Most agent websites handle cookie consent one of two ways. There is no banner at all, or there is a banner that says "We use cookies to improve your experience," linking to a privacy page nobody wrote. Neither one is doing what it is supposed to do.
What a cookie actually is on your site
A cookie is a small file a website asks the visitor's browser to store, so the site (or a tool embedded in it) can recognize that visitor on a later page or visit. On a typical agent website, almost every cookie comes from three sources: Google Analytics, which counts visits and tracks which pages get read; Google Ads, if you run pay-per-click campaigns and need to know which ad led to a form submission; and any embedded third-party widget, most often an IDX listing feed or a CRM chat box, each running its own tracking under its own policy.
None of that is unusual or aggressive. It is the same handful of tools almost every small business site runs. The problem is not the cookies themselves. It is that most banners either overstate what the site does with them or say nothing accurate at all.
The two rules that actually govern this, and they are not the same rule
California and the European Union built opposite systems, and conflating them is where most template banners go wrong.
California's CCPA, as amended by CPRA, is an opt-out model. A business can generally collect and use data first, then has to give visitors a working way to say no to having that data sold or shared, and it has to tell them plainly what it collects. Full coverage under CCPA only applies to a for-profit business that meets one of three thresholds: annual gross revenue over $26,625,000 as of 2025 (the figure adjusts every two years for inflation, per the California Privacy Protection Agency), buying or selling the personal information of 100,000 or more California residents a year, or earning half its revenue from selling personal data. A solo agent or small team almost never clears any of those bars.
The EU, UK, and Switzerland work the other way: opt-in. A site cannot set advertising or analytics cookies for a visitor in those regions until that visitor actively agrees, and the consent has to be a real choice, not a pre-checked box. This is not a suggestion for anyone running Google tools. Google's EU User Consent Policy makes it a contractual requirement for any site using Google Analytics or Google Ads, and it applies based on where the visitor is, not where the business is registered.
Why this matters even for a purely local practice
An agent working one city might assume none of this applies, and often that assumption is close to right for the California side. It is less safe on the EU side, because agent sites pick up international visitors in ways that are easy to miss: a relocation inquiry, a past client who moved overseas and still checks your market reports, a referral from an agent abroad sending a buyer your way.
Check your analytics location report before deciding this does not apply to you. If even a small share of sessions come from the EU, UK, or Switzerland, and you run Google Ads or Analytics, the consent requirement applies to those sessions specifically, not to your whole site universally, but the mechanism (a consent banner gating the relevant tags) is the same either way and is simpler to run site-wide than to try to geofence.
What Google actually requires, mechanically
Google's requirement is implemented through something called Consent Mode. In plain terms, it is a setting that tells Google Analytics and Google Ads to check for a visitor's consent choice before fully activating, and to fall back to a reduced, non-identifying mode of data collection when consent has not been given. Google's own documentation describes it as the mechanism that adjusts how tags behave based on the consent state your banner reports back to Google.
This is not something you configure by hand for each visitor. A consent banner (built in-house or through a consent management tool) collects the choice, and Consent Mode passes that choice to Google's scripts automatically. The part most agent sites get wrong is skipping the banner-to-Consent-Mode connection entirely: a banner that shows a message but never actually tells Google's tags what the visitor chose is decoration, not compliance.
What the privacy notice needs to say
The notice does not need to be long. It needs to be accurate about what is actually running on the site, which is the opposite of what most template text does.
Name the specific tools: Google Analytics, Google Ads if you run them, and any embedded IDX feed, CRM, or chat widget, since each of those sets its own cookies under its own policy and a notice that only covers your own analytics is incomplete. State plainly what each tool collects, in language a visitor would actually understand rather than legal phrasing copied from a template built for a different kind of business. Give a real way to ask a question, which for most agent sites is the same contact information already on the site.
The failure mode to avoid is a notice that promises mechanisms the site does not have, most commonly a "do not sell my data" link on a site that has never sold anyone's data and has no CCPA obligation to provide that link in the first place. An inaccurate privacy notice is a liability of its own, separate from whatever it was trying to prevent.
What to skip if you are a small, single-market site
Not every agent site needs the full apparatus a large brokerage runs.
Skip a paid consent management platform if a simple banner covers what your traffic actually requires. Many of these tools are built for sites running dozens of ad-tech vendors and cost real money for functionality a single-agent site does not use. Skip the CCPA-specific opt-out mechanics (the "do not sell" link, the specific rights language) if your business genuinely does not meet any of the three CCPA thresholds, though keep watching that threshold if your team is growing or your ad spend is scaling toward it. Skip a banner that blocks every script by default if your visitor base is entirely outside regions requiring opt-in consent, since defaulting to fully blocked can quietly break your own analytics and cost you the visibility our post on what to track in website analytics is built around.
What not to skip: a real, accurate notice naming your actual tools, and a working consent mechanism for the visitors who are legally entitled to one. That pair covers the overwhelming majority of what actually matters on a site this size.
The trust angle, separate from the legal one
There is a second reason to get this right that has nothing to do with which threshold applies. NAR's 2025 Profile of Home Buyers and Sellers found that home buying remains a high-trust decision built around the agent relationship, which is exactly why a visitor filling out a lead form on your site is handing over contact information to a stranger before ever speaking to them.
A privacy notice that is short, specific, and clearly written by someone who understands what the site does, rather than pasted from a generator, is a small but real trust signal at that exact moment. It sits next to the same judgment a visitor is making about the contact page itself: does this person seem careful, or does this look copied.
The takeaway
Get the two systems straight before writing anything. California's CCPA is opt-out and only fully applies once a business crosses one of three size thresholds most agent sites do not reach. The EU, UK, and Switzerland are opt-in, enforced through Google's own policy for anyone running Google Analytics or Ads, and triggered by where a visitor is located rather than where the business operates. Most agent sites need a short, accurate privacy notice naming the actual tools in use, and a working consent control for the visitors who are entitled to one under either system. Skip the parts built for a larger, more complex business, and get a lawyer's read on your specific situation before publishing anything that makes a legal claim, since none of this is legal advice and the thresholds shift over time.
A cookie banner that gates the actual tags, connected to Google's Consent Mode, and a privacy notice that says only what is true, together cover more real risk than a longer document nobody reads. If your current site has neither, that is the more useful place to start than researching every regional variation at once. For a broader look at what the rest of an agent site needs to earn trust and convert, see our real estate website security post on what HTTPS does and does not protect, and the full website rebuild service if the whole site needs a closer look rather than one page.



