Privacy Policy, Cookie Consent Banner, and Multi-State Opt-Out Pages – What Your Website Needs for Data Privacy Compliance

GDPR and CCPA have both made data privacy compliance a must-have for websites which entails privacy policies, ‘Do Not Sell’ pages, and cookie consent banners.
Data privacy regulations are more than just legal requirements; they’re a fundamental part of building trust with your customers. Whether you run an eCommerce store, a service-based business, or a content platform, you likely collect and/or share user data. But are you handling that data in a way that meets data privacy compliance standards?
Laws like the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR) require businesses to disclose how they collect and process user data. Ignoring these laws can lead to hefty fines, legal trouble, and a loss of customer trust.
Fortunately, implementing data privacy features on your website doesn’t have to be complicated. In this guide, we’ll break down the three key pieces of a website’s privacy disclosures:
- Privacy Policies – Why you need one and what it must contain.
- Multi-State 'Do Not Sell' & Opt-Out Pages – Required for businesses collecting consumer data across multiple U.S. states.
- GDPR-Compliant Cookie Consent – Required for websites serving customers in the EU or getting significant traffic from European users, this cookie consent banner ensures your website respects user choices for cookie tracking.
We’ll also provide examples of these three types of disclosures and show you how to set them up on Webflow and Shopify.
If you want to ensure your website is compliant but don’t know where to start, then we’d be happy to set up the necessary data privacy disclosures for you. Feel free to schedule a meeting with us here to get the help you need.
Article Last Updated: July 29, 2026
1. Privacy Policy: The Foundation of Compliance
Every website that collects any customer data (names, emails, payment details, IP addresses, etc.) needs a Privacy Policy. This isn't just a best practice; it's a legal requirement under multiple privacy laws, including the California Privacy Rights Act (CPRA), GDPR (for users in the European Union), other U.S. state laws such as Virginia's CDPA, Colorado's CPA, Connecticut's CTDPA, Utah's UCPA, Texas's TDPSA, Delaware's DPDPA, and other state-level privacy statutes.
Even if your business isn’t based in California or the EU, you are still required to comply if you serve customers in these regions.
What’s Included in a Privacy Policy?
A Privacy Policy is a publicly accessible document that explains:
- What data you collect (e.g., names, emails, IP addresses, cookies)
- How you collect data (e.g., contact forms, checkout pages, tracking scripts)
- Why you collect it (e.g., marketing, order fulfillment, analytics)
- Who you share it with (e.g., third-party apps, payment processors)
- How users can control their data (e.g., request deletion, update preferences)
Companies like Apple, Shopify, and Google are all great examples of how to make your privacy policy easy to read, navigate, and understand. Of course, privacy policies don’t need to be elaborate or well-designed. They can be just a page with words on it.
How to Implement a Privacy Policy
On Webflow:
- Create a static page for your privacy policy.
- Use a privacy policy generator or draft a custom policy tailored to your business.
- Add the page to your website footer and key areas like checkout and account creation.
On Shopify:
- Use Shopify’s built-in privacy policy generator found in Settings > Customer Privacy > Privacy Policy.
- Customize the policy to match your business practices.
- Add the page link to your footer, checkout pages, and customer account area.
PLEASE NOTE: We recommend having a lawyer review any legal documents or content that you use for the Privacy Policy to ensure it addresses the specific functions of your website.
2. Multi-State 'Do Not Sell' & Opt-Out Pages
Over the past few years, numerous states have enacted privacy laws with requirements similar to California's framework. These include Virginia (CDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Montana (MCA), Texas (TDPSA), Delaware (DPDPA), and others. While they share common themes, each law has different applicability thresholds, requirements, and mechanisms.
Understanding State Privacy Laws
The original California Consumer Privacy Act (CCPA) has been significantly expanded by the California Privacy Rights Act (CPRA), which went into effect on January 1, 2023. The CPRA strengthened consumer rights to include the right to correct personal information, the right to limit use, and the right to opt-out of certain data practices; not just the sale of data.
If your website collects, shares, or sells personal information from residents of states with privacy laws, you must provide a way for users to submit requests. Applicability varies by state:
- California (CPRA): Applies if you do business in California and either: (1) have gross annual revenue over $25 million; (2) buy, sell, or share personal information of 100,000+ California residents; or (3) derive 50%+ of revenue from selling personal information.
