Consent requirements by region

Guides to cookie and consent law in the EU and UK, India and the United States: what each requires, how long to keep records, and how to comply with Macaw.

Guides

Regions side by side

RequirementEU & UKIndiaUnited StatesMacaw
Consent model for cookiesOpt-inOpt-inOpt-out (opt-in for sensitive data)Opt-in everywhere
Prove who agreed, when, to what wordingGDPR Art. 7(1)DPDP s.6(10), Rule 3CCPA §7101 (requests)Stored records with notice versions
Reject as easy as accept, no pre-ticked boxesEDPB, CNILRule 3Dark-pattern rulesBuilt into the banner
Easy withdrawalArt. 7(3)s.6(4)Opt-out rightsReopen the banner from your footer
Honour browser opt-out signal (GPC)RecommendedNot requiredMandatory in 12+ statesNot yet: handle in your code
ChildrenArt. 8Parental consent under 18COPPA and state lawsNot yet: handle in sign-up
Keep recordsAccountability1 year logs; 7 years for consent managers24 months6 to 84 months, default 24

This guide summarises public regulator guidance and legal commentary to help you configure consent. It is not legal advice. Laws, deadlines and enforcement change; have your counsel confirm what applies to your business.