Most small US contractor and home service websites don’t legally need a cookie consent banner, because state privacy laws use an opt-out model instead of the EU-style banner that blocks cookies until someone clicks accept, and many local businesses fall below the size thresholds that trigger those laws at all. What actually matters is narrower: whether the business sells or shares personal data for targeted advertising, and whether it draws meaningful traffic from the EU, UK or a handful of specific US states with stricter rules.
Why US law works differently than GDPR
The EU model, built on the GDPR and Germany’s TDDDG, requires opt-in consent before non-essential cookies load at all. US law took a different path. There’s no federal cookie law, and the state laws that do cover privacy, California’s CCPA/CPRA, along with newer laws in Colorado, Connecticut, Virginia, Texas, Oregon, Montana and Utah, generally give consumers a right to opt out of having their data sold or used for targeted ads rather than requiring opt-in consent up front. In practice, that means a banner that blocks every cookie by default is rarely a legal requirement for a US business, even though many sites run one anyway out of caution or because a template shipped with it.
Where these laws do bite is sensitive data and children’s data, which several states treat with opt-in rules closer to the EU model. A contractor site collecting nothing more sensitive than a name, phone number and job description through a contact form sits well outside that category.
When a Do Not Sell or Share link actually applies
The trigger isn’t having a website, it’s what the business does with the data once collected. California’s CCPA/CPRA applies once a business crosses one of three thresholds: more than 25 million dollars in annual gross revenue, buying or selling personal data on 100,000 or more California residents or households in a year, or earning at least half of annual revenue from selling personal information. A one-truck plumbing outfit or a five-person electrical contractor almost never meets any of these, which means the “Do Not Sell or Share My Personal Information” link, and the requirement to honor Global Privacy Control signals sent automatically by some browsers, doesn’t apply.
| Situation | Do Not Sell/Share link needed | Why |
|---|---|---|
| Local contractor, contact form only, no ad retargeting | No | Below CCPA/CPRA thresholds |
| Regional home services company running retargeting ads and selling leads to a marketing partner | Possibly | Selling/sharing personal data for advertising can trigger the requirement regardless of size in some states |
| Multi-location franchise with over 25M in annual revenue | Yes, in covered states | Meets the revenue threshold directly |
| Any business collecting data from EU or UK visitors | Different rules apply | GDPR and UK GDPR, not US state law, govern that traffic |
Growing home service businesses that sell leads to a marketing network or a franchise parent company should check this more carefully, since sharing data with a third party for compensation can trigger disclosure obligations even at a modest size.
What Google actually requires
Separate from state law, Google has its own consent policy for advertisers and Analytics users. If a business runs Google Ads or Google Analytics and receives a meaningful share of traffic from the EU, UK or Switzerland, Google requires a valid consent mechanism and, for ad personalization data, implementation of Consent Mode, typically through a consent banner or a dedicated consent management platform. For a business that only serves and advertises to a local US market, that requirement doesn’t apply, since it’s tied to Google’s EU and UK consent rules rather than US law. The distinction matters because plenty of generic compliance guides don’t separate the two, and a contractor serving only local customers can end up installing a banner that solves a problem they don’t have.
Common tools that quietly raise the question
Even when the legal threshold isn’t met, some common website features are worth a second look because of what they load in the background. An embedded YouTube video from a past job can pull in Google-hosted resources the moment the page loads, not just when someone hits play, unless it’s embedded in privacy-enhanced mode. A live chat widget usually drops its own identifier to track a conversation across page views. An embedded Instagram feed on the homepage loads content directly from a third-party server, similar to an embedded Google Map. None of these automatically require a US-style Do Not Sell link, but they’re the kind of detail worth listing out if a business later expands into a state with tighter rules or starts drawing international traffic.
A practical checklist
- List every third-party tool actually running on the site: analytics, ad pixels, chat widgets, embedded video or social feeds.
- Check current annual revenue and data volume against the state thresholds that apply to the business’s home state and any state where it actively advertises.
- If retargeting ads or lead-selling partnerships are in place, confirm whether a Do Not Sell or Share link and Global Privacy Control support are required.
- If a meaningful share of traffic comes from the EU, UK or Switzerland, treat that segment under GDPR rules and Google’s Consent Mode requirement rather than US state law.
- Keep a simple, accurate privacy policy that reflects the tools actually in use rather than a generic template, since an inaccurate policy is a more common source of complaints than a missing banner.
- Revisit the list whenever a new tool, ad platform or lead-sharing partner gets added, since that’s usually what changes the answer.
For most single-location contractors serving a local market, this is a short exercise that ends with “no banner needed, keep the privacy policy accurate.” For businesses selling leads to a network, running EU-facing ads, or growing past the CCPA thresholds, it’s worth a proper legal review rather than guesswork. Legal Pages Every Business Website Needs covers the adjacent question of what a site’s legal pages should contain, and Contractor Website Must-Have Pages covers where a privacy policy fits among the rest of the required content. Inside our subscription web design service, keeping these pages current as tools change is part of the standard website care plan.