At least 12 US states now require businesses to honor a universal opt-out signal such as Global Privacy Control as of August 2026, according to compiled state Attorney General guidance across the states that have adopted the requirement so far. That is 12 of the 20 states with a comprehensive consumer privacy law currently in effect, and the count keeps climbing as newer state laws come online. Some states made the requirement effective the same day their general privacy law started; others waited a year or more.
How many states require businesses to honor a universal opt-out signal?
12 of the 20 states with a comprehensive privacy law in effect as of August 2026 legally require businesses to recognize an opt-out preference signal like Global Privacy Control (GPC) as a valid "do not sell or share" request, no separate opt-out click required. The other 8, including two of the earliest states to pass a privacy law at all, have chosen not to add that requirement, at least not yet.
Figure 1: 12 of the 20 states with an active comprehensive privacy law require honoring a universal opt-out signal. Source: IAPP US State Privacy Legislation Tracker (20-state count); Cookiebot 2026 GPC compliance guide (per-state requirement compilation).
A universal opt-out mechanism is any browser setting, extension, or other automated signal a consumer can turn on once and have it apply across every site they visit, rather than clicking "Do Not Sell My Personal Information" on each site individually. Global Privacy Control is by far the most widely recognized version of this signal, and it is the specific mechanism every one of the 12 states below has named in guidance or statute.
Which states have adopted a universal opt-out mandate, and when?
Colorado moved first, and California's underlying recognition of GPC as a valid opt-out actually predates Colorado's statutory mandate by three years, even though California folded it into existing CCPA opt-out rules rather than creating a standalone requirement. The table below lists all 12 states with an active mandate, each state's own privacy law effective date for comparison, and which authority enforces it.
| State | UOOM requirement effective | General law effective date | Enforcement authority |
|---|---|---|---|
| Colorado | July 1, 2024 | July 1, 2023 | Colorado Attorney General |
| Connecticut | January 1, 2025 | July 1, 2023 | Connecticut Attorney General |
| Delaware | January 1, 2025 | January 1, 2025 | Delaware Attorney General |
| Montana | January 1, 2025 | October 1, 2024 | Montana Attorney General |
| Oregon | January 1, 2025 | July 1, 2024 | Oregon Attorney General |
| Texas | January 1, 2025 | July 1, 2024 | Texas Attorney General |
| Nebraska | July 15, 2025 (conditional) | January 1, 2025 | Nebraska Attorney General |
| New Jersey | July 15, 2025 | January 15, 2025 | NJ Division of Consumer Affairs |
| Minnesota | July 31, 2025 | July 31, 2025 | Minnesota Attorney General |
| New Hampshire | January 1, 2026 | January 1, 2025 | New Hampshire Attorney General |
| Maryland | April 1, 2026 | October 1, 2025 | Maryland Attorney General |
| California | Recognized since 2021, codified under CPRA | January 1, 2023 (CPRA amendment) | California Privacy Protection Agency |
Source: Colorado Attorney General, Connecticut Attorney General, New Jersey Division of Consumer Affairs, California Privacy Protection Agency, Cookiebot 2026 GPC compliance guide (Delaware, Montana, Oregon, Texas, Nebraska, Minnesota, New Hampshire, Maryland dates).
California sits at the top of the list chronologically but the bottom of the table by design: its rule has existed in some form since 2021, longer than any statutory UOOM requirement in another state. The other 8 states with a comprehensive law in effect, including Virginia, the second state to pass one, have not added a UOOM requirement to their statutes as of this post's publication. Our full state-by-state privacy law tracker covers all 20 states' general effective dates and penalty structures side by side.
How fast did each state move from its law to its opt-out mandate?
Delaware is the only state that built the opt-out-signal requirement into its law's own start date, giving businesses zero lead time between the general effective date and the UOOM mandate. Connecticut sits at the opposite extreme: its Data Privacy Act took effect July 1, 2023, but the state did not require honoring opt-out preference signals until January 1, 2025, roughly 550 days later.
Figure 2: Connecticut (CT) gave businesses the longest runway before its opt-out mandate kicked in; Delaware (DE) gave none. States abbreviated: CO Colorado, NH New Hampshire, TX Texas, OR Oregon, NJ New Jersey, MD Maryland. Source: Connecticut Attorney General, Colorado Attorney General, New Jersey Division of Consumer Affairs, Cookiebot 2026 GPC compliance guide.
