DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Signals & standards

What is Global Privacy Control (GPC)?

Global Privacy Control (GPC) is a browser or browser-extension privacy signal that communicates a user's request to opt out of certain data uses, particularly the sale or sharing of personal information and, where applicable, cross-context targeted advertising.

GPC is designed to let people communicate an opt-out preference automatically instead of submitting the same request individually on every website. The signal can be transmitted to websites through technical mechanisms such as an HTTP request header and browser APIs.

Under the California Consumer Privacy Act (CCPA), a qualifying user-enabled opt-out preference signal such as GPC must be honored by covered businesses as a valid request to opt out of the sale or sharing of personal information.

What does Global Privacy Control mean?

Global Privacy Control is a privacy preference signal that allows a user to communicate an opt-out choice across websites.

Instead of visiting a website, finding its privacy settings, and manually selecting an opt-out option, a user can enable GPC in a supported browser or privacy extension. Participating websites can detect the signal and apply the relevant privacy preference.

The GPC specification is intended to make privacy rights easier to exercise at scale. The current W3C specification describes GPC as a signal that communicates a person's request not to sell or share their personal information and, where applicable, to opt out of cross-context targeted advertising.

GPC is also known as

Global Privacy ControlGPC signalGPC privacy signalGPC opt-outGlobal Privacy Control signalopt-out preference signaluniversal opt-out mechanism

How does GPC work?

A simplified GPC flow looks like this:

01

Enable

The user enables GPC in a supported browser, browser extension, or privacy tool.

02

Communicate

The browser communicates the preference to websites the user visits.

03

Detect

The website detects the GPC signal.

04

Determine

The website determines which legal obligations apply based on the user's context and applicable privacy laws.

05

Apply

The website applies the corresponding opt-out preference, such as disabling covered sale or sharing.

06

Propagate

Downstream systems and third parties should receive the appropriate updated privacy state.

07

Record

The business records or otherwise maintains appropriate evidence of how the request was handled, where required by its compliance program.

GPC is therefore more than a visual privacy setting. It is a machine-readable way to communicate a user's privacy preference to websites.

What does the GPC signal actually tell a website?

GPC generally communicates an opt-out preference. It is not a complete statement of every privacy right a user may have.

The W3C specification specifically distinguishes GPC from other privacy rights. For example, GPC is not designed to exercise deletion rights or every possible advertising opt-out or data-processing right.

A business should therefore avoid interpreting GPC as:

"The user has rejected every form of data processing."

Instead, the business should map the signal to the rights and processing activities covered by the applicable law.

GPC and the CCPA

GPC has a particularly important role under the California Consumer Privacy Act (CCPA).

California recognizes a user-enabled global privacy control as one method for consumers to submit a request to opt out of the sale or sharing of personal information. Covered businesses must honor qualifying opt-out preference signals as valid requests.

This is especially relevant to businesses whose processing involves:

  • Sale of personal information
  • Sharing of personal information
  • Cross-context behavioral advertising
  • Third-party advertising technology
  • Certain online tracking and advertising activities

The California Privacy Protection Agency also describes opt-out preference signals as a way for users to automatically communicate an opt-out request through a browser setting or extension.

Is GPC required under CCPA?

For businesses covered by the applicable CCPA opt-out requirements, a qualifying GPC or other valid opt-out preference signal must be honored when it meets the applicable requirements.

This does not mean that every website in every jurisdiction must implement GPC in exactly the same way.

The legal requirement depends on factors such as:

  • Whether the business is subject to the relevant privacy law
  • Whether the business engages in activities covered by the opt-out right
  • The user's jurisdiction and applicable law
  • Whether the signal satisfies the applicable legal requirements
  • Whether the signal is being used for the purpose recognized by that law

For California businesses and consumers, however, GPC is an important technical mechanism for exercising the CCPA right to opt out of sale or sharing.

GPC and CPRA

The California Privacy Rights Act (CPRA) amended the CCPA and expanded California privacy protections.

