All Blog Posts

What Is Global Privacy Control (GPC)? Definition, Legal Status, Other Opt-Out Signals, and How to Comply

Close
Read time
10 mins
Updated
Jul 21, 2026
Share

Global Privacy Control (GPC) is a technical specification that lets users signal their opt-out of the sale or sharing of personal data to every website they visit, through a single browser-level setting rather than opting out site by site.

It's part of a broader shift in how personal data is collected, used, and sold online. Governments are introducing new regulations, large tech platforms are rolling out new policies, and individuals are demanding more control over their own data. GPC gives people a simpler way to exercise that control. For businesses, it isn't just a technical update: in some regions, honoring it is a legal requirement, and doing so visibly signals a commitment to privacy.

Here's what GPC is, how it differs from Do Not Track (DNT), and how your business can implement it.

This article has been reviewed by Cookiebot's data protection experts.

What Is Global Privacy Control (GPC)?

Global Privacy Control (GPC) is a privacy feature that enables users to send a clear signal to websites about their preference to opt in or out of having their personal data accessed, sold, or shared. It works through browsers or other devices and applies this preference to every site the user visits without requiring manual input each time.

The main purpose of GPC is to simplify how people manage their privacy online while enabling businesses to meet legal obligations under regulations like the California Consumer Privacy Act (CCPA) and the General Data Protection Regulation (GDPR). Unlike other tools that require users to interact with cookie banners on every site, GPC simplifies the process with a universal setting.

In addition to being user-friendly, GPC addresses growing concerns about data misuse. It’s designed to align with modern laws that prioritize user consent and transparency in data handling practices.

How is GPC Different from Do Not Track (DNT)?

Do Not Track (DNT) was an earlier attempt to create a standardized mechanism for users to opt out of tracking across websites. However, it didn’t work as planned because websites weren’t legally required to follow it. As a result, the effectiveness of DNT depended entirely on voluntary adoption, which was inconsistent at best.

GPC improves on DNT in several ways:

  • Legal backing: Unlike DNT, GPC is supported by more laws, like the CCPA, which requires businesses to honor these signals.
  • Targeted approach: While DNT broadly addressed tracking, GPC focuses specifically on stopping data from being sold or shared, making it more relevant to today’s privacy needs.
  • Better adoption potential: GPC was created with input from regulators, privacy advocates, and industry leaders, to align it with existing laws and address previous gaps in functionality.

How Does GPC Work?

At its core, when the user has set it up, GPC sends a signal from a user’s browser or device to websites, communicating that the user wants to opt out of data sharing or data selling. Businesses receiving this signal are required to comply if privacy laws in their jurisdiction recognize GPC as a valid opt-out mechanism.

How Does the GPC Signal Work?

The GPC signal operates behind the scenes. Once a user enables GPC in their browser or through an extension, it sends a small message to any websites that the user visits. This message, embedded in the HTTP headers or accessible via JavaScript, informs the site of this person’s data-sharing preference.

Here’s how it works step by step:

  1. User activation: The user turns on GPC in their browser or installs a compatible tool.
  2. Signal transmission: When the user visits a website, the GPC signal is sent automatically.
  3. Website response: The website detects the GPC signal and adjusts its behavior by disabling the sale or sharing of user data.
  4. Legal compliance: If the company running the website operates under laws like the CCPA, it must honor the signal and process the user’s data accordingly.

By automating the opt-out process, GPC reduces user frustration while keeping websites accountable to privacy regulation requirements.

GPC and Opt-Out Mechanisms

One of GPC’s most significant advantages is its ability to work seamlessly with opt-out requirements in privacy laws. Instead of requiring users to interact with multiple cookie banners, GPC applies a single preference across all compliant websites.

GPC also supports businesses by simplifying the process of handling opt-out requests. Rather than relying solely on cookie banners or manual opt-out forms, GPC enables websites to process user preferences automatically.

Browser / ExtensionNative GPC SupportOn By DefaultNotes
Google ChromeNot YetN/A- Must comply with California's Opt Me Out Act (AB 566) by January 1, 2027.
- Roughly 65% global market share, so this is the single biggest driver of future GPC traffic.
- Extensions can enable GPC in the meantime.
Mozilla FirefoxYesNo (user-enabled in settings)- Widely used by privacy-conscious visitors.
- Worth testing GPC handling specifically against Firefox traffic.
BraveYesYesGPC is on by default for every user, making Brave traffic effectively 100% GPC-enabled.
DuckDuckGo (browser)YesYesSame default-on behavior as Brave.
Microsoft EdgeNot YetN/A- Also subject to the AB 566 mandate by January 1, 2027.
- Extensions can enable GPC in the meantime.
Apple SafariNot YetN/A- No public commitment to native support beyond the AB 566 mandate.
- Extensions can enable GPC in the meantime.
Privacy Badger (extension)Adds GPCYes (once installed)Available for Chrome, Firefox, Edge, and other Chromium browsers.
DuckDuckGo Privacy Essentials (extension)Adds GPCYes (once installed)Available across Chrome, Firefox, Edge, and Safari.

