What is Global Privacy Control (GPC), and what does it mean for your business?
Global Privacy Control (GPC) is now a legal requirement in 12 states. Learn how it works, which states require it, and what it means for marketing measurement.
Linnea Zielinski · 8 min read
When you move to a new house, you don't call every company you've ever ordered from to give them your new address one at a time. You file a single change-of-address form with the post office, and it forwards your mail automatically, no matter who's sending it or how many times you move. Global Privacy Control works a lot like that form, except it's for personal information instead of mail. A person sets their preference once in their web browser, and that browser announces it to every website they visit from then on, without them lifting a finger.
A growing list of state privacy laws now treats this signal as a legally binding obligation, and businesses that ignore it have already paid real fines for doing so. If your marketing stack leans on cookies, pixels, or other tracking to measure performance, it's worth understanding exactly what this signal asks of you and what happens when your business doesn't honor it.
Key takeaways
- Global Privacy Control (GPC) is a browser-based signal that automatically tells every website a person visits not to sell or share their personal information.
- GPC is what regulators call an opt-out preference signal, or universal opt-out mechanism, and it's treated very differently under the law than older tools like Do Not Track ever were.
- As of 2026, 12 states require businesses to honor GPC signals, including California, Colorado, Connecticut, and Oregon, with Maryland and Minnesota's requirements starting in July.
- Businesses have already been fined for failing to process opt-out requests properly, so this isn't a hypothetical risk.
- California now requires businesses to visibly confirm when they've honored a GPC signal instead of just processing it in the background.
- As more consumers turn on GPC, cookie- and pixel-based tracking loses more of the data marketers have relied on for years, which raises the stakes for measurement that doesn't depend on that data in the first place.
What is Global Privacy Control?
Global Privacy Control is a browser setting or extension that lets a person tell every website they visit, all at once, that they don't want their personal information sold or shared. It was built by a coalition of privacy advocates, publishers, and browser makers as a response to how clunky individual opt-out links had become across the web. Instead of hunting down a "do not sell my info" link on every site, a user can turn GPC on once in a supported browser, like Firefox, Brave, or DuckDuckGo, and it takes care of the rest across every website they visit afterward.
For consumers, that's a matter of convenience. For businesses, it's a compliance question, since a growing number of state privacy laws now require you to treat that signal as a valid, legally required opt-out request the moment it arrives.
How Global Privacy Control actually works
GPC is an active signal with real technical weight behind it, and understanding the mechanism helps explain why it's harder for businesses to ignore than older privacy tools were.
- It sends automatically. Every time a user with GPC enabled loads a page, their browser sends a Sec-GPC HTTP header and sets a matching JavaScript property, both of which tell your website the visitor wants to opt out of the sale or sharing of their data.
- It requires no extra clicks. The person never has to interact with a cookie banner or click "reject" for the signal to count. It's already there before your page finishes loading.
- It applies across every website the browser visits. One setting change covers every site that browser loads going forward, not just the one where the user happened to set their preference.
How GPC differs from Do Not Track
If this sounds familiar, you might be thinking of Do Not Track, an earlier browser signal that asked websites to skip tracking a visitor. DNT requests never carried any legal weight, so most businesses simply ignored them, and the standard faded into irrelevance.
GPC solves that problem by attaching itself to actual privacy laws. In states where it's legally required, treating a GPC signal as a valid opt-out preference signal is a compliance requirement enforced by the same attorney general's offices that oversee the rest of each state's data privacy laws, which gives consumers a form of online privacy rights that Do Not Track never had.
Which states require businesses to honor GPC signals
State privacy laws haven't all moved at the same pace, and requirements to recognize GPC as a valid universal opt-out mechanism have rolled out state by state rather than all at once. Here's where things stand as of 2026:
- California, under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act, where the state's attorney general has explicitly confirmed GPC as a valid method for consumers to exercise their consumer rights
- Colorado, under the Colorado Privacy Act, which also extends the requirement to cross-context behavioral advertising, not just data sales
- Connecticut, under the Connecticut Data Privacy Act
- Delaware
- Maryland
- Minnesota
- Montana
- Nebraska
- New Hampshire
- New Jersey
- Oregon, under the Oregon Consumer Privacy Act, which adds its own twist by requiring a visible confirmation once an opt-out request has been honored
- Texas
That brings the total to 12 states, and privacy attorneys widely expect that list to keep growing. If your business serves customers anywhere in the U.S., geo-targeting alone isn't a reliable way to sidestep these laws, since visitors from any of these states can trigger the obligation regardless of where your company is based.
What businesses need to do to comply
Recognizing a GPC signal is only half the job. Businesses also need to make sure that signal actually changes what happens to a user's data once it arrives.
- Detect the signal. Your website or consent management platform needs to check for the Sec-GPC header or the matching browser property on every page load, not just the landing page.
- Honor it automatically. Once detected, targeted advertising tools and any data collection tied to selling or sharing personal information need to stop without requiring the person to take any further action.