The CPRA did not create a completely separate privacy law from the CCPA. Instead, it amended the existing CCPA framework and added additional rights and requirements.

GPC is relevant to the CCPA/CPRA opt-out framework because California recognizes qualifying opt-out preference signals as a mechanism for communicating a consumer's request to opt out of sale or sharing.

GPC and cross-context behavioral advertising

GPC is particularly relevant to cross-context behavioral advertising.

Cross-context behavioral advertising generally involves using personal information obtained from a consumer's activity across businesses, websites, applications, or other contexts to target advertising.

Under California privacy rules, consumers have a right to opt out of the sale or sharing of personal information, including sharing associated with cross-context behavioral advertising.

A compliant implementation should therefore consider how a GPC signal affects:

  • Advertising pixels
  • Retargeting systems
  • Social-media advertising tags
  • Audience-building tools
  • Third-party advertising platforms
  • Cross-site identifiers
  • Advertising cookies
  • Data sharing with advertising partners

Does GPC replace a cookie banner?

No.

GPC does not automatically replace a consent banner.

A cookie banner and GPC address different privacy workflows:

Cookie banner

A cookie banner can ask for consent.

Preference centre

A preference centre can allow users to modify choices.

GPC

GPC can communicate an applicable opt-out preference automatically.

CMP

A CMP can interpret and enforce these signals across the website.

Depending on the jurisdictions and processing activities involved, a website may need several of these mechanisms together.

GPC vs "Do Not Sell or Share My Personal Information"

A website subject to California's opt-out requirements may provide a "Do Not Sell or Share My Personal Information" link or another qualifying privacy-choice mechanism.

GPC provides another way for a user to communicate the relevant opt-out preference.

California's guidance explains that businesses subject to the applicable opt-out requirements must honor qualifying opt-out preference signals, while also generally providing consumers with a way to exercise the right directly on the website.

Therefore, GPC should be treated as part of a broader privacy-choice system rather than as a replacement for every other consumer-facing privacy mechanism.

GPC vs opt-out preference signals

Opt-out preference signal is the broader concept.

GPC is one example of a user-enabled signal that can communicate a privacy preference to websites.

The California Privacy Protection Agency uses the term opt-out preference signal (OOPS) for mechanisms that allow a consumer to communicate an opt-out request automatically.

How does a website detect GPC?

At the technical level, GPC can be communicated through web mechanisms including:

  • The Sec-GPC HTTP request header
  • The navigator.globalPrivacyControl browser property

The W3C GPC specification defines the signal and its use for communicating applicable opt-out preferences.

A privacy platform or CMP can inspect the incoming signal and translate it into an internal privacy state.

For example:

  1. GPC detected
  2. applicable opt-out preference recorded
  3. covered sale/sharing disabled
  4. relevant trackers and integrations updated

The exact enforcement behavior should depend on the applicable legal requirements and the business's privacy architecture.

Does GPC block cookies?

Not by itself.

GPC is a signal, not a universal tracker blocker.

Detecting GPC does not automatically guarantee that:

  • Every cookie is deleted
  • Every script is blocked
  • Every advertising platform stops processing data
  • Previously collected data is erased
  • All analytics are disabled
  • Every third-party request disappears

A website needs an enforcement layer that translates the GPC signal into appropriate technical actions.

For example, a CMP may use the signal to:

  • Disable advertising scripts
  • Prevent covered third-party sharing
  • Suppress advertising pixels
  • Update consent or privacy states
  • Restrict data sent to downstream vendors
  • Update a privacy preference centre
  • Maintain evidence of the request

Does GPC mean "do not track"?

Not exactly.

GPC is commonly described as a global opt-out mechanism, but it should not be treated as a generic "turn off every type of tracking" command.

The legal effect of GPC depends on the applicable law and the processing activity.

The W3C specification specifically notes that GPC is not designed to exercise every privacy right or every possible advertising opt-out.

