---------------------------
Title: Montana Consumer Data Privacy Act (MTCDPA): A Comprehensive Guide
URL: https://www.cookiebot.com/us/montana-consumer-data-privacy-act-mtcdpa/
---------------------------

# Montana Consumer Data Privacy Act (MTCDPA): A Comprehensive Guide

## At a Glance

- The MTCDPA has applied to Montana residents since October 1, 2024.
- SB 297 substantially amended the law effective October 1, 2025.
- Applies to businesses that process the data of 25,000+ Montana consumers, or 15,000+ consumers if over 25% of revenue comes from selling personal data.
- The 60-day cure period no longer exists; the Montana Attorney General can enforce immediately.
- Civil penalties run up to $7,500 per violation, with no aggregate cap.
- New duty-of-care obligations apply to any business offering an online product or service to Montana residents under 18, regardless of size.

Montana became the ninth state in the United States to enact a consumer privacy bill, [SB 384](https://legiscan.com/MT/bill/SB384/2023), with the Montana Consumer Data Privacy Act (MTCDPA) coming into effect on October 1, 2024. That's no longer the whole story, though. A 2025 amendment, [SB 297](https://legiscan.com/MT/bill/SB297/2025), rewrote significant parts of the law, and any business that assessed its MTCDPA obligations before October 2025 needs to review.

The MTCDPA bears significant resemblance to the [Connecticut Data Privacy Act (CTDPA)](https://www.cookiebot.com/us/ctdpa-connecticut-data-privacy-act/) in terms of its provisions and requirements, and SB 297 pulled the law even closer to Connecticut's and Colorado's approach on minors' data. It is important to note that as of now, there is no federal privacy law in place across the United States.

## What Is the MTCDPA?

The Montana Consumer Data Privacy Act (MTCDPA) is a regulation that protects the privacy and data rights of residents within the state. It applies to businesses operating within Montana or providing goods and services to its residents. Under the MTCDPA, businesses are required to inform consumers about the collection and processing of their data, including if it's shared with third parties. Consumers have the right to opt out of data collection and processing.

To protect data security, both businesses and third parties must implement reasonable protective measures. The MTCDPA prioritizes consumer control, transparency, and accountability in data handling practices.

## Definitions in the Montana Consumer Data Privacy Act

Montana, along with a number of other states, has a privacy law that revolves around certain fundamental concepts and responsibilities of a number of entities. These are common to many privacy regulations. The definitions aim to balance clarity and thoroughness while remaining adaptable to changes in technology, supporting effective implementation and regulatory enforcement over time.

### Personal Data Definition Under the MTCDPA

The MTCDPA adopts a commonly used definition of personal data in privacy laws, which is also referred to as "personal information" in other laws. According to the law, personal data is defined as *"any information that is linked or reasonably linkable to an identified or identifiable individual."* However, publicly available information and de-identified data are excluded from this definition.

Unlike certain state-level data privacy laws, the MTCDPA does not provide a specific list of examples for personal data. Nevertheless, typical types of personal data encompass name, account/username, IP address, email address, Social Security number, driver's license number, or passport number. These examples highlight the kind of information that falls within the scope of personal data as recognized by the Act.

### Consent Definition Under the MTCDPA

The [General Data Protection Regulation (GDPR)](https://www.cookiebot.com/en/gdpr/) in the European Union established the benchmark for defining valid user consent, and this framework has served as a model for many subsequent regulations.

Under the MTCDPA, consent is defined as: *"a clear affirmative act signifying a consumer's freely given, specific, informed, and unambiguous agreement to allow the processing of personal data relating to the consumer. The term may include a written statement, a statement by electronic means, or any other unambiguous affirmative action."*

Notably, the Montana consumer protection law incorporates certain exceptions to the requirement of consent, which distinguish it from many other data privacy laws and align with common digital user experiences. These exceptions encompass situations such as:

- Accepting a general or broad term of use that includes descriptions of personal data processing alongside unrelated information
- Encountering personal data processing while interacting with content through actions like hovering over, muting, pausing, or closing
- Agreements obtained through the use of [dark patterns](https://www.cookiebot.com/en/dark-patterns/)

Furthermore, Montana's law, similar to Connecticut's, imposes a crucial provision that grants consumers the right to revoke their consent. This requirement emphasizes the importance of consumer control and gives individuals a mechanism to withdraw their consent once given.

