Global Privacy Control: Purpose, Fines, and How to Test It
Osman Husain
Last verified: September 29, 2026.
Global Privacy Control (GPC) is a signal that conveys a person's request that websites not sell or share their personal information. Whether a business has to honor GPC depends on the state, and state laws differ in how directly they say so.
Browsers and browser extensions send the signal automatically, so a person sets it once instead of opting out site by site.
History of the Global Privacy Control
Global Privacy Control (GPC) started in 2020 as a way for people to tell websites not to sell or share their data from one browser setting, instead of opting out site by site.
An earlier project titled the Do Not Track signal stalled due to a lack of enforcement. The GPC was meant to address that gap and give people a way to exercise opt-out rights granted to them from the California Consumer Privacy Act (CCPA)
Researchers, publishers, and devs launched the GPC on October 7, 2020.
How does GPC work?
Global Privacy Control works through one HTTP header and one JavaScript property, both provided whenever a person turns the setting on. The header is a piece of information a browser sends with each page request: Sec-GPC: 1. Its only valid value is 1, and a browser that follows the specification never sends Sec-GPC: 0. With GPC off, it sends no header at all.
The same preference is available as a JavaScript property, navigator.globalPrivacyControl, a read-only value that page scripts can check for when GPC is turned on. The World Wide Web Consortium (W3C) specification defines both.
As of September 2026, GPC is a W3C Working Draft, not a finished standard. The W3C's Privacy Working Group published the latest draft on September 24, 2026, and the document says it may be updated or replaced at any time.
The GPC project credits Ashkan Soltani, then at Georgetown Law, and Sebastian Zimmeck of Wesleyan University with leading the early work. Mozilla, DuckDuckGo, and other privacy advocates are notable partners of the project.
The request the GPC header script carries is specific. It asks that data not be sold to or shared with anyone other than the party the person intends to interact with, or used to target ads across sites. It isn't a request to delete data, because the specification says GPC isn't designed for deletion rights.
Laws use different names for this kind of signal. California's regulations call it an opt-out preference signal, and Colorado's statute calls it a universal opt-out mechanism. Colorado's Attorney General's recognized list names GPC.
The specification also gives websites a way to announce support: a small file at /.well-known/gpc.json with two fields, gpc and lastUpdate. Publishing it is optional.
A gpc value of true states that the site intends to honor GPC as far as the law requires. It doesn't prove the site does what it says. In a 2025 study of 11,708 websites, fewer than 200 sites published the file in each of three crawls run from December 2023 to April 2024.
The specification puts no duty on websites to honor the signal; the GPC project says it creates no legally binding obligations.

How do you turn Global Privacy Control on or off?
People turn Global Privacy Control on in the privacy settings of a browser that supports it, or by installing an extension in a browser that doesn't. They turn it off in the same setting, or by removing the extension.
Privacy Badger is a popular Chrome extension that can help manage GPC settings.
| Browser | Built-in support | Default | Where to switch it |
|---|---|---|---|
| Firefox on desktop | Yes, since Firefox 120 | Off in normal windows, on in Private Windows | Settings > Privacy & Security > Additional protections > Tell websites not to sell or share my data. See Mozilla's guide |
| Firefox for Android | Yes, since version 122 | On in private browsing | Menu > Settings > Privacy and Security > Enhanced Tracking Protection > Tell websites not to share & sell data. See Mozilla's Android guide |
| Brave | Yes | On by default on desktop and Android | A browser flag on desktop and Android. On iOS, Brave sets the JavaScript property but sends no header. See Brave's help page |
| DuckDuckGo browsers and extensions | Yes | On by default | DuckDuckGo's GPC help page states the default and gives no steps |
| Chrome | No built-in setting | Not applicable | An extension such as Privacy Badger or the DuckDuckGo extension. Chrome on Android doesn't support extensions |
| Edge and Opera | No built-in setting | Not applicable | The same extensions, which both list Edge and Opera |
| Safari | No user setting | Not applicable | None. Safari 27 added a way for apps that embed Safari's engine to turn GPC on, described in the release notes |
Brave's switch is a browser flag, brave://flags/#brave-global-privacy-control-enabled, rather than a normal settings toggle.
