Why the state-law argument against pre-consent blocking misunderstands how notice, choice, intentional interaction, and third-party sharing work online.

Some marketing agencies, dealer website providers, and even some privacy lawyers (who should know better) make a familiar argument:
The United States follows an opt-out privacy model, not an opt-in model. State laws such as the California Consumer Privacy Act allow adults to opt out of sales, sharing, and targeted advertising. Therefore, a dealer may load analytics cookies, retargeting pixels, chat trackers, and other marketing technologies as soon as a visitor reaches the website. A consent banner and pre-consent blocking are unnecessary because the visitor can always opt out later.
The premise is generally true but incomplete. Most comprehensive state privacy laws give adults an opt-out right over sales and targeted advertising rather than requiring affirmative consent.
But “opt out” does not necessarily mean “disclose first and offer the choice afterward.” And it certainly does not mean that a consumer’s arrival on a dealer website constitutes permission to transmit information immediately to every advertising, analytics, identity-resolution, chat, and retargeting company embedded in the site.
I am not even addressing here the separate reasons that the California Invasion of Privacy Act (CIPA) and other state wiretap or interception laws may require consent before certain tracking technologies operate. Even when the analysis is confined to comprehensive state privacy laws, the “load everything now, honor opt-outs later” position is much weaker than its proponents suggest.
The relevant question is whether the dealer can apply the customer’s choice before sending the data
An opt-out framework can work in a conventional dealership data flow.
Suppose a customer purchases or finances a vehicle. The dealer collects information through its DMS or CRM and provides the applicable privacy notices during the transaction. The dealer then sends an optional customer file or API transmission to an OEM, CDP, or marketing company for marketing, audience development, or profiling.
Before sending that file, the dealer can check its suppression records. If the customer opted out, the dealer can exclude that customer’s information. If the customer did not opt out, the dealer may proceed, assuming the disclosure is otherwise lawful. Most of this can be automated in the CRM and DMS through checkboxes on the customer record.
That is a functioning opt-out model. The customer has not been required to affirmatively authorize the optional disclosure. But the dealer has given notice and can apply the customer’s choice before the data is sent.
The FTC’s Privacy Rule for covered auto-dealer financial information illustrates the same structure. When no exception applies, the dealer must provide an opt-out notice and a reasonable opportunity to opt out before disclosing covered nonpublic personal information to a nonaffiliated third party. The FTC’s dealer guidance specifically states that, when the service-provider exception is not satisfied, a dealer must give consumers a reasonable opportunity to opt out before disclosing their personal information to a marketing company. The framework is still opt-out—the customer must object—but the disclosure does not occur before the notice and opportunity.
Of course, that example should be limited to optional secondary disclosures. Information sent to an OEM to complete a requested transaction, administer a warranty, or conduct a recall can receive different treatment. California, for example, provides a specific exception for certain vehicle and ownership information shared between a new motor vehicle dealer and manufacturer for warranty repairs or recalls, provided the information is not sold, shared, or used for another purpose. Cal. Civ. Code § 1798.145(g)(1).
The comparison is therefore between two optional marketing disclosures:
- a later transfer from a DMS or CRM that the dealer can suppress before sending; and
- an advertising or analytics transmission that occurs automatically during page load.
In the DMS or CRM example, the dealer can apply the customer’s choice before sending the optional data. In the cookie example, the data may be sent before the customer can make any choice. That is the important distinction.
Page-load tracking reverses the order
Online tracking often follows the opposite sequence.
A visitor lands on a dealer website. Before the visitor clicks, scrolls, reads the banner, or opens the privacy settings, an advertising pixel or analytics script may transmit a browser identifier, IP address, page URL, vehicle viewed, device information, and other event data to an outside platform (all of these things are typically defined as PII under state privacy laws)
The California Attorney General described the timing problem directly in the Healthline enforcement action, explaining that online trackers “run invisibly in the background in the first milliseconds when a webpage loads.” The Attorney General alleged that Healthline’s tracking technologies transmitted identifying information and article titles to advertising companies, that some transmissions continued despite opt-outs, and that information traveled downstream through the advertising ecosystem. People v. Healthline Media, LLC (Cal. Super. Ct., S.F. Cnty. filed July 1, 2025). (California DOJ)
By the time the banner appears, the initial event may already have been sent.