### Sensitive Data / Sensitive Personal Information Definition Under the MTCDPA

This encompasses more distinct categories of personal information, specifically those that have the potential to cause harm if mishandled, including information that reveals:

- Racial or ethnic origin
- Religious beliefs
- Mental or physical health condition or diagnosis
- Information about a person's sex life or sexual orientation
- Citizenship or immigration status
- Processing of genetic or biometric data for the purpose of uniquely identifying an individual
- Personal data collected from a known child (under 13 years of age)
- Precise geolocation data (within 1,750 feet or 533.4 meters)

### Controller Definition Under the MTCDPA

Businesses engaged in the collection and processing of personal information are likely to be classified as controllers, as per the definition provided by the MTCDPA, which states: *"an individual who or legal entity that, alone or jointly with others, determines the purpose and means of processing personal data."*

### Processor Definition Under the MTCDPA

When businesses share personal data with third-party entities for processing purposes, Montana privacy laws define the business as the controller and the third-party entity as the processor: *"an individual who or legal entity that processes personal data on behalf of a controller."*

### Sale Definition Under the MTCDPA

The MTCDPA defines a sale as *"the exchange of personal data for monetary or other valuable consideration by the controller to a third party."* However, there are some exceptions to the definition:

- Disclosure of personal data to a processor that processes the personal data on behalf of the controller
- Disclosure of personal data to a third party for the purposes of providing a product or service requested by the consumer
- Disclosure or transfer of personal data to an affiliate of the controller
- Disclosure of personal data in which the consumer directs the controller to disclose the personal data or intentionally uses the controller to interact with a third party
- Disclosure of personal data that the consumer intentionally made available to the public via a channel of mass media and did not restrict to a specific audience
- Disclosure or transfer of personal data to a third party as an asset that is part of a merger, acquisition, bankruptcy, or other transaction, or a proposed merger, acquisition, bankruptcy, or other transaction in which the third party assumes control of all or part of the controller's assets

### Targeted Advertising Definition Under the MTCDPA

Refers to *"displaying advertisements to a consumer in which the advertisement is selected based on personal data obtained or inferred from that consumer's activities over time and across nonaffiliated internet websites or online applications to predict the consumer's preferences or interests."*

The objective is to use the personal data in order to anticipate the interests and preferences of consumers, aiming to enhance relevance and personalize the advertising experience.

Targeted advertising does not include:

- Advertisements based on activities on a controller's own websites or online applications
- Advertisements based on the context of a consumer's current search query or visit to a website or online application
- Advertisements directed to a consumer in response to the consumer's request for information or feedback
- Processing personal data solely to measure or report advertising frequency, performance, or reach

## Who Must Comply with the MTCDPA?

The MTCDPA applies to organizations operating within Montana and any businesses that provide products or services specifically targeted towards Montana residents. As of October 1, 2025, SB 297 lowered both applicability thresholds. Organizations, referred to as "controllers" under the law, must meet one of two criteria:

- Control or process the personal data of 25,000 or more Montana residents during a calendar year

**or**

- Derive over 25 percent of gross revenue from the sale of personal data **and** control or process personal data of 15,000 or more state residents

Before October 1, 2025, these thresholds were 50,000 and 25,000 respectively. Montana's resident number threshold, which determines the applicability of the law, was already low compared to many other states, and SB 297's 2025 reduction makes it one of the lowest numerical thresholds of any state comprehensive privacy law.

This is not surprising considering Montana's relatively small population. It is interesting to note that the original threshold was set at 100,000 residents, but was subsequently lowered through a House amendment before being lowered again by SB 297.

Unlike some recently enacted state-level data privacy laws, Montana's law does not solely rely on a revenue-based threshold. This means that businesses would be required to comply with the regulation if their annual gross revenues exceeded a specific dollar threshold, even if they did not meet the threshold for the number of consumers whose data was processed.

With the absence of a revenue-only threshold, businesses of any size or value that meet the personal data or personal data plus revenue percentage thresholds outlined in the Montana privacy law must become MTCDPA-compliant.

