BusinessMCP

Legal

Website Tracking Laws by Country: US, UK, EU, Canada, Australia

Every market regulates website tracking differently: the EU wants consent before non-essential cookies, the US wants opt-outs honored, Canada and Australia sit in between — and the email rules diverge even harder. Here is the comparative matrix, the PECR-vs-GDPR explainer, and what cookieless first-party analytics changes.

By the BusinessMCP team12 min readAugust 15, 2026
Website Tracking Laws by Country: US, UK, EU, Canada, Australia — illustrated overview

Key takeaways

  • The deepest divide is the consent model: the EU and UK are opt-in for non-essential cookies and trackers, the US is opt-out (honor sale/sharing opt-outs like GPC), and Canada and Australia run consent-and-notice models in between.
  • PECR and GDPR are different laws doing different jobs: PECR governs storing or accessing anything on the device (cookies, localStorage) and electronic marketing; GDPR governs the lawful basis for processing personal data. You can owe one, both, or neither.
  • B2B cold-email rules diverge more than tracking rules: opt-out in the US (CAN-SPAM), corporate-subscriber leeway in the UK, member-state-by-member-state in the EU, and consent-based in Canada (CASL) and Australia (Spam Act).
  • Cookieless first-party analytics changes the cookie-consent question, not the privacy question: with no non-essential device storage the banner trigger generally is not engaged, but GDPR-style obligations still apply wherever personal data (like an IP, briefly) is processed.
  • This is orientation, not legal advice — laws move, states keep legislating, and a lawyer who knows your markets beats any comparison table, including this one.

Website tracking laws by country: the short version

Website tracking laws by country sort into three broad families. The opt-in family (EU, UK): get consent before setting non-essential cookies or similar identifiers, with GDPR governing whatever personal data you process. The opt-out family (US): track by default under sectoral and state law, but disclose it, honor sale/sharing opt-outs — including the GPC browser signal in several states — and never deceive. The consent-and-notice family (Canada, Australia): principle-based privacy statutes where implied consent and clear notice do much of the work, paired with unusually strict email laws.

One scoping note before the matrix: this page compares regimes at a high level. For the EU specifically — lawful bases, why company-level visitor identification is defensible and person-level is not, the full compliance checklist — our GDPR and visitor identification guide is the canonical deep dive, and we will point there rather than re-explain it.

The comparison matrix

The table agencies bookmark. Each cell is the general rule; the sections below add the nuance that matters.

Website tracking and B2B outreach law by region (general position, as of August 2026)
RegionConsent modelCookies & trackersB2B cold emailKey law · regulator
United StatesOpt-outNo general banner requirement; state laws require notice + opt-out of sale/sharing/targeted ads; GPC binding in several statesLegal without prior consent under CAN-SPAM: no deceptive headers, identify ads, postal address, honored opt-outCAN-SPAM + ~20 state privacy laws · FTC, state AGs, California CPPA
United KingdomOpt-in for non-essential trackersPECR: consent before storing/accessing non-essential identifiers on the device; reform easing low-risk analytics is in progressCorporate email addresses sit outside PECR’s individual-subscriber consent rule — generally workable with identification + opt-out; UK GDPR still appliesUK GDPR + PECR · ICO
European UnionOpt-in for non-essential trackersePrivacy (national implementations): prior consent for non-essential cookies and similar tech; GDPR lawful basis on topVaries by member state — soft opt-in for existing customers in some; Germany and Austria effectively require prior consent even for B2BGDPR + ePrivacy Directive · national DPAs, coordinated by the EDPB
CanadaConsent (express or implied)PIPEDA: consent scaled to sensitivity and expectations — implied consent with clear notice generally workable for ordinary analytics; Quebec’s Law 25 is stricterCASL is among the strictest regimes: express or implied consent required (existing relationship, or a relevantly published business address), plus identification + unsubscribePIPEDA + CASL · OPC (privacy), CRTC (CASL)
AustraliaNotice-basedNo cookie-specific consent law: fair collection + privacy-policy disclosure under the Privacy Act’s APPs; small-business exemption currently narrows its reachSpam Act: consent required, but may be inferred from an existing relationship or a conspicuously published work address relevant to the role; identify sender + unsubscribePrivacy Act 1988 + Spam Act 2003 · OAIC (privacy), ACMA (spam)

Read the columns separately: a region’s cookie rule and its email rule are different laws with different logic, and the common mistake is assuming they travel together. The US pairs the loosest email regime with a fast-thickening state privacy patchwork; Canada pairs a flexible privacy statute with one of the world’s strictest email laws.

