What is Global Privacy Control (GPC)?
GPC is designed to let people communicate an opt-out preference automatically instead of submitting the same request individually on every website. The signal can be transmitted to websites through technical mechanisms such as an HTTP request header and browser APIs.
Under the California Consumer Privacy Act (CCPA), a qualifying user-enabled opt-out preference signal such as GPC must be honored by covered businesses as a valid request to opt out of the sale or sharing of personal information.
What does Global Privacy Control mean?
Global Privacy Control is a privacy preference signal that allows a user to communicate an opt-out choice across websites.
Instead of visiting a website, finding its privacy settings, and manually selecting an opt-out option, a user can enable GPC in a supported browser or privacy extension. Participating websites can detect the signal and apply the relevant privacy preference.
The GPC specification is intended to make privacy rights easier to exercise at scale. The current W3C specification describes GPC as a signal that communicates a person's request not to sell or share their personal information and, where applicable, to opt out of cross-context targeted advertising.
GPC is also known as
How does GPC work?
A simplified GPC flow looks like this:
Enable
The user enables GPC in a supported browser, browser extension, or privacy tool.
Communicate
The browser communicates the preference to websites the user visits.
Detect
The website detects the GPC signal.
Determine
The website determines which legal obligations apply based on the user's context and applicable privacy laws.
Apply
The website applies the corresponding opt-out preference, such as disabling covered sale or sharing.
Propagate
Downstream systems and third parties should receive the appropriate updated privacy state.
Record
The business records or otherwise maintains appropriate evidence of how the request was handled, where required by its compliance program.
GPC is therefore more than a visual privacy setting. It is a machine-readable way to communicate a user's privacy preference to websites.
What does the GPC signal actually tell a website?
GPC generally communicates an opt-out preference. It is not a complete statement of every privacy right a user may have.
The W3C specification specifically distinguishes GPC from other privacy rights. For example, GPC is not designed to exercise deletion rights or every possible advertising opt-out or data-processing right.
A business should therefore avoid interpreting GPC as:
"The user has rejected every form of data processing."
Instead, the business should map the signal to the rights and processing activities covered by the applicable law.
GPC and the CCPA
GPC has a particularly important role under the California Consumer Privacy Act (CCPA).
California recognizes a user-enabled global privacy control as one method for consumers to submit a request to opt out of the sale or sharing of personal information. Covered businesses must honor qualifying opt-out preference signals as valid requests.
This is especially relevant to businesses whose processing involves:
- Sale of personal information
- Sharing of personal information
- Cross-context behavioral advertising
- Third-party advertising technology
- Certain online tracking and advertising activities
The California Privacy Protection Agency also describes opt-out preference signals as a way for users to automatically communicate an opt-out request through a browser setting or extension.
Is GPC required under CCPA?
For businesses covered by the applicable CCPA opt-out requirements, a qualifying GPC or other valid opt-out preference signal must be honored when it meets the applicable requirements.
This does not mean that every website in every jurisdiction must implement GPC in exactly the same way.
The legal requirement depends on factors such as:
- Whether the business is subject to the relevant privacy law
- Whether the business engages in activities covered by the opt-out right
- The user's jurisdiction and applicable law
- Whether the signal satisfies the applicable legal requirements
- Whether the signal is being used for the purpose recognized by that law
For California businesses and consumers, however, GPC is an important technical mechanism for exercising the CCPA right to opt out of sale or sharing.
GPC and CPRA
The California Privacy Rights Act (CPRA) amended the CCPA and expanded California privacy protections.
The CPRA did not create a completely separate privacy law from the CCPA. Instead, it amended the existing CCPA framework and added additional rights and requirements.
GPC is relevant to the CCPA/CPRA opt-out framework because California recognizes qualifying opt-out preference signals as a mechanism for communicating a consumer's request to opt out of sale or sharing.
GPC and cross-context behavioral advertising
GPC is particularly relevant to cross-context behavioral advertising.
Cross-context behavioral advertising generally involves using personal information obtained from a consumer's activity across businesses, websites, applications, or other contexts to target advertising.
Under California privacy rules, consumers have a right to opt out of the sale or sharing of personal information, including sharing associated with cross-context behavioral advertising.
A compliant implementation should therefore consider how a GPC signal affects:
- Advertising pixels
- Retargeting systems
- Social-media advertising tags
- Audience-building tools
- Third-party advertising platforms
- Cross-site identifiers
- Advertising cookies
- Data sharing with advertising partners
Does GPC replace a cookie banner?
No.
GPC does not automatically replace a consent banner.
A cookie banner and GPC address different privacy workflows:
Cookie banner
A cookie banner can ask for consent.
Preference centre
A preference centre can allow users to modify choices.
GPC
GPC can communicate an applicable opt-out preference automatically.
CMP
A CMP can interpret and enforce these signals across the website.
Depending on the jurisdictions and processing activities involved, a website may need several of these mechanisms together.
GPC vs "Do Not Sell or Share My Personal Information"
A website subject to California's opt-out requirements may provide a "Do Not Sell or Share My Personal Information" link or another qualifying privacy-choice mechanism.