### Exemptions to Montana Consumer Data Privacy Act Compliance

The exemptions listed in the Montana consumer protection act are largely consistent with the exemptions found in other current US privacy laws, generally following existing federal laws. The following entities are exempt from compliance:

- [Health Insurance Portability and Accountability Act (HIPAA)](https://usercentrics.com/knowledge-hub/health-insurance-portability-and-accountability-act-hipaa/)
- Health Information Technology for Economic and Clinical Health Act
- Patient Safety and Quality Improvement Act
- [Fair Credit Reporting Act (FCRA)](https://usercentrics.com/knowledge-hub/fair-credit-reporting-act-fcra/)
- [Children's Online Privacy Protection Act (COPPA)](https://www.cookiebot.com/en/coppa-compliance-requirements-checklist/)
- Family Educational Rights and Privacy Act (FERPA)
- Driver's Privacy Protection Act
- Farm Credit Act (FCA)
- Airline Deregulation Act

Additional exemptions within the Montana consumer privacy act encompass HR data, health records, research data related to human subjects that fall under the purview of other federal laws or standards, and data processed or maintained for employment-related purposes.

Exempted institutions include:

- State government entities
- National securities association
- Insurance companies
- Institutions of higher education
- Nonprofit organizations established to detect and prevent insurance fraud

As of October 1, 2025, SB 297 narrowed two of these exemptions. Financial institutions are no longer exempt as entities. Only the specific data they process under the [Gramm-Leach-Bliley Act (GLBA)](https://www.cookiebot.com/us/gramm-leach-bliley-act-glba/) remains exempt. Similarly, the broad nonprofit exemption now applies only to nonprofits established to detect and prevent insurance fraud; other nonprofits meeting the numerical thresholds above are covered.

Exclusions to the MTCDPA's definition of "consumer" include individuals acting in an employment or business context.

## What Are Consumers' Rights Under the Montana Privacy Law?

The law grants consumers several key rights concerning their personal information. In cases where children are involved, parents or legal guardians can exercise these rights on behalf of the child regarding the processing of their personal information.

The Montana privacy law grants consumers the following key rights:

- **Right to access:** Confirm if the controller is processing the consumer's personal information and access that data. (As of October 1, 2025, SB 297 narrowed this right so controllers must withhold certain categories of sensitive information from an access response, even when the request is otherwise valid.)
- **Right to correction:** Rectify any inaccurate or outdated information held by the controller that was provided by the consumer.
- **Right to delete:** Request the deletion of personal data held by the controller, with some exceptions.
- **Right to portability:** Obtain a readily usable copy of personal data previously provided to the controller by the consumer, with some exceptions.
- **Right not to be discriminated against:** Controllers are prohibited from unlawfully discriminating against consumers, including for exercising their rights.
- **Right to opt out:** Choose not to have personal data sold, be subjected to targeted advertising, or be subjected to profiling in furtherance of automated decisions with significant legal or similar effects on the consumer. (This right previously covered only "solely" automated decisions; SB 297 broadened it effective October 1, 2025.)

These rights empower consumers and promote greater control and transparency over their personal information.

The Montana data privacy law does not include the private right of action, which allows consumers to file lawsuits against controllers in case of violations. Currently, only California residents possess this right within the United States.

Do you know what your website is tracking?
Start your free scan and learn what personal data is being collected by all active cookies and trackers on your website. Get your personalized report and privacy compliance risk level in minutes.

[Start Scan](https://www.cookiebot.com/en/cookie-checker/)

## What the MTCDPA Means for Businesses

One of the main areas where companies have compliance responsibilities under Montana's privacy law is with consumers' rights. Consumers, or "data subjects," can make [data subject access requests (DSARs)](https://usercentrics.com/knowledge-hub/data-subject-access-requests/), and the law has guidelines for companies' responses. Additionally, there are restrictions and requirements for companies' collection and use of personal data, which center around security and privacy.

### MTCDPA Compliance Requirements for Consumer Requests

Controllers are obligated to inform consumers about their rights and provide mechanisms for exercising those rights through verifiable requests. This information must be clearly outlined in the controller's privacy notice or policy page on their website.

Upon receiving a consumer request, the controller must respond within 45 days, with some exceptions. These exceptions may include cases where the consumer's identity cannot be reasonably verified or when an excessive number of requests are submitted within a 12-month period.