United States: opt-out by design, patchwork by state

The US has no comprehensive federal privacy law for commercial tracking. What exists is the FTC’s deception/unfairness authority (your privacy policy must be true), sectoral statutes, and a growing stack of state laws — California’s CCPA/CPRA first, with roughly twenty states having passed comprehensive laws since (the IAPP tracker is the running scoreboard). The state-law pattern: notice of collection, consumer rights (access, deletion), and an opt-out of “sale”, “sharing”, and targeted advertising — with several states treating the Global Privacy Control browser signal as a binding opt-out you must honor automatically.

For first-party analytics the practical position is stable: measuring your own site is generally fine with disclosure; the regulated edge is sharing data with ad platforms — conversion APIs, custom-audience uploads — which is where opt-outs and GPC bite. On email, CAN-SPAM permits unsolicited B2B email without prior consent, provided headers are truthful, the message identifies itself, a postal address is included, and opt-outs are honored promptly.

Visitor arrives with the GPC signal set
Visitor is in a state whose law binds GPC
Suppress ad-sharing for them: CAPI forwarding + audience uploads
First-party analytics continues, disclosed in your policy

GPC governs sale/sharing to third parties — it is not a do-not-track signal, and no US law requires blinding your own analytics.

PECR vs GDPR: the UK’s two-law system explained

The UK question we get most from agencies: what is the difference between PECR and the UK GDPR? They are two different laws doing two different jobs, and you can be subject to either, both, or neither for a given piece of processing.

PECR vs GDPR at a glance
DimensionPECRUK GDPR
What it governsSpecific activities: storing/accessing info on a device (cookies, localStorage, pixels) and electronic marketing (email, SMS, calls)Any processing of personal data, whatever the technology
TriggerThe act of reading/writing on the device — even if no personal data is involvedThe data being personal — even if no cookie is involved
Consent rulePrior consent for non-essential storage/access; marketing consent rules split individual vs corporate subscribersConsent is one of six lawful bases — legitimate interests often fits analytics
B2B emailThe consent rule protects individual subscribers; corporate subscribers ([email protected]) are generally outside itStill applies to the personal data in that email (a name is personal data) — so identification, opt-out, and a lawful basis are still owed

Two consequences follow. First, the cookie-banner obligation is a PECR question, not a GDPR one — the ICO’s cookie guidance is explicit that consent is needed for non-essential storage or access regardless of whether personal data is involved. Second, the UK is the friendliest major opt-in market for B2B email: PECR’s consent rule for marketing email protects “individual subscribers,” and corporate email addresses generally fall outside it — though the UK GDPR still governs the personal data involved, so you owe a lawful basis, identification, and a working opt-out.

One moving part to watch: the UK’s Data (Use and Access) Act 2025 amends this regime, and is expected to ease PECR consent for certain low-risk purposes such as first-party analytics cookies. As of August 2026, treat the ICO’s current guidance as the operative rule and check it before relying on any relaxation.

European Union: the deep end (covered elsewhere)

The EU pairs the ePrivacy Directive (the “cookie law,” implemented country by country) with the GDPR, coordinated by national DPAs and the EDPB. The headline rules: prior consent before non-essential cookies or similar identifiers, and a documented lawful basis for any personal-data processing — with enforcement genuinely active, including against dark-pattern consent banners.

We will not re-explain the GDPR mechanics here, because we already did it properly: our visitor identification and GDPR guide covers the lawful bases, why company-level visitor identification is generally defensible under legitimate interests while person-level identification of EU visitors is not, the cookieless question, and the full compliance checklist (DPA, legitimate-interest assessment, disclosure language). If the EU is a market you sell into, read that one — it is the canonical version.

The one EU nuance worth repeating in a by-country comparison: B2B email is not harmonized. Several member states allow a soft-opt-in or legitimate-interest approach for B2B outreach; Germany and Austria, under their unfair-competition rules, generally treat cold email without prior consent as unlawful even between businesses. A single “EU email policy” is a category error — segment DACH separately.

Canada and Australia: flexible privacy law, strict email law

Canada runs on PIPEDA federally: consent-based, but with consent scaled to sensitivity and reasonable expectations — for ordinary, non-sensitive analytics, implied consent with clear and prominent notice is generally workable, while sensitive data or surprising uses need express consent. Quebec’s Law 25 layers stricter, more GDPR-like requirements (including transparency defaults for tracking technologies) on businesses serving Quebec. The sting is email: CASL requires consent before sending commercial electronic messages — express, or implied via an existing business relationship or an email address the recipient conspicuously published in a role-relevant context — plus sender identification and a working unsubscribe, with penalties that are famously large.

