a small business can sit below all of them.
If your business has ordinary US traffic, does not target the EU or UK, and uses only standard tools that you disclose accurately, you may not need a consent banner at all. You may need a better privacy notice and a clean list of the tags on your site instead. That changes if you cross a state threshold, sell nationwide at high volume, advertise across borders, or handle health, children's or other sensitive data. In those cases, a qualified privacy lawyer is the right next call.

Know Whether a State Privacy Law Covers Your Business
State laws are where US tracking duties mostly live, and each one sets its own bar. The key point is that these laws use volume, revenue or sale tests rather than a single small-business rule, so you have to check the numbers against your own business. The figures below come from the state attorneys general and the statutes themselves. They change, so treat them as a starting point and read the official source before you rely on one.
California sets the best-known tests
The California Attorney General's CCPA page explains that the law covers for-profit businesses doing business in California that meet at least one of three tests: more than $25 million in annual gross revenue, buying, selling or sharing the personal information of 100,000 or more California residents or households, or earning 50% or more of annual revenue from selling California residents' personal information. Covered businesses must give the required notices and honor requests to opt out of the sale or sharing of personal information, including through Global Privacy Control, a browser signal covered below.
Other states count consumers, not visitors to a page
Other broad state privacy laws generally count how many of their residents' personal data you process in a year, often with a lower number if you also make money from selling data.
| State | Main coverage test | Lower test if you sell data |
|---|---|---|
| California (CCPA) | Over $25 million revenue, or 100,000 CA residents or households | 50% or more of revenue from selling CA residents' data |
| Colorado | 100,000 consumers a year | 25,000 consumers plus revenue from selling data |
| Connecticut (amended, effective July 1, 2025) | 35,000 consumers, not counting payment-only data | Any sensitive-data processing or any sale of personal data |
| Delaware | 35,000 consumers | 10,000 consumers plus sale of data |
| Montana | 50,000 consumers | 25,000 consumers plus sale of data |
| Oregon | 100,000 consumers | 25,000 consumers plus sale of data |
| Texas and Nebraska | Small Business Administration small-business exemption, with exceptions | Texas generally exempts SBA-defined small businesses except for sensitive-data sales |
You can read the details on the official pages for Colorado's Privacy Act, Connecticut's Data Privacy Act, Delaware's statute, Oregon's privacy law and the Texas Attorney General's consumer privacy page. Virginia, Iowa, Indiana, Kentucky and Utah use higher volume tests, and several add sale-revenue tests; the Virginia code and Utah code are the primary texts for two of them.
What a threshold means for a local business
A local business with ordinary traffic can easily sit below these numbers, but that is something to confirm, not assume. Texas and Nebraska are a reminder that a size label alone does not settle it, because their exemptions have exceptions. Sector rules for health or children's data can also apply regardless of size. And even where a law covers you, it does not turn every analytics cookie into a banner mandate. The duties are notice and opt-out, and a banner is only one way to deliver them.

Spot When EU or UK Rules Reach Your US Site
Being based in the US does not always keep you outside European rules. According to the European Commission's guidance on who data protection law applies to, the EU GDPR can reach a business outside the EU if it offers goods or services, paid or free, to people in the EU, or monitors their behavior there. The Commission's own example says that a provider whose customers simply travel to the EU, without the business specifically targeting people there, is not covered on that basis.
Targeting is a question of fact. Signs worth noticing include marketing aimed at the EU, prices in euros, shipping to EU countries, ad campaigns in EU languages, or behavioral tracking of EU visitors. If any of those describe your site, get qualified advice. Where EU ePrivacy rules apply through a member state's law, consent is generally required before non-essential storage or access on a visitor's device, with a limited exemption for essential cookies.
The UK has its own pair of rules: PECR and UK GDPR. The ICO's guidance on cookies and similar technologies says organizations must tell users about cookies, explain what they do and why, and get active consent, except for strictly necessary uses. Analytics and advertising tracking are not automatically treated as essential. The ICO also makes clear in its guidance on storage and access technologies that the rules cover more than cookies. If your business targets or monitors people in the UK, assess that reach separately from the EU.
