ConsentPixel – Privacy · Verified

CIPA & Consent · Explainer

Your Privacy Policy Is Not a Consent Banner

It's one of the most common — and most expensive — misunderstandings in website privacy: the belief that because your privacy policy discloses the trackers you run, visitors have somehow consented to them. They're two different legal things. A privacy policy is a one-way notice of what you do. Consent is the visitor actively agreeing to it. And in August 2026, a California court said so directly — rejecting a major retailer's argument that its posted privacy policy was enough to prove consent. Here's the distinction, why courts keep drawing it, and what actually counts.

CP ConsentPixel Team September 2026 13 min read Information, not legal advice
Aug 2026
A California court held a posted privacy policy alone was not enough to establish CIPA consent (Asercion v. Ulta)
Disclosure ≠ consent
A policy tells people what you do; consent is them agreeing — different legal categories
$5,000
Statutory damages per violation under Cal. Penal Code §637.2 — and a policy is not a defense on its own

Key takeaways

  • A privacy policy is a disclosure; consent is an agreement. One is you telling visitors what you do. The other is visitors affirmatively agreeing to it. You cannot disclaim your way to consent.
  • "By continuing to browse, you agree" is not consent. Courts on both sides of the Atlantic reject implied consent from inaction — consent requires a clear affirmative act.
  • An August 2026 ruling made this explicit. In Asercion v. Ulta, a federal court rejected the argument that a posted privacy policy gave CIPA consent to install trackers, and let the wiretapping claims proceed.
  • Browsewrap fails; clickwrap works. A footer policy link users never click isn't consent. An affirmative opt-in before trackers fire is.
  • Your policy still matters — as the disclosure layer. It's what makes consent "informed." But it's a component of consent, never a substitute for it.

The category error at the heart of it

Ask a room of business owners whether their website has consent for its analytics and advertising trackers, and a lot of them will answer with some version of: "Yes — it's all in our privacy policy." That answer feels right. The policy lists the cookies. It names the vendors. It explains what data is collected and why. Surely that covers it?

It doesn't — and the reason is a genuine category error, not a technicality. A privacy policy and consent are two different legal instruments that do two different jobs. Conflating them is like confusing a restaurant posting its allergen information with a customer telling the kitchen it's fine to use nuts. The disclosure is necessary. It is not the same as the agreement.

Here's the distinction in one line, because everything else follows from it:

A privacy policy is you telling visitors what you do. Consent is visitors agreeing to let you do it. Telling someone your plan is not the same as them saying yes to it.

— The whole distinction, in one sentence

A policy is a one-way notice: it sits on a page and states your practices. It requires no response from the visitor to exist. Consent is a two-way act: it only exists when the visitor does something — clicks, toggles, agrees — that unambiguously signals agreement. You can have a flawless, comprehensive, lawyer-drafted privacy policy and zero valid consent, because nobody ever agreed to anything. The policy just described what you were going to do anyway.

Laying the two next to each other makes the gap obvious — and shows why one can never quietly become the other:

A disclosure

Privacy Policy

  • One-way. You telling visitors what you do.
  • Passive. It exists on a page whether or not anyone reads it.
  • "Here's what happens." A statement of practice.
  • Often a footer link the visitor never opens.
  • Being accurate is necessary — but it isn't agreement.
An agreement

Consent

  • Two-way. The visitor actively agreeing.
  • Active. It only exists once they take an affirmative act.
  • "Yes, you may." A decision the visitor makes.
  • A clear choice presented before trackers fire.
  • Must be given before the tracking happens, not after.
PRIVACY POLICY = disclosure You ──▶ Visitor (one way) CONSENT = agreement You ◀──▶ Visitor (two way) Two different things — one can't substitute for the other A disclosure informs consent. It does not replace it.

Notice the last row of each column, because it's where the legal exposure lives. Consent has to be given before the tracking happens — that's the entire premise of the CIPA and GDPR "prior consent" standard. A privacy policy, by its nature, can't satisfy that: it just sits there while the page loads and the trackers fire. There's no moment where the visitor agreed, because a policy doesn't ask for agreement. It only informs.

The ruling that said it out loud

If this were only a theoretical distinction, you could argue about it. But in August 2026 a federal court applied it to a real company and a real privacy policy — and the policy lost.