DuckDuckGo's default doesn't mean the header reaches every site. Its iPhone, iPad, Android, and Mac apps send the header only to sites known to respect GPC. Its Windows app and browser extensions send both the header and the JavaScript property, and DuckDuckGo turns GPC off on some sites so they keep working.
Which US states require businesses to honor Global Privacy Control?
California, Colorado, Connecticut, Delaware, Minnesota, Montana, New Hampshire, and Oregon direct businesses to honor an opt-out signal such as GPC in their statute or regulation text. Other states reach the signal indirectly.
Texas and Nebraska reach signals only through their authorized-agent rules, which let a consumer designate an agent to opt out on their behalf. Maryland lets a business offer either a signal or a link. The August 2026 board briefing from the California Privacy Protection Agency (CPPA) counts at least a dozen states. That adds Maryland, Nebraska, New Jersey, and Texas to the states named above.
Most of these laws use the word controller for a covered business: the business that decides how personal data is used.
| Group | State | What the law says | Effective date |
|---|---|---|---|
| Required in the text | California | Businesses that sell or share personal information must treat a qualifying opt-out preference signal as a valid opt-out under Regulation 7025 | Current text effective January 1, 2026 |
| Required in the text | Colorado | Controllers must allow opt-outs through a user-selected universal opt-out mechanism under C.R.S. 6-1-1306. The Attorney General's recognized list has one entry, GPC | July 1, 2024 |
| Required in the text | Connecticut | Controllers must allow opt-outs through a signal under C.G.S. 42-520 | January 1, 2025 |
| Required in the text | Delaware | Controllers must allow opt-outs through a signal under 6 Del. C. 12D-106 | January 1, 2026 |
| Required in the text | Minnesota | Controllers must allow opt-outs through a signal under Minn. Stat. 325M.14 | July 31, 2025 |
| Required in the text | Montana | Controllers must allow opt-outs through a signal under MCA 30-14-2809 | January 1, 2025 |
| Required in the text | New Hampshire | Controllers must allow opt-outs through a signal under RSA 507-H:6 | January 1, 2025 |
| Required in the text | Oregon | Controllers must allow a consumer or authorized agent to send a signal under ORS 646A.578 | January 1, 2026 |
| Via authorized agent | Texas | A controller must honor an opt-out sent by an authorized agent through a browser or global device setting if it can verify the consumer and the agent's authority. Section 541.055 lists four exceptions, such as an unclear request or a residency the controller can't verify, and never uses the word signal | January 1, 2025 |
| Via authorized agent | Nebraska | The same authorized-agent route under LB 1074, with the same four exceptions | January 1, 2025 |
| One allowed method | Maryland | A controller may offer a link or a signal under Senate Bill 541 | October 1, 2025 |
| Rules proposed | New Jersey | The Attorney General proposed rules to frame universal opt-out mechanisms | Proposed June 2, 2025 |
| Not required | Alabama | House Bill 351 creates no signal method | May 1, 2027 |
| Coming | Louisiana | Act 502 uses Texas's authorized-agent wording | January 1, 2027 |
| Coming | Vermont | Controllers must allow opt-outs through a signal under Act 145 | January 1, 2028 |
Several of these laws describe the signal as one sent with the consumer's consent. Enzuzo's US state privacy law tracker has more details.
California also regulates the browsers that send the signal. From January 1, 2027, the Opt Me Out Act requires browser makers to include a setting that lets consumers send an opt-out preference signal. That duty falls on browser developers; website duties come from California's regulations.

Business obligations under the Global Privacy Control
Under the regulations of the California Consumer Privacy Act (CCPA), a business that sells or shares personal information and collects it online must treat a qualifying opt-out preference signal as a valid opt-out request. GPC qualifies as an opt-out preference signal.
