United States

Privacy & Compliance / Regional guide

Website Tracking Compliance in the United States

Summary

Website tracking is legal in the US, with conditions that vary by law and by state. With no single federal privacy law, tracking is governed by state consumer privacy laws, older wiretap and video-privacy statutes now applied to pixels, and health privacy rules. The common threads are honoring opt-outs, including GPC, and getting consent where a law needs it.

The US picture looks complicated because it is assembled from different laws written at different times. For a marketing or analytics team, it comes down to a manageable set of obligations, and most of them are about what your tags do and when.

The sections below cover the laws that govern US website tracking, what compliance requires in practice, and where enforcement comes from. The last section shows how to verify your site meets US requirements.

The laws that govern US website tracking

State consumer privacy laws. More than a dozen states have comprehensive privacy laws, sharing a baseline: opt-out of sale, sharing, and targeted advertising, honoring browser opt-out signals where required, and protecting sensitive data. US state privacy laws for marketers.

California CCPA and CPRA. The most developed state regime, where passing data to ad platforms through tags is a sale or share that visitors can opt out of, including by Global Privacy Control. CCPA and CPRA for tags.

CIPA (California wiretapping). A 1960s wiretap law plaintiffs apply to session replay, chat, and pixels that fire without consent. CIPA and website tracking.

VPPA (video privacy). A federal law restricting sharing what a person watched tied to their identity, now applied to pixels on pages with video. VPPA and pixels.

FERPA and COPPA (education and children’s data). FERPA covers student education records, and COPPA covers data collected online from children under 13 and counts cookies as personal information. FERPA and COPPA for tracking.

GLBA (financial data). Limits how banks, lenders, and fintechs share customer financial data, with pixel lawsuits run on wiretap laws. GLBA and financial-site tracking.

HIPAA (health data). Without the patient’s authorization, sending patient health information to a tracking vendor needs a signed business associate agreement and a Privacy Rule permission. HIPAA and tracking pixels. Is Google Analytics HIPAA compliant?

What US tracking compliance requires in practice

Three things carry most of the load. Honor opt-outs, including Global Privacy Control, which 12 states require (nine directly, three through an authorized agent). Get consent before tracking fires where a specific law calls for it: session replay, chat and pixels that raise CIPA exposure, video pages under the VPPA, and pages with sensitive or health data. And know what your tags collect and share, since sensitive data in a tag is where health, wiretap, and state-law exposure overlap.

Where the enforcement comes from

US tracking risk arrives two ways. State Attorneys General and California’s CPPA bring regulatory enforcement under the consumer privacy laws. Private plaintiffs bring class actions under CIPA and the VPPA, which do allow individual suits. California’s consumer privacy law allows private suits only for certain data breaches. For specific US cases, fines, and settlements, see our Enforcement Watch tracker, which tracks the actions behind these laws.

How to verify your site meets US requirements

The obligations behind many US enforcement actions, honoring opt-outs and GPC, and getting consent where CIPA exposure or sensitive and health data calls for it, are testable. DataTrue loads your site in a real browser, in each consent and opt-out state and with Global Privacy Control enabled, and records what every tag does. You can see whether opt-outs and GPC stop the sharing tags, whether anything fires before consent on the pages where you need it, and whether sensitive or health data is leaving. Sensitive Data Detection inspects the payloads with fictitious personas. The result is a timestamped record that covers the whole US baseline at once. DataTrue gives teams tools to help them become and stay compliant. It does not certify compliance.

Choosing where a DataTrue test runs from: Ireland, the USA, Canada, the UK, Australia or France.

See how consent verification works

Questions

Is website tracking legal in the United States?

Yes, with conditions. There is no single federal privacy law. Tracking is governed by state consumer privacy laws in more than a dozen states, older wiretap and video-privacy statutes applied to pixels, and health privacy rules. The common requirements are honoring opt-outs, including GPC where required, and getting consent where a specific law needs it.

Is there a US federal privacy law for website tracking?

Not a comprehensive one. Federal exposure comes from specific statutes like the VPPA for video and HIPAA for health data, and the FTC’s Health Breach Notification Rule covers health apps and similar services outside HIPAA. General consumer privacy is governed at the state level, with more than a dozen states having comprehensive laws.

What is the biggest US tracking litigation risk?

Class actions under CIPA and the VPPA, because those laws let individuals sue. CIPA sets statutory damages per violation, and the VPPA sets liquidated damages of at least $2,500. State consumer privacy laws are enforced by regulators, and California allows private suits only for certain data breaches, so they carry a different kind of risk.

How do I make my US tracking compliant?

Honor opt-outs and Global Privacy Control, get consent before tags fire where CIPA exposure or sensitive and health data calls for it, keep sensitive and health data out of tags that share it, and verify with testing that all of that actually happens on every page.

30-day free trial

See what your tags do in every consent state

DataTrue loads your real pages as a visitor who accepts, rejects, or sends an opt-out signal, and reads what each tag sends. A tag that ignores the visitor’s choice shows up in a test.

What DataTrue checks
  • Every page, with coverage scans
  • Scheduled runs, with alerts when a result changes
  • Full journeys, like checkout and signup, in each consent state
  • What each tag sent, field by field
Also in the full platform
  • PII detection with test personas
  • iOS and Android app testing
  • Pre-publish testing for GTM and Adobe Tags
  • REST API, plus Slack and Jira alerts
Start a free 30-day trial ★★★★★ 4.6/5 on G2

The full platform, every feature, free for 30 days.

A DataTrue opt-out consent test listing the tags that should be blocked, with pass or fail for each
A consent-state test in DataTrue