GPC provides another way for a user to communicate the relevant opt-out preference.
California's guidance explains that businesses subject to the applicable opt-out requirements must honor qualifying opt-out preference signals, while also generally providing consumers with a way to exercise the right directly on the website.
Therefore, GPC should be treated as part of a broader privacy-choice system rather than as a replacement for every other consumer-facing privacy mechanism.
GPC vs opt-out preference signals
Opt-out preference signal is the broader concept.
GPC is one example of a user-enabled signal that can communicate a privacy preference to websites.
The California Privacy Protection Agency uses the term opt-out preference signal (OOPS) for mechanisms that allow a consumer to communicate an opt-out request automatically.
How does a website detect GPC?
At the technical level, GPC can be communicated through web mechanisms including:
- The Sec-GPC HTTP request header
- The navigator.globalPrivacyControl browser property
The W3C GPC specification defines the signal and its use for communicating applicable opt-out preferences.
A privacy platform or CMP can inspect the incoming signal and translate it into an internal privacy state.
For example:
- GPC detected
- applicable opt-out preference recorded
- covered sale/sharing disabled
- relevant trackers and integrations updated
The exact enforcement behavior should depend on the applicable legal requirements and the business's privacy architecture.
Does GPC block cookies?
Not by itself.
GPC is a signal, not a universal tracker blocker.
Detecting GPC does not automatically guarantee that:
- Every cookie is deleted
- Every script is blocked
- Every advertising platform stops processing data
- Previously collected data is erased
- All analytics are disabled
- Every third-party request disappears
A website needs an enforcement layer that translates the GPC signal into appropriate technical actions.
For example, a CMP may use the signal to:
- Disable advertising scripts
- Prevent covered third-party sharing
- Suppress advertising pixels
- Update consent or privacy states
- Restrict data sent to downstream vendors
- Update a privacy preference centre
- Maintain evidence of the request
Does GPC mean "do not track"?
Not exactly.
GPC is commonly described as a global opt-out mechanism, but it should not be treated as a generic "turn off every type of tracking" command.
The legal effect of GPC depends on the applicable law and the processing activity.
The W3C specification specifically notes that GPC is not designed to exercise every privacy right or every possible advertising opt-out.
This distinction is important because:
Does GPC apply under GDPR?
GPC is not inherently a substitute for GDPR consent.
The GPC specification describes potential use of the signal in GDPR contexts, including communicating certain requests concerning the sale or sharing of personal data and applicable rights. However, organizations should not assume that detecting GPC automatically satisfies every GDPR obligation or replaces the legal analysis required for a particular processing activity.
For GDPR-covered websites, businesses may still need mechanisms for:
- Valid consent
- Consent withdrawal
- Prior consent where required
- Cookie and tracker controls
- Privacy notices
- Data-subject rights
- Lawful-basis management
- Vendor management
- Records of processing
GPC and US state privacy laws
GPC is increasingly relevant beyond California because several US state privacy laws include mechanisms for universal or opt-out preference signals.
However, the exact legal requirements differ by state.
A website operating across multiple US jurisdictions should therefore avoid implementing a simplistic rule such as:
"If GPC is present, block everything."
Instead, the website should use jurisdiction-aware rules that determine:
- Which law applies
- Which consumer right is being exercised
- Which processing activities are covered
- Which vendors or systems must be restricted
- Whether additional user interaction is required
- How the preference should be stored and honored
GPC and consent management platforms
A Consent Management Platform (CMP) can act as the enforcement layer between the GPC signal and a website's technology stack.
A typical flow is:
- Browser
- GPC signal
- CMP
- privacy rule engine
- trackers/vendors
- privacy state
A mature CMP should be able to:
- Detect GPC
- Determine applicable jurisdictional rules
- Map GPC to the appropriate privacy state
- Enforce the resulting preference
- Prevent or restrict relevant trackers
- Communicate the state to integrations
- Provide preference-management controls
- Maintain appropriate evidence
This makes GPC complementary to a CMP rather than an alternative to one.
GPC and third-party trackers
GPC becomes especially important when a website uses third-party technologies for:
- Advertising
- Retargeting
- Audience creation
- Social-media advertising
- Cross-site analytics
- Data enrichment
- Marketing automation
Simply detecting GPC is not enough.
The website should verify that the relevant third-party technologies actually respond to the resulting privacy state.
For example, a business may detect GPC correctly but still send advertising identifiers to a third party. In that situation, the signal is being received but not effectively enforced.
GPC implementation checklist
Businesses implementing GPC should consider the following checklist:
Detect the signal
Confirm that the website can reliably identify incoming GPC preferences.
Determine the applicable law
Use jurisdiction and processing context to determine what the signal means for the visitor.
Map the signal to a privacy state
Define exactly what happens when GPC is present.
Stop applicable sale or sharing
Ensure covered data sharing and advertising activities are restricted as required.
Control third-party technologies
Review advertising, retargeting, analytics, social, and data-provider integrations.
