Website tracking laws by country: the short version
Website tracking laws by country sort into three broad families. The opt-in family (EU, UK): get consent before setting non-essential cookies or similar identifiers, with GDPR governing whatever personal data you process. The opt-out family (US): track by default under sectoral and state law, but disclose it, honor sale/sharing opt-outs — including the GPC browser signal in several states — and never deceive. The consent-and-notice family (Canada, Australia): principle-based privacy statutes where implied consent and clear notice do much of the work, paired with unusually strict email laws.
One scoping note before the matrix: this page compares regimes at a high level. For the EU specifically — lawful bases, why company-level visitor identification is defensible and person-level is not, the full compliance checklist — our GDPR and visitor identification guide is the canonical deep dive, and we will point there rather than re-explain it.
The comparison matrix
The table agencies bookmark. Each cell is the general rule; the sections below add the nuance that matters.
| Region | Consent model | Cookies & trackers | B2B cold email | Key law · regulator |
|---|---|---|---|---|
| United States | Opt-out | No general banner requirement; state laws require notice + opt-out of sale/sharing/targeted ads; GPC binding in several states | Legal without prior consent under CAN-SPAM: no deceptive headers, identify ads, postal address, honored opt-out | CAN-SPAM + ~20 state privacy laws · FTC, state AGs, California CPPA |
| United Kingdom | Opt-in for non-essential trackers | PECR: consent before storing/accessing non-essential identifiers on the device; reform easing low-risk analytics is in progress | Corporate email addresses sit outside PECR’s individual-subscriber consent rule — generally workable with identification + opt-out; UK GDPR still applies | UK GDPR + PECR · ICO |
| European Union | Opt-in for non-essential trackers | ePrivacy (national implementations): prior consent for non-essential cookies and similar tech; GDPR lawful basis on top | Varies by member state — soft opt-in for existing customers in some; Germany and Austria effectively require prior consent even for B2B | GDPR + ePrivacy Directive · national DPAs, coordinated by the EDPB |
| Canada | Consent (express or implied) | PIPEDA: consent scaled to sensitivity and expectations — implied consent with clear notice generally workable for ordinary analytics; Quebec’s Law 25 is stricter | CASL is among the strictest regimes: express or implied consent required (existing relationship, or a relevantly published business address), plus identification + unsubscribe | PIPEDA + CASL · OPC (privacy), CRTC (CASL) |
| Australia | Notice-based | No cookie-specific consent law: fair collection + privacy-policy disclosure under the Privacy Act’s APPs; small-business exemption currently narrows its reach | Spam Act: consent required, but may be inferred from an existing relationship or a conspicuously published work address relevant to the role; identify sender + unsubscribe | Privacy Act 1988 + Spam Act 2003 · OAIC (privacy), ACMA (spam) |
Read the columns separately: a region’s cookie rule and its email rule are different laws with different logic, and the common mistake is assuming they travel together. The US pairs the loosest email regime with a fast-thickening state privacy patchwork; Canada pairs a flexible privacy statute with one of the world’s strictest email laws.
United States: opt-out by design, patchwork by state
The US has no comprehensive federal privacy law for commercial tracking. What exists is the FTC’s deception/unfairness authority (your privacy policy must be true), sectoral statutes, and a growing stack of state laws — California’s CCPA/CPRA first, with roughly twenty states having passed comprehensive laws since (the IAPP tracker is the running scoreboard). The state-law pattern: notice of collection, consumer rights (access, deletion), and an opt-out of “sale”, “sharing”, and targeted advertising — with several states treating the Global Privacy Control browser signal as a binding opt-out you must honor automatically.
For first-party analytics the practical position is stable: measuring your own site is generally fine with disclosure; the regulated edge is sharing data with ad platforms — conversion APIs, custom-audience uploads — which is where opt-outs and GPC bite. On email, CAN-SPAM permits unsolicited B2B email without prior consent, provided headers are truthful, the message identifies itself, a postal address is included, and opt-outs are honored promptly.
GPC governs sale/sharing to third parties — it is not a do-not-track signal, and no US law requires blinding your own analytics.
PECR vs GDPR: the UK’s two-law system explained
The UK question we get most from agencies: what is the difference between PECR and the UK GDPR? They are two different laws doing two different jobs, and you can be subject to either, both, or neither for a given piece of processing.
| Dimension | PECR | UK GDPR |
|---|---|---|
| What it governs | Specific activities: storing/accessing info on a device (cookies, localStorage, pixels) and electronic marketing (email, SMS, calls) | Any processing of personal data, whatever the technology |
| Trigger | The act of reading/writing on the device — even if no personal data is involved | The data being personal — even if no cookie is involved |
| Consent rule | Prior consent for non-essential storage/access; marketing consent rules split individual vs corporate subscribers | Consent is one of six lawful bases — legitimate interests often fits analytics |
| B2B email | The consent rule protects individual subscribers; corporate subscribers ([email protected]) are generally outside it | Still applies to the personal data in that email (a name is personal data) — so identification, opt-out, and a lawful basis are still owed |
Two consequences follow. First, the cookie-banner obligation is a PECR question, not a GDPR one — the ICO’s cookie guidance is explicit that consent is needed for non-essential storage or access regardless of whether personal data is involved. Second, the UK is the friendliest major opt-in market for B2B email: PECR’s consent rule for marketing email protects “individual subscribers,” and corporate email addresses generally fall outside it — though the UK GDPR still governs the personal data involved, so you owe a lawful basis, identification, and a working opt-out.
