Book a Demo

Cookie Consent Laws to Watch Before 2027 — The Full Watchlist

What's next before 2027: Connecticut and India deadlines, January 2027 US privacy laws and browser opt-out signals, and the EU Digital Omnibus.

Written by
Daniel
Published on
Cookie Consent Laws to Watch Before 2027 — The Full Watchlist

If you updated your cookie banner this spring, congratulations: you are compliant with the past.

As of August 18, 2026, several of the year's biggest US and UK dates have already landed — Connecticut's SB 1295 amendments, Virginia's VCDPA tweaks, California DROP processing, and the UK DUAA complaints-procedure requirement. What remains is still unusually busy: Connecticut's October 2026 geolocation-sale ban, India's DPDP consent-manager and full-enforcement cliffs, three brand-new US state privacy laws with 2027 effective dates, California's browser opt-out requirement, and an EU Digital Omnibus proposal that is still changing — and is not law.

None of this requires panic. Most of it requires a calendar. This post is that calendar — what is now in force, what is genuinely still coming, what is still just a proposal, and what to prepare for first.

(For what is already in force and enforced today, see do you need to update your cookie banner in 2026; for how we got here, the 2026 changes retrospective; for the opt-in vs opt-out map, where opt-in cookie consent is required.)

Already live as of August 18, 2026: Connecticut's SB 1295 CTDPA amendments (July 1), Virginia's VCDPA amendments (July 1), California DROP processing for data brokers (August 1), and the UK DUAA complaints-procedure requirement (June 19). Still ahead on the confirmed pipeline: Connecticut's precise-geolocation sale ban on October 1, 2026; India's DPDP consent-manager phase on November 13, 2026; then on January 1, 2027 the Oklahoma and Louisiana privacy laws, California's browser opt-out and ADMT requirements, and Vermont's Age-Appropriate Design Code — followed by Alabama in May 2027 and full DPDP enforcement in India that same month. The EU's broader Digital Omnibus is still a proposal: the June Council Presidency text changed the Commission's cookie approach, Ireland is iterating on it, and Parliament is developing its own position.

Here is the watchlist at a glance:

Date Jurisdiction What happens Status (Aug 2026)
Jun 19, 2026 UK DUAA complaints-procedure requirement In force
Jul 1, 2026 Connecticut CTDPA amendments (SB 1295): lower thresholds, minors' ad ban In force
Jul 1, 2026 Virginia VCDPA amendments on specific data categories In force
Aug 1, 2026 California Data brokers must process DROP deletion requests In force
Oct 1, 2026 Connecticut SB 4 / PA 26-64: precise-geolocation sale ban (+ related CTDPA updates) Upcoming
Nov 13, 2026 India DPDP Rules Phase 2: Consent Manager registration framework Upcoming
Jan 1, 2027 Oklahoma Oklahoma Consumer Data Privacy Act takes effect Upcoming
Jan 1, 2027 Louisiana Louisiana Data Privacy Act (SB 386 / Act 502) takes effect Upcoming
Jan 1, 2027 California Opt Me Out Act (AB 566): browsers must offer a configurable opt-out preference signal Upcoming
Jan 1, 2027 California CCPA ADMT (automated decision-making) compliance date Upcoming
Jan 1, 2027 Vermont Age-Appropriate Design Code (Act 63) takes effect Upcoming
Jan 1, 2027 Connecticut Data broker registration required to sell/license brokered data Upcoming
May 1, 2027 Alabama Alabama Personal Data Protection Act takes effect Upcoming
May 13, 2027 India DPDP Phase 3: full substantive duties + enforcement powers Upcoming
Jul 1, 2027 Kentucky KCDPA amendments (HB 692) take effect Upcoming
TBD EU Digital Omnibus cookie rules: Council and Parliament positions still being developed Proposed only; no mandate or EP position
TBD Canada Bill C-36 would replace PIPEDA's privacy provisions; Alberta PIPA amendments expected C-36 at second reading; not law

United States: the 2026–2027 pipeline keeps filling

The wave that brought Tennessee, Minnesota, and Maryland online in 2025, then Indiana, Kentucky, and Rhode Island on January 1, 2026, has not crested. Mid-2026 added another cluster of hard dates; the rest of the year and early 2027 keep the calendar full.

