Global Privacy Control,
honoured and provable.
Global Privacy Control is now a legal opt-out in a dozen US states, and regulators test for it. This guide explains what the GPC signal is, where you must honour it, what honouring it actually involves, and how to test your own site. A practitioner's summary, not legal advice.
Last updated Published by TryTrustableNot legal advice
Global Privacy Control (GPC) is a browser setting that tells every website a visitor does not want their personal data sold or shared for targeted advertising. The browser sends it as the Sec-GPC: 1 request header and exposes it to scripts as navigator.globalPrivacyControl. California and eleven other states require businesses that sell personal data or use it for targeted advertising to treat the signal as a valid opt-out, with no extra click, form or login.
What is Global Privacy Control?
Global Privacy Control is a simple signal that a person's browser sends to every website they visit, meaning: do not sell or share my personal information. It was launched in 2020 by a group of browser makers, publishers and privacy researchers, and in November 2024 it became a work item of the W3C Privacy Working Group, where it is being standardised. Unlike its predecessor, Do Not Track, it has legal force: several US privacy laws require businesses to treat it as an opt-out.
How does the GPC signal work?
- HTTP header. With GPC on, the browser adds
Sec-GPC: 1to every request. - JavaScript. Scripts can read
navigator.globalPrivacyControl, which istruewhen the header would be sent. - Site declaration. A site can publish
/.well-known/gpc.jsonwith{"gpc": true, "lastUpdate": "2026-10-06"}to state that it honours the signal.
Brave and DuckDuckGo send GPC by default, Firefox offers it as a setting, and extensions such as Privacy Badger add it to other browsers. From 1 January 2027, California requires every browser maker to offer a setting that sends an opt-out preference signal (Civil Code 1798.136), so the number of visitors sending it will rise.
Which states require you to honour GPC?
Twelve states require businesses within their privacy laws to treat a universal opt-out signal as a valid opt-out of sale and targeted advertising. Colorado formally recognised GPC as the first approved signal. Most companies honour it for all US visitors, because geolocation is imprecise and the cost of getting it wrong is an enforcement action.
| State | Must honour from | Law |
|---|---|---|
| California | Already in force | CCPA, 11 CCR 7025 |
| Colorado | 1 July 2024 | Colorado Privacy Act |
| Connecticut | 1 January 2025 | Connecticut Data Privacy Act |
| Texas | 1 January 2025 | Texas Data Privacy and Security Act |
| Montana | 1 January 2025 | Montana Consumer Data Privacy Act |
| New Hampshire | 1 January 2025 | SB 255 |
| Nebraska | 1 January 2025 | Nebraska Data Privacy Act |
| New Jersey | 15 July 2025 | New Jersey Data Privacy Act |
| Minnesota | 31 July 2025 | Minnesota Consumer Data Privacy Act |
| Maryland | 1 October 2025 | Maryland Online Data Privacy Act |
| Oregon | 1 January 2026 | Oregon Consumer Privacy Act |
| Delaware | 1 January 2026 | Delaware Personal Data Privacy Act |
| Vermont | 1 January 2028 | Data Privacy and Online Surveillance Act |
| Louisiana | Unclear (law in force 1 January 2027) | Louisiana Data Privacy Act |
Each law applies only above its own threshold; see the full list on our US state privacy laws page.
What does honouring GPC mean in practice?
California's regulations (11 CCR 7025) set the most detailed rules, and they are a safe standard everywhere:
- Treat it as an opt-out of sale and sharing for that browser or device and any profile linked to it, including pseudonymous ones, and for the consumer if you know who they are.
- Ask for nothing more. You cannot require a login, form or extra click to make it effective.
- It wins over a stored setting. If the signal conflicts with an earlier choice to allow sale, you process the opt-out, though you may ask the person whether they want to make an exception.
- Silence is not consent. If a known consumer stops sending the signal, that does not opt them back in.
- Show it. Since 1 January 2026 you must display whether you processed the signal, for example "Opt-Out Request Honored".
GPC does not require you to block essential cookies or first-party analytics that is not a sale or share. It is an opt-out from selling, sharing and targeted advertising, not an EU-style opt-in banner.
