The banner covers 16 privacy laws. You select the ones that apply to your site, and the banner then applies the consent model of the market each visitor is in: opt-in, opt-out or notice.
Opt-in: cookies wait for a choice
For these laws, the banner blocks non-essential cookies until the visitor chooses, with Reject all beside Accept all at the same size and no pre-ticked boxes.
- GDPR in the European Union and United Kingdom
- LGPD in Brazil
- DPDP in India, whose consent rules apply from May 2027
- Law 25 in Quebec
- POPIA in South Africa
- PDPA in Thailand
- PDPL in Saudi Arabia
Canada’s PIPEDA is opt-in for advertising. Advertising and profiling cookies wait for consent, implied consent covers low-sensitivity tracking, and you can change this per category.
Opt-out: cookies can run until the visitor opts out
For these laws, the banner shows no blocking wall. A “Do Not Sell or Share My Personal Information” link appears on every page, with a preference centre where the visitor can opt out.
Notice: the banner informs and records
- PDPA in Singapore: deemed consent by notification covers many purposes. The banner gives the notice and records the choice.
- Privacy Act 1988 in Australia: there is no cookie-consent rule as such. The banner gives the notice and keeps a record where a cookie can identify someone.
Choosing the laws for your site
You decide which regulations apply to each website and select them in the GrantCookie application. GDPR and CCPA templates come with every plan. The banner works out where each visitor is, at the level of country or region, and applies the rule for the regulations you selected.
These descriptions say what the banner does. They are not legal advice, and compliance with privacy and data protection law is your responsibility. Each regulation guide explains what the law asks of your website.