Just landed: Connecticut SB 1295, Virginia, and California DROP

Connecticut's SB 1295 amendments took effect July 1, 2026. They matter even if you ignored the CTDPA the first time:

  • The applicability threshold dropped from 100,000 to 35,000 consumers — and disappears entirely if you process sensitive data or offer personal data for sale.
  • Targeted advertising and data sales involving minors aged 13–17 are flatly prohibited where you know (or wilfully disregard) the user's age. Consent does not cure it.
  • Privacy notices must explicitly disclose targeted-advertising processing and sales.
  • A separate profiling impact-assessment obligation applies to covered profiling activities created or generated on or after August 1, 2026.

If you run ads or analytics with meaningful Connecticut traffic and have not re-checked coverage under the 35,000 threshold, that is overdue — not optional.

Virginia amendments to the VCDPA, signed in April 2026, also took effect July 1, 2026, tightening rules around specific sensitive data categories.

California's DROP (the Delete Request and Opt-out Platform under the Delete Act): registered data brokers must process consumer deletion requests submitted through DROP as of August 1, 2026 — retrieving requests at least every 45 days. This is now an enforcement issue, not a future date. On August 11, CalPrivacy ordered LocateSmarter to pay $116,490 over late data-broker registration and an opt-out flow that demanded partial Social Security numbers. The agency called it the first action against a data broker under the CCPA and the first under both the CCPA and Delete Act.

California Opt Me Out Act: browser signals on January 1, 2027

California's Opt Me Out Act (AB 566) was signed on October 8, 2025 and becomes operative on January 1, 2027. From that date, a business that develops or maintains a browser must include an easy-to-find, configurable function that sends an opt-out preference signal (OOPS) to businesses the consumer visits. Global Privacy Control (GPC) is the best-known example of this class of signal.

For most website teams, this is a reach-and-testing deadline rather than a new banner design. Covered businesses already have to honour valid OOPS under the CCPA; AB 566 makes the control a built-in browser requirement. Verify that the signal reaches every sale/share path before browser support becomes much more widespread.

Next up: Connecticut SB 4 on October 1, 2026

Connecticut is not done. Public Act 26-64 (formerly SB 4, as amended) takes effect October 1, 2026 for most of its privacy amendments, including a ban on selling a consumer's precise geolocation data (defined as identifying location within a 1,750-foot radius). Data-broker registration to sell or license brokered personal data in Connecticut follows on January 1, 2027, with a state deletion mechanism arriving later (DCP must establish it by July 1, 2028).

If your stack collects or monetizes precise location — or you sit near the data-broker definition — put October 1 and January 1 on the same calendar as Oklahoma.

January 1, 2027: six US deadlines land at once

  • Oklahoma Consumer Data Privacy Act — signed in March 2026, effective January 1, 2027. Another opt-out-model comprehensive law in the Virginia mold.
  • Louisiana Data Privacy Act (SB 386 / Act 502) — signed May 29, 2026 and effective January 1, 2027. Add Louisiana to your US opt-out matrix; the US state cookie banner requirements guide covers the mechanics.
  • California Opt Me Out Act — browser developers must offer a configurable opt-out preference signal; see the subsection above.
  • California ADMT rules — under the CCPA regulations finalized in September 2025, businesses using automated decision-making technology for significant decisions must comply by January 1, 2027, including notices and opt-outs.
  • Vermont's Age-Appropriate Design Code (Act 63) — effective January 1, 2027 for services reasonably likely to be accessed by under-18s: data minimization by default, no targeted nudging, restrictions on push notifications. Similar laws have drawn First Amendment challenges, so watch for litigation — but do not bank on it.
  • Connecticut data-broker registration — see SB 4 above.

