Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Necessary

usprivacy Cookie (IAB CCPA) – What It Is & Does

usprivacy is a technical cookie defined by the IAB CCPA framework (US Privacy String) that stores a visitor's decision regarding the sale/sharing of their personal data under California's CCPA/CPRA law. It appears mostly on sites targeting US audiences, but can also show up on Romanian sites using global advertising platforms.

Name
usprivacy
Provider
IAB CCPA
Category
Necessary
Type
HTTP cookie
Lifetime
1 year
Consent
No, but it must be listed in the cookie policy

What is the usprivacy cookie?

The usprivacy cookie is part of the US Privacy String specification published by the IAB (Interactive Advertising Bureau) to standardize how websites communicate a user's opt-out choice regarding the sale or sharing of personal data, as required by US privacy laws such as CCPA/CPRA.

It is typically set by a Tag Manager, a consent management platform (CMP), or directly by an advertising script (SSP/DSP) embedded on the site, when the page loads or when the visitor expresses a privacy preference.

What data it stores

The cookie's value is an encoded string following the US Privacy String format (generally letters and digits indicating the specification version and opt-out flags), and it does not directly contain a name, email, or other directly identifying information.

This value is read by advertising scripts and SSP/DSP platforms integrated on the site to determine whether the visitor's data can be used for targeted advertising or must be excluded from such processing.

What it is used for

The cookie's purpose is purely functional: it stores the visitor's decision (or lack thereof) regarding the sale/sharing of their data with third parties, as defined by US privacy laws (CCPA/CPRA).

For site administrators, this cookie helps meet the technical requirements of the IAB advertising ecosystem when the site has US traffic or customers, avoiding data transmission to ad networks without an expressed preference.

Does it require consent?

In CookieFix's classification, usprivacy is marked as strictly necessary, since it does not track visitor behavior for marketing purposes but only stores a privacy preference. This classification should still be verified case by case, depending on the specific script setting it on each site.

Under GDPR and Romanian Law 506/2004 (transposing the ePrivacy Directive), strictly necessary cookies do not require prior consent, but must be disclosed in the site's cookie policy along with their purpose and duration. Site administrators should confirm exactly which script sets this cookie and verify it is not also used for marketing tracking, in which case it should be reclassified.

How to block or delete usprivacy

  • Visitors can delete or block this cookie from their browser settings (Chrome, Firefox, Edge, Safari), in the per-site cookie management section.
  • Site administrators can control when this cookie fires by configuring the correct category (strictly necessary, or marketing if applicable) in a CMP such as CookieFix, which automatically blocks improperly tagged scripts until the visitor makes a choice.
  • If the script generating it belongs to a marketing platform, it should be moved to the appropriate category and blocked by default until consent is given.

Frequently asked questions

It's a technical cookie from the IAB US Privacy String standard that stores a visitor's opt-out choice regarding the sale/sharing of their data under the US CCPA/CPRA law.

Generally no, as it's classified as strictly necessary, but site administrators should check the script setting it, since some implementations may tie it to marketing purposes.

It's usually set by a Tag Manager, a CMP, or directly by an advertising script (SSP/DSP) implementing the IAB privacy specification.

Its typical duration is about 1 year, after which the browser removes it automatically unless it's renewed.

Updated 7 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.