Every business owner has seen the pop-up: "We use cookies. Accept All." Almost none of them know whether their own site is supposed to have one. For most small businesses in New York the honest answer is narrower and less alarming than the internet suggests — but it turns on one question: does your site carry advertising trackers?
What cookies and pixels actually are
A cookie is a small text file a website asks your browser to save and hands back on every later visit — a note the site leaves for itself so it can recognize you. What matters is who reads the note. A first-party cookie is set by the site you are on: your cart remembering three pounds of chicken cutlets. A third-party cookie is set by another company whose code is embedded in the page, letting it recognize the same person across hundreds of unrelated sites. That is the part people object to.
A tracking pixel was originally a one-pixel transparent image loaded from an advertiser's server. Today it is almost always a small piece of JavaScript — the Meta Pixel, the Google Ads remarketing tag, the TikTok Pixel — reporting what page the visitor is on and what they did there.
Owners consistently miss this: a pixel does not need a cookie to be a privacy problem. When a Meta Pixel fires, the visitor's browser makes a direct request to Meta's servers carrying their IP address, the page URL, and whatever event you configured — "viewed product," "submitted contact form." Meta receives that whether or not any cookie was stored. "We blocked third-party cookies, so we're fine" is not a real answer.
The distinction that decides everything
Every privacy regime draws the same line: technology you genuinely need to deliver the service, versus technology you use to measure and monetize the visitor.
| Category | Examples | EU consent needed? |
|---|---|---|
| Strictly necessary | Shopping cart, login session, security tokens, fraud prevention | No |
| Analytics | Google Analytics 4, Microsoft Clarity, Hotjar, session recording | Yes (narrow national exceptions) |
| Advertising | Meta Pixel, Google Ads remarketing, TikTok Pixel, LinkedIn Insight Tag | Yes, unambiguously |
| Non-essential extras | Embedded YouTube videos, third-party chat widgets, embedded maps | Usually yes |
"Strictly necessary" means necessary for the visitor, not for you. Analytics feels essential to the business owner and is not, legally, essential to the visitor. France's regulator recognizes a narrow exemption for tightly configured first-party audience measurement with no cross-site tracking, but only on demanding conditions, and it does not travel: the UK's regulator has offered no equivalent, and UK law here is itself being amended. Do not plan around a national carve-out.
Where the EU rule actually comes from
This is the most commonly misstated fact about cookie banners, including by the people selling compliance software. The GDPR did not create the cookie banner. The requirement comes from the ePrivacy Directive (2002/58/EC), as amended in 2009 by Directive 2009/136/EC — the law people nicknamed "the cookie law." Its Article 5(3) says you may not store information on, or read information from, a user's device without consent, unless it is strictly necessary for a service they asked for.
What the GDPR did, from May 25, 2018, was redefine what consent means: freely given, specific, informed, unambiguous, and given by a clear affirmative action. That killed "by continuing to browse you agree" and the pre-ticked box. European regulators have built on that to insist rejecting be as easy as accepting — a regulatory interpretation rather than a line of statutory text, but the one actually being enforced. France's regulator has issued cookie-banner fines against very large US technology companies running from tens of millions into the hundreds of millions of euros, in part for burying "reject all" behind extra clicks.
So: ePrivacy creates the consent requirement; GDPR sets the standard for what counts as consent. One practical consequence — ePrivacy covers storing any information on a device, not just personal data, so "this cookie is anonymous" does not get you out of it in Europe.
Does this reach a business in Boro Park or Monsey?
Usually not. GDPR Article 3(2) reaches non-EU businesses only when they offer goods or services to people in the EU, or monitor behavior taking place in the EU. Recital 23 says explicitly that a site merely being accessible from Europe is not enough; it points to factors like currency, language, and shipping options. Regulators look for those real targeting signals: prices in euros, EU shipping options, a language chosen for an EU market. A grocery delivering to Brooklyn and Rockland zip codes is not targeting the EU. Neither is a Monsey caterer or a plumber who works five towns.