In certain circumstances where fulfilling a consumer request is challenging, the controller can extend the response period by an additional 45 days if reasonably necessary, as long as the consumer is promptly notified.

If a controller denies a request, the consumer retains the right to appeal the decision, and the controller must provide guidance on how to proceed with the appeal process. The controller is given a timeframe of 60 days to respond to such appeals.

### Purpose Limitation Within the MTCDPA

Controllers are permitted to process personal data for the purpose(s) they have communicated, provided that the processing is deemed *"adequate, relevant, and reasonably necessary"* and proportionate to the stated purposes.

### Security of Data Under the MTCDPA

Controllers are obligated to safeguard personal data by establishing, implementing, and maintaining reasonable administrative, technical, and physical security measures. These measures should be suitable for the type and amount of personal information being processed.

### Data Protection Assessments (DPAs) Under the Montana CDPA

Controllers must conduct and document data protection assessments when they process information:

- For the purposes of targeted advertising
- To sell the personal data
- Categorized as sensitive personal data
- For the purposes of profiling if there is a reasonably foreseeable or heightened risk of harm to consumers

The Attorney General can request a DPA from a controller for the purposes of investigating an alleged violation.

### Consent Rules in the MTCDPA

Similar to other US states with privacy laws, Montana follows an opt-out model, meaning that in many cases, user consent is not required before collecting and processing personal data. However, consent is necessary for the collection or processing of [sensitive personal data](https://usercentrics.com/knowledge-hub/sensitive-information-guide/). Consumers must receive clear notice regarding data processing and have the ability to opt out of sale, targeted advertising, or profiling.

In accordance with the federal [Children's Online Privacy Protection Act (COPPA)](https://usercentrics.com/knowledge-hub/childrens-online-protection-act-coppa/), the MTCDPA aligns with regulations for children. Prior consent from the parent or guardian of any known child under the age of 13 must be obtained before processing their personal data. Montana's data privacy regulation treats data of children under 13 as sensitive by default, thus covering all children's personal data.

Furthermore, Montana's law provides additional safeguards for children. If a known consumer is at least 13 years old but under 16 years old, their consent (not a parent or guardian's) is required prior to processing their personal data for the purposes of sale or targeted advertising.

### Protections for Minors Under the MTCDPA

SB 297 introduced Connecticut- and Colorado-style duty-of-care obligations for minors, effective October 1, 2025. These apply to any entity conducting business in Montana or offering an online service, product, or feature to users under 18, regardless of the entity's revenue or whether it meets the numerical thresholds described above.

Covered organizations must use reasonable care to avoid a heightened risk of harm to minors. The provision applies based on what a controller knows or willfully disregards about a user's age, but does not require age verification or age-gating.

### Nondiscrimination Requirements of the MTCDPA

Controllers are strictly prohibited from engaging in unlawful discrimination against consumers and from processing personal data in a manner that violates state or federal anti-discrimination laws. Discrimination against consumers for exercising their rights is also strictly forbidden. For instance, a consumer cannot be denied access to a website simply because they choose to opt out of personal information collection.

However, it is important to note that certain website features or functions may require the activation of specific cookies. If a consumer opts out of allowing the collection of personal information through these cookies, it may impact the optimal functioning of the site. It is important to understand that this limitation is not considered discriminatory.

Controllers have the option to provide voluntary incentives, such as discounts, to encourage consumers' voluntary participation in activities like loyalty programs or newsletter signups, which involve the collection and processing of personal data. However, it is essential that these incentives are reasonable, as disproportionate offers can raise concerns and be viewed unfavorably by data protection authorities, as they could resemble bribes.

### MTCDPA Statutes Concerning Transparency

Controllers are obligated to provide consumers with transparent and easily accessible information regarding data processing. Typically, this information is presented on the company's website through a privacy notice or policy. As per the MTCDPA, the information provided must include the following:

- Categories of personal data processed by the controller
- Purpose(s) for processing personal data
- How consumers may contact the controller, exercise their rights and/or appeal a controller's decision (e.g., if a request for access is denied)
- Categories of personal data that the controller sells to third parties, if any
- Categories of third parties to whom the controller sells personal data, if any
- Notice about the right to opt out of the sale of personal data to third parties or processing personal data for targeted advertising or profiling and how to exercise that right

As of October 1, 2025, SB 297 added further transparency requirements. Privacy notices must now also explain consumers' rights under the MTCDPA, include a "last updated" date each time the notice changes, and be made available in every language in which the controller offers its relevant products or services.