A later opt-out may prevent some future transmissions. But it cannot make the first transmission not have occurred. Nor does the opt-out itself ensure that the recipient will:
- delete the event already received;
- reverse an identity match;
- remove the visitor from an advertising audience;
- disregard the event in attribution or campaign optimization;
- delete or disable the identifier associated with the visitor; or
- pass the instruction to every downstream recipient.
A notice displayed after the transmission may accurately describe what occurred. But it cannot give the visitor any meaningful control over a disclosure that has already been completed.
A visit to a dealer website is not an intentional interaction with every vendor embedded in it
The CCPA’s definitions make the “track now, opt-out later” argument even less persuasive.
A consumer who opens a dealer’s website ordinarily intends to interact with the dealer. That does not mean the consumer also intends to interact with every ad platform, analytics company, chat provider, identity-resolution vendor, social network, or retargeting company whose technology the dealer has placed behind the page.
California defines “intentionally interacts” as a consumer intending to interact with a person, or intending to disclose personal information to that person, through one or more deliberate interactions. It also defines a “third party” to include a person other than the business with which the consumer intentionally interacts, unless the recipient qualifies as a service provider or contractor. Cookies, beacons, pixel tags, IP addresses, and similar technologies are expressly included in the statute’s definition of unique identifiers. Cal. Civ. Code § 1798.140(s).
California’s regulations reinforce the point by defining the “first party” as the consumer-facing business with which the consumer intends and expects to interact. The regulations even give the example of a first-party business allowing a third-party ad network to collect personal information through the first party’s website. The regulation does not treat the ad network as part of the first party merely because its code appears on the first party’s website. Cal. Code Regs. tit. 11, §§ 7001(q), 7012(g).
This distinction matters because the CCPA defines “sharing” broadly. Sharing includes electronically communicating personal information to a third party for cross-context behavioral advertising, whether or not money changes hands. The statutory exception applies when the consumer uses or directs the business to intentionally disclose personal information or intentionally interact with a third party. Cal. Civ. Code § 1798.140(ah).
An automatically executing pixel is not a deliberate consumer direction. It is a disclosure initiated by the dealer’s website configuration.
A consumer who knowingly opens a clearly identified, third-party chat service or clicks a clearly branded social-media feature may present a different factual question. But a hidden retargeting tag that fires during page load cannot fairly be characterized as a deliberate interaction between the visitor and the advertising company.
That means a dealer cannot simply say:
The consumer visited our website, so the consumer intentionally interacted with every company receiving data from it.
The consumer visited the dealer’s website. Unless there was a separate, deliberate interaction or direction, the embedded recipient may remain a third party. If the recipient uses the dealer-site event together with information obtained across other businesses or websites to target advertising, the activity falls within the CCPA’s definition of cross-context behavioral advertising. California’s regulations expressly state that a person providing cross-context behavioral advertising is a third party, not a service provider or contractor for that service. Cal. Code Regs. tit. 11, § 7050(b).
The label “analytics” does not change that result. A genuinely restricted analytics provider performing services solely for the dealer may qualify as a service provider or contractor. But that status depends on the contract and the vendor’s actual conduct. A provider that combines dealer-site information with data from other customers, uses the information for its own purposes, contributes it to an identity graph, or uses it for cross-context advertising cannot necessarily be treated as a service provider merely because the product is marketed as “analytics.” California’s service-provider rules restrict independent use, use outside the direct business relationship, and combining information with other sources except where specifically permitted.
“Intentional interaction” and “consent” are different, but both reject passive page loading and “inform-only” cookie banners as authorization
The CCPA’s concepts of “intentional interaction” and “consent” are not identical. The consumer-directed exception to sale or sharing uses the language of deliberate direction and intentional interaction; it does not say that formal statutory consent is required in every case.
But both concepts undermine the idea that merely arriving on a webpage supplies blanket authorization for hidden third-party transmissions.
Where the CCPA requires or permits a business to rely on consent, “consent” means a freely given, specific, informed, and unambiguous indication through a statement or clear affirmative action. Acceptance of broad terms, passive conduct, closing content, and dark-pattern-obtained agreement do not qualify. Cal. Civ. Code § 1798.140(h). California’s regulations similarly state that silence or failure to act affirmatively is not consent and that closing or navigating away from a consent pop-up without affirmatively accepting does not establish consent. Cal. Code Regs. tit. 11, § 7004(a)(3). Sorry to disappoint anyone still relying on the old “We use cookies to enhance your experience” banner with an “Accept” button or a close (“X”) icon.)