Later in 2027

  • Alabama Personal Data Protection Act — signed April 17, 2026, effective May 1, 2027.
  • Kentucky HB 692 — amendments to the KCDPA effective July 1, 2027.

The upshot: the US still is not adopting EU-style opt-in, but the matrix of opt-out rights, minors' protections, geolocation restrictions, and universal opt-out signals keeps expanding. Our US state cookie banner requirements guide covers the per-state mechanics.

United Kingdom: the DUAA's big bang already happened — but it's not finished

The Data (Use and Access) Act's main PECR changes commenced on February 5, 2026: new consent exceptions for low-risk purposes (first-party statistics, appearance preferences, emergency assistance) and PECR fines raised from £500,000 to GDPR levels — up to £17.5 million or 4% of global turnover. The ICO's final Storage and Access Technologies guidance followed on April 29, 2026. The DUAA requirement to operate a formal data-protection complaints procedure commenced on June 19, 2026. All of that is "now," not "next" — see the 2026 banner update guide.

What is still ahead:

  • The ICO's review of PECR regulation 6 for online advertising. Alongside the final guidance, the ICO said its work on how storage-and-access rules apply to online advertising continues separately, with further updates to follow. If you are hoping the UK relaxes consent for some advertising use cases, this is the workstream to watch through late 2026.

The ICO also noted that 99% of the UK's top 1,000 websites now meet its cookie banner standards — which tells you how the remaining 1% should expect to be treated.

India: the DPDP countdown is real, with two hard dates

India's DPDP Rules were notified on November 13, 2025 — final, not draft — with an 18-month phased rollout:

  • November 13, 2026 (Phase 2): the Consent Manager registration framework becomes operational (Rule 4). Registered Consent Managers must be India-incorporated companies meeting net-worth and interoperability requirements. This is the year to decide whether you will engage a Consent Manager or keep consent records in-house — and to make withdrawal flows actually work.
  • May 13, 2027 (Phase 3): the substantive obligations — notice, consent, breach notification, data principal rights, cross-border rules — become fully enforceable, with penalties up to INR 2.5 billion (roughly USD 26 million).

If you have an Indian user base, the rest of 2026 is the build-and-test window before Phase 2. The architecture signal matters even if India is not your market: consent is being treated as auditable, interoperable infrastructure, not a banner you bolt on.

The long-stalled ePrivacy Regulation proposal was formally withdrawn in early 2025. On November 19, 2025, the Commission proposed the broader Digital Omnibus. The Commission's original proposal would have moved rules for personal data stored in or accessed from terminal equipment into new GDPR Article 88a, while proposed Article 88b would have introduced automated, machine-readable consent signals. Those were proposals, never rules in force.

The Cyprus Presidency's June compromise, ST 10729/26, took a different proposed route:

  • In ST 10729/26, proposed GDPR Articles 88a and 88b are removed. That June text therefore omits the Commission's proposed EU-wide automated consent-signal mechanism.
  • In the June text, the cookie changes stay in the ePrivacy Directive. It would amend Article 5(3), rather than moving this part of the regime into GDPR Article 88a.
  • In the June text, one-click refusal and a six-month cooling-off period remain proposed. It would require an easy, intelligible single-click refusal (or equivalent) and would stop a provider re-requesting consent for the same purpose for at least six months after refusal.
  • In the June text, some no-consent cases would be expanded or clarified. Its proposed Article 5(3) wording includes tightly framed audience-measurement and technical-security purposes.

ST 10729/26 is not the Council's position. It was prepared as a possible negotiating mandate, but the Presidency removed the item from the June 26 Coreper agenda after a blocking minority emerged. The file moved to the Irish Presidency without a Council mandate.

Nor is that June text frozen. At the July 16 Antici Group (Simplification) consultation, the Irish Presidency asked Member States for views before developing another revised compromise. According to the consultation report, the starting compromise still omitted Article 88b, while governments were asked whether an expanded ePrivacy consent-exemption whitelist was sufficient, including a possible fraud-detection and prevention exception.