Australia is notice-based on the tracking side: the Privacy Act 1988 and its Australian Privacy Principles require fair collection and privacy-policy disclosure rather than cookie-by-cookie consent, and a small-business exemption currently keeps many companies under roughly AU$3M turnover outside the Act entirely (reform proposals to narrow that exemption have been under discussion for years — check status before relying on it). Email mirrors Canada: the Spam Act 2003 requires consent, which may be inferred from an existing relationship or a conspicuously published work address relevant to the recipient’s role, plus identification and unsubscribe, enforced by ACMA.

What changes with cookieless first-party analytics

Across every regime above, the tracking rules hinge on two questions: do you store or read identifiers on the visitor’s device, and do you share data with third parties for advertising? Cookieless first-party analytics — no cross-site cookies, no fingerprinting, identifiers scoped to your own site or absent entirely — changes the answer to the first question, which is why it travels so well across jurisdictions.

  • EU/UK: the ePrivacy/PECR consent trigger is the storage or access itself. A genuinely cookieless tracker generally does not engage it — but GDPR still governs whatever personal data (an IP address, briefly) is processed, so you still owe a lawful basis and disclosure. “Cookieless” that hides a persistent cross-site ID in localStorage is a cookie by another name.
  • US: first-party measurement was never the regulated edge; sale/sharing is. Cookieless changes little legally, but honoring GPC on the ad-sharing layer (conversion APIs, audience uploads) remains required in the states that bind it.
  • Canada/Australia: notice-and-fairness obligations are unchanged — disclose the measurement in your privacy policy either way; cookieless mostly removes the awkward “tracking technologies” disclosure debt.

This is the posture we built BusinessMCP around: cookieless first-party measurement globally, company-level identification with an enrich-then-discard approach to IPs, GPC honored on the ad-sharing layer for US visitors, and consent-gating available as an opt-in for sites that want it — the mechanics are in our consent mode guide. The one-sentence summary of five jurisdictions: measure your own site honestly and disclose it, get consent where the device is touched, and treat email as its own legal problem in every country.

Frequently asked questions

Is website visitor tracking legal in the US without consent?

Generally yes for first-party measurement: no federal law requires prior consent for analytics on your own site. But state privacy laws require disclosure and an honored opt-out of sale/sharing/targeted advertising — several states treat the GPC browser signal as binding — and your privacy policy must accurately describe what you do, or the FTC’s deception authority applies. This is information, not legal advice.

Do I need a cookie banner in the UK?

If you set or read non-essential cookies or similar identifiers (including localStorage), yes — PECR requires prior consent regardless of whether personal data is involved. Genuinely cookieless analytics generally does not engage that trigger, though UK GDPR still governs any personal data processed. The Data (Use and Access) Act 2025 is expected to ease the rule for low-risk analytics; check current ICO guidance before relying on it.

What is the difference between PECR and GDPR?

PECR governs specific activities — storing or accessing information on a device (cookies and similar tech) and electronic marketing — and applies even when no personal data is involved. GDPR governs the processing of personal data whatever the technology. A cookie can need PECR consent with no GDPR question; an IP lookup can raise GDPR questions with no cookie. Many activities engage both.

Can I send cold email to business contacts in Canada or Australia?

Only with consent — but both regimes recognize implied or inferred consent for B2B contexts: an existing business relationship, or an email address the recipient conspicuously published in a context relevant to your message (CASL in Canada, the Spam Act in Australia). Sender identification and a working unsubscribe are mandatory in both, and CASL’s penalties are severe, so document your consent basis per contact.

Does cookieless analytics mean I can ignore privacy law?

No — it narrows one obligation, not all of them. Going cookieless generally removes the EU/UK cookie-consent trigger, but GDPR-style rules still apply to any personal data processed, US state laws still require honoring sale/sharing opt-outs like GPC on the ad side, and Canada and Australia still expect fair collection and privacy-policy disclosure. Cookieless changes the banner question, not the honesty questions.

BM

BusinessMCP Team

Every guide is written from running BusinessMCP on its own platform — the match rates, reply rates, and deliverability lessons are from our own data, not recycled blog folklore. About BusinessMCP

Turn your business into one AI-ready MCP server

Connect your tools, install one tracking script, and expose your unified data to any AI agent through a single secure endpoint.

Get started free