Skip to content
Adrythm
Email, texting and privacy

Global Privacy Control

GPC signal / universal opt-out mechanism / browser opt-out signal

In short

Global Privacy Control is a signal a web browser sends to every site a person visits, saying they do not want their personal information sold or shared. California's CCPA counts it as a valid opt-out request, and Colorado recognizes it as a universal opt-out, so covered businesses must honor it automatically.

Global Privacy Control is a setting or extension in a browser. Once it is on, the browser sends the signal to every website the person visits. The project's own site says the signal is meant to communicate a Do Not Sell or Share request under the California Consumer Privacy Act and similar state laws.

California treats it as a real request. The Attorney General's CCPA page lists opting out of sale or sharing, including via a user-enabled global privacy control, among consumer rights. After a business receives an opt-out request, it cannot sell or share that person's personal information unless they later authorize it again.

Colorado goes further in naming it. Under the Colorado Privacy Act, consumers can opt out of the sale of their personal data or its use for targeted advertising through a universal opt-out mechanism. The Colorado Attorney General says GPC was the first such mechanism recognized and is currently the only one it considers valid.

The difference from a Do Not Sell or Share link is scale. A link works one site at a time. The signal reaches every participating site at once, without the visitor clicking anything.

In practice

A furniture store covered by the CCPA runs advertising pixels that share visitor data with ad platforms. A visitor arrives with Global Privacy Control switched on in their browser. The site has to treat that visit as an opt-out request, which means the sharing that request covers stops for that visitor without them touching the store's opt-out link.

Not the same as

Do Not Sell or Share link
The link asks a visitor to opt out on one site by hand. Global Privacy Control sends that request automatically to every participating site the browser visits.

Why it matters to you

A site can have a correct Do Not Sell or Share link and still ignore opt-outs arriving as a browser signal. For a covered business running ad tracking, honoring the signal belongs in the website's code or consent tool. Ask whoever built the site whether it reads the signal and what changes when it does.

What to ask or check

  1. 01Does the website detect the Global Privacy Control signal, and what stops when it arrives?
  2. 02Does the consent or cookie tool treat the signal as an opt-out of sale and sharing?
  3. 03Is the business covered by the CCPA or the Colorado Privacy Act in the first place?

What people get wrong

That an opt-out only counts when someone clicks the Do Not Sell or Share link. The California Attorney General lists a user-enabled global privacy control as a way to request that businesses stop selling or sharing personal information.

CCPA business thresholds

The CCPA business thresholds are the three tests that decide whether California's privacy law covers a for-profit company doing business in the state. Meeting any one is enough: revenue above $26,625,000 a year, buying, selling or sharing personal information of 100,000 or more consumers or households, or earning half its revenue from selling or sharing it.

Notice at collection

A notice at collection is the disclosure California's privacy law requires before or as a covered business collects personal information. It says what is collected and why, whether it is sold or shared, and how long it is kept. So it belongs wherever the information is gathered, such as a website form.

Consent mode

Consent mode is how an advertising tag is told whether a visitor agreed to be tracked. Both major platforms now require a consent signal, and the penalties differ in kind: Google's policy allows it to suspend or terminate your account, while Microsoft simply stops recording your conversions.

DKIM

DKIM attaches a cryptographic signature to a message so a receiver can confirm the signed parts were not altered. The standard describes it as a domain claiming some responsibility for the message, and it separates the signer from the purported author. Modifying a message in transit breaks the signature.

SPF

SPF is a DNS record listing which servers may send mail using your domain in the envelope sender. The specification caps it at ten DNS-querying terms, and receivers must return permerror if that is exceeded, which means the check fails. It does not check the From address a recipient sees.

DMARC

DMARC is a DNS record that tells receiving mail systems what you think about messages using your domain that fail authentication. The current standard, RFC 9989, is explicit that receivers can honor your request but are not required to. It was revised in 2026, and the percentage rollout tag was removed.

Want this explained against your own numbers?

Twenty minutes, a straight answer, and no follow-up sequence if you decide not to work with us.