Meet What Google Analytics and Meta Already Ask of You
Your tools come with their own terms, and those apply whether or not any law requires a banner. This is the part a US small business can act on right away.
Google's Privacy Disclosures Policy says a site using Google Analytics must disclose that it uses Analytics and how Analytics collects and processes data. If you have turned on Analytics Advertising Features, Google's policy requirements for those features add more: you must disclose the features you use, the use of first-party and third-party identifiers, and how visitors can opt out. Google's EU User Consent Policy separately requires notice and consent for users in the EEA, the UK and Switzerland for covered products and uses.
Consent Mode is a common point of confusion. Google's page about consent mode states it plainly: "Consent mode doesn't provide a consent banner or widget." It receives a visitor's choice from a banner and adjusts your tags to match. It is plumbing, not the decision about what the law requires. Google's help page on verifying consent settings shows where those settings live in your account.
Meta's Business Tools Terms place responsibility on the business using a Meta Pixel, the Conversions API, a social plug-in or a similar tool. You are expected to give clear and prominent notice, obtain all necessary rights, permissions and consents, and keep a lawful basis for the data you send to Meta. That page can require a Meta login in some locations, so save a dated copy of the terms when you set up the Pixel.

Set Up Only What Your Site Actually Needs
A proportionate setup starts with telling the truth about your site, then adding controls only where a rule calls for them. It helps to know the difference between three things that tend to get lumped together. Once those are clear, the order of work is simple: fix the notice, add controls where a rule applies, and honor opt-out signals where the law expects it. Each step below is small on its own, and you may find you need only the first.
A privacy notice, an opt-out and a banner are different things
A privacy notice is the page that explains what you collect and why. An opt-out is a working way for a visitor to say no to the sale or sharing of their data, which covered state laws require. A consent banner is an interface that asks before non-essential tracking runs, which EU and UK rules generally require. A generic "we use cookies" pop-up with a single OK button is none of these. It does not replace the required notice, and it does not make unwanted tracking lawful.
Start with an accurate privacy notice
Put a privacy notice where visitors can find it. It should identify your business, the categories of data you collect, why you collect them, the third parties that matter, how long you keep data, how to contact you, and any rights that apply. Build it from a real inventory of your tags, pixels, booking tools, chat, video, maps and forms, not from generic banner text copied from another site.
Add controls only where a rule applies
If a state law covers you, or you reach EU or UK visitors in a way that triggers consent, set up a banner or consent tool that actually blocks or controls non-essential tracking under the relevant rule. Record choices where required, and give visitors an equally easy way to change their minds later. For a US-only local site below the thresholds, a privacy notice and truthful vendor disclosure may be proportionate without a decorative banner. That is not a reason to skip an opt-out you are required to offer.
Honor Global Privacy Control where it applies
Global Privacy Control is a signal a browser sends to say the visitor opts out of sale or sharing. The specification itself is a technical standard, not a law. Covered California businesses must treat a valid GPC signal as an opt-out request, according to the California Attorney General, and the Colorado Attorney General says the Colorado Privacy Act requires controllers to accept recognized universal opt-out mechanisms from July 1, 2024. GPC is not the same as the older Do Not Track setting.

Run the Fifteen-Minute Check Before You Spend Anything
You can do a first pass yourself before you pay for a banner subscription. It is practical triage, not a legal ruling, and it gives a lawyer or a developer something concrete to work from if you need one.
A fifteen-minute cookie and tracking check
- 1
Minutes 1 to 5
Open your site in a private browser window, accept nothing, and use your browser's developer tools or [Google Tag Assistant](https://support.google.com/tagassistant/answer/10039345) to see what loads on your home, contact, booking and form-success pages.
- 2
Minutes 5 to 8
Write down each outside tool you find, such as Google Analytics, Google Ads, Meta, Microsoft Clarity, Hotjar, an embedded calendar, chat, maps, video or payment tools.
- 3
Minutes 8 to 11
Compare that list with your privacy notice and note every tool it does not mention.