Update the consent/privacy platform
Ensure the CMP or privacy preference centre reflects the user's state.
Preserve appropriate evidence
Maintain records that demonstrate how privacy preferences were detected and enforced where appropriate.
Test repeatedly
Test GPC with:
- Advertising cookies
- Marketing pixels
- Analytics tags
- Retargeting scripts
- Third-party requests
- Server-side integrations
- Consent-management systems
Test across jurisdictions
Do not assume the same GPC behavior is legally appropriate for every visitor.
Keep privacy notices aligned
Your privacy policy and preference centre should accurately explain how opt-out requests are handled.
Common GPC implementation mistakes
Detecting GPC but doing nothing
A signal that is merely logged but does not change the applicable privacy state does not provide meaningful enforcement.
Treating GPC as a cookie blocker
GPC communicates a privacy preference. Your technology stack still needs to enforce the resulting preference.
Treating GPC as universal consent refusal
GPC is not equivalent to rejecting every processing purpose.
Ignoring third-party systems
Your first-party website may respond correctly while advertising and analytics vendors continue receiving covered information.
Assuming one rule works everywhere
Privacy laws differ across jurisdictions. A global website needs rules that account for those differences.
Removing the privacy-choice interface
GPC does not necessarily eliminate the need for other required consumer-facing privacy mechanisms.
Failing to test after deployment
A CMP configuration can detect GPC while a tag manager, server-side integration, or vendor continues processing data incorrectly.
GPC and ConsentX
ConsentX can use GPC as part of a broader privacy-preference and consent-management workflow.
A practical ConsentX implementation can:
Detect GPC
Apply the corresponding visitor privacy state
Enforce applicable tracker and vendor rules
Coordinate GPC with regional privacy rules
Integrate with consent and preference management
Help prevent unauthorized advertising activity
Maintain consent and preference evidence
Provide an auditable privacy-management layer
The key principle is that GPC detection should lead to enforcement, not merely detection.
GPC vs CMP
| GPC | CMP |
|---|---|
| Communicates a user's privacy preference | Manages privacy preferences and consent |
| Browser/user-controlled signal | Website-controlled software |
| Primarily communicates opt-out preferences | Can manage multiple consent and opt-out states |
| Works across participating websites | Usually configured for a specific website or organization |
| Does not enforce itself | Can enforce rules across tags and vendors |
| Does not replace all privacy rights | Can provide a broader privacy-management workflow |
GPC and a CMP therefore work well together.
GPC vs Google Consent Mode
GPC and Google Consent Mode solve different problems.
GPC communicates a user's privacy preference to a website.
Google Consent Mode communicates relevant consent states to supported Google tags and services so their behavior can adjust according to those states.
A website can therefore use both:
- GPC
- CMP/privacy rules
- applicable privacy state
- Google Consent Mode and other vendor controls
This is particularly important for websites that operate advertising and analytics technologies across multiple jurisdictions.
Does GPC make a website privacy compliant?
No.
Implementing GPC is an important part of privacy compliance for businesses subject to laws that recognize applicable opt-out preference signals, but it does not by itself make a website compliant.
A complete privacy program may also require:
- Appropriate consent mechanisms
- Privacy notices
- Cookie and tracker controls
- Data-subject rights workflows
- Vendor management
- Data retention controls
- Security measures
- Data minimization
- Records and evidence
- Regional privacy rules
- Consumer preference management
GPC should therefore be treated as one component of a broader privacy compliance architecture.
Key takeaways
- Global Privacy Control (GPC) is a browser-level or browser-extension privacy signal.
- It communicates an applicable opt-out preference to websites.
- California recognizes qualifying GPC signals as valid opt-out requests under the CCPA framework.
- GPC is particularly relevant to sale, sharing, and cross-context behavioral advertising.
- GPC is not the same as cookie consent.
- GPC does not automatically block every cookie or tracker.
- GPC does not replace a CMP.
- GPC does not exercise every possible privacy right.
- Businesses should map GPC to jurisdiction-specific privacy rules and enforce the resulting state across relevant technologies.
- Effective GPC compliance requires testing not only the signal itself but also downstream trackers, vendors, advertising systems, and data flows.
- GPC is best implemented as part of a broader privacy and consent-management architecture.
Turn GPC detection into enforcement
The key principle is that GPC detection should lead to enforcement, not merely detection. ConsentX can use GPC as part of a broader privacy-preference and consent-management workflow: detecting the signal, applying the corresponding visitor privacy state, enforcing applicable tracker and vendor rules, and maintaining preference evidence.
Related terms
California privacy framework governing consumer privacy rights, including opt-out rights.
A technical mechanism for communicating a consumer's opt-out preference.
Advertising based on personal information obtained from activity across businesses or contexts.
Software used to manage consent and privacy preferences.
The process of obtaining and managing user choices regarding cookies and related technologies.
Obtaining required consent before activating applicable non-essential processing or trackers.
Google's framework for communicating relevant consent states to supported Google tags.
A California privacy-choice mechanism associated with the CCPA opt-out right.
An interface through which users can review or change applicable privacy choices.