Artifact GuideUSGPC

US CPRA GPC

A covered business that sells or shares personal information must process a qualifying GPC signal as a sale-or-sharing opt-out for the browser, device, and associated consumer profile.

Apply the cited California statute and regulations to the actual entity, data flow, system, and recipient role; escalate unresolved legal interpretation.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

is a browser or device mechanism that can send an . Under section 7025 of the California Consumer Privacy Act (CCPA) regulations, as amended to implement the California Privacy Rights Act (CPRA), a covered business that sells or shares personal information must treat a qualifying signal as a sale-or-sharing opt-out for the browser or device, associated profiles, and the known consumer. This page explains signal qualification, scope, conflicts, timing, downstream action, frictionless processing, and test evidence.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about GPC under the US CPRA?

A covered business that sells or shares personal information must treat a qualifying or other as a request to opt out for the browser or device that sends it. The signal must use a format commonly used and recognized by businesses, such as an HTTP header or JavaScript object, and the sending mechanism must make clear that it is meant to opt the consumer out of sale and sharing. If the business knows the consumer, the signal also applies to the consumer and associated profiles, including pseudonymous profiles. The signal is a request made directly by the consumer, so the business cannot require signed authorization or verification.

The business must process the signal even if it also posts a "Do Not Sell or Share My Personal Information" link. It may omit that link only if it meets the separate statutory and regulatory conditions for frictionless processing, including fully effectuating the opt-out and making the required privacy-policy disclosures. Frictionless processing cannot charge a fee, change the product experience, or display an interstitial in response to the signal.

GPC covers sale and sharing. Deletion, correction, access, and sensitive-data limitation use their own request processes. Map the signal to every relevant online sale and cross-context behavioral advertising flow, the associated profile when known, and downstream recipients. Stop sale or sharing as soon as feasibly possible and no later than 15 business days, notify affected third parties for transfers during that period, show a confirmation state, and keep dated logged-in and logged-out tests.

  • Test recognized signal formats across browsers, devices, consent tools, tags, server-side transfers, and account states.
  • Apply the signal before optional scripts or downstream sale or sharing occurs; do not wait for login to honor the browser or device request.
  • Document any conflict with a business-specific privacy setting or financial incentive and follow the specific section 7025 rule rather than silently overriding the signal.
Citations
California Privacy Protection Agency FAQ

Official CPPA consumer guidance confirming that businesses must honor qualifying opt-out preference signals, including Global Privacy Control, for sale/sharing opt-outs.

Question 2

What evidence should teams keep for GPC under the US CPRA?

Keep browser and device test cases, the raw signal observed, linked-profile behavior, sale/share tags blocked, downstream instructions, conflict and consent handling, privacy-choice status shown to the consumer, persistence tests, and dated results across logged-in and logged-out journeys.

  • Signal record: raw header or JavaScript value, sending mechanism and disclosure, detection timestamp, browser or device, account state, pseudonymous and known-profile associations, and confirmation state.
  • Behavior record: tag and server-side transfer results before and after detection, offline propagation when the consumer is known, third-party notices, suppression timestamps, persistence across sessions, and the 15-business-day outside deadline.
  • Decision record: link-versus-frictionless path, privacy-policy disclosure, financial-incentive or account-setting conflict, consent record if the consumer changes the choice, owner approval, exception note, and dated regression test.
Citations
California Privacy Protection Agency FAQ

Official CPPA consumer guidance confirming that businesses must honor qualifying opt-out preference signals, including Global Privacy Control, for sale/sharing opt-outs.

Question 3

Which mistakes create risk when handling GPC under the US CPRA?

Common failures include detecting GPC without changing downstream behavior, honoring it only after login, treating a cookie banner as the sale-or-sharing request mechanism, claiming frictionless processing when offline sales remain unaffected, overriding the signal with an older cookie or account setting without following the conflict rule, or blocking one ad-tech endpoint while other sale or sharing flows continue.

  • Detecting the signal after sale or sharing has already occurred on the page.
  • Honoring GPC in a browser cookie while server-side or linked-profile transfers continue.
  • Claiming frictionless processing when the signal cannot fully effectuate the business's sale-or-sharing opt-out.
Citations
California Privacy Protection Agency FAQ

Official CPPA consumer guidance confirming that businesses must honor qualifying opt-out preference signals, including Global Privacy Control, for sale/sharing opt-outs.

Global Privacy Control project site

The GPC project's public overview supports the description of the browser-level signal; California legal effects come from the statute and CPPA regulations.

Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Official CPPA regulations source for opt-out preference signal processing, privacy-choice links, and related CPRA implementation requirements.
"Office of Administrative Law approved the California Privacy Protection Agency’s regulations"
cppa.ca.gov
Referenced sections
  • Official CPPA consumer guidance confirming that businesses must honor qualifying opt-out preference signals, including Global Privacy Control, for sale/sharing opt-outs.
"Businesses must honor opt–out preference signals (“OOPS”) that meet certain requirements, such as the Global Privacy Control"
globalprivacycontrol.org
Referenced sections
  • The GPC project's public overview supports the description of the browser-level signal; California legal effects come from the statute and CPPA regulations.
"GPC lets users signal their desired privacy, just by browsing"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.