CCPA regulations set six duties:
- The opt-out covers the browser or device that sent the signal and any profile tied to it, including profiles that use an ID instead of a name. If the business knows who the consumer is, it covers the consumer too.
- A business can't require extra information or a verifiable consumer request before honoring the signal.
- The CPPA's briefing says a business that knows a consumer must apply the signal to all personal information tied to the account.
- The business must act on an opt-out as soon as feasibly possible, and no later than 15 business days after receiving it.
- If the signal conflicts with a setting the consumer made with that business that allows sale or sharing, the business must process the signal. It may tell the consumer about the conflict and offer a chance to consent.
- A business must show whether it processed the signal, for example with a notice that the opt-out preference signal was honored.
Colorado's statute has a similar conflict rule: a controller may invite a consumer to consent after a clear notice, and that consent takes precedence over the signal.
California's statute lets a business choose between honoring a signal and posting the Do Not Sell or Share link, but under the regulation the link is never enough on its own. A business that posts the link must also process the signal. A business that processes the signal in the regulation's frictionless manner may omit the link.
California's Attorney General's GPC page puts the duty on covered businesses: those that sell or share personal information must honor GPC as a valid request to stop doing so. A business that doesn't sell or share personal information doesn't have to process the signal.
A business that ignores the signal faces California's penalties: up to $2,500 per violation and $7,500 per intentional violation. Inflation adjustments put those figures at $2,663 and $7,988, respectively.
Global Privacy Control enforcement and fines
California enforcement actions show three ways businesses have failed to honor Global Privacy Control: ignoring the signal, applying it to one device only, and leaving cookie trackers running. The actions run from Sephora in 2022 to Disney and PlayOn Sports in 2026.
| Case | Regulator and date | Penalty | What the order or complaint says about signals |
|---|---|---|---|
| Sephora | California Attorney General, August 2022 | $1.2 million | The complaint alleged three violations, and one was that the site was not configured to detect or process any global privacy control signals. Testing found turning GPC on changed nothing. The CPPA's briefing calls it the Attorney General's first CCPA settlement |
| Todd Snyder | CPPA, order May 2025 | $345,178 | For 40 days from late 2023 the cookie banner flashed and vanished, so consumers couldn't opt out, and signals such as GPC were not processed |
| Healthline Media | California Attorney General, July 2025 | $1.55 million | By Healthline's own count, about 65,000 Californians had opted out, mainly using GPC. Investigators still found 118 cookies associated with third-party advertising companies after the opt-out form, GPC, and the banner were all used |
| Tractor Supply | CPPA, order September 2025 | $1,350,000 | The order says the site didn't honor opt-out preference signals until July 2024 |
| Disney | California Attorney General, February 2026 | $2.75 million | Disney applied a GPC opt-out only to the device that sent it, even for logged-in users. The judgment requires the opt-out to apply across all Disney streaming services tied to the account |
| PlayOn Sports | CPPA, order February 2026 | $1,100,000 | The CPPA found PlayOn failed to configure its properties to recognize and honor opt-out preference signals in 2023 and 2024. It updated its site in December 2024, before the CPPA's Enforcement Division contacted it |
Two other CPPA orders require GPC handling as a fix, without finding that either company ignored the signal. The Honda order requires Honda to apply GPC to consumers it can identify. The Ford order requires Ford to audit its site's cookies, web beacons, and pixels for signals such as GPC. The order also requires written confirmation within 90 days of its effective date.
Investigations continue past these orders. In September 2025, California's Attorney General and the CPPA, with the Colorado and Connecticut attorneys general, announced a joint sweep of businesses that appear not to process GPC opt-outs. No company names or outcomes have been published, and Connecticut described the matters as ongoing in February 2026.

How many websites honor Global Privacy Control, and how many people use it?
It's estimated that anywhere between 40 million to 150 million people have enabled GPC. Consumer Reports, DuckDuckGo, and others told Colorado authorities in a November 2023 registry application that they "conservatively estimate at least 75 million daily users." GPC itself says the number could be as high as 150 million.