This distinction is important because:

GPC ≠ universal deletion requestGPC ≠ universal cookie blockerGPC ≠ consent refusal for every processing purposeGPC ≠ complete privacy compliance

Does GPC apply under GDPR?

GPC is not inherently a substitute for GDPR consent.

The GPC specification describes potential use of the signal in GDPR contexts, including communicating certain requests concerning the sale or sharing of personal data and applicable rights. However, organizations should not assume that detecting GPC automatically satisfies every GDPR obligation or replaces the legal analysis required for a particular processing activity.

For GDPR-covered websites, businesses may still need mechanisms for:

  • Valid consent
  • Consent withdrawal
  • Prior consent where required
  • Cookie and tracker controls
  • Privacy notices
  • Data-subject rights
  • Lawful-basis management
  • Vendor management
  • Records of processing

GPC and US state privacy laws

GPC is increasingly relevant beyond California because several US state privacy laws include mechanisms for universal or opt-out preference signals.

However, the exact legal requirements differ by state.

A website operating across multiple US jurisdictions should therefore avoid implementing a simplistic rule such as:

"If GPC is present, block everything."

Instead, the website should use jurisdiction-aware rules that determine:

  • Which law applies
  • Which consumer right is being exercised
  • Which processing activities are covered
  • Which vendors or systems must be restricted
  • Whether additional user interaction is required
  • How the preference should be stored and honored

GPC and consent management platforms

A Consent Management Platform (CMP) can act as the enforcement layer between the GPC signal and a website's technology stack.

A typical flow is:

  1. Browser
  2. GPC signal
  3. CMP
  4. privacy rule engine
  5. trackers/vendors
  6. privacy state

A mature CMP should be able to:

  • Detect GPC
  • Determine applicable jurisdictional rules
  • Map GPC to the appropriate privacy state
  • Enforce the resulting preference
  • Prevent or restrict relevant trackers
  • Communicate the state to integrations
  • Provide preference-management controls
  • Maintain appropriate evidence

This makes GPC complementary to a CMP rather than an alternative to one.

GPC and third-party trackers

GPC becomes especially important when a website uses third-party technologies for:

  • Advertising
  • Retargeting
  • Audience creation
  • Social-media advertising
  • Cross-site analytics
  • Data enrichment
  • Marketing automation

Simply detecting GPC is not enough.

The website should verify that the relevant third-party technologies actually respond to the resulting privacy state.

For example, a business may detect GPC correctly but still send advertising identifiers to a third party. In that situation, the signal is being received but not effectively enforced.

GPC implementation checklist

Businesses implementing GPC should consider the following checklist:

1

Detect the signal

Confirm that the website can reliably identify incoming GPC preferences.

2

Determine the applicable law

Use jurisdiction and processing context to determine what the signal means for the visitor.

3

Map the signal to a privacy state

Define exactly what happens when GPC is present.

4

Stop applicable sale or sharing

Ensure covered data sharing and advertising activities are restricted as required.

5

Control third-party technologies

Review advertising, retargeting, analytics, social, and data-provider integrations.

6

Update the consent/privacy platform

Ensure the CMP or privacy preference centre reflects the user's state.

7

Preserve appropriate evidence

Maintain records that demonstrate how privacy preferences were detected and enforced where appropriate.

8

Test repeatedly

Test GPC with:

  • Advertising cookies
  • Marketing pixels
  • Analytics tags
  • Retargeting scripts
  • Third-party requests
  • Server-side integrations
  • Consent-management systems
9

Test across jurisdictions

Do not assume the same GPC behavior is legally appropriate for every visitor.

10

Keep privacy notices aligned

Your privacy policy and preference centre should accurately explain how opt-out requests are handled.

Common GPC implementation mistakes

Mistake 1

Detecting GPC but doing nothing

A signal that is merely logged but does not change the applicable privacy state does not provide meaningful enforcement.