Once Chrome and Edge ship native support ahead of the January 2027 mandate, GPC is set to become a default setting for a substantial share of all web traffic. In the meantime, businesses should expect GPC signals from Chrome and Edge visitors who've installed a compatible extension, even without native browser support.

Browser Support for GPC

Different browsers and extensions offer different levels of GPC support, which matters for both users and the businesses receiving their signals.


Is GPC Legally Required?

Privacy laws around the world are changing to better protect people's rights, and GPC is becoming a vital part of maintaining compliance. Here's how it aligns with major regulations. See the official GPC specification at globalprivacycontrol.org and the CPPA's enforcement guidance for complete requirements.

CCPA and Global Privacy Control

The CCPA/CPRA gives California residents the right to opt out of the sale of their personal information. The California Attorney General has explicitly stated that GPC is a valid method for users to exercise this right.

This means businesses operating in California must:

  • Detect and process GPC signals as opt-out requests
  • Avoid selling or sharing data for users who have sent a GPC signal
  • Update their CCPA privacy policies to reflect how they handle GPC requests

Failure to honor GPC under the CCPA/CPRA could result in penalties, including fines or legal action.

New in 2026: The Opt-Out Confirmation Requirement

California's updated CCPA regulations are effective January 1, 2026, and go beyond requiring businesses to process GPC signals. Businesses must now visibly confirm to users that their opt-out has been honored. The California Privacy Protection Agency (CPPA) explicitly cites displaying "Opt-Out Request Honored" as a compliant method.

Cookiebot™ CMP handles this automatically. When a visitor arrives with GPC enabled, the banner is suppressed and visible confirmation is displayed to the user. There is no additional configuration required.

In addition to California, Colorado (CPA) and Connecticut (CTDPA) require businesses to recognize GPC as a valid opt-out signal. Cookiebot CMP supports GPC detection across all major U.S. state privacy laws. In September 2025, the CPPA announced a joint enforcement sweept with Colorado and Connecticut targeting GPC non-compliance.

Which States Require Businesses to Honor GPC?

Beyond California, several U.S. states have enacted privacy laws that emphasize consumer rights and data protection. These are the states that currently require recognizing GPC or a comparable universal opt-out mechanism.

U.S. StateGPC Recognition Required?Privacy RegulationEffective Date
AlabamaNoAPDPAMay 1, 2027
ArkansasNoAPDPAJuly 1, 2025
CaliforniaYesCCPA/CPRAJanuary 1, 2023 (CPRA amendments)
ColoradoYesCPAJuly 1, 2024
ConnecticutYesCTDPAJanuary 1, 2025
DelawareYesDPDPAJanuary 1, 2025
IndianaNoICDPAJanuary 1, 2026
IowaNoICDPAJanuary 1, 2025
KentuckyNoKCPDAJanuary 1, 2026
LouisianaNoLDPAJanuary 1, 2027
MarylandYesMODPAApril 1, 2026
MinnesotaYesMNCDPAJanuary 1, 2025
MontanaYesMCDPAJanuary 1, 2025
NebraskaYes (Applies only where the controller is already required to honor UOOMs under another state's law, not as a freestanding obligation.)NDPAJuly 15, 2025
New HampshireYesNHDPAJanuary 1, 2026
New JerseyYesNJDPAJanuary 1, 2025
OklahomaYesOCDPAJanuary 1, 2026
OregonYesOCPAJanuary 1, 2025
Rhode IslandNoRIDTPPAJanuary 1, 2026
TennesseeNoTIPAJanuary 1, 2025
TexasYesTDPSAJanuary 1, 2025
UtahNoUCPADecember 31, 2023
VermontYesVDPOSAJanuary 1, 2028
VirginiaNoVCDPAJanuary 1, 2023

The remaining 26 U.S. states have not yet enacted a comprehensive privacy law, so GPC recognition isn't a legal requirement for visitors from those states. Many businesses choose to honor GPC everywhere regardless, since doing so satisfies every state that does require it without needing to vary behavior by visitor location.

Many of these laws also include provisions for consumer rights to opt out of data processing for targeted advertising, data sales, or profiling. While not all explicitly reference GPC, the mechanism supports the broader intent of these regulations by offering an easy and standardized way for visitors to exercise their rights. Businesses operating in these states should:

  • Monitor emerging privacy legislation and its compatibility with GPC
  • Detect and honor GPC signals as an additional method to respect user preferences
  • Update data processing systems and privacy notices to reflect obligations across jurisdictions

GDPR and Global Privacy Control

While the GDPR doesn’t specifically mention GPC, its principles align with the initiative. The GDPR emphasizes visitor consent and the right to object to data processing, both of which are supported by GPC.