In Asercion v. Ulta Salon, Cosmetics & Fragrance, Inc. (N.D. Cal., Aug. 21, 2026), the plaintiff visited Ulta's website in May 2025 to browse for Mother's Day gifts. He alleged that Ulta had embedded code causing third-party trackers to install on his browser, collect his browsing activity in real time, and transmit it to third parties for targeted advertising — without his consent. Ulta moved for judgment on the pleadings, and its central argument was exactly the one this article is about: our posted privacy policy gave him consent.

The court rejected it. It denied the motion and let the CIPA claims proceed, holding that a posted privacy policy alone was not enough to establish consent to install tracking technology. As one legal analysis put it plainly:

For businesses that treat posted privacy policies as a complete defense to CIPA suits, this ruling shows that a policy alone may not be enough. CIPA consent requires more than a posted privacy policy.

— On Asercion v. Ulta (N.D. Cal., Aug. 21, 2026)

Two other parts of the decision are worth noting because they close off the usual escape routes. The court let the §631 interception claim proceed because the trackers allegedly captured the substantive contents of the visitor's activity — product views and more — while in transit. And it let the §638.51 pen register claim proceed too, rejecting Ulta's argument that the provision only reaches telephone technology. (The allegations remain unproven at this stage; the ruling is about whether the case can go forward, and it can.)

⚠ The specific belief this ruling punctures
"We have a thorough privacy policy that discloses all our trackers, so we have a consent defense." After Asercion, that's a much weaker position. A policy is evidence you disclosed — it is not, on its own, evidence the visitor agreed. Those are the two different things this whole article is about, and a court has now said so in as many words.

Why "by continuing to browse, you agree" fails

There's a specific move sites make to try to bridge the gap between a policy and consent — and it's the exact move courts reject. It's the line you've seen a hundred times: "By continuing to browse this site, you agree to our Privacy Policy." Or a small banner that says "We use cookies" with only an "OK" or an X to dismiss it.

The problem is that these try to manufacture consent out of inaction. Continuing to scroll, or not leaving the site, or dismissing a notice, are not affirmative acts of agreement — they're just… using the website. Consent has to be an unambiguous, affirmative choice, and "the visitor didn't leave" is neither unambiguous nor a choice. The visitor may not have read the notice, may not have understood it as a request for agreement, and certainly never did anything that means "yes."

This is why the "informed" part of consent and the "agreement" part are separate requirements. Your privacy policy can supply the informed element — it's where the detail lives. But it cannot supply the agreement element, because agreement is something only the visitor can give, by doing something. A notice that a visitor passively receives, however well-written, is a disclosure wearing the costume of consent.

Does your site rely on a policy where it needs consent?

The fastest way to find out: scan your site and see which trackers fire on page load — before any visitor has clicked, agreed, or opted in. If they fire before consent, a privacy policy won't cover them. About 10 seconds, no account.

Scan your site free →

Browsewrap vs clickwrap: the line courts actually draw

Courts have a well-developed vocabulary for this exact distinction, borrowed from decades of contract law: browsewrap versus clickwrap. Understanding which one you have tells you immediately whether you're relying on a disclosure or actually collecting consent.

🚫 Browsewrap

Terms (or a privacy policy) the visitor is deemed to accept simply by using the site — a footer link, a "by continuing you agree" line. No affirmative action required, and usually none taken.

Courts increasingly reject as consent

✅ Clickwrap

A clear notice plus an affirmative act — clicking "Accept," ticking a box, choosing preferences — before data flows. The visitor unambiguously agreed.

The defensible standard

Your own CIPA case tracker is full of this line being drawn. In Camplisson v. Adidas, terms buried in a website footer were treated as "no consent at all" — a footer-only disclosure failed the conspicuousness a valid consent defense requires. In Podraza v. Nourish, the site relied on browsewrap — a buried notice users were deemed to accept by visiting — and the court found it inadequate, letting the wiretapping claims survive. Compare Sisti v. Bosley, where the site used clickwrap that required affirmative acceptance before access, and the claims were dismissed with prejudice. Same statute, opposite outcomes — and the deciding factor was whether the visitor was made to actually agree, or merely deemed to.

