Beyond Switzerland: Aiara now covers the USA, Brazil and South Africa
Anyone with visitors from the United States needs no consent banner — quite the opposite. We have extended Aiara with the American opt-out model and added privacy sections for Brazil and South Africa. What lies behind it and how to enable it.

Until recently a clear boundary applied to Aiara: Switzerland and the EU. That was a deliberate decision — better two legal systems done properly than ten done half-heartedly. In the meantime, however, enquiries accumulated from customers whose websites are also accessed outside Europe. We have therefore extended Aiara by three legal systems: the United States, Brazil and South Africa.
The USA works exactly the other way round
The most important point first, because it is the biggest difference: the USA has no consent model. What is self-evident here — ask first, then set cookies — is unknown to American law in this form. There, processing is permitted until a person objects.
That has an immediate consequence for the interface: a visitor from California is not shown a banner asking for agreement. They see a permanently available link — usually "Your Privacy Choices" — through which they can object to the sale and sharing of their data. Anyone not offering this link is in breach. Anyone showing a European consent banner instead does not comply either.
Aiara detects the region and switches automatically. For visitors from Switzerland and the EU everything stays as it was.
One signal for more than twenty states
The USA has no uniform privacy law. California has the CCPA as amended by the CPRA, Virginia the VCDPA, then come Colorado, Connecticut, Utah, Texas, Oregon and around fifteen further states with their own rules. Implementing each individually would be a bottomless pit.
The advertising industry has created a shared solution for this: the Global Privacy Platform of the IAB Tech Lab. It has a national section that combines the requirements of all states into a single signal. Aiara uses precisely that section. The practical advantage: we do not need to know which state someone is in — the signal applies nationwide. Detection at state level would be technically demanding, error-prone and of no use for the purpose.
Global Privacy Control is honoured automatically
One point often overlooked in practice: in California and further states, websites must respect the Global Privacy Control. This is a signal that the browser or a privacy extension sends automatically, meaning: this person objects to their data being shared.
Legally this is not a wish but a valid objection. Californian authorities have enforced in several proceedings that it must be honoured. Aiara evaluates the signal as soon as US mode is active and implements the objection without asking. The selection window then carries a note that the browser signal was detected and already honoured — and the switch is locked, because there is nothing left to decide.
What an objection actually switches off
Precision pays here, because it is easy to go too far or not far enough. An objection under Californian law is directed against the sale, the sharing and targeted advertising. It is not directed against audience measurement for one's own purposes — that does not count as a sale there.
On an objection, Aiara therefore switches off the marketing category and leaves analytics running. This is deliberate and differs from a refusal under the GDPR, which affects both. Anyone wanting to switch off everything can do so via the usual categories — but the legal requirement is the narrower one.
Brazil and South Africa: familiar model, new texts
For these two the effort was smaller, because they work like the GDPR: both operate with consent. The banner therefore did not need rebuilding — only the legal texts were missing.
Brazil has, in the Lei Geral de Proteção de Dados, a law closely resembling the GDPR but with its own terms and authorities. The privacy policy now names the legal bases under Article 7, the data subject rights under Article 18, the supervisory authority ANPD and the "Encarregado" — the local equivalent of the data protection officer. Added to this is the banner in Portuguese, as a fifth language alongside German, French, Italian and English.
South Africa regulates data protection in the Protection of Personal Information Act. The section names the eight conditions for lawful processing, the data subject rights, the Information Officer and the Information Regulator as the complaints body. A particularity is the consent requirement for electronic direct marketing to people who are not yet customers — stricter than many expect.
Do you even need this?
Probably not, and we say so deliberately clearly. The CCPA only applies from 25 million US dollars in annual revenue or from data on 100,000 Californian consumers. The other states set comparable thresholds. A tradesman from Winterthur with a few visitors from overseas does not fall under it.
It becomes relevant in three cases:
- Larger e-commerce with US business that actually reaches the thresholds
- Contractual requirements, where a business partner demands the coverage
- Group policies, where a subsidiary must meet the same standards as the parent
Anyone without one of these cases simply leaves the features switched off. They are disabled by default, and whoever does not enable them will not notice the extension.
How to enable it
Two places, both in the dashboard:
In the banner editor you will find a switch under "USA (CCPA and others)". When active, the opt-out model applies to visitors from the United States — with the "Your Privacy Choices" link instead of the consent banner.
In the questionnaire under "Jurisdiction" there are three new entries: visitors from the USA, from Brazil and from South Africa. Each adds its own section to your privacy policy. The texts are generated and updated automatically as usual.
The two are independent of each other. Anyone needing only legal texts for Brazil, but no US mode, simply ticks the one box.
What the extension is not
Finally the limitation that belongs with it: Aiara now covers five legal systems — Switzerland, the EU, the USA, Brazil and South Africa. That is not "worldwide". Canada, the United Kingdom, Australia, Japan, India and many others have their own laws that we do not represent. Anyone with an audience in those countries who genuinely falls under the respective thresholds needs more than we offer today.
We selected the three legal systems that were actually asked for. Should further ones follow, the same criterion decides: genuine demand rather than the longest possible list on a website.
Frequently Asked Questions
Does the Californian privacy law apply to my Swiss company?
Usually not. The CCPA only applies from 25 million US dollars in annual revenue or from data on 100,000 Californian consumers. Most Swiss SMEs are far below that. It becomes relevant for larger e-commerce with US business, or when a client requires it contractually.
What is the difference between consent and opt-out?
In Switzerland and the EU, non-essential cookies may only be set once someone has agreed. In the USA the opposite applies: processing is permitted until a person objects. That is why a US visitor sees no banner, but a permanent link through which they can object.
What is Global Privacy Control?
A signal that the browser or an extension sends automatically, expressing: this person objects to their data being shared. In California and further states it counts as a legally valid objection and must be honoured without asking. Aiara evaluates it automatically.
Do I need a Portuguese banner for Brazil?
It is not prescribed literally, but the information must be comprehensible — and it is most likely to be so in the local language. Aiara therefore now delivers the banner in Portuguese as well. The privacy policy remains in four languages; Brazilian visitors receive the English version.
What happens to my existing banner?
Nothing. All new features are switched off by default. Anyone who does not need them will not notice the extension. And even if you enable US mode, not a single detail changes for visitors from Switzerland and the EU.
Ready for clean cookie consent?
Aiara handles cookie banners, privacy policies and legal notices for your website — FADP and GDPR compliant.
Discover Aiara

