Policies

Global Privacy Control is the opt-out you cannot ignore

GPC is a browser signal that twelve US states require businesses to honor as an opt-out, and a broken opt-out is what regulators have fined.

Policies 5 min read The UserGuard team

Key takeaways
  • As of 2026, at least nineteen US states have comprehensive privacy laws in force, and twelve require businesses to honor universal opt-out mechanisms like GPC.
  • GPC arrives as the Sec-GPC: 1 request header and as navigator.globalPrivacyControl; honor either, and detect it before ad and analytics tags initialize.
  • US regulators have fined broken opt-out mechanisms, not missing cookie banners — Sephora paid $1.2 million in 2022 partly for failing to process GPC signals.

What the signal actually is

Global Privacy Control is a preference a browser sends on the user's behalf. No popup, no click on your site. The browser, extension, or mobile app announces on every request that this person opts out of the sale and sharing of their personal information. It is a standing instruction rather than a one-time form submission, and it travels with the visitor everywhere they go.

The important part is legal, not technical. Under California's regulations, a GPC signal is treated as a valid consumer opt-out request for businesses in scope. You do not get to ask the user to confirm it in a banner, and you do not get to weigh it against a cookie choice they made last month. It arrives as a request, and it counts as one.

This is where teams used to European rules get confused. GDPR and ePrivacy run on prior opt-in: nothing non-essential fires until someone agrees, and under EDPB and regulator guidance, refusing has to be as easy as agreeing. CCPA and CPRA run the other way. They are opt-out laws, not consent-banner laws: notice at collection, a working Do Not Sell or Share My Personal Information mechanism, and mandatory honoring of GPC. None of this is legal advice; your counsel should confirm your own scope.

How it reaches your site

There are two mechanisms and you should handle both. On the wire, the browser sends a request header, Sec-GPC: 1, with every HTTP request it makes to you. In the page, the same preference is exposed to JavaScript as navigator.globalPrivacyControl, which reads true. Treat either as authoritative. A visitor arriving with the header set has already opted out before your first byte of HTML renders.

Who sends it shapes your expectations. GPC ships on by default in some privacy-focused browsers, is an available setting in others, and is added by a range of browser extensions. Chrome does not send it out of the box. So the share of traffic carrying the signal looks small in most analytics dashboards, and that is exactly why the handling gets skipped until someone checks.

The trap is timing. Most tag setups read consent state after the page loads, then fire. If your GPC check happens after analytics and advertising tags have already initialized, you have shared data belonging to someone who opted out before they arrived. Server-side detection of the header, or a synchronous check before any tag boots, is the difference between honoring the signal and merely logging it.

The states that require honoring it

As of 2026, at least nineteen states have comprehensive privacy laws in force, and twelve of them require businesses to honor universal opt-out mechanisms like GPC. California was first and remains the loudest, but the obligation now spans Colorado, Connecticut, Texas, Oregon, Montana, and others. Indiana, Kentucky, and Rhode Island are among the newest comprehensive laws, which is a reminder that the map redraws every year.

The rules are not identical. Some states apply the opt-out to sale and targeted advertising, some extend it to profiling. Maryland went further than the rest and bans the sale of sensitive data outright, regardless of any signal or consent. Applicability thresholds differ too, so a business covered in one state may fall out of scope in another. Confirm your own exposure with counsel; this post is not legal advice.

One practical consequence: geography alone will not solve this. A visitor's state determines which law applies, but the signal arrives regardless of where they sit, and treating it as a global instruction is simpler than maintaining a dozen conditional carve-outs that drift out of date. The engineering cost of honoring GPC everywhere is close to zero. The cost of a wrong geo-fence is not.

Enforcement has followed a single pattern

US privacy enforcement has been narrower than people expect. Regulators have not gone after companies for the absence of a cookie banner. They have gone after companies whose opt-out did not work, and a broken GPC response is easy to prove, because an investigator can load your site with the signal switched on and watch the trackers fire anyway.

Sephora paid $1.2 million in 2022 for, among other things, failing to process GPC signals. Honda paid $632,500 in 2025 over opt-out flows that asked more of users than the law allows. Healthline paid $1.55 million in 2025 after continuing to share data with advertising partners following opt-outs. Todd Snyder paid $345,178 in 2025 for a banner that was simply misconfigured.

Read those together and the pattern is hard to miss. None of them turned on the prose in a privacy policy. They turned on a mechanism that was broken, asymmetric, or quietly ignored, and each of those failures surfaces in about thirty seconds of network inspection. GPC is among the cheapest items on that list to get right and the most conspicuous to get wrong.

What a site owner must wire up

Start by detecting the signal in both places, the Sec-GPC header on the request and navigator.globalPrivacyControl in the page, and treat either as an opt-out for sale and sharing. Then make sure that detection runs before your tags do. Then keep a record of what happened: which visit, which signal, which timestamp, and what your site actually did in response.

Reflect the state in the interface too. If GPC is on, your banner should not offer a fresh choice as though nothing happened, and your Do Not Sell or Share My Personal Information page should show the opt-out already applied. If you serve EEA or UK visitors through Google advertising or measurement, Consent Mode v2 has been required since March 2024, and its four signals, ad_storage, analytics_storage, ad_user_data, and ad_personalization, need to move in step.

UserGuard is built to detect GPC on every tier, with geo-targeting alongside it. Neither is paywalled, including on the $10 per site plan, because a compliance feature you have to upgrade for is one you will not have on the day it matters. Consent events are designed to be tied to site, banner version, region, and timestamp, and exported as CSV. UserGuard is newly launched. It is not a Google-certified CMP and not IAB TCF validated; TCF is roadmap, not shipped.

  • Detect Sec-GPC: 1 and navigator.globalPrivacyControl; honor either one
  • Suppress ad and analytics tags before they initialize, not after
  • Log the signal, timestamp, and resulting state, and be able to export it

Go deeper: GPC handling, on every tier · what each plan includes

Start today

Evidence from day one. Refundable for thirty.

Create an account, drop one script on a site, and the first scan verifies your cookies in minutes. Honest consent UX, consent analytics and accessibility controls, from $10 a site. Thirty days to get your money back if it is not right.

Get started 30-day money-back guarantee · cancel anytime