This is where the banner issue is more nuanced than either side sometimes admits.
The CCPA does not impose a universal European-style opt-in requirement for every cookie used with every adult visitor. But it also does not say that a page visit constitutes consent or deliberate direction to every third-party vendor.
A properly designed banner can matter because it can:
- identify the applicable categories and purposes;
- distinguish necessary technology from optional third-party sales/sharing;
- give the visitor a deliberate choice;
- create a record of that choice;
- process a browser-level opt-out signal;
- prevent the optional technologies from executing until the choice is resolved; and
- provide other important legal disclosures.
The banner is not legally effective merely because it exists. It must actually control the relevant data flows.
California’s regulations state that a generic cookie banner or cookie-control tool is not, by itself, an acceptable method for exercising the right to opt out of sale or sharing. That is because a mechanism that addresses only cookies or collection does not necessarily address the sale or sharing of personal information. An acceptable mechanism must address the underlying sale and sharing. Cal. Code Regs. tit. 11, § 7026(a)(4).
Some people cite this rule as though it means cookie banners are unnecessary. It means almost the opposite: a banner alone is not enough unless it is connected to the actual third-party transmissions and rights it purports to control.
For example, a banner that appears after the tag has fired, offers only “Accept” and “Settings,” treats continued browsing as agreement, or leaves the transmission active after “Reject/Decline” is selected does not establish meaningful choice and can even be deceptive.
California’s notice rules make timing substantive
California requires a business that controls collection to provide notice at or before the point of collection. The Notice at Collection must explain the categories and purposes of collection and whether the information is sold or shared. Collection, use, retention, and sharing must also be reasonably necessary and proportionate to the disclosed purpose or another compatible purpose. Cal. Civ. Code § 1798.100(a), (c).
The regulations explain why the timing matters. The purpose of the Notice at Collection is to provide timely information so the consumer has a tool for exercising “meaningful control.” The Notice of Right to Opt Out is intended both to inform the consumer and to provide an opportunity to exercise the right. The regulations also provide that a business may not sell or share information collected during a period when the required opt-out notice was not posted unless the business obtains consent. Cal. Code Regs. tit. 11, §§ 7012(a), 7013(a), (h).
These provisions do not expressly announce a universal pre-load consent rule for every adult-facing advertising technology. But they are difficult to reconcile with the categorical claim that a business may complete an optional third-party disclosure before the notice and control intended to govern that disclosure are available.
California also requires the speed of the privacy control to correspond to the speed of the technology. Its regulations give the example of programmatic advertising that instantaneously sells and shares information through real-time bidding. When the business can stop that transfer instantaneously, it must comply with an opt-out immediately rather than use the outer 15-business-day period. Cal. Code Regs. tit. 11, § 7026(f)(3)(A).
For a visitor transmitting Global Privacy Control, the issue is even clearer. The opt-out instruction accompanies the browser interaction. The website should evaluate that signal before initiating covered advertising calls. A design that transmits the data first and evaluates GPC second is not an unavoidable feature of the internet. It is an implementation decision that allows the advertising system to execute before the privacy system.
Healthline and Honda show that regulators care about what the technology actually does
The Healthline matter is significant not only because the Attorney General recognized that trackers operate in milliseconds. The Attorney General also alleged that Healthline displayed a consent-management mechanism that purported to disable targeted-advertising cookies but did not actually disable them. The enforcement action focused on the actual transmissions—not merely the wording of the banner or privacy policy. Healthline resolved the allegations through a stipulated settlement, so the matter is not a judicial merits decision establishing a categorical pre-consent rule. It nevertheless provides strong evidence of California’s functional approach to online tracking. (California DOJ)
The California Privacy Protection Agency took a similar approach in its Honda enforcement matter. Honda’s cookie-management interface identified advertising cookies as active by default and stated that they could build interest profiles and display advertisements on other sites. The CPPA concluded that Honda’s use of those advertising cookies constituted CCPA “sharing.” It treated the cookie tool as a method for exercising the opt-out right and required Honda to provide a “Reject All” option symmetrical with “Allow All.” In re American Honda Motor Co., Inc. (Cal. Priv. Prot. Agency Mar. 7, 2025). (California Privacy Protection Agency)
Together, Honda and Healthline together establish an important enforcement principle:
The existence of a banner does not determine compliance. The actual network activity must correspond to the choice represented to the consumer.
