Comparison

Cookie Consent: EU Opt-In vs US Opt-Out

The two consent models that split the world, opt-in before cookies in the EU and opt-out of sale in the US, and how one banner can serve both.

6 min read

Cookie consent runs on two opposite defaults. The EU and UK use opt-in: nothing non-essential runs until the visitor agrees. Most US state laws use opt-out: things run by default, and the visitor has the right to turn off the sale or sharing of their data. A site with visitors in both places has to do both, from the same page.

The Opt-In Model (EU, UK, and Beyond)

In opt-in regions, consent is a precondition. Non-essential cookies stay blocked until the visitor makes an affirmative choice, silence or a pre-ticked box does not count, and refusing has to be as easy as accepting. This model has spread well beyond Europe; Brazil's LGPD and a growing list of national laws follow the same consent-first logic.

The EU and UK are close but no longer identical here. In 2026 the UK narrowed its rule, exempting cookies used strictly for analytics, functionality, security, or software updates from prior consent, an exception the EU has not adopted. The consent-first default still holds in both; the UK simply carved out a few low-risk purposes.

The Opt-Out Model (US States)

Under CCPA/CPRA and the other US state laws, businesses can run analytics and advertising by default but must offer a clear way to opt out of the "sale" or "sharing" of personal information, and must honor an opt-out preference signal sent by the browser. The visible surface is usually a "Your Privacy Choices" link rather than an upfront wall. The obligation is about giving control, not about asking first.

Why Geo-Targeting Matters

Showing the strict EU banner to every visitor worldwide is a common overcorrection: it can depress analytics and ad performance in markets that never required opt-in, and it trains US visitors to dismiss a wall that does not apply to them. Showing the US-style link to EU visitors is worse, because it misses a legal requirement. Matching the experience to the visitor's location is how one setup stays both compliant and commercially sane.

One Banner, Two Models

The practical answer is a single consent tool that detects region and switches behavior: opt-in blocking where it is required, opt-out choices where those apply, and the right disclosures in each. That beats running separate tools per market, which drift out of sync and double the maintenance.

How Concord Fits

Concord serves region-aware consent from one configuration: opt-in blocking for the EU and UK, a "Your Privacy Choices" opt-out for US state laws, and the correct disclosures for each visitor. The choices flow into the same platform that handles your privacy requests and data mapping, so a consent decision and a later deletion request are part of one record rather than two disconnected systems.

Get Started

Run Your Privacy Program on One Platform

Concord brings consent, privacy requests, data mapping, and policy management together, so a rights request is a workflow, not a fire drill.