At a Glance
- A CMP (consent management platform) is the system that runs your cookie banner, records what visitors chose, and applies that choice across your site and with third-party platforms.
- A cookie banner and a CMP are not the same thing. A banner with nothing behind it can’t prove what happened. A CMP is where the configuration, storage, and other key functions live.
- More than 20 states now have their own privacy laws, and California’s CIPA, originally a 1967 wiretapping statute, is now driving a wave of private lawsuits over ordinary website tools.
- 12 states require you to recognize Global Privacy Control (GPC) and similar opt-out signals, whether or not a visitor interacts with your banner at all.
- The law(s) that applies depends on where your visitors and customers live, not where your business is based.
- Being able to show what a visitor chose, and respond to a data request, can matter months or years after the fact, not just on launch day.
You’ve almost certainly seen a cookie banner before, maybe built one yourself. But a banner by itself doesn’t do much. A consent management platform (CMP) is the system working behind that banner, recording choices, applying them, maintaining proof, and running automatic updates.
Here’s what a CMP actually does, its increasing necessity to U.S. businesses, and why it matters more than many business owners realize.
What Is a CMP, in Plain Terms?
The cookie or consent banner is the part your visitors see and click, whether on your website, app, connected TV, or other platform. It’s there to enable visitors to make choices about the collection and use of their personal data for analytics, advertising, and other purposes.
The consent management platform, or CMP, is what’s running behind it. It’s the system that decides what that banner should say, remembers what a visitor chose, and makes that choice hold everywhere else it needs to — across your tags, your tools, and your other properties.
The banner and the CMP work together, but they’re not the same thing. That distinction is worth being clear on before you set either one up, which is where the next section comes in.
A Cookie Banner Is Not the Same as a CMP, and Here’s the Difference
A lot of websites have a banner with little behind it. It pops up, the visitor clicks something (or scrolls by or closes it without interacting), and the banner disappears. Nothing was actually recorded, or what was recorded can’t be signaled beyond the banner itself, and the tracking tools may have already been running before the visitor made a choice at all.
That gap is what separates a banner from a CMP. Without the system behind it, a banner can ask the question but can’t enforce the answer, and it can’t prove later what happened. A CMP is what closes that gap.
What Does a CMP Do for Your Website?
A CMP handles this, continuously, once it’s set up:
- Shows the right banner to the right visitor, in the right language, based on their location, and applies the law that applies there (geotargeting)
- Blocks or allows tracking tools to run based on what the visitor actually chose, not before
- Honors consents and opt-outs from browser-based signals via Global Privacy Control (GPC) or another universal opt-out mechanism (UOOM)
- Keeps an exportable, timestamped record of what was shown, what was chosen, and when
- Updates itself automatically as tracker lists and applicable laws change
U.S. Privacy Laws, Lawsuits, and Enforcement: Why You Need a CMP
The U.S. doesn’t have one national privacy law. Instead, more than 20 states now have their own comprehensive privacy laws, each with somewhat different rules about who has to comply, consent, opt-outs, and enforcement. There are also federal laws governing use of children’s or other sensitive data like that used for healthcare or financial services.
This patchwork is a significant part of why a manual, single-banner approach doesn’t hold up.
CIPA and Similar Laws and Litigation Risk
California adds a second layer of risk that’s specific to it. The California Invasion of Privacy Act (CIPA), originally a 1967 wiretapping law, has been used in a wave of private lawsuits arguing that ordinary website tools like analytics and chat widgets amount to illegal wiretapping.
That can mean statutory damages up to $5,000 per violation, no proof of harm required. SB 690 would narrow this, but it’s not law yet. It passed the Legislature and is awaiting the Governor’s signature by September 9, 2026. If signed, it removes one specific claim type (tracking tools as illegal “pen registers”) starting January 1, 2027, applied back two years.
It leaves CIPA’s broader wiretapping claims untouched, so that risk stays either way. And CIPA isn’t the only older law being used this way. FSCA in Florida and WESCA in Pennsylvania are being used similarly, and the federal VPPA and ECPA are being cited alongside CIPA in some cases. California legislation doesn’t touch any of these.
Global Privacy Control (GPC) and Other Opt-Out Signals
On top of state law and CIPA litigation, 12 states and counting now require businesses to recognize browser-based opt-out signals like Global Privacy Control (GPC). This means that an individual sets their privacy preferences once in their browser settings or via a plugin. Those preferences are then signaled to every website that person visits, without the visitor needing to interact with a consent banner or other mechanism.
As of January 1, 2027, a new California law (AB 566, the Opt Me Out Act) will require browsers serving California residents to build in an opt-out preference signal, which is commonly implemented via GPC.
A CMP like Usercentrics provides a practical way for businesses to manage these increasingly complex requirements.
How to Choose the Right Framework for Your Business
“Framework” just means the specific rule set your CMP applies for a given state or law. The right one for you depends on:
Where your visitors are
The law(s) that applies is generally based on the visitor’s state, not where your business is registered.
Whether you sell or share personal data, or run targeted ads
This is what triggers opt-out obligations, including GPC recognition, in most states.
Your business size and data handling volume
Several state laws only apply once you cross a certain number of state residents’ records processed or a revenue threshold, which is worth checking against your actual numbers rather than assuming a law doesn’t apply to you.
Whether you handle sensitive data
Health, precise location, financial, or children’s data can trigger stricter, opt-in-based rules in some states.
A framework that only covers California isn’t enough if you have meaningful traffic from Colorado, Connecticut, Texas, or any of the other states with their own rules. And if you expand globally, entirely different jurisdictional requirements will apply and you will need to manage them too.
Learn more: Cookies, consent, and confusion: A beginner’s guide to website tracking
Selecting the Right Templates for Your CMP
Once you know which state laws apply to your business, you configure your CMP by selecting the matching templates rather than building each one yourself, whether state by state or “all U.S.” Templates like the Usercentrics CIPA Template come built around a specific law’s requirements, so the right rules apply automatically for visitors from that state.
You can also manually make granular selections for how the banner appears and which consent choices it offers. And the larger your operational footprint, the more templates you’ll want selected to cover every jurisdiction where you do business.
Multi-State Privacy Compliance and Why “Just Following California” Isn’t Enough
It’s a common assumption that complying with California’s rules covers most of the risk. California has more regulations than many states, but an increasing number of states now have their own comprehensive privacy laws.
Several have requirements California doesn’t have, and, importantly, these laws apply based on where your visitors live, not where you’re headquartered. A business with no offices in Colorado can still be fully subject to Colorado’s privacy law if Colorado residents visit its site. And a business based in a state with no privacy law on the books yet can be subject to 20 of them if it has customers around the country.
This is the practical meaning of “extraterritoriality” for a U.S. business. Your obligations follow your traffic, not your address. Multi-state compliance isn’t an advanced feature. For any site with a national audience, it’s close to the default requirement.
Staying Audit-Ready: Proving Privacy Compliance and Responding to Data Requests
If a regulator, a customer, or a plaintiff’s attorney asks what happened on your site for a specific visitor, “we have a banner” isn’t an answer. You need to be able to show:
- What banner that visitor saw, and what they chose
- That their opt-out was actually applied across your tools, not just recorded
- A complete, timely response to a data subject access request (DSAR), including what data you hold, and where it came from, and who had access to it
A CMP that keeps this record automatically, for as long as your state’s law requires, is what turns “audit-ready” into something you don’t have to build from scratch under pressure.
That’s the difference between scrambling to reconstruct what happened and simply pulling up the record. The former costs you time when a deadline is already running, and the latter is just Tuesday — when you’re able to stay focused on growing your business.