If you run a small business website, there’s a decent chance your cookie banner (if you even have one) only gives visitors one option: Accept. No Reject. No Manage Preferences. Just a button and a hope that nobody thinks too hard about it.
That setup used to be pretty normal. It’s not anymore, and it’s worth understanding why.
Why This Is Suddenly a Big Deal
Over the past couple of years, there’s been a real spike in demand letters and lawsuits tied to California’s Invasion of Privacy Act, or CIPA. The argument behind these suits is that when a website uses analytics, ad pixels, or other tracking technology without giving visitors a genuine way to opt out, it can be treated the same as unauthorized wiretapping.
That sounds like a stretch, and legally speaking it’s still being sorted out in the courts. But the practical result is the same either way: a growing number of small businesses, medical practices, nonprofits, and local service companies are getting letters out of nowhere, sometimes over something as simple as a cookie banner that only says Accept.
And this isn’t just a California problem. It applies to any business whose website gets visited by people in California, which in the age of the internet is basically everyone.
What Actually Needs to Change
The good news is that fixing this isn’t complicated or expensive. Three things matter here:
A real consent banner. Visitors need the option to Accept, Reject, or Manage their preferences, not just one button that assumes yes.
An up-to-date privacy policy. It should actually reflect what your site tracks and who that data goes to, not a template you copied five years ago and forgot about.
Scripts that actually respect the choice. This is the part people miss most often. A banner can look compliant while Google Analytics or a Meta Pixel is still firing in the background the second someone lands on your site, whether they clicked Reject or not. The banner has to actually block those scripts until consent is given, or it’s not doing its job.
How I Approach This for Clients
When I work through this with a client, I start by auditing what’s actually firing on their site before anyone interacts with the banner at all. That tells me exactly what needs to be gated and what, if anything, is already fine.
From there, I usually set clients up with Termageddon, which handles both the privacy policy and the cookie consent banner in one place. I like it because it updates the policy automatically as laws change from state to state, so nobody has to manually track new legislation every time something shifts.
If you’ve been putting this off, or didn’t even realize it was something to think about, now’s a good time to take five minutes and check your own site. I’m happy to take a free look and tell you exactly where you stand.
And if you do end up needing a privacy policy and consent solution, I use Termageddon and have a code for 10% off the first year: use this link with code APPLEWOOD.
Reach out if you want a second set of eyes on your site. This stuff is a lot less painful to fix than it is to get a demand letter about.
Comments are closed