Parliament is active on a separate track, not simply waiting behind the Council. Its official procedure file records the Salla/Kaljurand draft report on June 22 and committee amendments tabled on July 27; it still says "awaiting committee decision." EU Perspectives reports roughly 1,840 amendments, with political talks restarting after summer, an autumn targeted assessment expected, and a committee vote targeted before February 2027 (with no formal vote date yet). Parliament's live cookie debate still covers the Commission's automated/machine-readable signals, the six-month re-ask rule and publisher impact. MEP Markéta Gregorová has argued that automated signals could reduce banner fatigue while warning that the Commission has not explained the mechanism or how to prevent dominant browser companies gaining more power.

Do not conflate that disputed EU automated-consent design with California OOPS. California's AB 566 is enacted and concerns an opt-out signal for sale and sharing under the CCPA; the EU mechanism remains a contested proposal about consent and refusal for terminal access.

The timetables now pull against each other. Ireland's official Presidency programme aims for Council–Parliament agreement by the end of 2026, while Parliament's reported committee target runs up to February 2027. Even if political agreement came in 2026, the proposed transition and transposition periods would put application in 2027 or later, depending on the final text.

Supportive: Both institutions are still trying to reduce repetitive prompts without discarding meaningful choice.

Cynical: A June Council draft, 1,840 Parliament amendments and incompatible political timetables are not a deployment specification.

What is in force today has not changed: the ePrivacy Directive, the GDPR and national enforcement still apply. There is no Council mandate, no Parliament position and no formal trilogue. Change nothing yet; banners stay. See our developer's guide to the ePrivacy Directive.

Canada: Bill C-36 is real, but not scheduled

Canada is the "watch but don't build yet" file:

  • Federal: Bill C-27 died when Parliament was dissolved in early 2025. Its successor, Bill C-36, received first reading on June 15, 2026. LEGISinfo now lists it at second reading, with no second-reading activity yet. If enacted, it would create the Protecting Privacy and Consumer Data Act and repeal Part 1 of PIPEDA. It is not law; PIPEDA remains the federal private-sector law in force.
  • Alberta: a legislative committee delivered 12 recommendations for amending PIPA in February 2025, including children's-privacy obligations and a penalty-based enforcement regime; amendments are anticipated in 2026.
  • Quebec: Law 25 is fully in force — its opt-in consent rules belong on your "now" list, not your watchlist. Our Canada consent banner guide covers it.

How to prioritize: a traffic-based triage

You do not prepare for every deadline at once. You rank them by your traffic and the cost of being wrong.

Priority Prepare for If you have... By when
1 Connecticut SB 1295 catch-up (if not done) US traffic + ads/analytics Overdue (in force Jul 1, 2026)
2 Connecticut SB 4 geolocation / broker prep Precise location or brokered data Oct 1, 2026 / Jan 1, 2027
3 India DPDP Phase 2 (Consent Managers) Indian users Nov 13, 2026
4 Oklahoma + Louisiana + CA OOPS/ADMT + Vermont AADC US traffic (AADC: minors) Jan 1, 2027
5 Alabama, Kentucky amendments, India Phase 3 US / India traffic May–Jul 2027
6 UK PECR reg 6 review + EU Digital Omnibus + Canada C-36 UK / EU / Canada users Monitor — not a build trigger yet

Three rules of thumb:

  1. Hard dates beat big headlines. Connecticut's October 2026 geolocation ban will affect more real businesses this year than the Digital Omnibus. Enacted law with a date outranks any proposal.
  2. Minors' data is the common thread. Connecticut, Vermont, Oregon's under-16 sale ban, India's parental-consent rules — if your audience skews young, this is your biggest 2026–2027 workstream.
  3. Don't rebuild for proposals. Monitor the Digital Omnibus and Canada's Bill C-36 quarterly; build when there is final text and a commencement date.