One moving part to watch: the UK’s Data (Use and Access) Act 2025 amends this regime, and is expected to ease PECR consent for certain low-risk purposes such as first-party analytics cookies. As of August 2026, treat the ICO’s current guidance as the operative rule and check it before relying on any relaxation.
European Union: the deep end (covered elsewhere)
The EU pairs the ePrivacy Directive (the “cookie law,” implemented country by country) with the GDPR, coordinated by national DPAs and the EDPB. The headline rules: prior consent before non-essential cookies or similar identifiers, and a documented lawful basis for any personal-data processing — with enforcement genuinely active, including against dark-pattern consent banners.
We will not re-explain the GDPR mechanics here, because we already did it properly: our visitor identification and GDPR guide covers the lawful bases, why company-level visitor identification is generally defensible under legitimate interests while person-level identification of EU visitors is not, the cookieless question, and the full compliance checklist (DPA, legitimate-interest assessment, disclosure language). If the EU is a market you sell into, read that one — it is the canonical version.
The one EU nuance worth repeating in a by-country comparison: B2B email is not harmonized. Several member states allow a soft-opt-in or legitimate-interest approach for B2B outreach; Germany and Austria, under their unfair-competition rules, generally treat cold email without prior consent as unlawful even between businesses. A single “EU email policy” is a category error — segment DACH separately.
Canada and Australia: flexible privacy law, strict email law
Canada runs on PIPEDA federally: consent-based, but with consent scaled to sensitivity and reasonable expectations — for ordinary, non-sensitive analytics, implied consent with clear and prominent notice is generally workable, while sensitive data or surprising uses need express consent. Quebec’s Law 25 layers stricter, more GDPR-like requirements (including transparency defaults for tracking technologies) on businesses serving Quebec. The sting is email: CASL requires consent before sending commercial electronic messages — express, or implied via an existing business relationship or an email address the recipient conspicuously published in a role-relevant context — plus sender identification and a working unsubscribe, with penalties that are famously large.
Australia is notice-based on the tracking side: the Privacy Act 1988 and its Australian Privacy Principles require fair collection and privacy-policy disclosure rather than cookie-by-cookie consent, and a small-business exemption currently keeps many companies under roughly AU$3M turnover outside the Act entirely (reform proposals to narrow that exemption have been under discussion for years — check status before relying on it). Email mirrors Canada: the Spam Act 2003 requires consent, which may be inferred from an existing relationship or a conspicuously published work address relevant to the recipient’s role, plus identification and unsubscribe, enforced by ACMA.
Frequently asked questions
Is website visitor tracking legal in the US without consent?
Generally yes for first-party measurement: no federal law requires prior consent for analytics on your own site. But state privacy laws require disclosure and an honored opt-out of sale/sharing/targeted advertising — several states treat the GPC browser signal as binding — and your privacy policy must accurately describe what you do, or the FTC’s deception authority applies. This is information, not legal advice.
Do I need a cookie banner in the UK?
If you set or read non-essential cookies or similar identifiers (including localStorage), yes — PECR requires prior consent regardless of whether personal data is involved. Genuinely cookieless analytics generally does not engage that trigger, though UK GDPR still governs any personal data processed. The Data (Use and Access) Act 2025 is expected to ease the rule for low-risk analytics; check current ICO guidance before relying on it.
What is the difference between PECR and GDPR?
PECR governs specific activities — storing or accessing information on a device (cookies and similar tech) and electronic marketing — and applies even when no personal data is involved. GDPR governs the processing of personal data whatever the technology. A cookie can need PECR consent with no GDPR question; an IP lookup can raise GDPR questions with no cookie. Many activities engage both.
Can I send cold email to business contacts in Canada or Australia?
Only with consent — but both regimes recognize implied or inferred consent for B2B contexts: an existing business relationship, or an email address the recipient conspicuously published in a context relevant to your message (CASL in Canada, the Spam Act in Australia). Sender identification and a working unsubscribe are mandatory in both, and CASL’s penalties are severe, so document your consent basis per contact.
Does cookieless analytics mean I can ignore privacy law?
No — it narrows one obligation, not all of them. Going cookieless generally removes the EU/UK cookie-consent trigger, but GDPR-style rules still apply to any personal data processed, US state laws still require honoring sale/sharing opt-outs like GPC on the ad side, and Canada and Australia still expect fair collection and privacy-policy disclosure. Cookieless changes the banner question, not the honesty questions.
Sources
- [1]GDPR.eu — GDPR explained
- [2]UK ICO — Guide to PECR
- [3]European Data Protection Board (EDPB)
- [4]FTC — CAN-SPAM Act compliance guide
- [5]California Attorney General — CCPA
- [6]Office of the Privacy Commissioner of Canada — PIPEDA
- [7]OAIC — the Privacy Act (Australia)
- [8]Spam Act 2003 (Australia) — Federal Register of Legislation
BusinessMCP Team
Every guide is written from running BusinessMCP on its own platform — the match rates, reply rates, and deliverability lessons are from our own data, not recycled blog folklore. About BusinessMCP
Turn your business into one AI-ready MCP server
Connect your tools, install one tracking script, and expose your unified data to any AI agent through a single secure endpoint.
Get started free