Controllers must also provide a clear and conspicuous way to opt out that's separate from the privacy notice itself, for example, a "Your Privacy Rights" link in the site footer.

### MTCDPA Requirements for Contracts With Third Parties

Controllers must have contracts in place with third-party processors (service providers) with clear information about:

- Duty of confidentiality
- Instructions for processing data
- Nature and purpose of processing
- Type of data subject to processing
- Duration of processing
- Rights and obligations of both parties

### GPC and Universal Opt-Out Signal References Under the MTCDPA

The MTCDPA is one of an increasing number of state-level laws that reference the [Global Privacy Control (GPC)](https://www.cookiebot.com/en/global-privacy-control/) "universal opt-out" or similar mechanism. Since January 1, 2025, the consumer must be able to *"opt out of any processing of the consumer's personal data for the purposes of targeted advertising, or any sale of such personal data through an opt-out preference signal sent with the consumer's consent."*

By utilizing this signal, consumers can create a unified set of personal data privacy consent preferences one time via browser settings or a plugin. These preferences can then be communicated to all the websites that users visit.

## MTCDPA Enforcement and Penalties

The exclusive responsibility for enforcing the MTCDPA lies with the Attorney General in Montana. The law does not grant consumers the right to pursue legal action individually, though consumers can report suspected violations or complaints regarding denied requests to the office of the Attorney General.

Since October 1, 2025, the AG no longer has to provide written notice before acting. SB 297 removed that requirement along with the cure period, and the AG may instead issue a civil investigative demand or bring an enforcement action directly on reasonable cause to believe a violation has occurred.

### The MTCDPA Cure Period Has Been Eliminated

The MTCDPA originally included a 60-day cure period that gave organizations a chance to address and rectify identified issues before facing enforcement. Cure periods in other state-level data privacy laws vary from 30 to 90 days. Some are permanent, but many sunset a year or so after the law comes into effect.

The MTCDPA cure period was eliminated by SB 297 effective October 1, 2025, which was six months ahead of its original April 1, 2026 sunset date. The Montana Attorney General can now bring an enforcement action as soon as a violation is discovered, without first giving organizations a chance to fix the issue.

### Consequences of Violating the MTCDPA

The Attorney General can initiate an enforcement action, including civil investigative demands, drawing on investigatory powers granted under the Montana Consumer Protection Act. Unlike the original 2023 law, SB 297 now specifies civil penalties of up to USD 7,500 per violation, with no cap on the aggregate total across multiple violations.

## Montana TikTok Ban and TikTok Lawsuit

On May 17, 2023, Montana's governor signed [SB 419](https://legiscan.com/MT/text/SB419/id/2783560), banning TikTok within the state, ostensibly over concerns that China could access residents' data. "All social media applications tied to foreign adversaries" were also barred from state devices and business use.

[TikTok sued](https://www.npr.org/2023/05/22/1177541355/tiktok-sues-lawsuit-montana-law-ban) soon after, arguing the ban was unconstitutional and that any national security concern was a federal, not state, matter. A federal judge agreed enough to block it, and the law never took effect, thanks to a preliminary injunction issued before its planned January 1, 2024 start.

The federal side ultimately overtook it. Congress passed its own TikTok divestiture law in 2024, the Supreme Court upheld it in January 2025, and a sale to a US-led ownership group (Oracle, Silver Lake, MGX) closed in January 2026. That sale tripped a clause in SB 419 voiding the state ban outright, and Montana and TikTok jointly dismissed the case in February 2026, ending it for good, unenforced throughout.

The law had threatened fines of up to USD 10,000 per day against app stores like Apple and Google, and against TikTok itself, for failing to block access.

## MTCDPA Compliance and Consent Management

Montana's consumer privacy law aligns with the prevailing opt-out model in use with other state-level data privacy laws in the United States. An exception is situations involving sensitive personal data. Under this model, controllers are not required to obtain user or data subject consent prior to collecting or processing personal data.

