Artifact GuideUSGPC Handling

US CPRA GPC Handling

A business that sells or shares personal information must treat a qualifying Global Privacy Control signal as an opt-out request for the browser or device and the profiles it can associate with that browser or device.

Use this guide to set the signal scope, stop covered transfers, handle account and incentive conflicts, and keep evidence that the control works.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
8

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Global Privacy Control () is a technical opt-out preference signal. Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), a business that sells or shares personal information must process a qualifying signal as a request to opt out of both sale and sharing. The signal applies to the browser or device and associated profiles; if the consumer is known, it also applies to that consumer. GPC does not by itself request deletion, correction, access, or a limit on sensitive-personal-information use.

Section 1

When must a business honor GPC?

The duty applies to a business that sells or shares personal information and receives a signal in a format commonly used and recognized by businesses, such as an HTTP header or JavaScript object. The sending platform, technology, or mechanism must make clear to the consumer that the signal opts the consumer out of sale and sharing. A business that does not sell or share personal information is not required to process the signal as an opt-out request.

For this right, a sale is a transfer or other communication of personal information to a third party for money or other valuable consideration. Sharing is a transfer or other communication to a third party for cross-context behavioral advertising, whether or not consideration changes hands. Each definition has specified exclusions, including qualifying consumer-directed and service-provider or contractor disclosures.

Posting a "Do Not Sell or Share My Personal Information" or alternative privacy-choices link does not replace handling. A business that sells or shares personal information online must still process a qualifying opt-out preference signal. A cookie banner alone is not an adequate sale-or-sharing opt-out method because cookie collection and sale or sharing are different questions.

A business may omit the opt-out links only if it processes signals in a and meets every additional condition in section 7025(g), including full effectuation of the request and the required privacy-policy disclosures. Frictionless processing cannot charge a fee, require valuable consideration, change how the product or service functions, or display a pop-up or other interstitial in response to ; a neutral processed-status display and a privacy-settings link are allowed. The exception removes only the link requirement; the duty to honor GPC remains.

  • Confirm that the entity is a CCPA business and identify every transfer classified as a sale or sharing.
  • Detect the signal on every covered website, application, domain, and collection path, including tag-manager and consent-platform integrations.
  • Treat as a request directly from the consumer; the signed-permission rule for an authorized agent does not apply.
  • Do not require an account, identity verification, or information beyond what is necessary to send the signal.
Section 2

How far does the signal apply?

Apply the signal to the browser or device and every consumer profile, including a pseudonymous profile, that the business associates with it. If the business knows the consumer, such as when the consumer is signed in, apply the opt-out to that consumer as well. That may extend the choice to the account and to offline sale or sharing tied to the known consumer.

Do not make optional identification a condition of honoring the device-level request. The business may invite the consumer to provide information so the request can reach offline records, but information supplied for that purpose may be used, disclosed, and retained only to process the opt-out. If the consumer supplies nothing, the browser-or-device and associated-profile opt-out still applies.

  • Anonymous visitor: stop sale and sharing tied to the browser or device identifier and any linked pseudonymous profile.
  • Known visitor: also apply the opt-out to the known consumer, account, and linked offline flow.
  • Later visit without : if the consumer is known and previously sent GPC, do not treat the signal's absence as consent to opt back in.
  • Processed status: display on the website whether the business processed the signal as a valid sale-or-sharing opt-out request.
  • Downstream timing: stop sale and sharing as soon as feasibly possible and no later than 15 business days after receiving the request.
Section 3

How should conflicts and opt-in requests work?

If conflicts with a business-specific setting that allows sale or sharing, process GPC as the opt-out. The business may explain the conflict and offer a consent choice that complies with the regulations. If the consumer validly consents, the business may ignore the signal while that consumer remains known to it.

A financial incentive program has a narrower branch. If participation requires consent to sale or sharing and the consumer is known, the business may ask the consumer to affirm withdrawal from the program. If the consumer does not affirm, the business may ignore only for that known consumer's participation in the program. If the business does not ask, or can no longer identify the consumer, it must process GPC for the browser or device and associated profile. Except where the regulations allow otherwise, wait at least 12 months after an opt-out before asking the consumer to consent to sale or sharing.

  • Keep the default state at opted out until the consumer completes a valid opt-in.
  • Use the required two-step process: the consumer clearly requests to opt in, then separately confirms that choice.
  • Do not treat closing a notice, accepting broad terms, or a dark-pattern interaction as consent.
  • Check the separate opt-in rules before selling or sharing personal information when the business has actual knowledge that the consumer is under 16.
Section 4

What should implementation evidence show?

Privacy should own the legal classification and notice language; engineering or product should own detection and state propagation; advertising operations should stop covered tags and transfers; vendor management should confirm downstream instructions and contracts. Assign one control owner to reconcile these parts.

Test with on and off, signed in and signed out, on a new device, after cookie clearing, and after a privacy-setting conflict. Evidence should show the received signal, identifiers and profiles in scope, decision time, suppression state, downstream action, and any consumer-facing confirmation. Avoid retaining raw request data beyond what is needed to process and demonstrate the control.

  • Inventory every pixel, SDK, API, audience export, identity graph, and offline transfer that can sell or share personal information.
  • Record how the preference propagates to first-party profiles, consent tools, tag managers, advertising partners, and offline suppression lists.
  • Notify and direct any third party that received the information after the request but before compliance, as section 7026 requires.
  • Repeat tests after changes to domains, applications, identity resolution, advertising vendors, consent tools, or financial incentive programs.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Official CPPA source for sections 7001, 7004, 7013, 7025, 7026, and 7028 governing opt-out preference signals, request methods, consent, and opt-in.
cppa.ca.gov
Referenced sections
  • Defines an opt-out preference signal, states the qualification test, requires businesses that sell or share personal information to process it, sets the narrow conditions for omitting opt-out links, and explains why a cookie control alone is not a sale-or-sharing opt-out method.
cppa.ca.gov
Referenced sections
  • Identifies GPC as an example of a qualifying opt-out preference signal and explains that covered businesses must honor such signals as sale-and-sharing opt-outs.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.