For businesses in the European Union, respecting GPC signals can:

  • Show compliance with the GDPR’s data subject rights
  • Promote transparency and increase trust between companies and their website visitors
  • Demonstrate a proactive approach to privacy to reduce the risk of non-compliance penalties

By adopting the GPC, businesses operating under the GDPR can position themselves as leaders in privacy-first practices.

Your 8-Step GPC Compliance Support Checklist

To stay compliant with GPC requirements and protect user privacy, businesses should follow specific steps in their data collection and management practices. Below is a concise checklist to guide you through the process of GPC implementation and ongoing compliance.

1. Implement the GPC Specification

Add the GPC code to the back-end systems of your website and apps to enable your data collection processes to be privacy-compliant with this requirement. It is also essential that your systems are capable of detecting and processing GPC signals to respect user preferences.

2. Update Privacy Policies

Your privacy policy should clearly communicate how you handle GPC or comparable signals, including the impact they will have on your data collection and usage. Additionally, make sure your policy aligns with relevant privacy laws such as the CCPA/CPRA and the GDPR to remain compliant with global privacy standards.

3. Provide Multiple Opt-Out Methods

Offer at least two ways for visitors to opt out of data sharing, with one of those options being the GPC signal. If required to comply with California privacy laws, make sure to include a visible "Do Not Sell or Share My Personal Information" link on your website or mobile app to provide an easy opt-out choice for visitors.

4. Honor GPC Signals

Make sure your systems are configured to treat GPC requests as valid opt-out signals. You must also block all third-party data-sharing channels for visitors who have GPC enabled, including scripts, tags, pixels, and cookies.

5. Test Implementation

Verify that your website is correctly responding to GPC signals from various browsers and extensions. It’s important to conduct regular testing to confirm that your systems are in compliance.

Integrate GPC signals into your consent management platform (CMP) and tag management system (TMS) to streamline your data handling processes. Additionally, confirm that your TMS, like Google Tag Manager, is configured to fire tags based on the browser's GPC setting, so user preferences are automatically respected.

7. Audit Data Practices

Conduct a comprehensive audit of your current data collection, handling, and sharing practices. Identify areas where GPC will affect how you collect, use, and sell consumer data to make all necessary adjustments.

8. Document Your Compliance Efforts

Keep detailed records of your GPC implementation and compliance activities. This documentation will be crucial if regulators request proof of compliance, you receive data subject access requests, or if you need to demonstrate your efforts in an audit.

What Happens if You're Not Compliant with Global Privacy Control?

Failing to comply with global privacy control exposes businesses to several risks.  

  • Regulatory risks: While GPC isn’t mandatory everywhere, regulators like the California Attorney General suggest honoring GPC signals to comply with the CCPA/CPRA. 
  • Financial risks: Although there are no direct penalties for ignoring GPC, violations of broader privacy laws like the GDPR can lead to fines of up to EUR 20 million or 4 percent of global revenue. Ignoring privacy preferences can result in costly legal challenges.  
  • Reputational risks: Consumers value privacy and lose trust in companies that disregard their choices. This can lead to lost customers and negative publicity.  

On the upside, adopting GPC demonstrates a commitment to privacy, builds trust with customers, and positions your business well as privacy laws evolve.

How to implement GPC support with Cookiebot™ CMP

Cookiebot CMP automatically detects and honours GPC signals for visitors from states where GPC recognition is legally required, including California, Colorado, and Connecticut. When a visitor arrives with GPC enabled, the CMP suppresses the banner, honors the opt-out, and displays visible confirmation to the visitor. Your site can meet California's 2026 CCPA requirements with no extra setup.

Frequently asked questions

Global Privacy Control (GPC) is a tech and tech initiative and a browser-based mechanism that enables users to automatically communicate their privacy preferences to websites, such as opting out of data sharing or selling.

A GPC signal is a browser-based mechanism that automatically communicates privacy preferences that users have set to websites they visit, indicating their desire to opt out of data sharing and sales. When enabled, it acts like an automated "Do Not Sell Or Share My Personal Information" request, enabling users to exercise their privacy rights across multiple websites without having to manually configure settings on each one.

You have two options to enable GPC. You can use a browser that has built-in GPC support, such as Firefox, Brave, or DuckDuckGo. Alternatively, you can install browser extensions like Privacy Badger, Disconnect, or OptMeowt, which add GPC functionality to browsers that don't natively support it, like Google Chrome or Apple Safari.

To disable Global Privacy Control (GPC), turn off the GPC signal in your browser settings or browser extension that supports it. You can also clear your cookies and cache, then refresh the page to reset your privacy preferences.

Global opt-outs in GPC are browser-based signals that automatically communicate a user's preference to opt out of data sharing and sales across multiple websites. These universal opt-out mechanisms allow users to set their privacy preferences once, which are then automatically applied to all websites that support GPC.