Leading Consent Management Platform

Compliant with GDPR, CCPA, COPPA, LGPD, PECR, PDPA, PIPEDA, and more.

US State Privacy Setup

US State Privacy shows a privacy notice with opt-out choices to visitors from US states that have a comprehensive privacy law, and sends the IAB GPP signals that your ad partners read. It works together with CCPA for California.

Supported states

CCPA/CPRA in California, plus 19 states: Virginia, Colorado, Utah, Connecticut, Florida, Montana, Oregon, Texas, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island.

1. Turn on US State Privacy

In your project, open US Privacy Settings and turn on Enable US State Privacy (IAB GPP). The GPP API turns on automatically. Then choose:

  • Apply To: All US states, or Selected states to cover only the states you tick. With all states, states that have their own GPP section get it, and every other state gets the US National section.
  • GPP Sections: the US National and state sections (default), the US National section only, or the state sections only.
  • MSPA Signatory: turn on only if your company has signed the IAB Multi-State Privacy Agreement. Then choose the MSPA Mode: Opt-Out Option Mode, or Service Provider Mode.
  • API-Only Mode (US State Privacy): hides the banner, so you can use your own consent screen and record the choice with __unicapi('agreeAll') or __unicapi('rejectAll').

IAB TCF Lite projects cover all US states with both GPP sections and no MSPA. Choose IAB TCF Advanced to change these settings.

When CCPA is enabled too, California visitors see the US State Privacy notice, and the US Privacy (CCPA) signal is kept in sync with their choice.

2. What visitors see

The first layer offers a one-click opt-out of the sale and sharing of personal information and of targeted advertising. The detailed settings are behind Manage Options. An opt-out turns off advertising; other purposes are not affected.

Visitors whose browser sends Global Privacy Control (GPC) are opted out automatically, without opening the notice.

Add this element where the link should appear, for example in your footer:

<div id="uniconsent-config"></div>

UniConsent shows the Do Not Sell or Share My Personal Information link there. When you use sensitive data purposes, it shows a single Your Privacy Choices link with the opt-out icon instead.

4. Sensitive personal data

Under Custom Purposes, edit a purpose and tick Sensitive Data (US), then choose its GPP Sensitive Category. US visitors must opt in to a sensitive purpose explicitly: accepting the notice does not grant it. These purposes appear under Limit the Use of My Sensitive Personal Information, and the choice is sent in the sensitive data fields of the IAB GPP sections.

5. Custom content

Under Custom Content, the US State Privacy Content field sets the text of the notice, per language. Without it, the default content is used.

6. Test

Open your site with a US state as the location:

?uniconsent_test=1&uniconsent_reset=1&uniconsent_geo=USTX

Check the signals with __gpp('ping', console.log) in the browser console, or paste the GPP string into the GPP decoder. See Testing UniConsent for every location code.

Mobile apps

The mobile SDKs (26.10.0 and later) apply the same settings in apps. They write the IAB GPP and US Privacy keys that ad SDKs read, and treat the device setting that limits ad tracking as an opt-out. US users are never prompted automatically. New mobile app projects start with US State Privacy off, so turn it on in the project.

Still have questions?

Contact us: support@uniconsent.com