The pattern across all of them. Where the "consent" was a policy or a notice the visitor passively received, it failed. Where it was an affirmative act the visitor had to take before tracking began, it held. That's the disclosure-versus-agreement line, drawn case after case.

The same rule, on the other side of the Atlantic

This isn't a California quirk. The EU reached the identical conclusion years earlier, and stated it even more crisply — which is useful if any of your visitors are in Europe.

Under the GDPR, consent must be freely given, specific, informed, and unambiguous, and given by a clear affirmative act (Article 4(11)). That last phrase does the same work as the browsewrap/clickwrap line: it rules out anything passive. Europe's top court made the point concrete in Planet49 (2019), holding that a pre-ticked box is not valid consent — if the user has to un-tick something to refuse, they never affirmatively agreed. A later case, Orange România (2020), went further and put the burden on the business to prove the visitor gave consent by active behaviour.

The through-line is the same as CIPA's: a privacy policy is the "informed" ingredient, not the consent itself. The policy (and the banner's first layer) supply the information a visitor needs to make a real choice. But under both regimes, the choice still has to be made — actively, by the visitor, before non-essential trackers run. "Continued browsing" and "by using this site you agree" fail in Brussels for exactly the reason they fail in California. For the full EU picture, see our guide to what GDPR cookie consent actually requires.

So what actually counts as consent?

If a privacy policy is the disclosure and not the agreement, what does the agreement have to look like? The requirements are consistent across CIPA-era US litigation and GDPR, and none of them is exotic:

  • An affirmative act, before trackers fire. The visitor clicks or toggles a real choice on a consent interface — and non-essential trackers stay blocked until they do. The order matters: consent given after tracking has started can't retroactively cure it.
  • Informed — which is where your policy comes back in. The visitor needs to know what they're agreeing to. That's the job the privacy policy and the banner's first layer actually do: they supply the information. So the policy isn't useless — it's essential — it's just the informed ingredient, not the whole recipe.
  • Specific and granular. A single "Accept everything" isn't specific consent to five different purposes. Categories — analytics, advertising, and so on — should be separable choices.
  • Freely given. A real reject option, roughly as easy and prominent as accept. A choice between "Accept" and a hard-to-find "Settings" link isn't freely given.
  • Recorded. You need to be able to show the agreement happened — when, and to what. (Proving it is its own topic; we cover the evidence side in cookie banner vs. real compliance.)

And one more point that trips people up, because it sits right next to this one: even a real consent banner fails if it doesn't actually block the trackers until the visitor agrees. That's a different failure from the one in this article — it's a banner that asks for consent but doesn't enforce it — and we cover it separately in why most cookie banners are "fake." The two problems stack: relying on a policy instead of a banner is one failure; having a banner that doesn't block is another. You need to clear both.

Where your privacy policy fits — kept honestly
None of this means your privacy policy is optional or unimportant. It's legally required, and it's the disclosure that makes consent "informed." The point is narrower and exact: a policy is a component of valid consent, never a substitute for it. Keep the policy accurate and accessible — and pair it with an actual consent mechanism that asks the visitor to agree, before anything fires.

How ConsentPixel fits

This is the gap ConsentPixel is built to close. A privacy policy is the disclosure layer — and ConsentPixel can even generate one from your real scan data so it's accurate. But the part a policy can never be is the consent mechanism: ConsentPixel blocks third-party trackers from firing until the visitor gives an affirmative opt-in, honors opt-out signals, and logs each decision so the agreement is provable. The policy tells visitors what you do; the pixel is how they actually agree — and how you make sure nothing fires until they have. Together they cover both halves; the policy alone only ever covered one. This is information, not legal advice — your policy and your specific situation are still worth reviewing with counsel.

Frequently asked questions

Does a privacy policy count as consent?

No. A privacy policy is a disclosure — a one-way notice of what your site does with data. Consent is a separate thing: the visitor affirmatively agreeing to it. A policy can make consent "informed" by supplying the necessary information, but it cannot be the agreement itself, because agreement requires the visitor to take an action. In August 2026, a federal court in Asercion v. Ulta rejected the argument that a posted privacy policy alone established CIPA consent to install trackers. This is general information, not legal advice.

Is "by continuing to browse, you agree" valid consent?

