Artifact GuideUSGPC

US CCPA GPC

A qualifying Global Privacy Control signal is a CCPA request to opt out of sale or sharing; honor it for the browser, device, and any known consumer profile required by the regulations without forcing a form or identity check.

Test recognized and unrecognized users end to end, including browser and device state, known accounts, offline scope, downstream transfers, conflicts, and the 15-business-day outer deadline.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

(GPC) is an example of an opt-out preference signal. A business that sells or shares personal information must process a qualifying signal as a valid request to opt out of sale or sharing. The business cannot require a form or identity verification before honoring it.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What is GPC and how should teams handle it under the US CCPA?

Process the signal for the browser or device that sends it and every consumer profile, including a pseudonymous profile, associated with that browser or device. If the business knows the consumer, treat the signal as applying to the consumer, their account, and identifiable offline sale or sharing. Do not wait for a separate form, account creation, or identity verification.

A qualifying signal must use a format commonly used and recognized by businesses, such as an HTTP header or JavaScript object, and the sending mechanism must tell the consumer that the signal is meant to opt out of sale and sharing. The regulations do not require the disclosure to mention California. The GPC specification expresses the signal through the Sec-GPC header and the navigator.globalPrivacyControl JavaScript property, but the legal test is section 7025 rather than a product name alone.

If the signal conflicts with a business-specific setting that permits sale or sharing, process the opt-out first. The business may explain the conflict and seek fresh consent through a compliant choice. A financial-incentive conflict has a separate confirmation branch. Absence of the signal on a later visit is not consent to opt in when the consumer is known to the business.

GPC is not a delete request and does not by itself withdraw every form of consent or limit every use of sensitive personal information. Scope it to the CCPA sale and sharing opt-out unless another applicable signal or consumer instruction communicates an additional choice. Stop covered sale or sharing as soon as feasibly possible and no later than 15 business days after receipt.

  • Detect the Sec-GPC signal and any other signal that meets the regulatory requirements.
  • Apply the opt-out before covered advertising or other sale or sharing occurs.
  • Link the status to a known consumer profile when the regulations require it, while avoiding unnecessary identity collection.
  • Propagate the choice to tag managers, consent tools, APIs, audience systems, data stores, and downstream recipients.
  • Disclose in the privacy policy how preference signals are processed, including browser, device, account, and offline scope.

Must a business honor under the CCPA?

A business that sells or shares personal information must process when the signal meets section 7025's format and consumer-disclosure requirements. The business must treat it as a valid request to opt out of sale or sharing for the sending browser or device and associated profiles, including pseudonymous profiles. If the consumer is known, the request also applies to that consumer.

Can a business require a form, login, or identity check before honoring GPC?

No. The business cannot require information beyond what is necessary to send the signal and cannot make the consumer submit a separate form or verifiable consumer request. It may offer an optional way to identify the consumer so the opt-out can reach offline activity, but it must still honor the signal for the browser or device and associated profiles if the consumer provides nothing further.

How far does a GPC opt-out apply?

At minimum, it applies to the browser or device that sent the signal and every profile the business associates with that browser or device. When the consumer is known, it also applies to the consumer, the account, and identifiable offline sale or sharing. A later visit from a device without the signal does not reverse the choice for a known consumer.

What happens when GPC conflicts with an account setting or financial incentive?

For a conflicting account setting that allows sale or sharing, the business must process GPC as an opt-out but may notify the consumer and request compliant consent to change the choice. If GPC conflicts with a financial incentive that requires consent to sale or sharing, the business may ask whether the consumer intends to leave the program. If the business cannot identify the consumer after cookies are cleared, it must honor GPC for the new browser or device.

Does honoring GPC let a business remove its privacy-choice link?

Only if the business meets the statute and section 7025 rules for frictionless processing. It must honor the signal without a fee, degraded experience, or responsive pop-up; explain the practice in its privacy policy; and let the signal fully effectuate the opt-out, including offline sale or sharing when applicable. Otherwise, the business must honor GPC and keep the required Do Not Sell or Share or alternative privacy-choice link.

How quickly must a GPC opt-out take effect?

The business must stop selling or sharing the consumer's personal information as soon as feasibly possible and no later than 15 business days after receiving the request. It must also notify third parties that received the information during the interval between receipt and compliance and direct them to honor and forward the request as required by section 7026.

Citations
Question 2

What evidence should teams keep for GPC under the US CCPA?

Keep end-to-end evidence for recognized and unrecognized users. A server log showing that the header arrived does not prove that downstream sale or sharing stopped.

  • Raw request showing the signal, detection result, timestamp, browser or device, and known-account status.
  • Before-and-after network tests for advertising tags, server-side events, APIs, audiences, and downstream transfers.
  • Preference records and propagation logs showing which systems received the opt-out and when.
  • Conflict handling, consumer notices, privacy-policy disclosure, defects, remediation, owner, and review date.
Citations
Question 3

Which mistakes create risk when handling GPC under the US CCPA?

A confirmation in one layer does not cure sale or sharing that continues through another layer. Test the full transfer path.

  • Displaying a confirmation while advertising tags or server-side events continue covered transfers.
  • Applying the signal only to the current page instead of the browser or device, or failing to associate it with a known consumer when required.
  • Requiring a form, account login, or identity verification before processing the signal.
  • Treating GPC as consent withdrawal, deletion, or a blanket sensitive-information limit without a separate legal and technical basis.
  • Overwriting the signal with a less privacy-protective default or failing to explain a genuine conflict with a business-specific setting.
Citations
Primary sources

References and citations

Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.