New Jersey split the difference at exactly six months, a pattern Texas, Oregon, and Maryland roughly followed too. The New Jersey Data Privacy Act's own key dates show the state gave businesses until July 15, 2025 to start honoring opt-out signals, six months after the law's January 15, 2025 start date, the same window regulators used to phase in the law's other new disclosure requirements. A six-month runway after a law's own effective date has become the closest thing to a standard pattern among the states that stagger the requirement rather than making it a day-one obligation.
How has adoption grown since Colorado's first mandate?
One state required honoring a universal opt-out signal in 2024. Twelve do as of August 2026, a twelvefold increase in about two years. The growth has not been a steady drip; nearly all of it happened in a single 13-month window between January 2025 and February 2026, when eight states added the requirement in quick succession as their own newly passed privacy laws came online.
Figure 3: Growth from a single state to a dozen states happened almost entirely in 2025. Source: Compiled from Colorado, Connecticut, New Jersey, and California official guidance, corroborated by Cookiebot's 2026 GPC compliance guide.
The 2023 count of "1" reflects California's earlier informal recognition of GPC rather than a hard statutory mandate; treat 2024, when Colorado's requirement took effect, as the first year any state legally forced the issue. Four more state privacy laws, in Alabama, Louisiana, Oklahoma, and Vermont, had been enacted but were not yet in effect as of mid-2026, and at least one of them, Vermont, has a UOOM requirement already written into its statute for a future date, which means this count is very likely to keep climbing through 2027 and 2028.
Does universal opt-out apply to your business?
Whether a business has to honor a GPC signal at all depends on two separate questions: does a state's general privacy law apply to the business in the first place, and does that state's law include a UOOM mandate. A business can clear the first test and still have no legal obligation to honor GPC if it only operates in one of the 8 states without the requirement.
Figure 4: Two independent tests determine whether a business must honor GPC: which state's law applies, and whether that state's law includes a UOOM mandate. Source: Compiled from the 12-state list above.
Businesses that serve consumers across multiple states face the more complicated version of this test, since they may need to honor GPC for California and Colorado visitors while having no such obligation for visitors from Virginia or Utah on the same site, unless the business simply chooses to apply the rule everywhere for consistency, which most large platforms with a working GPC integration already do.
What is the full timeline of state opt-out mandates?
Six years separate California's first informal GPC recognition from Vermont's already-scheduled 2028 requirement, the furthest-out effective date currently on the books for any state.
Figure 5: Five states turned the requirement on within the first six months of 2025 alone. Source: Same compiled state-by-state sources as the adoption table above.
The 2028 Vermont date is a scheduled future requirement rather than a currently active one, and it is worth treating as tentative since a state legislature can still amend an effective date before it arrives, as several states already have with cure periods and threshold changes elsewhere in these same laws.
Which states move fastest, and which penalize hardest?
Speed of adoption and penalty size turn out to be mostly unrelated. Colorado paired a slow rollout with the highest per-violation penalty in this group, while Delaware paired the fastest possible rollout with a mid-range penalty.
Figure 6: Colorado and Connecticut sit far apart on rollout speed despite similar penalty philosophies; Delaware and New Jersey sit at nearly opposite corners entirely. Source: Days-to-mandate figures from the gap chart above; penalty caps from Colorado Revised Statutes 6-1-112, Connecticut General Statutes 42-110o, Oregon SB 619, Delaware Code Title 6, and New Jersey Division of Consumer Affairs guidance.
There is no consistent pattern connecting how quickly a state phased in its opt-out mandate to how much it can fine a business that ignores one, which means a business cannot assume a state that moved slowly will also go easy on enforcement once its mandate finally takes effect.
What happens when a business ignores a state-mandated opt-out signal?
Ignoring a legally required GPC signal is not a theoretical risk. The California Privacy Protection Agency announced a joint investigative sweep with the Colorado and Connecticut Attorneys General in September 2025 and fined two companies specifically for failing to honor GPC opt-out requests: American Honda Motor Co. paid $632,500, and clothing retailer Todd Snyder paid $345,178.
| Company | Fine | Violation | Announced |
|---|---|---|---|
| American Honda Motor Co. | $632,500 | Failure to honor GPC opt-out signal | September 2025 |
| Todd Snyder | $345,178 | Failure to honor GPC opt-out signal | September 2025 |
Source: California Privacy Protection Agency, joint investigative sweep announcement, September 9, 2025.
