
Global Privacy Control: does your site honour the signal
At a glance
US-03CriticalCal. Civ. Code § 1798.135(b); Cal. Code Regs. tit. 11, §§ 7025 and 7026(a)(1)
Peeky sends the Global Privacy Control signal the way a browser would and compares which advertising trackers run with and without it.
Last checked against the source:
The rule
Global Privacy Control, GPC, is a technical signal. The W3C Global Privacy Control specification defines it as one “transmitted over HTTP and through the DOM, that conveys a person’s request to websites and services to not sell or share their personal information with third parties.” The law gives that signal effect in California.
Section 1798.135(b)(1) of the California Consumer Privacy Act treats opt-out through “an opt-out preference signal sent with the consumer’s consent by a platform, technology, or mechanism, based on technical specifications set forth in regulations” as a way for a business to meet the opt-out requirement in place of the link. Section 1798.135(b)(3) adds that “a business may elect whether to comply with subdivision (a) or subdivision (b)”, meaning the link or the signal.
On its face the statute gives a choice. The regulations remove most of it for websites.
Section 7025(b) says a business that sells or shares personal information must process opt-out preference signals that meet its criteria, which include a format “commonly used and recognized by businesses” and a clear disclosure by the sending platform that the signal opts the consumer out. Under Section 7025(c)(1), the business must “treat the opt-out preference signal as a valid request to opt-out of sale/sharing submitted pursuant to Civil Code section 1798.120 for that browser or device and any consumer profile associated with that browser or device, including pseudonymous profiles.” Section 7026(a)(1) then requires a business that collects personal information online, “at a minimum,” to let consumers opt out through a preference signal and at least one other method.
So the signal is not optional in practice for an online business that sells or shares. Where the signal conflicts with a setting the visitor made on the business’s own site, Section 7025(c)(3) says the business still processes the signal as an opt-out. Section 7025(f) describes processing “in a frictionless manner”: no fee, no change to the visitor’s experience, and no notification in response to the signal. The provisions on opt-out preference signals have been operative since 29 March 2023.
The Attorney General’s CCPA page says the same in plain terms. It calls GPC “a ‘stop selling or sharing my data switch’ that is available on some internet browsers” and names a user-enabled global privacy control as an acceptable opt-out method for online businesses, one that must be honored as a valid request to stop the sale or sharing of personal information. Penalties follow the other US-02 provisions: fines of up to $2,663 for each offence or $7,988 for each intentional one, as adjusted from 1 January 2025 under Sections 1798.155(a) and 1798.199.90(a). The Stipulated Final Order the CPPA Board adopted on 27 February 2026 alleged that PlayOn Sports failed to configure its digital properties to recognise and honour opt-out preference signals, and treated each failure to honour a signal as a separate count. PlayOn did not admit liability.
Enforcement has moved from guidance toward testing. On 9 September 2025 the CPPA announced a joint investigative sweep with the Attorneys General of California, Colorado and Connecticut into businesses that may not process opt-out requests made through GPC. From January 2027, a separate law, AB 566, requires browsers operating in California to offer an easy opt-out preference signal setting, which the CPPA’s announcement says will give Californians new privacy options in web browsers, where today only a handful of browsers offer one. That law was not yet in force on 7 October 2026.
What PeekWell checks and how
US-03 is run where the site’s markets include California. It asks one question: when the browser sends the signal, do the advertising trackers that ran without it still run?
The scan makes two passes of the same public page, each in a fresh browser with no saved choices. The first is an ordinary visit. In the second, the scan sets the signal the way a supporting browser does: a Sec-GPC header with the value 1 on requests, and navigator.globalPrivacyControl set to true for scripts on the page. It then reloads and records the network requests again. The W3C specification defines both. The request domains in each pass are matched against the same maintained list of sale and sharing tracker signatures, and the two passes are compared. If the trackers are the same with the signal as without it, that becomes a finding, and the two lists of requests are the evidence.
Code makes the decision from that comparison, and a language model never decides that a tracker ran. The method matches US-02, which covers the link, except that this pass tests behaviour and needs no link to look for.
The scan has limits, and the report says so. It sees public pages and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. It reads what a browser does when it loads the page, so a site that honours the signal later, on its servers, or that passes data to vendors by a route a browser visit cannot see, will not show that here. It cannot tell whether a signal sent while logged in is applied across a person’s other devices, which was the issue in the Disney matter. It does not read your contracts or know what a tag does beyond the category on its list, and a list only knows the trackers on it. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
An early one was Sephora, announced by the Attorney General on 24 August 2022. The Attorney General alleged that Sephora did not process opt-out requests sent through user-enabled global privacy controls, and that it had not disclosed that it sold personal information. The Attorney General’s statement said the company did not cure within the 30-day period then available. The settlement was $1.2 million and required Sephora to support the signal and report to the Attorney General.