Generally no. That language tries to manufacture consent from inaction — continuing to scroll or not leaving the site — but consent requires a clear affirmative act. Courts applying CIPA treat passive, browsewrap-style notices as inadequate, and under the GDPR the CJEU's Planet49 decision confirmed that implied consent and pre-ticked boxes don't qualify. The visitor has to actively agree, typically by clicking or toggling a real choice, before non-essential trackers run.

What did Asercion v. Ulta actually decide?

In Asercion v. Ulta (N.D. Cal., Aug. 21, 2026), a federal court denied Ulta's motion for judgment on the pleadings and rejected its argument that a posted privacy policy gave the plaintiff consent to install tracking technology. The court let the CIPA §631 interception and §638.51 pen register claims proceed, and dismissed only a related unfair-competition claim for a pleading deficiency. The takeaway widely drawn from it is that a privacy policy alone may not be enough to establish CIPA consent. The allegations remain unproven; the ruling concerns whether the case can proceed, not final liability.

What's the difference between a disclosure and consent?

A disclosure is you telling people what you do — a privacy policy is the classic example. Consent is those people agreeing to let you do it. A disclosure is one-way and passive: it exists on the page whether or not anyone reads or responds to it. Consent is two-way and active: it only exists once the visitor takes an affirmative act signaling agreement. Privacy law generally requires both — the disclosure to make the choice informed, and the consent as the actual permission — and one cannot substitute for the other.

Do I still need a privacy policy, then?

Yes, absolutely. A privacy policy is legally required in most cases, and it's the disclosure that makes consent "informed" — so it's a necessary part of doing consent properly, not something to drop. The point of this article is only that a policy is a component of valid consent, not a replacement for the consent mechanism. Keep the policy accurate and accessible, and pair it with an actual opt-in that asks visitors to agree before non-essential trackers fire.

If I add a real consent banner, am I fully covered?

A real, affirmative consent banner solves the problem in this article — relying on a policy or passive notice instead of asking the visitor to agree. But there's a second, separate failure to avoid: a banner that asks for consent while the trackers fire anyway because it doesn't technically block them until the visitor opts in. Both have to be right — a genuine consent mechanism, and one that actually gates the scripts. Scanning your site to see what fires before consent is the quickest way to check the second half.

The bottom line

The belief that a privacy policy covers consent is one of the most common reasons businesses are surprised by a CIPA demand letter. It comes from treating two different legal instruments as one. A privacy policy discloses; consent agrees. The policy is you stating your practices. Consent is the visitor saying yes to them — actively, before the tracking starts.

Courts have now made this explicit. Asercion v. Ulta rejected the "our policy is our consent" defense outright, and the browsewrap-versus-clickwrap cases have been drawing the same line for years: a footer link is not agreement; an affirmative opt-in is. The EU reached the identical conclusion in Planet49.

So keep your privacy policy — it's required, and it's the disclosure that makes consent informed. Just don't mistake it for the consent itself. Pair the disclosure with a real mechanism that asks visitors to agree, and blocks trackers until they do.

See where your site relies on a policy instead of consent

Scan your site to see which trackers fire on page load — before any visitor has agreed to anything. If they fire before consent, a privacy policy won't cover them. Free, about 10 seconds, no account.

Scan your site free →
No account needed for the scan · then a 14-day free trial, no credit card required
CP

The ConsentPixel Team

Privacy & Consent Compliance

ConsentPixel — Privacy · Verified is a CIPA-first consent platform delivered as a single JavaScript pixel: it blocks third-party trackers until a visitor gives an affirmative opt-in, honors opt-out signals, and logs each decision as evidence. This article is educational and not legal advice.

Information, not legal advice. This article explains the general distinction between a privacy policy and consent for educational purposes and does not constitute legal advice or create an attorney–client relationship. Case descriptions — including Asercion v. Ulta (N.D. Cal., Aug. 21, 2026) — reflect publicly reported court records as of September 2026; the allegations in that matter remain unproven and the ruling concerns whether the case may proceed, not final liability. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2; actual exposure varies by case. How CIPA, the GDPR, and related laws apply to your website depends on your specific facts — consult qualified counsel. ConsentPixel — Privacy · Verified is not a law firm, and no single tool or document by itself makes a website compliant with any law.

Scroll to Top