That enforcement risk is compounded by a compliance gap that has not closed much on its own. Only 45% of websites legally required to honor Global Privacy Control actually did so when researchers tested 11,708 US sites in April 2024, according to a Wesleyan University and Princeton University study published at USENIX Security 2025; see our full breakdown of that compliance study for the year-by-year trend. A business operating in any of the 12 states above cannot assume its cookie consent platform is already handling this correctly by default, since the study found compliance stuck in the mid-40s across three separate testing rounds. Keeping a privacy policy's opt-out disclosures current is a smaller lift than fixing a broken GPC integration after a regulator's sweep finds it first.
The Bottom Line
12 states now require honoring a universal opt-out signal, up from just one two years ago, and the pace shows no sign of slowing given that Vermont already has a 2028 requirement written into law before most of the current 12 states even reached their first anniversary of enforcement. The practical takeaway for any business collecting personal data across state lines is that "does GPC apply to us" is no longer a single yes-or-no question. It depends on which states a business's consumers live in, and that list of states keeps growing every few months. Coordinating a working GPC integration once for every visitor, rather than turning it on or off state by state, remains the simpler and lower-risk approach given how quickly this list has grown since 2024.
Frequently Asked Questions
How many US states require businesses to honor a universal opt-out signal? At least 12 states require it as of August 2026: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas, according to compiled state Attorney General guidance and privacy-law tracking. That is 12 of the 20 states with a comprehensive privacy law in effect.
Which state was first to require honoring Global Privacy Control? Colorado, effective July 1, 2024, a full year after the Colorado Privacy Act itself took effect on July 1, 2023, according to the Colorado Attorney General's own guidance page on universal opt-out mechanisms.
Do all US privacy laws require honoring a universal opt-out signal? No. Virginia, Utah, Iowa, Indiana, Tennessee, and Kentucky all have a comprehensive privacy law in effect but no statutory requirement to honor Global Privacy Control or a similar signal, according to compiled state-by-state tracking from Cookiebot's 2026 GPC compliance guide.
What happens if a business ignores a state-mandated opt-out signal? It can trigger real fines. The California Privacy Protection Agency fined American Honda Motor Co. 632,500 dollars and retailer Todd Snyder 345,178 dollars in a September 2025 joint enforcement sweep with the Colorado and Connecticut Attorneys General, specifically for failing to honor Global Privacy Control opt-out requests.
Where the Numbers Come From
- Colorado Attorney General. "Universal Opt-Out and the Colorado Privacy Act." Global Privacy Control recognized as the sole valid universal opt-out mechanism, requirement effective July 1, 2024.
- Connecticut Office of the Attorney General. "The Connecticut Data Privacy Act." Confirms all covered controllers must honor opt-out preference signals starting January 1, 2025.
- New Jersey Division of Consumer Affairs. "New Jersey Data Privacy Law FAQ." Universal opt-out mechanism deadline of July 15, 2025, six months after the law's January 15, 2025 effective date.
- California Privacy Protection Agency. "Joint Investigative Sweep Announcement." American Honda ($632,500) and Todd Snyder ($345,178) settlements for failing to honor Global Privacy Control, announced September 9, 2025.
- Cookiebot (Usercentrics). (2026). "Global Privacy Control: What It Is and Which States Require It." Compiled state-by-state universal opt-out mechanism effective dates, including Delaware, Montana, Oregon, Texas, Nebraska, New Hampshire, and Maryland, and the list of states with no current requirement.
- IAPP. "US State Privacy Legislation Tracker." 20 states with a comprehensive privacy law in effect as of January 2026, used for the total state count this post compares against.
- Hausladen, Wang, Eng, Wang, Wijaya, May, and Zimmeck: Websites' Global Privacy Control Compliance at Scale and over Time (USENIX Security 2025). Wesleyan University and Princeton University. Longitudinal crawl of 11,708 US websites finding 45% GPC compliance in April 2024.
- Global Privacy Control. Official specification site. Signal adoption figures, including over 66,000 participating websites, checked August 2026.
- Recording Law. "What Is the TDPSA? Texas Data Privacy and Security Act." Texas universal opt-out mechanism requirement effective January 1, 2025.
Note: All figures verified as of August 2026. The Delaware, Montana, Oregon, Nebraska, New Hampshire, Maryland, and Minnesota dates rely on Cookiebot's compiled tracker rather than a direct read of each state's Attorney General guidance page, unlike the Colorado, Connecticut, New Jersey, and California dates, which are confirmed directly against official state sources; readers relying on this post for a compliance decision in those seven states should confirm the specific date against that state's current statute or Attorney General guidance before acting. Vermont's 2028 requirement is a scheduled future date and could still change before it arrives. This post is refreshed at least twice a year as more states add opt-out-signal requirements.