Healthline followed on 1 July 2025 with a $1.55 million settlement, where the Attorney General alleged data kept going to advertising third parties after consumers opted out, and the release says GPC requests must be honored. The CPPA’s Tractor Supply decision on 30 September 2025 listed GPC in the same sentence as the opt-out mechanism, with a $1,350,000 fine and a requirement to scan its properties for tracking technologies. The Disney settlement of 11 February 2026, for $2.75 million, shows the next stage: the Attorney General said Disney did act on the signal, but only for the specific device, even when the visitor was logged in. The PlayOn Sports order of 27 February 2026 alleged that PlayOn had failed to configure its digital properties to recognise and honour opt-out preference signals; PlayOn did not admit liability.
The facts are testable from outside, the agencies have said they test them, and a fix that works in one place can still leave gaps.
Smaller companies and larger companies
The signal rule has no separate small-business track. It applies to any business that meets the CCPA’s thresholds and sells or shares personal information. A site on a hosted builder can cross the 100,000 consumers-or-households threshold on traffic alone.
In a small company the usual cause is configuration. The cookie banner has Accept and Reject, but nobody wired the banner to read the browser signal. Or a pixel pasted into the theme sits outside the banner tool’s control. We could not confirm a decision against a clearly small business at a regulator’s own page, so the note under the cases says so.
In a larger company the cause is scope. Several teams own tags, the site spans brands and apps, and the signal has to carry from the browser to the tag manager, the server and the vendors. The Disney matter is the example. The signal was honoured for one device and not across the account.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
The Walt Disney Company
The Attorney General said that for consumers who opted out through the Global Privacy Control, Disney limited the request to the specific device the consumer was using, even when the consumer was logged into their account. Disney settled, with civil penalties and a requirement to put in opt-out methods that fully stop its selling and sharing.
Read the California Attorney General (United States) publication about The Walt Disney CompanyHealthline Media LLC
The Attorney General alleged that Healthline continued to share data with some advertising third parties even for consumers who exercised their right to opt out, and said businesses must honor opt-out requests, including those sent through the Global Privacy Control. Healthline settled and agreed to make its opt-out mechanisms work correctly.
Read the California Attorney General (United States) publication about Healthline Media LLCTractor Supply Company
The CPPA's Board decision alleged that Tractor Supply failed to provide an effective mechanism to opt out of the selling and sharing of personal information, including through opt-out preference signals such as Global Privacy Control. To resolve the allegations, the company agreed to pay the fine, to scan its digital properties to inventory tracking technologies, and to a yearly certification of compliance by an officer or director for four years.
Read the CPPA (California, United States) publication about Tractor Supply CompanySephora
The Attorney General alleged that Sephora failed to disclose that it was selling consumers' personal information and did not process opt-out requests made through user-enabled global privacy controls. Sephora agreed to update its disclosures, set up opt-out methods including the Global Privacy Control, and report to the Attorney General.
Read the California Attorney General (United States) publication about Sephora
Smaller companies
No decision against a clearly small business could be confirmed at a regulator's own page. The decisions we could confirm involve companies large enough to clear the CCPA's thresholds, and the regulators' pages do not describe company size.
How to fix it
The steps below follow the specification’s two signals, the header and the script property, and the regulations’ requirement that the signal is treated as a valid opt-out request for the browser or device and its associated profiles.
- Test with the signal on. Use a browser that sends GPC, such as Brave, DuckDuckGo or Firefox with the setting on, or an extension. With the network tab open, load your pages and note which advertising and cross-site requests still fire.
- Read the signal where decisions are made. On the server, look for the Sec-GPC header with a value of exactly 1. In the page, check navigator.globalPrivacyControl. Pass the result to your consent tool and tag manager.
- Stop the tags before they load. For a visitor who sent the signal, do not load advertising, retargeting or cross-site tags, and do not pass their data to those vendors. Many consent tools have a GPC option. Switch it on and test, since a setting that exists is not proof it works.
- Do not make the visitor repeat it. If you process the signal in a frictionless manner, the regulations bar a fee, a changed experience or a notification in response to it. If the visitor’s own settings on your site conflict with the signal, process the signal as the opt-out; you may then tell the visitor and offer a choice to consent.