What to actually do this quarter

  • Confirm Connecticut SB 1295 coverage under the 35,000-consumer / sensitive-data / sale triggers — and close any gap.
  • Inventory precise geolocation collection and sale/share paths ahead of Connecticut's October 1, 2026 ban.
  • Audit whether you serve targeted ads to known or likely 13–17-year-olds in the US.
  • Put November 13, 2026 (India Phase 2) on the compliance calendar with a named owner.
  • Test that valid GPC/OOPS signals stop CCPA sale/share processing end-to-end before AB 566 expands browser support on January 1, 2027.
  • If you profile for significant decisions, scope California ADMT notice and opt-out work for January 1, 2027.
  • Confirm your CMP can add a new regional ruleset (Oklahoma, Louisiana, Alabama, Connecticut broker mode) as configuration, not code.
  • Set a quarterly check on the Digital Omnibus, the ICO's PECR reg 6 advertising work, and Canada's Bill C-36 — and resist doing more than that.

Where CookieChimp fits

The pattern across every jurisdiction above is the same: rules keep changing, and the teams that cope are the ones whose consent setup is configuration, not hardcoded UI. CookieChimp is built for exactly that — geo-targeted banners that apply the right ruleset per region, automatic cookie scanning so new tags don't outrun your policy, consent logs that prove what each user saw and chose, and built-in Google Consent Mode v2 and Global Privacy Control support as US states keep adding signal requirements. When the January 2027 dates arrive, they should be settings changes, not a sprint. And if you're wondering whether one banner can stretch across all of this: can one cookie banner cover every country?

FAQ

Which US states have new privacy laws taking effect in 2027?

Oklahoma's Consumer Data Privacy Act and Louisiana's Data Privacy Act take effect January 1, 2027. Alabama's Personal Data Protection Act follows on May 1, 2027, and Kentucky's HB 692 amendments on July 1, 2027. California's Opt Me Out Act and automated decision-making (ADMT) rules, plus Vermont's Age-Appropriate Design Code, also have January 1, 2027 dates.

Will the EU Digital Omnibus get rid of cookie banners?

Not under any text that is law today. The Commission proposed GDPR Articles 88a and 88b, including automated signals; the June Council Presidency text removed both articles and instead proposed one-click refusal and a six-month same-purpose no-reprompt rule in ePrivacy Article 5(3). But Ireland is developing another Council compromise, and Parliament is still debating the Commission's cookie package through its own amendments. There is no Council mandate, Parliament position or formal trilogue. None of these options is in force: current ePrivacy/GDPR rules still apply, so change nothing yet and keep the banner.

What changes in Connecticut in 2026?

Two waves. On July 1, 2026, SB 1295 dropped the CTDPA applicability threshold from 100,000 to 35,000 consumers (with no threshold at all if you process sensitive data or sell personal data), banned targeted advertising and sales involving consumers aged 13–17, and expanded sensitive-data rules — those amendments are now in force. On October 1, 2026, SB 4 / Public Act 26-64 adds a ban on selling precise geolocation data, with data-broker registration required from January 1, 2027.

When does India's DPDP Act become fully enforceable?

The DPDP Rules were notified on November 13, 2025 with a phased rollout. Phase 2 (Consent Manager registration, Rule 4) takes effect November 13, 2026. Phase 3 — the substantive obligations for notice, consent, breach notification, and user rights — becomes fully enforceable on May 13, 2027, with penalties up to INR 2.5 billion.

Is anything still changing in the UK after the February 2026 PECR changes?

Yes. The DUAA complaints-procedure requirement commenced on June 19, 2026. Separately, the ICO is still reviewing how PECR regulation 6 applies to online advertising, with further updates promised. The new consent exceptions and the higher £17.5m/4% PECR fines are already in force.

Should I wait for new laws before updating my consent setup?