How to implement GPC on your website
- Read the signal early, on the server from the
Sec-GPCheader and in the browser fromnavigator.globalPrivacyControl, before any advertising tag loads. - Gate every advertising tag on it: pixels, retargeting, ad SDKs and anything your tag manager fires. Set Google Consent Mode's advertising signals to denied for those visitors.
- Cover server-side flows, such as conversion APIs and data exports to ad platforms, which a browser-only fix misses.
- Record the opt-out with a timestamp and the fact that GPC triggered it, so you can prove it later.
- Link it to the account when a person logs in, and apply the opt-out to offline sharing you can tie to them.
- Display the status and update your privacy policy to say you honour GPC.
- Tell your vendors. Pass the opt-out to processors and partners that receive the data.
How to test whether your site honours GPC
| Test | How | Pass |
|---|---|---|
| The signal reaches you | Open the site in Brave, DuckDuckGo, or Firefox with GPC turned on; in the console, navigator.globalPrivacyControl | true |
| Advertising stops | Reload with GPC on and watch the network panel for ad and retargeting pixels | No advertising or cross-site tracking requests fire |
| No cookies left behind | Clear site data, reload with GPC on, inspect cookies and local storage | No advertising identifiers set |
| Server side too | Send a request with the header, e.g. curl -H 'Sec-GPC: 1', to pages that render tags server side or forward events | Server-side and tag-manager forwarding respects the opt-out |
| The opt-out is recorded | Check your consent records for that browser | An opt-out entry that says GPC was the reason |
| Status is shown | Look at the page with GPC on | Visible confirmation the opt-out was processed (required in California) |
| It sticks to the account | Log in with GPC on, then later without it | The opt-out stays on the known consumer's profile |
Run the tests on your highest-traffic pages, not only the homepage.
Our free cookie scanner automates the core test: it reloads your homepage with Global Privacy Control switched on and reports any advertising that still runs, and it checks for a Do Not Sell or Share link. The cookie consent checker covers the rest of the banner.
Is GPC being enforced?
Yes. California's first public CCPA settlement, in 2022, turned partly on a retailer's failure to process GPC. On 9 September 2025 the Attorneys General of California, Colorado and Connecticut announced a joint investigative sweep, contacting businesses that appeared not to be honouring the signal. The pattern is clear: regulators can test GPC from their own browsers, so it is one of the easiest violations to find.
How TryTrustable honours GPC
The consent platform reads the Sec-GPC header on the server before the banner renders. For US visitors, a browser sending GPC is recorded as an opt-out of advertising without any click, and the entry in the tamper-evident consent ledger notes that GPC was the reason. Scripts that would load advertising are blocked, Google Consent Mode v2 receives the denied state, and withdrawals are relayed to processors' webhooks with each delivery logged. See the consent product. Server-side flows you run outside the banner still need your own check.
The things people ask us
Is Global Privacy Control legally binding?
In California and eleven other states, yes, for businesses that are covered by the state's privacy law and sell personal data or use it for targeted advertising. Elsewhere it is a strong signal of the person's wishes but not a specific legal requirement.
What is the difference between GPC and Do Not Track?
Do Not Track was a browser header with no legal meaning, and most sites ignored it. GPC is narrower, an opt-out of sale and sharing, and state laws require businesses to honour it.
Which browsers support Global Privacy Control?
Brave and DuckDuckGo send it by default and Firefox has a setting for it. Other browsers need an extension such as Privacy Badger. California's Civil Code 1798.136 requires all browsers to offer a setting from 1 January 2027.
Do I have to honour GPC if I do not sell data?
The duty applies to selling, sharing for cross-context behavioural advertising and targeted advertising. If you genuinely do none of these, there is nothing to opt out of, but most sites with ad pixels do one of them.
Does GPC mean I must block all cookies?
No. It is an opt-out from sale, sharing and targeted advertising. Strictly necessary cookies and first-party analytics that is not a sale or share can continue.
How do I check if a website honours GPC?
Turn GPC on in your browser, confirm navigator.globalPrivacyControl is true in the console, reload the site and check that no advertising requests fire. Our free scanner runs this test for you.
Does GPC apply under GDPR?
GDPR does not mention it. In the EU and UK, non-essential cookies need opt-in consent anyway, so a GPC visitor is already protected if your banner works.
Prove you honoured every GPC opt-out.
Thirty minutes: we scan your site with GPC on, show what still fires, and walk through how the opt-out lands in the ledger.