- Carry it across the account. For logged-in visitors, store the opt-out against the account as well as the device, since the regulations say that if the consumer is known the signal must also be treated as an opt-out for the consumer, and apply it across your other sites, apps and connected TV products. The Disney settlement turned on that gap.
- Say it in your policy. Section 1798.135(c)(2) lets a privacy policy include a statement that the business responds to opt-out preference signals. Keep the statement true to what step 3 does.
- Re-scan. Run a scan again. The finding should clear when the tags that ran without the signal no longer run with it.
if (navigator.globalPrivacyControl === true) {
// do not load advertising or cross-site tags for this visitor
// record the opt-out against the visitor's account, if they have one
}
The server header is the more reliable place to decide, because it is there before any tag has loaded. Whether your setup meets the law is a question for your legal adviser. Peeky reports only what it sees.
Questions
What is Global Privacy Control?
It is a setting in a browser or browser extension that tells every site you visit not to sell or share your personal information. The browser sends a signal with each page request, so the visitor doesn't have to hunt for an opt-out link on each site. Brave, DuckDuckGo and Firefox support it, and extensions add it to other browsers.
Do websites have to honour Global Privacy Control?
In California, a business that sells or shares personal information has to treat the signal as a valid opt-out request. The regulations say so in section 7025, and the Attorney General's site names a user-enabled global privacy control as an acceptable opt-out method for online businesses and says it must be honored as a valid request to stop the sale or sharing of personal information. The statute itself lets a business choose between the link and the signal, so the regulations are where the web requirement sits.
How does a website detect the GPC signal?
The browser adds a Sec-GPC header with the value 1 to its requests, and it sets navigator.globalPrivacyControl to true for scripts on the page. A site can read either one. The W3C specification says a server must ignore the header unless its value is exactly 1.
How do I implement Global Privacy Control on my website?
Read the signal on the server or in the page, and stop advertising and cross-site tags for that visitor before they load. Many consent tools have a setting that does this. The test is whether the tags that ran without the signal stay quiet with it. How to fix it has the steps.
Does the GPC signal apply to my logged-in account?
It should reach further than one device, according to the Attorney General. In the Disney settlement the Attorney General said Disney limited the signal to the device in use even when the person was logged in, and the settlement requires opt-out methods that fully stop the selling and sharing. The regulations tie the signal to the browser or device and any profile associated with it, and say that if the consumer is known, the business must also treat the signal as an opt-out for the consumer.
Filed with
The rule
California Consumer Privacy Act, Cal. Civ. Code §§ 1798.120, 1798.135(b) and 1798.185(a)(19) (as posted by the CPPA, effective 1 January 2025)
Read the rule (California Consumer Privacy Act, Cal. Civ. Code §§ 1798.120, 1798.135(b) and 1798.185(a)(19) (as posted by the CPPA, effective 1 January 2025))Sources
- California Consumer Privacy Act of 2018, statute text posted by the CPPA (effective 1 January 2025)
- Cal. Code Regs. tit. 11, § 7025, Opt-Out Preference Signals
- Cal. Code Regs. tit. 11, § 7026, Requests to Opt-Out of Sale/Sharing
- Cal. Code Regs. tit. 11, § 7013, Notice of Right to Opt-out of Sale/Sharing
- California Attorney General, California Consumer Privacy Act (CCPA) page
- California Attorney General, CCPA enforcement case examples (updated 24 August 2022)
- W3C Privacy Community Group, Global Privacy Control (GPC) specification
- Global Privacy Control, project site
- California Attorney General, Attorney General Bonta announces settlement with Sephora (24 August 2022)
- California Attorney General, Attorney General Bonta announces largest CCPA settlement to date, $1.55 million from Healthline.com (1 July 2025)
- CPPA, Nation's Largest Rural Lifestyle Retailer to Pay $1.35M Over CCPA Violations (30 September 2025)
- California Attorney General, Attorney General Bonta announces $2.75 million settlement with Disney (11 February 2026)
- CPPA, Stipulated Final Order, 2080 Media, Inc. d/b/a PlayOn Sports, Case No. ENF24-S-PL-24 (adopted 27 February 2026)
- CPPA, California Privacy Protection Agency announces joint investigative privacy sweep (9 September 2025)
- CPPA, Governor signs groundbreaking privacy bill making it easier for Californians to protect their personal data (8 October 2025)
Last checked against the source:
For information only. Not legal advice.