- Audit every connected tool. Ad pixels, tracking scripts, and other third-party tools all need to respect GPC signals individually. If even one keeps firing after the signal arrives, your business is still out of compliance.
- Keep a record. Several states require businesses to log opt-out requests, including the ones that come in through GPC, as part of demonstrating you remain compliant over time.
Getting this right typically means involving whoever manages your consent management platform and your broader data privacy program, since marketing, legal, and engineering all touch a different part of the process.
What happens if a business ignores a GPC signal
Regulators have shown they're willing to enforce this. In 2022, Sephora paid $1.2 million to settle California's claims that it failed to properly process opt-out requests, including ones sent through GPC. In 2025, Tractor Supply settled for $1.35 million over similar gaps in how it handled opt-out preference signals across its site.
Both cases point to the same underlying issue: it's rarely that a business intentionally ignored consumer rights on purpose. More often, a business had a consent banner in place, but the data flowing to ad platforms and other third-party tools never actually got the message. That gap between what a banner promises and what a website's backend does is exactly where the legal impact tends to land, and it's why a compliance checkbox alone doesn't guarantee you're covered.
What growing GPC adoption means for your marketing measurement
Compliance is the immediate concern, but there's a second effect worth watching. Every user who turns on GPC, and every state that makes it legally required, chips away a little more at the tracking data marketing teams have depended on for years. Cookies and pixels already take a hit from ad blockers and browser restrictions. GPC adds another, more permanent layer on top of that, since people tend to turn it on once and forget about it.
If your measurement strategy leans heavily on tracking individual users across touchpoints, that data pool is only going to keep shrinking as more consumers make this choice. Marketing mix modeling takes a different approach. Rather than trying to track individual people, it looks at aggregate spend and outcome data over time, math instead of tracking, so it doesn't degrade every time another state passes a privacy law or a browser changes what it allows pixels to see.
Where Prescient comes in
Prescient AI's platform is built on marketing mix modeling, so it was never dependent on the kind of user-level tracking that GPC and other opt-out preference signals are designed to block in the first place. Instead of trying to stitch together individual customer journeys, we measure how your marketing actually moves revenue by looking at your spend and results in aggregate, across every channel you run, including the retail and omnichannel partners your customers shop through.
That means your reporting doesn't get shakier every time GPC adoption grows or another state adds itself to the list. If you want to see how that works, we'd be glad to walk you through it. You can book a demo using anonymized data from a real brand to see what your measurement could look like without the tracking dependency.
FAQs
Is Global Privacy Control legit?
Yes. Unlike Do Not Track, GPC is backed by actual state privacy laws in a growing number of states, and regulators, including California's attorney general, have confirmed it counts as a valid opt-out preference signal. Businesses that ignore it in states where it's legally required have already faced real fines.
What's the difference between CCPA and GDPR?
The California Consumer Privacy Act, updated by the California Privacy Rights Act, is a U.S. state law that gives residents the right to opt out of having their personal information sold or shared, with GPC as one accepted way to exercise that right. The GDPR is a European Union regulation that takes a broader consent-first approach, generally requiring businesses to get explicit permission before any data collection happens, rather than offering an opt-out after the fact.
Which states require GPC?
As of 2026, 12 states require businesses to honor GPC signals: California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. Maryland and Minnesota's requirements began in July 2026, and more states are expected to add similar privacy regulations over time.
Does Chrome support GPC?
Chrome doesn't turn GPC on by default the way Firefox, Brave, and DuckDuckGo do, but Chrome users can still send the signal through a browser extension. California has pushed for GPC to eventually come standard in major web browsers, so this may change.
Is Global Privacy Control the same as Do Not Track?
No. They look similar on the surface, since both are browser settings that ask websites to limit tracking, but Do Not Track never had any legal requirement behind it, so most businesses ignored it. GPC is different because a growing number of state privacy laws require businesses to honor it as a valid opt-out request.
Do you still need a cookie consent banner if you honor GPC?
Generally, yes. GPC covers the sale and sharing of personal information for things like targeted advertising, but it doesn't automatically replace every consent requirement tied to cookies more broadly. Most businesses still need a banner for other privacy choices, while also making sure their backend systems actually honor GPC signals when a user's browser sends one.
The Halo
Exclusive insights, every week.
Subscribe to The Halo for sharper marketing thinking.
You're subscribed to The Halo!
Quick question (optional): How familiar are you with MMM?
Thanks for sharing! Enjoy The Halo.
Keep reading
View all
Virginia privacy laws: What marketers need to know about the VCDPA
Read article
Understanding how Colorado privacy laws change your marketing measurement
Read article
What California's data privacy law means for your marketing data
Read article
What is privacy-preserving ad measurement?
Read articleBest identity graph for cross-device tracking in martech
Read articleWhat is a tracking pixel audit (and how do you run one)?
Read article