What is GPC and how should teams handle it under the US CCPA?
GPC, or Global Privacy Control, is a browser or device privacy signal that tells a business the consumer wants to opt out of sale or sharing of personal information. Under the CCPA, businesses that sell or share personal information must process a valid opt-out preference signal as an opt-out request for that browser or device, and for the consumer when the business knows who the consumer is.
Teams should treat a GPC signal as an opt-out request, not as a general privacy preference. The practical response is to stop the sale or sharing that the signal covers, update the consumer's status where the business knows the consumer, and keep evidence of how the request was handled and when it was reviewed.
- Write the GPC decision in one sentence before drafting controls.
- Attach the external source URL and a short source quote to the evidence record.
- Route unclear cases to legal, privacy, security, or compliance review before launch.
CCPA statutory source for opt-out preference signals and sale/share opt-out duties.
Confirms privacy-policy disclosure duties for opt-out preference signal handling.
CPPA regulation text defining opt-out preference signals and processing requirements.