One caveat: the cookie rule itself lives in the ePrivacy Directive, implemented separately by each member state, so its territorial reach is not literally governed by Article 3(2). Regulators apply a similar targeting analysis in practice, and Article 3(2) is the right mental model for a small US business — but if you are near the line, ask a lawyer, not a blog post.
The interesting case in this community is the seforim store, because Hebrew book dealers really do ship to Antwerp, London, and Zurich. If your checkout offers Belgium as a destination, quotes prices in euros or pounds, or you have advertised there, the analysis changes. The UK has its own pair — UK GDPR plus the Privacy and Electronic Communications Regulations (PECR) — and PECR's cookie rule works the same way. If you sell internationally, see our guide to legal requirements for online stores.
What US law actually requires
There is no federal law requiring a general cookie banner. What the US has is a patchwork of state privacy laws — roughly twenty states have enacted comprehensive ones, and the count keeps moving as new laws pass and take effect — taking a different approach. They mostly do not require consent before tracking. They require disclosure, plus a right to opt out afterward. Two exceptions run the other way: most of these laws do require opt-in consent for sensitive categories of data, and the federal Children's Online Privacy Protection Act requires verifiable parental consent before a site directed at children under 13 collects personal information — including the persistent identifiers used for behavioral advertising. If your site is aimed at children, get advice rather than general guidance.
The word that matters is "sale"
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), defines "sale" broadly: disclosing personal information to a third party for monetary or other valuable consideration. A second category, "sharing," covers disclosure for cross-context behavioral advertising. You never received a check — but California enforcers take the position that sending visitor data to an ad platform so it can show those people your ads later is valuable consideration. The California Attorney General's 2022 settlement with the retailer Sephora, for $1.2 million, rested in part on that theory and in part on a failure to honor browser-based opt-out signals. A settlement is not a court ruling, so treat this as an enforcement position rather than a decided question — but it is the position being enforced.
The critical detail for a small business: the CCPA has thresholds. It applies only to a for-profit business doing business in California that meets one of these:
- annual gross revenue above the statutory $25 million figure, which California adjusts for inflation and which now sits somewhat above that number — check the current figure before relying on it;
- buying, selling, or sharing personal information of 100,000 or more California consumers or households a year; or
- deriving 50% or more of annual revenue from selling or sharing personal information.
A kosher butcher in Brooklyn hits none of those, and most other state laws use similar volume thresholds. Texas is the outlier: its Data Privacy and Security Act, effective July 1, 2024, has no revenue or volume threshold, but exempts businesses qualifying as small under the US Small Business Administration's definition — with the catch that even a small business must get consent before selling sensitive personal data.
New York does not currently have a comprehensive consumer privacy law of the California type, though it does have narrower statutes aimed at children's data and health data, and comprehensive bills are introduced every session. The law people usually name — the SHIELD Act — is a data security and breach notification law requiring reasonable safeguards for New York residents' private information; its breach-notification changes took effect in 2019 and its data-security requirements in March 2020. It is not a cookie law and does not require a banner.
The risk nobody mentions: pixel lawsuits
The realistic danger to an American small business is not a regulator. It is a plaintiff's firm. There has been a large wave of class actions and pre-suit demand letters using old wiretapping statutes — most prominently the California Invasion of Privacy Act (CIPA), plus comparable laws in states including Pennsylvania and Massachusetts — against sites running session-replay tools and advertising pixels, arguing the third-party script is an unauthorized interception of the visitor's communication with the site. A parallel wave has run under the federal Video Privacy Protection Act (VPPA) against sites hosting video alongside a Meta Pixel.
Courts have not agreed with each other on any of this. Some judges let these claims proceed; others dismiss them as a strained reading of statutes written for telephone wiretaps. Massachusetts shows how fast it moves: its highest court held in 2024 that the state wiretap statute does not cover ordinary website browsing tracking, largely closing that door there — while federal appellate courts have split on the VPPA over something as basic as who counts as a "consumer." The law is genuinely unsettled and varies by jurisdiction; do not treat any one decision you read about as the national rule. What is settled is the economics: demand letters are cheap to send, and defending even a meritless suit is not. Exposure concentrates on sites that run third-party ad or recording scripts, get real traffic, and touch sensitive subject matter.
