WordPress Consent Plugins for US State Privacy Laws

Twenty US states now have comprehensive consumer privacy laws in effect, after Indiana, Kentucky and Rhode Island switched on together on 1 January 2026. Twelve of them require you to honour the Global Privacy Control signal, a browser setting that opts a visitor out automatically before they have seen your site at all. In California you must also show them you did it.
Almost every WordPress consent article is shaped around Europe, which produces the wrong architecture for a US audience. The American model is opt-out, not opt-in, and a banner demanding permission before anything loads is solving a problem several of these states do not have while ignoring the one they do. This article covers the structural difference, which states impose what, and how the plugins compare on US support specifically.
Verified August 2026. This is a practical guide, not legal advice.
How the US model differs
Under GDPR you may not set non-essential cookies until someone agrees. Under the US state laws you generally may process data by default, and the consumer’s rights are to find out, to object, and to opt out of specific things, principally the sale of personal data and targeted advertising. The obligation is to provide a working exit, prominently, not to wait at the entrance.
The practical consequences for a WordPress site are three. You need a clearly linked opt-out mechanism, historically the “Do Not Sell or Share My Personal Information” link. You need to honour Global Privacy Control automatically, without any visitor interaction. And “sale” is defined broadly enough in most of these statutes that sharing data with an advertising platform for targeting counts, which surprises businesses that have never sold a list in their lives.
There is also a category of data most of these laws treat as opt-in regardless: sensitive data, which typically covers health, precise geolocation, biometrics, race, religion, sexual orientation, immigration status, and children’s data. If your site touches any of those, the American picture starts resembling the European one.
Global Privacy Control, and why it is the hard part
GPC is a signal a browser or extension sends with every request saying the visitor opts out. As of 1 January 2026, twelve states require businesses to recognise it: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas.
It is the hard part because it is invisible. A banner is visible, testable, and obviously present or absent. GPC handling either happens silently and correctly or fails silently, and nobody notices until an enforcement letter arrives. It also cannot be satisfied by a consent interface alone: the signal arrives before any interaction, so your site has to read it server-side or early enough client-side to suppress the relevant tags on that first page load.
California now goes further, requiring a visible confirmation when a GPC signal is detected, such as a badge indicating the opt-out request has been honoured. That is a genuine functional requirement and a useful shortlisting question: ask any vendor directly whether their plugin can display it.
The 6 options compared
1. Complianz
The default recommendation for a WordPress site facing both regimes, at $59 a year for a single site with no traffic meter. Its structural advantage is that it treats jurisdiction as a configuration question rather than a product question.
You tell it which regions you serve and it produces the appropriate behaviour for each: opt-in with blocking for European visitors, opt-out with a preferences link for American ones, and the corresponding policy text. That geo-conditional model is the correct architecture, because showing a US visitor a European-style consent wall costs you measurement for no legal benefit, and showing a European visitor a Do Not Sell link satisfies nothing. Confirm GPC handling and the California confirmation badge against your own configuration before relying on either.
- Price: From $59 a year, single site, flat
- US support: Geo-conditional opt-out model with US policy text
- Best for: Sites serving both the US and Europe
- Watch out for: Verify GPC behaviour yourself, it is invisible
2. Termly
US-first in a category that is overwhelmingly European in orientation, which makes it worth a look precisely because its defaults assume the American structure rather than bolting it on. There is a real free tier, and paid pricing works out at roughly $0.67 per site per day, which is around $245 a year and reads differently depending on whether you have one site or thirty.
The daily per-site unit is the thing to model. For a single business site it is expensive against a $59 flat licence. For an agency it scales linearly with no cliff, which some prefer to tier boundaries. Termly also bundles policy generation, which is genuinely relevant here since these statutes impose specific notice content requirements that a generic European policy will not satisfy.
- Price: Free tier; paid around $0.67 per site per day
- US support: Strongest orientation, US assumptions by default
- Best for: US-only businesses and agencies
- Watch out for: Expensive for a single site against flat licences
3. CookieYes
From $10 a month on a pageview meter and built around serving several jurisdictions from one implementation, which is exactly the shape of the problem when twenty states have twenty variations of the same idea.
Its multi-regime handling is the reason to consider it and the pageview meter is the reason to check the maths. A US content business with substantial traffic and thin margins per visitor can find this the most expensive option in the list within a year, while a low-traffic professional services site pays almost nothing. Model your peak month rather than your average. As with everything here, verify GPC handling on a live page rather than trusting the feature list, since it is the requirement most commonly claimed and least commonly tested.
- Price: From $10 a month, scaling with pageviews
- US support: Multi-jurisdiction from a single banner
- Best for: Low-traffic sites needing many regimes fast
- Watch out for: Traffic growth drives cost past flat licences
4. Osano
The enterprise answer, with a free tier that exists mainly to introduce the platform and paid plans from around $199 a month. That is roughly $2,400 a year against a $59 plugin, and the gap has to be justified by something other than the banner.
What justifies it, when it is justified, is organisational rather than technical: consent records maintained to a standard that survives legal review, vendor and data-flow monitoring across a portfolio, and the assurances a compliance function needs to sign something off. For a company with a legal department and multiple properties that is a reasonable purchase. For a WordPress site with a marketing team of one it is a category error, and the free tier is a better way to discover that than a subscription.