Mistake 2

Treating GPC as a cookie blocker

GPC communicates a privacy preference. Your technology stack still needs to enforce the resulting preference.

Mistake 3

Treating GPC as universal consent refusal

GPC is not equivalent to rejecting every processing purpose.

Mistake 4

Ignoring third-party systems

Your first-party website may respond correctly while advertising and analytics vendors continue receiving covered information.

Mistake 5

Assuming one rule works everywhere

Privacy laws differ across jurisdictions. A global website needs rules that account for those differences.

Mistake 6

Removing the privacy-choice interface

GPC does not necessarily eliminate the need for other required consumer-facing privacy mechanisms.

Mistake 7

Failing to test after deployment

A CMP configuration can detect GPC while a tag manager, server-side integration, or vendor continues processing data incorrectly.

GPC and ConsentX

ConsentX can use GPC as part of a broader privacy-preference and consent-management workflow.

A practical ConsentX implementation can:

Detect GPC

Apply the corresponding visitor privacy state

Enforce applicable tracker and vendor rules

Coordinate GPC with regional privacy rules

Integrate with consent and preference management

Help prevent unauthorized advertising activity

Maintain consent and preference evidence

Provide an auditable privacy-management layer

The key principle is that GPC detection should lead to enforcement, not merely detection.

GPC vs CMP

GPCCMP
Communicates a user's privacy preferenceManages privacy preferences and consent
Browser/user-controlled signalWebsite-controlled software
Primarily communicates opt-out preferencesCan manage multiple consent and opt-out states
Works across participating websitesUsually configured for a specific website or organization
Does not enforce itselfCan enforce rules across tags and vendors
Does not replace all privacy rightsCan provide a broader privacy-management workflow

GPC and a CMP therefore work well together.

GPC vs Google Consent Mode

GPC and Google Consent Mode solve different problems.

GPC communicates a user's privacy preference to a website.

Google Consent Mode communicates relevant consent states to supported Google tags and services so their behavior can adjust according to those states.

A website can therefore use both:

  1. GPC
  2. CMP/privacy rules
  3. applicable privacy state
  4. Google Consent Mode and other vendor controls

This is particularly important for websites that operate advertising and analytics technologies across multiple jurisdictions.

Does GPC make a website privacy compliant?

No.

Implementing GPC is an important part of privacy compliance for businesses subject to laws that recognize applicable opt-out preference signals, but it does not by itself make a website compliant.

A complete privacy program may also require:

  • Appropriate consent mechanisms
  • Privacy notices
  • Cookie and tracker controls
  • Data-subject rights workflows
  • Vendor management
  • Data retention controls
  • Security measures
  • Data minimization
  • Records and evidence
  • Regional privacy rules
  • Consumer preference management

GPC should therefore be treated as one component of a broader privacy compliance architecture.

Key takeaways

  • Global Privacy Control (GPC) is a browser-level or browser-extension privacy signal.
  • It communicates an applicable opt-out preference to websites.
  • California recognizes qualifying GPC signals as valid opt-out requests under the CCPA framework.
  • GPC is particularly relevant to sale, sharing, and cross-context behavioral advertising.
  • GPC is not the same as cookie consent.
  • GPC does not automatically block every cookie or tracker.
  • GPC does not replace a CMP.
  • GPC does not exercise every possible privacy right.
  • Businesses should map GPC to jurisdiction-specific privacy rules and enforce the resulting state across relevant technologies.
  • Effective GPC compliance requires testing not only the signal itself but also downstream trackers, vendors, advertising systems, and data flows.
  • GPC is best implemented as part of a broader privacy and consent-management architecture.

Turn GPC detection into enforcement

The key principle is that GPC detection should lead to enforcement, not merely detection. ConsentX can use GPC as part of a broader privacy-preference and consent-management workflow: detecting the signal, applying the corresponding visitor privacy state, enforcing applicable tracker and vendor rules, and maintaining preference evidence.

Frequently asked questions