No. Everything enforceable today — EU/UK opt-in rules, US state opt-outs, Quebec's Law 25 — stays enforceable regardless of what is coming. Build a setup where each new law is a configuration change, then add jurisdictions as their dates arrive.

References

  1. MultiState, "20 State Privacy Laws in Effect in 2026: Key Dates & Changes": multistate.us
  2. Wiley, "Major Changes to Connecticut's Consumer Privacy Law Will Take Effect July 1, 2026": wiley.law
  3. Foley & Lardner, "Connecticut Dramatically Expands Its Data Privacy Act" (Jul 2026): foley.com
  4. Proskauer, "From Data Brokers to DNA: Connecticut Enacts Sweeping Privacy Amendments" (SB 4 / PA 26-64): privacylaw.proskauer.com
  5. Moore & Van Allen (JD Supra), "Privacy in Bloom: Four States Reshape the Data Protection Landscape This Spring": jdsupra.com
  6. California Privacy Protection Agency, "California Finalizes Regulations to Strengthen Consumers' Privacy": cppa.ca.gov
  7. CalPrivacy, "DROP for data brokers": privacy.ca.gov
  8. Vermont General Assembly, "Bill Status S.69 (Act 63) — Age-Appropriate Design Code": legislature.vermont.gov
  9. ICO, "Statement on the commencement of the Data (Use and Access) Act (DUAA)" (5 Feb 2026): ico.org.uk
  10. ICO, "Final storage and access technologies guidance published" (29 Apr 2026): ico.org.uk
  11. European Commission, Digital Omnibus proposal, COM(2025) 837: eur-lex.europa.eu
  12. Press Information Bureau (India), "DPDP Rules, 2025 Notified" (Nov 2025; Rules gazette-dated 13 Nov 2025): pib.gov.in
  13. India Briefing, "India's DPDP Timeline: Critical Compliance Deadlines for 2026-27": india-briefing.com
  14. Parliament of Canada, Bill C-36 first-reading text: parl.ca
  15. Council of the European Union, proposed Digital Omnibus negotiating mandate, ST 10729/26: data.consilium.europa.eu
  16. Council of the European Union, revised Coreper agenda withdrawing the Digital Omnibus mandate item, ST 10932/2/26 REV 2: data.consilium.europa.eu
  17. European Parliament Legislative Observatory, Digital Omnibus procedure 2025/0360(COD): oeil.europarl.europa.eu
  18. California Legislature, AB 566 (California Opt Me Out Act), chaptered text: leginfo.legislature.ca.gov
  19. California Privacy Protection Agency, "Governor Signs Groundbreaking Privacy Bill" (Oct 8, 2025): privacy.ca.gov
  20. California Privacy Protection Agency, LocateSmarter CCPA and Delete Act enforcement action (Aug 11, 2026): privacy.ca.gov
  21. Parliament of Canada, Bill C-36 status — LEGISinfo: parl.ca
  22. Louisiana Legislature, SB 386 status — signed as Act 502: legis.la.gov
  23. Louisiana Legislature, SB 386 enrolled text (effective Jan 1, 2027): legis.la.gov
  24. Agence Europe, "Cyprus Presidency of EU Council hands 'Digital Omnibus' over to Ireland for lack of agreement between Member States" (Jun 26, 2026): agenceurope.eu
  25. EUR-Lex, ePrivacy Directive 2002/58/EC (current consolidated text): eur-lex.europa.eu
  26. EU Perspectives, "EU braces for data rules battle with 1,840 amendments" (Aug 10, 2026): euperspectives.eu
  27. Agence Europe, "Irish Presidency consults EU countries on pseudonymisation, data processing for AI and cookies" (Jul 15, 2026): agenceurope.eu
  28. Council of the European Union, Programme of the Irish Presidency (Jul–Dec 2026): irish-presidency.consilium.europa.eu

The laws will keep coming; your banner rebuild doesn't have to. Get started with CookieChimp and turn the next effective date into a configuration change.

The content of this article is provided for information purposes only and does not constitute legal or other advice.