However, consumers must be given the choice to opt out of the collection and processing of their personal data for purposes such as sale, targeted advertising, or profiling. This information should be clearly provided on the website, typically within the [privacy notice or policy page](https://www.cookiebot.com/en/how-to-write-a-privacy-policy/).

Businesses typically facilitate opt-out through a banner, link, or button. A consent management platform (CMP), such as [Cookiebot™ CMP](https://www.cookiebot.com/en/cookie-consent-solution/), automates the detection of cookies and tracking technologies on websites and apps, categorizes them, and can block them until consent is received or facilitate opt-outs where required. It also streamlines how businesses inform users about the categories of data collected, the services controllers and processors use, and any third parties that receive the data. Montana's privacy law, along with similar regulations worldwide, requires these notifications.

Because the United States has no comprehensive federal data privacy law, companies operating nationwide or internationally often need to comply with multiple state and international regulations at once. A CMP simplifies this by letting businesses customize banners and geotarget consent experiences. With geotargeting, a business can tailor data processing details, consent information, and choices to a user's location, and present that information in the user's preferred language, improving clarity and user experience.

## Staying Compliant With the Montana Consumer Data Privacy Act

Organizations conducting business in Montana and meeting one of the thresholds must be MTCDPA-compliant, including with the SB 297 amendments that have been in effect since October 1, 2025. Businesses that have already complied with other state-level data privacy laws in the U.S., such as Connecticut's law, will find a significant portion of the work already done. Taking a [privacy by design](https://www.cookiebot.com/en/privacy-by-design/) approach benefits all aspects of an organization, regardless of specific regulatory requirements.

Meeting MTCDPA requirements primarily involves understanding the specifics of Montana's law and implementing a solution that provides users with the necessary notifications and opt-out options. Cookiebot™ helps websites manage cookie and tracking notifications.

Further updates to the MTCDPA are possible over time, as SB 297 shows these US regulations continue to evolve alongside changing technology and consumer expectations. Seeking guidance from qualified legal counsel or your organization's data privacy expert, such as a [Data Protection Officer (DPO)](https://usercentrics.com/knowledge-hub/what-is-dpo-data-protection-officer/), is recommended to help meet these obligations.

Beyond meeting requirements, proactively safeguarding user privacy is a valuable business endeavor. It fosters user trust, enhances user experiences, and strengthens long-term customer relationships, leading to higher-quality data for marketing operations and increased revenue.

Privacy protection in Montana, across the U.S., or globally?
Cookiebot™ CMP helps you meet privacy requirements wherever you do business. Get geolocation rules, custom banners, automatic updates, and more. Try it free for 14 days.

[Start Free Trial](https://admin.cookiebot.com/signup?lang=en)

*Usercentrics A/S (Cookiebot™) does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.*

## The most used solution for compliant use of cookies and online tracking

- Used on **2.4M** — websites and apps
- Manages **8.8B** — monthly user consents
- Supports **47+** — languages
- Powers **600,000+** — customers

[Dynamic listing — customer logos loaded at runtime]

## Summary

Montana's MTCDPA has applied since October 2024, but SB 297 rewrote major parts of it effective October 1, 2025, with lower applicability thresholds, an eliminated cure period, new per-violation penalties, and new protections for minors. This guide covers who must comply, what changed, and how a consent management platform like Cookiebot™ can help.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/us/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/us/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/us/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot WordPress Plugin](https://www.cookiebot.com/us/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/us/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/us/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/us/)
- [Pricing](https://www.cookiebot.com/us/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/us/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/us/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/us/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/us/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/us/lgpd/)
- [TCF v2.3 (IAB)](https://www.cookiebot.com/us/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/us/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/us/microsoft-consent-mode-cmp/)
- [View all regulations](/us/regulations-and-frameworks/#united-states-state&united-states-federal)

### Partners
- [Become an affiliate](https://www.cookiebot.com/us/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/us/resellers/)
- [Find a partner](https://www.cookiebot.com/us/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/us/blog/)
- [Customer stories](https://www.cookiebot.com/us/customer-stories/)
- [Customer directory](https://www.cookiebot.com/us/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/us/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/us/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/us/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/us/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/us/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/us/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/us/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/us/cookie-declaration/) · [Data Processing Agreement](/us/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/us/legal-notice/) · [Accessibility Statement](/en/accessibility-statement-wcag-compliance/)