If you have ever added a cookie banner "just in case" and then wondered whether California actually asked for it, you are in good company. The short answer surprises people: no CCPA provision requires a cookie consent banner. What the law requires is narrower, and in some ways more demanding than a pop-up.
What the law asks for instead
The CCPA is an opt-out regime. A business can generally collect personal information and run advertising tags without first asking permission, provided it tells visitors what it collects and gives them a working way to say no to sale or sharing. The main obligations that touch a website:
- A notice at collection, given at or before the point the site collects personal information (§ 7012).
- A "Do Not Sell or Share My Personal Information" link in the homepage header or footer, or the "Your Privacy Choices" link with the official icon as the alternative (§ 7013, § 7015). A business that processes opt-out preference signals in a frictionless manner has a further route, set out in § 7013.
- Treating a Global Privacy Control signal as a valid opt-out request (§ 7025).
- Opt-in consent before selling or sharing the data of anyone the business knows is under 16 (§ 1798.120(c)).
That last item is the one real consent requirement, and it turns on knowing a visitor's age rather than on cookies.
Why a banner still shows up
Many sites run one banner worldwide because the EU's ePrivacy and GDPR rules do ask for consent before non-essential cookies, and because a banner is a convenient place to hang an opt-out. That is a fine choice. It does not change what California cares about, which is what your site does with a visitor's choice.
Once a banner is your mechanism, § 7004 governs how it behaves. The path to the privacy-protective option can't be longer or harder than the path to the other one, so a bright "Accept all" next to a grey "Manage preferences" is a design problem, not just a style one. Consent gathered through a dark pattern is void.
Litigation is a separate track. SB 690, signed on September 30, 2026, moves CIPA § 638.51 pen register claims over website tracking to the Attorney General from January 1, 2027. Section 631 wiretapping claims keep their private right of action, which is why some sites still hold tags until a visitor chooses. That is a CIPA risk decision; the CCPA doesn't mandate it.
What website owners should do
Decide whether you want a banner, then make the rest of the page agree with it. Confirm the footer link is present and works, check that a GPC signal stops sale and sharing tags on the next page load, and make sure a visitor who declines in your banner doesn't keep getting pixels. We cover the browser-side method in how to check what fires before consent.
Where Privisy fits
Your banner tool records what it was configured to do. Privisy loads the live site as a visitor would, with and without a GPC signal, and reports the footer link, the trackers that fire, and whether the opt-out took effect. The CCPA checker is a quick place to start, and the full audit covers the rest.
See what your site actually does
Privisy audits your opt-out link, trackers, and GPC response on the live site.
Get Your Audit