Health-adjacent sites are their own category
If you are a therapist, an ABA provider, or a medical billing company — anyone whose visitors are identifiable as seeking care — treat advertising pixels as off-limits until a lawyer says otherwise. The US Department of Health and Human Services issued guidance in December 2022 warning that online tracking technologies used by HIPAA covered entities can result in impermissible disclosure of protected health information. A federal court in Texas vacated part of that guidance in 2024 — broadly, the portion covering unauthenticated public web pages — so its exact reach is contested; do not assume it is fully in force, or that it is gone. The underlying risk did not disappear, because the Federal Trade Commission has pursued similar conduct under different authority against companies that were not covered entities at all, including 2023 actions against GoodRx (a $1.5 million civil penalty) and BetterHelp ($7.8 million for consumer refunds). The safe move costs nothing: keep advertising pixels off any page about symptoms, insurance, or appointment booking.
Why most cookie banners do nothing at all
A very large share of small-business cookie banners are decorative. The failure works like this. The site's Google Analytics and Meta Pixel code sits in the page header and runs the instant the page loads. Then a banner appears. Click "Accept," it saves a note and hides. Click "Reject," it saves a different note and hides. In both cases the trackers already fired, before the click. Nothing was ever blocked.
This is worse than having no banner. Under EU rules it fails the core requirement, because consent must come before the storage or access. Under US rules it delivers no opt-out to anyone who asked for one. And it is a public statement about how your site behaves that is not true — precisely the sort of thing consumer-protection regulators exist to police. Checking takes no technical skill: ask whoever built the site whether the banner actually blocks the scripts or just records the click. If nobody can answer, assume the worst.
Notice banner versus a real consent manager
| Notice banner | Consent management platform | |
|---|---|---|
| What it does | Tells visitors cookies are in use | Prevents non-essential scripts from running until permission is given |
| Granularity | One "OK" button | Separate toggles per category |
| Record keeping | None | Logs each consent with timestamp and choices, so you can prove it |
| Withdrawal | No way to change your mind | Persistent link to reopen and change settings |
| Browser signals | Ignored | Reads Global Privacy Control and applies it automatically |
| Sufficient in the EU | No | Yes, if configured correctly |
That last row does a lot of work. A consent platform left on defaults, with every script still hard-coded into the page template, blocks nothing either. It has to be wired to the actual scripts — usually through a tag manager — or it is expensive decoration.
Global Privacy Control (GPC) is where US law is heading. It is a signal a browser or extension sends automatically meaning "I opt out." California's regulators take the position that CCPA-covered businesses must honor opt-out preference signals like GPC; Colorado, Connecticut, and several other states likewise require covered businesses to honor a universal opt-out mechanism. It needs no banner and no click from the visitor. All of these obligations attach only to businesses their statutes actually cover — but if a state law does cover you, honoring GPC matters more than the pop-up does.
Google Consent Mode, in plain terms
Consent Mode is not a law and not a banner. It is a way for your banner to tell Google's tags what the visitor decided, so the tags adjust their own behavior instead of being blocked outright. Since March 2024, Google has required advertisers serving users in the European Economic Area or the UK to send these signals to keep using audience and remarketing features.
There are two configurations. In basic mode, Google's tags do not load until the visitor consents — cleanest legally, but you lose all data from anyone who declines. In advanced mode, the tags load immediately in a restricted, cookieless state, send anonymized pings, and Google uses statistical modeling to estimate the conversions you can no longer observe. Be clear-eyed about advanced mode: it still sends a request to Google before the visitor consented to anything, and European regulators have expressed unease about that, though no decision has squarely resolved it. Consent Mode is a Google product requirement, not a legal safe harbor.
Three worked examples
A kosher grocery delivering to local zip codes
Online order form, Google Analytics 4, no Facebook ads, no remarketing, ships nowhere outside a forty-mile radius. What is needed: a privacy policy naming Google Analytics and explaining what it collects. On those facts no cookie banner and no opt-out link are legally required, and that is realistically the whole of it. To be tidy, turn off Google Signals in your Analytics settings — the setting that enables advertising-related data sharing — which makes the already-thin "sharing" argument thinner still.