- 4
Minutes 11 to 13
Ask whether you ship or market to the EU or UK, and roughly how many residents of any one state's data you process in a year.
- 5
Minutes 13 to 15
If a state opt-out rule may apply, test GPC in a supporting browser or extension and write down what happens.
Save a screenshot of what you found. The results sort you into one of a few outcomes. If your notice misses tools, you have a small content job. If tags fire before a choice in a region that needs consent, you have a configuration job followed by testing. If form, health or other sensitive data is flowing into analytics or ad tags, treat that as the urgent one, because it can matter more than any banner design. Google's page on HIPAA and Google Analytics is a good read if you work in health care. And if the check turns up covered-state volumes, EU or UK targeting, children's data or data sales, take your inventory to a privacy professional.
No regulator or study located for this post ranks which of these problems shows up most often on small business sites, so start with whatever your own check found.
Do you know what your site needs?
Pick an answer to begin.
1. Does any general US federal law require every commercial website to show a cookie banner?
2. What does Google Consent Mode do?
3. You use Google Analytics with no banner. What does Google still require?
Frequently Asked Questions About does my small business website need a cookie banner
Do all US websites need a cookie banner?
No, not as a blanket rule. Whether you have duties depends on whether a state law covers your business, what your site tracks, and whether you target visitors in places such as the EU or UK.
What is the CCPA small business threshold?
The CCPA covers for-profit businesses doing business in California with over $25 million in annual gross revenue, that buy, sell or share the personal information of 100,000 or more California residents or households, or that earn 50% or more of revenue from selling that information.
Does CCPA require a cookie banner?
Covered businesses must give notices and honor opt-outs of sale or sharing. A banner can be one way to do that, but the law's requirement is the notice and the opt-out, not the banner itself.
Do I need Google Analytics consent in the US?
Google requires you to disclose your use of Analytics and how it collects and processes data. Its EU User Consent Policy requires notice and consent for users in the EEA, the UK and Switzerland.
What is Global Privacy Control?
It is a browser signal that tells a site the visitor opts out of the sale or sharing of their data. Covered California businesses must honor it, and Colorado requires controllers to accept recognized universal opt-out signals.
Do EU or UK visitors change the answer for a cookie consent US website?
They can. Offering goods or services to people in the EU or UK, or monitoring their behavior there, can bring GDPR, UK GDPR and cookie consent rules into play. Customers who simply travel there do not trigger GDPR on that basis alone.
Final Thoughts
No general US law requires every small business website to show a cookie banner. The answer for your site depends on what it loads, who visits and from where, and whether a state threshold applies. Google and Meta ask for disclosure whether or not you need a banner, and a privacy notice that matches your real tools is the foundation for every other step. Remember that all of this is general information, not legal advice, and that facts like EU targeting or sensitive data are the moment to bring in a lawyer.
Once you know what your site loads, you can answer a customer's or a vendor's privacy question without guessing. You can also add a booking tool or an ad pixel later and know what to update when you do.
If you would rather hand off the inventory and the fixes, Web Leveling can help. Our website maintenance work covers edits and watchful eyes, so an updated privacy notice or a tag change goes live without you touching the code. If your check shows you only need a clearer notice, we will say so and leave the banner out. We work with small and medium businesses across the country and overseas. Send us what your fifteen-minute check found, and we will help you sort out the next step.
Terms
Cookie and privacy words in this post
Tap a term to see what it means.
Cookie banner. A pop-up or bar that asks visitors to accept or refuse certain tracking before it runs.
Privacy notice. The page that explains what data a site collects, why, who it is shared with and what rights visitors have.
Opt-out. A working way for a visitor to stop the sale or sharing of their personal information.
CCPA. The California Consumer Privacy Act, a state law that applies to businesses crossing set revenue or volume thresholds.
Global Privacy Control. A browser signal that tells a website the visitor opts out of sale or sharing of their data.
Consent Mode. A Google tool that passes a visitor's choice from a banner to Google tags; it is not a banner itself.
Tracking pixel. A small piece of code, such as the Meta Pixel, that reports visitor actions to another company.



