Consent & Cookies
What is Opt-In vs Opt-Out Consent?
Opt-in and opt-out are the two consent models in privacy law: opt-in (the EU approach) prohibits tracking until the user affirmatively agrees, while opt-out (the general US approach) permits it by default until the user objects.
Under the opt-in model — GDPR and ePrivacy in the EU and UK — the default state is no processing: non-essential cookies stay off, marketing lists stay empty, and data flows begin only after a clear affirmative action. Silence, inactivity, and pre-ticked boxes mean no. The burden sits on the business to obtain and prove consent before acting.
Under the opt-out model that dominates US state privacy law, businesses may generally collect and use personal information by default, but consumers hold rights to stop specific uses: opting out of the sale or sharing of their data, of targeted advertising, and of certain profiling. The burden sits on the consumer to object — though laws increasingly automate that objection through universal signals like the Global Privacy Control, which businesses in California and a growing list of states must honor as a valid opt-out.
The models also diverge on exceptions. Even opt-out states import opt-in requirements for higher-risk categories: sensitive personal information under several state laws, consumer health data under Washington's My Health My Data Act, and data about children. Conversely, the EU's opt-in regime carves out strictly necessary cookies and recognizes non-consent legal bases (like legitimate interest) for some non-tracking processing under GDPR — though not for the device access governed by ePrivacy.
Global websites reconcile the two with geolocation: EU and UK visitors receive a blocking opt-in banner, US visitors receive default-on behavior with functioning opt-out mechanics. The operational risk is misclassification — an EU visitor served the US experience has been tracked unlawfully from the first pageview.
Why it matters for eCommerce
The model determines your addressable marketing audience. In opt-in markets, banner design and trust directly set the share of shoppers you can retarget; in opt-out markets, audience quality depends on honoring GPC and Do Not Sell or Share requests cleanly so consented segments stay clean. One storefront, two consent architectures, decided by geolocation at the edge.
Frequently asked questions
- Which countries require opt-in consent for cookies?
- The EU member states and the UK (via ePrivacy rules and GDPR), along with a number of jurisdictions modeled on them — Brazil's LGPD and others lean opt-in for tracking. The US, by contrast, is opt-out for most processing under its state privacy laws.
- Are there opt-in requirements inside US privacy law?
- Yes. Several state laws require opt-in consent for processing sensitive personal information, Washington's MHMD requires consent for collecting consumer health data, and COPPA requires parental consent for children under 13. Opt-out is the default, not the whole story.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Run a free scan