- Price: Free tier; paid from around $199 a month
- US support: Comprehensive, built for US enterprise compliance
- Best for: Organisations with a compliance function
- Watch out for: Around forty times the cost of a flat plugin licence
5. WebToffee GDPR Cookie Consent
Despite the name it handles US regimes, and its pricing structure suits American content and ecommerce sites unusually well: $69 a year for a single site with explicitly unlimited pageviews, then $199 for five sites, $399 for twenty-five and $1,199 for a hundred.
Unlimited pageviews matters more in the US market than the European one, because the American sites most exposed to these laws are frequently high-traffic media and ecommerce properties whose economics do not tolerate a compliance bill that scales with success. The consent log exports to CSV, which covers the record-keeping side. Check the US-specific interface elements, the opt-out link and preference centre, on a staging site before committing, since the product’s centre of gravity is still the European framework.
- Price: $69/yr single site, unlimited pageviews; $199 for 5
- US support: Present, with a European centre of gravity
- Best for: High-traffic US sites and agencies
- Watch out for: Test the opt-out interface before buying
6. iubenda
A hosted platform with a genuine free tier and paid plans from around €4.99 a month on a pageview basis, making it the cheapest paid entry point here by a wide margin.
Its strength is breadth of paperwork rather than depth of blocking: policies, consent, and the surrounding documentation generated from one configuration and kept current as the underlying law changes. For a small US business that needs to be defensibly compliant across several states without employing anyone to think about it, that is a reasonable trade. Read the tier limits closely, because the free tier’s constraints are real and the low headline price attaches to a modest pageview allowance that a growing site leaves quickly.
- Price: Free tier; paid from around €4.99 a month
- US support: Multi-jurisdiction policies and consent
- Best for: Small businesses wanting documentation handled
- Watch out for: Low entry price buys a small pageview allowance
Comparison table
| Option | Price | Meter | US orientation | Best fit |
|---|---|---|---|---|
| Complianz | From $59/yr | None | Geo-conditional, both regimes | US plus Europe |
| Termly | Free; ~$0.67/site/day | Per site per day | US-first by default | US-only, agencies |
| CookieYes | From $10/mo | Pageviews | Multi-regime | Low-traffic sites |
| Osano | Free; from ~$199/mo | Platform tiers | Enterprise-grade | Compliance functions |
| WebToffee | $69/yr single site | None, unlimited views | Present, EU-centred | High-traffic US sites |
| iubenda | Free; from ~€4.99/mo | Pageviews | Multi-jurisdiction paperwork | Small businesses |
Which states, and do you even qualify
Most of these statutes follow the Virginia template and apply only above a threshold, commonly processing the personal data of 100,000 consumers in a year, or 25,000 consumers where a set share of revenue comes from selling personal data. A great many small businesses fall below every threshold in every state, and the correct response for them is a clear privacy policy and no purchase at all.
Three exceptions deserve attention because they catch people who assumed they were exempt:
- Texas has no numeric threshold. It applies to entities doing business in Texas that process or sell personal data and do not qualify as a small business under the federal definition. Size, not visitor count, decides it.
- Rhode Island set its bar unusually low, at 35,000 consumers, or 10,000 where more than 20% of revenue derives from selling personal data. A regional publisher can cross that without noticing.
- California uses a revenue trigger as well as a volume one, alongside a share-of-revenue test, so a profitable business with modest traffic can be in scope where a busy hobby site is not.
Count your annual unique visitors from each state before assuming anything. The number is usually far lower than the anxiety suggests, and where it genuinely is low, the honest answer is that you have a documentation obligation rather than a software one.
Related guides
Frequently asked questions
Do I need a cookie banner in the US?
Usually not in the European sense. What you need is a conspicuous opt-out mechanism, honoured GPC signals, and an accurate privacy notice. A blocking consent wall is the wrong shape for the American statutes and costs you measurement for nothing.
Am I “selling” data if I run ads?
Quite possibly. Most of these laws define sale broadly enough that sharing identifiers with an advertising platform for targeting qualifies, with or without money changing hands. Assume targeted advertising triggers the opt-out obligation unless you have advice saying otherwise.
How do I test whether GPC is working?
Install a browser extension that sends the signal, load your site in a fresh session, and check the network tab for advertising and analytics requests. They should be suppressed without you touching anything. In California, look for the visible confirmation as well.
Can I use one banner for the US and the EU?
Yes, and you should, but configure it geo-conditionally rather than identically. European visitors get opt-in with pre-consent blocking; US visitors get an opt-out interface and GPC handling. Every option above supports region-based behaviour.
What if I am below every threshold?
Then your obligations are largely limited to being honest in your privacy policy about what you collect and why. Publish an accurate notice, offer a contact route for requests, and revisit annually or when your traffic changes materially.
Do these laws cover employee or B2B data?
California’s regime notably extends to employee and business contact data, where most other states exempt them. If you are a California employer, that widens the scope considerably beyond your website.
The verdict
If you serve both the US and Europe: Complianz at $59 a year, flat, configured geo-conditionally so each audience gets the right model rather than the strictest one.
If you are US-only: Termly, whose defaults assume the American structure instead of adapting to it, priced per site per day so it scales cleanly across a portfolio.
If your traffic is high: WebToffee at $69 a year with unlimited pageviews, so compliance costs do not grow with the audience you are working to build.
And check your thresholds before buying anything. Twenty states with laws does not mean twenty states with laws that apply to you. Count your visitors by state, note that Texas and Rhode Island are the ones most likely to catch you unexpectedly, and buy software only once you know you are in scope.