- Other States: Have varying thresholds. Some apply to smaller businesses, while others have higher revenue thresholds. Even if you don't meet the threshold, you may still need an opt-out mechanism if you use ad tracking services like Google Ads or Meta Pixel.
What's On A Multi-State 'Do Not Sell' or Opt-Out Page?
A multi-state opt-out page should:
- Clearly explain consumer rights across all applicable state laws (rights to know, delete, correct, limit, and opt-out)
- Include links to the full privacy policy for detailed disclosures
- Provide a request mechanism (form or contact method) for users to exercise their rights
- Be easily accessible from your footer and privacy policy pages
Many businesses now use a single unified opt-out page rather than separate state-specific pages, since the requirements largely overlap. Alternatively, some use privacy management platforms (OneTrust, TrustArc, etc.) that handle multi-state compliance automatically. This approach simplifies compliance and provides better tracking of consumer requests.
If you’re looking for examples, we’ve successfully implemented CCPA compliant pages for our clients Fat Shack and Intrepid Benefits.
How to Implement Multi-State Opt-Out Pages
On Webflow:
- Create a page titled "Do Not Sell My Personal Information" or "Privacy Request."
- Include disclosure information covering the state laws applicable to your business (i.e. CCPA's requirements).
- Embed a form (or link to an external form service) that allows users to submit requests for all applicable states.
- Link this page in your footer and privacy policy.
- For multi-state coverage, consider using a unified form that handles requests across all applicable states simultaneously.
On Shopify:
- Use Shopify's out-of-the-box compliance page found in Settings > Customer Privacy > Data sales opt-out page.
- Alternatively, create a custom page with disclosure information covering applicable state laws and add a request form (i.e. CCPA's requirements).
- Ensure links are easily accessible in the footer and checkout areas.
- If you're subject to multiple state laws, consider using a unified privacy request portal or third-party service to streamline request handling across states.
3. GDPR-Compliant Cookie Consent Banner
If your website receives traffic from Europe, GDPR requires you to obtain explicit user consent before storing cookies or tracking them. This means if you use Google Analytics, the Meta Pixel, or other ad trackers on your website, and have even a single person from Europe using your website, then you need to offer cookie consent.
Of course, it's unlikely that a website who gets a few hundred European visitors every month will be litigated over GDPR non-compliance. But it's better to be safe than sorry. Not to mention, cookie consent banners are fairly easy to implement.
What Is A Cookie Consent Banner?
You’ve likely already experienced cookie consent banners in droves. It’s that popup that asks you to accept, decline, or customize preferences regarding the site storing cookies on your device. They’re usually quite large and hard to miss. A cookie consent banner needs to give users the ability to decline data tracking, in addition to informing them of what data is collected and how it is used.
At the bottom of the VTRVR website, you’ll see how we implemented this cookie consent pop-up for them. If you go to most major websites – i.e. BBC, HubSpot, ESPN, etc. – you’ll likely come across one of these banners too.
How to Implement A Cookie Consent Banner
On Webflow:
- Choose a third-party tool that offers cookie consent forms.
- Embed the script in Webflow’s custom code section.
- Ensure users can opt in/out before tracking starts.
On Shopify:
- Enable Shopify’s built-in cookie consent tool found in Settings > Customer Privacy > Cookie Banner.
- Customize the banner text to explain your cookie usage.
- Ensure compliance for EU visitors.
What’s The Worst That Could Happen?
The laggards will find themselves in lawsuits and/or receive hefty fines. It’s inevitable. Failing to comply with data privacy laws isn’t just a technical oversight, it’s a liability that can cost you heavily in lawsuits, fines, and customer trust.
Governments are being pressured to crack down on consumer privacy and you don’t want to be caught in the crosshairs. Recently, we’ve seen countless companies get litigated over website accessibility standards. The same holds true for data privacy.
The good news? These are simple fixes that can be implemented quickly.
If you want help implementing these privacy protections, we’re happy to help! Please feel free to schedule time with us here to go over your website’s data privacy compliance.