California is the best example, but not the entire state-law landscape
California is a useful example because each shows why describing a law simply as “opt-out” leaves out much of the statutory structure. But it is not the only state whose laws and regulations combine opt-out rights with notice, minimization, purpose limitation, consent requirements, assessments, contractual controls, and universal opt-out signals.
Oregon gives consumers opt-out rights over sales and targeted advertising, but it also requires specific privacy notice disclosures, data minimization, data protection assessments, and recognition of universal opt-out mechanisms. Oregon requires consent for sensitive data and for a “secondary purpose” that is not reasonably necessary for and compatible with the purposes specified in the privacy notice. The Oregon Department of Justice expressly cautions that, depending on the processing involved, a cookie banner may be sufficient for some entities but not for others. ORS 646A.574–.578.
Connecticut likewise gives consumers the right to opt out of sales and targeted advertising and has required covered controllers to honor qualifying opt-out preference signals since January 1, 2025. But Connecticut also requires notice, data minimization, consent for sensitive data, assessments for targeted advertising and sales, and consent before processing personal data for a material new purpose that is neither reasonably necessary for nor compatible with the disclosed purposes. Conn. Gen. Stat. §§ 42-518, 42-520.
The same layered structure appears elsewhere. Colorado combines opt-out rights with transparency, purpose specification, data minimization, restrictions on secondary use, sensitive-data obligations, risk assessments, and a universal opt-out mechanism. Delaware similarly gives opt-out rights while prohibiting processing for purposes that are neither reasonably necessary nor compatible with disclosed purposes unless consent is obtained.
The details, definitions, thresholds, exceptions, and effective dates vary by state. This is not a substitute for a state-by-state analysis. But the broader point applies across many comprehensive privacy laws:
The opt-out right is one part of the statute. It is not a blanket authorization that overrides notice, minimization, purpose limitation, consent, processor restrictions, universal signals, or the requirement that privacy controls actually work.
What this means for dealer websites
A dealer should not treat all website technologies as legally equivalent.
Technology strictly necessary to render and secure the site, remember the visitor’s privacy choice, prevent fraud, balance traffic, detect bots, or complete a service expressly requested by the visitor presents a different analysis from optional retargeting, persistent behavioral analytics, audience development, session replay, social-media tracking, identity resolution, conversion tracking, and shopper-intent technologies.
A narrowly configured analytics provider may also present a different analysis if it is genuinely operating as the dealer’s service provider or processor, uses the information only for a specific first-party purpose, does not combine it across customers, does not use it for advertising or its own purposes, and is subject to compliant contractual and technical restrictions.
But a dealer should not assume those facts merely because a vendor calls its product “analytics” or “performance.” The dealer must understand what data leaves the site, when it leaves, where it goes, what the recipient may do with it, whether the recipient combines it with other information, and whether the recipient is actually functioning as a processor, service provider, contractor, controller, or third party.
For analytics and retargeting, the strongest and most reliable architecture is therefore:
Evaluate GPC and any previously recorded privacy choice before optional technology executes. Load only necessary technology initially. Keep optional analytics, advertising, and retargeting technologies blocked until the visitor accepts. If they decline, treat it as an opt-out.
The real meaning of “opt out”
The claim is not that every state opt-out law secretly imposes an affirmative-consent regime for every form of adult data processing.
The claim is that an opt-out can only function when the business can provide notice and apply the consumer’s choice before the actual sharing occurs. It cannot provide meaningful control over an initial disclosure that is completed before the consumer receives the notice, before the control is available, or before an opt-out signal accompanying the visit is evaluated.
Pre-activation blocking of online tracking tech is therefore not simply an attempt to import European consent law into the United States. It is the most reliable way to make U.S. notice-and-choice requirements function in an environment where optional third-party disclosures otherwise occur before notice and choice can have any practical effect.
THIS ARTICLE IS NOT LEGAL ADVICE AND SHOULD NOT BE USED AS A SUBSTITUTE FOR COMPETENT COUNSEL.