But whether sites respect that choice remains a key compliance gap.
A 2025 study of 11,708 websites found that fewer than half of the sites opted users out through all of their opt-out signals.
The study's authors, at Wesleyan and Princeton, checked whether sites that sell or share data set these flags when GPC was on.
Among sites that sell or share data and set at least one flag, 43% to 45% opted users out through all of their flags across three crawls from December 2023 to April 2024. Another 45% to 46% of the same sites opted out through none. The rest opted out through some of their flags.
An earlier August 2022 crawl of 1,806 sites found that 54 of the 464 sites with a US Privacy String (12%) opted users out after a GPC signal.
A recent September 2026 study checked 998 sites. Of the sites the authors classed as subject to the CCPA, 110 claim to honor GPC and set targeting cookies with GPC on and off. Of those 110, 43 (39.1%) showed no reduction in those cookies with GPC on.
GPC's effect on tracking is easier to measure than its user count. Some cookies are set after a visitor accepts a banner on one site and then get sent to trackers on other sites. A 2025 measurement study of about 5,000 sites with banners that offer a reject option called these intractable cookies.
Getting compliant with GPC
A business respects Global Privacy Control by detecting the signal on every request and applying the opt-out to every tag, pixel, and tracker that sells or shares data. It can build this in its own code, or use a consent management platform that supports GPC.
- Detect the signal. A server can read the
Sec-GPCheader, and page scripts can readnavigator.globalPrivacyControl, as the specification describes. - Apply it to every tracker on the site. Tractor Supply's order requires it to configure trackers used for cross-context advertising, meaning ads based on activity across sites, to give full effect to signals. It must also scan for trackers at least quarterly.
- Carry it to the logged-in person. Disney's judgment requires the opt-out to apply across all streaming services tied to the account.
- Publish
gpc.jsononly if it matches what the site does. The file is published per origin, so a company with several domains publishes it on each one.
California's duties apply on top: show the consumer that the signal was honored, and ask for nothing extra.

Testing your GPC setup
A website can test its Global Privacy Control handling by turning GPC on, reloading, confirming the signal arrives, and checking that trackers stop.
- Turn GPC on in a browser with a built-in setting, such as Firefox or Brave, and reload. A page that's already open keeps the setting it loaded with.
- Open the GPC project's home page. It shows a banner reading GPC signal detected when the browser reports the signal to page scripts, and GPC signal not detected otherwise. It works as a quick GPC checker for the browser in use. It reads only the JavaScript property, so step 4 is the check for the header.
- Run
navigator.globalPrivacyControlin the browser console. It returns true when GPC is on and false when it's off. In a browser with no GPC support, the property doesn't exist, so the console returns undefined. - Open the browser's developer tools, choose the Network tab, click the first request for the page, and look under Request Headers for
Sec-GPC: 1. With GPC off, the header is absent. The GPC project also runs a reference server that reports whether a request carried the header. - Open the site with GPC off, then on. In developer tools, compare the requests to third-party domains on the Network tab and the cookies listed under the Application tab. Look for ones that still appear with GPC on. Healthline's complaint shows why: investigators found 118 cookies associated with third-party advertising companies still set after an opt-out form, GPC, and a cookie banner had all been used.
Passing these checks shows that a browser's signal reaches the site and changes what its trackers do. It doesn't show that the site meets any state's requirements. Enzuzo's consent management guide covers how the signal fits with opt-out links and cookie banners.
How is Global Privacy Control different from Do Not Track, opt-out links, and cookie banners?