A caterer running Google Ads remarketing
Same site, but the owner pays to show ads to people who viewed the menu and did not call. Visitor data now goes to Google for cross-context behavioral advertising. What is needed: first, a caveat the internet always skips — the CCPA's machinery only switches on if the business crosses one of the thresholds above, and a local caterer will not. What the pixel changes is the risk picture, not usually which statute applies. So: describe the arrangement in the privacy policy using the statutes' own vocabulary — that personal information may be "sold" or "shared" for advertising — add a "Your Privacy Choices" link that genuinely turns the tag off for that visitor, and honor Global Privacy Control. Strictly speaking none of that is compelled for a purely local, under-threshold US business, and neither is a blocking banner. But it is all cheap, it is what an accurate privacy policy requires you to work out anyway, and Google's and Meta's own terms do independently require honest notice.
A therapy practice or ABA provider
A "Services" page listing conditions treated, plus an intake form. What is needed: remove advertising pixels entirely, or at minimum from every page that reveals why someone is there. Keep analytics if you want, but disable any feature storing advertising identifiers, and do not put an unfamiliar chat widget on an intake page. This is the one category where the honest advice is to spend money on a lawyer before you spend it on marketing tools.
What it costs, and what happens if you skip it
Rough ranges, not quotes. A privacy policy written for your actual site: often a few hundred dollars from a lawyer, though it varies by firm and by how complicated your site is, and it is sometimes included in a competent build. Free generators beat nothing, but they routinely list tools you do not use and omit ones you do. A real consent management platform: usable free tiers exist for very small sites, and paid plans for a small business site have generally run somewhere around ten to fifty dollars a month — check current vendor pricing, because it moves. Wiring one up correctly is a few hours of developer time, not a project.
What happens if a local business with only basic analytics does nothing? Realistically, very little. No EU regulator has any interest in a Brooklyn butcher, and the state-law thresholds are nowhere close to being crossed. Anyone telling you otherwise is selling something. For a business running ad pixels the risk is real, but it arrives as a demand letter, not a regulator. There is also the quiet cost of a banner that slows your pages and irritates people for no compliance benefit — every third-party script is one more thing a visitor's browser must download before they find your phone number.
What to actually do
- Find out what is on your site. Ask your developer for a plain list of every third-party script. If nobody can tell you, that is the finding.
- Delete what you do not use. Most small businesses carry trackers installed years ago by someone long gone, feeding a dashboard nobody opens. Removing one is free, instant, and eliminates every legal question about it.
- Publish a privacy policy that matches reality — not a template describing a company you are not.
- If you run ad pixels, add the opt-out mechanics, honor Global Privacy Control, and use a blocking consent banner rather than a decorative one.
- If you ship or advertise internationally, get a proper consent management platform and configure it for those visitors.
- Test the banner you already have. If it blocks nothing, it is a liability dressed as a solution.
Consent rules for text and email marketing follow similar logic and trip up more small businesses than cookies do — covered separately in our guide on email and SMS marketing law. If you would rather someone sorted out the whole picture, tell us about your site and we will look at what is actually loading on it.
The short version
- The EU cookie banner comes from the ePrivacy Directive, not the GDPR. The GDPR only defines what counts as valid consent. A US business serving US customers is almost certainly outside its reach.
- No US law requires a general cookie banner. State privacy laws instead require disclosure and an opt-out from the "sale" or "sharing" of personal information — and advertising pixels can trigger that even though no money changes hands. Those laws only bite if your business crosses their thresholds, and sites aimed at children are a separate federal problem.
- Basic analytics plus local customers means your obligation is a truthful privacy policy. That is genuinely it.
- Retargeting pixels change your position materially — they call for real disclosure, a working opt-out, and respect for Global Privacy Control, whether or not a statute technically reaches you.
- Most small-business cookie banners block nothing. The trackers fire before the click, which is worse than having no banner at all.
- Health-adjacent sites should keep advertising pixels off entirely. That single decision removes most of the real risk.