This article explains how to configure Cookiebot Multi-State Privacy Law (MSPL) preset so your website's consent banner complies with US state privacy laws. Once you've set it up, see this article on how to setup coexisting configurations if you want your website to be displayed depending on the visitor's location.
Understanding MSPL
What is MSPL and why does it matter?
The United States has no single federal privacy law. Instead, individual states have passed their own – the California Privacy Rights Act (CPRA) in California, the Virginia Consumer Data Protection Act (VCDPA) in Virginia, the Colorado Privacy Act (CPA) in Colorado, and a growing number of others. Each carries its own scope, thresholds and consumer rights, and new state laws continue to take effect.
For most website owners, maintaining a separate domain group and geolocation rule for every state is time-consuming and difficult to keep up to date. The Multi-State Privacy Law (MSPL) template removes that work: it's an out-of-the-box legislation preset in Cookiebot that gives you a single, unified configuration covering all your US website traffic.
Behind the scenes, MSPL template aggregates the strictest applicable requirements from the currently active US state privacy laws into one cohesive configuration. When you select it, it applies automatically to all of your US-based website visitors – so you do not need to build and maintain a per-state matrix of geolocation rules. Usercentrics maintains the MSPL template centrally — as state laws take effect or change, we update the template so your configuration stays current without any action from you.
MSPL or a state-specific preset — which should you choose?
Both approaches are valid. Which one suits you depends on how much control you need over individual state configurations.
- Choose the MSPL preset if you want one configuration covering all US visitors, with minimal setup and ongoing maintenance.
- Choose the state-specific presets – CCPA (California Consumer Privacy Act), CPA (Colorado Privacy Act), CTDPA (Connecticut Data Privacy Act), UCPA (Utah Consumer Privacy Act), VCDPA (Virginia Consumer Data Protection Act) – if you need to tailor the banner and consent behaviour per state, for example where your legal team has specific requirements for a particular jurisdiction.
You can also combine approaches by creating multiple domain groups and using coexisting configurations to serve a different banner depending on the visitor's location.
Want to know more about US state privacy laws? Check out our overview: Regulations and frameworks
MSPL requirements for CMPs
US state privacy laws generally regulate the data collection, storage, processing and sharing practices of for-profit businesses doing business in, or targeting residents of, the relevant state. When it comes to a business' website, the MSPL template puts the following measures in place:
- A way to opt out of the sale and sharing of personal information. Visitors must be provided with a mechanism that allows them to opt out of the sharing and sale of personal information to third parties. The wording must specifically be: "Do not Sell or Share My Personal Information".
- Honoring the Global Privacy Control (GPC) signal. GPC signal lets a visitor set their privacy preference once in their browser, instead of opting out on every website individually. Cookiebot CMP monitors for the GPC signal and automatically triggers an opt-out when it's enabled in a visitor's browser.
- Double opt-in. Cookiebot CMP lets visitors opt in again manually after an initial opt-out — whether they opted out themselves or Cookiebot CMP honored the GPC signal on their behalf.
Configure your CMP for MSPL
This guide focuses solely on the tools needed to make your website's use of cookies and online tracking compliant with MSPL. It doesn't cover other aspects of MSPL compliance.
These steps aren't intended as legal advice, if you're in doubt, seek advice from a trusted legal source or your data protection authority.
Setting up your Cookiebot CMP for MSPL compliance is straightforward. Follow these steps to configure it.
First time set up
If you are setting up Cookiebot for the first time, you can select the MSPL preset. This configures the banner to comply with US state privacy laws, and you can still adjust it afterward to suit your needs.
Adding MSPL as an additional legislation
If you already have a Cookiebot Admin account set up, add MSPL by creating a new, separate domain group configured for US state privacy laws.
Follow the following steps to create the additional domain group.
- Add a new domain group.
- If you only have one domain group: go to "Domains & Aliases" in the left-hand menu, then click "Manage your domain groups"
- If you already have multiple domain groups: click "Manage" at the top of the domain group section in the left-hand menu.
- If you only have one domain group: go to "Domains & Aliases" in the left-hand menu, then click "Manage your domain groups"
- Click the "+ Create group" button
- Name the new group "MSPL" and click "Create group." You'll see it added to your list of domain groups.
- Click the "Configure CMP" icon next to your new MSPL group to open its settings.
- Click "Legislation presets" on the right side of the screen and select the MSPL preset.
- Click "Save changes." Your MSPL domain group is now active and ready to use.
The display banner setting
The checkbox labeled "Display banner" determines whether a banner is displayed to a visitor to ask for consent.
Mark the checkbox if you would like the banner to be displayed and offer the "Do Not Sell or Share My Personal Information" option to all new visitors (a requirement under several US state privacy laws in some circumstances, including when targeting visitors under the age of 16).
Displaying the banner gives the user a choice on whether tracking may take place. If left unticked, the banner will not be displayed and visitors will not be asked for their consent. Tracking will automatically be enabled on your website.
Right to Restrict Sensitive Personal Information
US state privacy laws (for example, CPRA sections 7026 and 7013) give visitors the right to opt out of the sale and sharing of their personal information to third parties. You must give visitors a way to withdraw consent so they can exercise this right. You can do this by:
- Enabling the Cookiebot CMP privacy trigger,
- Adding a link where visitors can withdraw consent, or
- Linking to your privacy policy with the Cookiebot cookie declaration embedded, which also provides the required disclosure information.
We recommend adding at least one withdrawal option to your standard site template so visitors can withdraw consent from any page on your website.
Comments
0 comments
Please sign in to leave a comment.