Unlike Do Not Track, whose W3C working group closed in January 2019 for lack of deployment, GPC is a current W3C draft that California's regulations treat as a valid opt-out request. Unlike an opt-out link or a cookie banner, which a person uses site by site, GPC is set once in the browser.
| Mechanism | What it is | Where the choice is made | Status |
|---|---|---|---|
| Global Privacy Control | A browser or extension signal, Sec-GPC: 1, asking websites not to sell or share personal information |
Once, in the browser | State law in California, Colorado, and other states directs businesses to honor it |
| Do Not Track | An older W3C header, DNT, expressing a tracking preference |
Once, in the browser | The W3C group closed in 2019, and the EFF cites weak adoption and no enforcement mechanism. Firefox removed the setting in version 135 |
| Do Not Sell or Share link | A link on a business's website | Site by site, by the person | In California, posting the link doesn't excuse a business from processing the signal |
| Cookie banner | A consent prompt on a website | Site by site, by the person | In California, the signal wins over a business-specific setting unless the consumer consents after notice |
How does Enzuzo handle Global Privacy Control?
On Pro and Enterprise plans, Enzuzo's consent management platform can detect a visitor's Global Privacy Control signal and automatically opt them out of non-essential services and cookies once GPC support is turned on. Enzuzo's setup guide also asks customers to add a small /.well-known/gpc.json file to their site.
Book a call with a GPC expert to see it implemented on your site
Frequently asked questions
Is Global Privacy Control legit?
Global Privacy Control is a legitimate signal, developed through the W3C, and California's Attorney General says covered businesses must honor it. The specification is still a Working Draft, and the GPC project notes that the signal alone creates no legally binding obligations. State law supplies the duty.
What does GPC signal detected mean?
GPC signal detected means the browser sent a Global Privacy Control request, so the site received Sec-GPC: 1 or can read navigator.globalPrivacyControl as true. The GPC project's home page shows the message when it can read that property as true, and it doesn't check the header. Other sites can show a message of their own.
What does Sec-GPC: 1 mean?
Sec-GPC: 1 is the HTTP request header a browser sends when Global Privacy Control is on. The value is always 1, and browsers with GPC off send no header at all. Servers ignore the header unless the value is exactly 1, and intermediaries between the browser and the site must not remove it.
Does Chrome support Global Privacy Control?
Chrome doesn't offer a built-in Global Privacy Control setting as of September 2026, according to MDN, Mozilla's web documentation. People using Chrome can send the signal by installing an extension such as Privacy Badger or the DuckDuckGo extension. Chrome on Android doesn't support extensions.
Does GPC apply to logged-in users?
Under California's rules, Global Privacy Control applies to a logged-in person's whole account, beyond the browser that sent it. The CPPA's briefing says a business that knows who a consumer is must apply the signal to all personal information tied to the account. Disney's 2026 judgment requires opt-outs to reach all of its streaming services tied to the account.
How many people use GPC?
One estimate puts GPC use at 75 million daily users or more: the self-reported figure Consumer Reports, DuckDuckGo, and their fellow applicants gave Colorado in a November 2023 filing. The GPC project's own pages give figures from 40 million to more than 150 million, so any count is a rough guide.
Is GPC a replacement for Do Not Track?
Global Privacy Control is a separate signal from Do Not Track, not a formal successor. Mozilla removed the Do Not Track setting from Firefox in version 135 and points people to the GPC setting instead. The W3C's Do Not Track group closed in January 2019, while GPC is a current Working Draft.
Is GPC recognized outside the United States?
As of September 2026, the European Data Protection Board, France's CNIL, the UK's Information Commissioner's Office, and Canada's privacy commissioner don't treat GPC as consent or as a way to object. GDPR Article 21(5) lets a person object by automated means, and people usually raise it for GPC. It covers the right to object; cookie consent under the ePrivacy Directive is separate.
Explore consent management
- Consent management: What is consent management
- Laws: U.S. state privacy laws
- Google Consent Mode: Google Consent Mode
Osman Husain
Osman is the content lead at Enzuzo. He has a background in data privacy management via a two-year role at ExpressVPN and extensive freelance work with cybersecurity and blockchain companies. Osman also holds an MBA from the Toronto Metropolitan University.
LinkedIn →More related blogs
Your next read
Start managing consent
the easy way.
Free forever plan available. No credit card required.