Artifact GuideUSGPC Handling Workflow

US CPRA GPC Handling Workflow

Treat a qualifying browser or device privacy signal as a sale-or-sharing opt-out, stop covered disclosure as soon as feasibly possible, extend the opt-out to associated profiles, and preserve proof that downstream flows stopped.

The CCPA regulations require businesses that sell or share personal information to process the signal; a privacy link or cookie banner does not replace that duty.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

An such as is a technical signal that clearly communicates a consumer's choice to stop sale or sharing of personal information. A business that sells or shares must treat a commonly used, recognized signal as a valid opt-out for the browser or device and every associated consumer profile, including pseudonymous profiles. Do not require identity verification, an account, or extra steps. The signal does not request deletion or stop collection and first-party use by itself.

Section 1

How should a GPC Handling Workflow run under the US CPRA?

Detect the signal at every consumer-facing domain, app, and relevant endpoint and stop sale or sharing as soon as feasibly possible. Confirm that the format is commonly used and recognized, such as an HTTP header or JavaScript object, and that the sending mechanism tells consumers the signal opts them out of sale and sharing. The regulations do not condition validity on a California-only disclosure.

Apply the signal to the browser or device and all associated profiles. If the consumer is known, apply it to that consumer, including offline sale or sharing. If the consumer is unknown, do not demand identifying information; optional information may be offered only to extend the request and may be used, disclosed, and retained only to process the opt-out.

A conflicting business-specific setting does not cancel the signal. Honor it, then the business may notify the consumer and seek CCPA-compliant consent. A financial-incentive program may use the regulation's separate confirmation branch. When the consumer is known, the later absence of a signal is not consent to opt back in.

Posting a Do Not Sell or Share link, Alternative Opt-out Link, or privacy-policy form does not excuse signal processing. A business may omit specified links only when it processes signals in a , makes the required privacy-policy disclosures, and the signal fully effectuates online and offline sale-or-sharing opt-outs.

  • Inventory every sale or sharing path, including tags, pixels, software development kits, identity graphs, ad-tech endpoints, and downstream third parties.
  • Test signal detection before consent tools initialize and confirm through network and server evidence that blocked recipients receive no personal information after the signal.
  • Apply the preference to the browser or device and to a known profile when it can be associated with the consumer; do not require verification.
  • Stop sale or sharing as soon as feasible and no later than 15 business days; notify third parties that received information after the request but before compliance and preserve transmission or suppression evidence.
  • Record test date, signal value, environment, resulting network behavior, profile state, exceptions, owner, and remediation.
Section 2

What fields should the GPC Handling Workflow template capture?

The privacy engineering or consent owner should maintain evidence that the signal was detected, translated into a sale-or-sharing opt-out, applied to the correct scope, propagated downstream, and preserved where the business can recognize the consumer.

  • Domain, app, environment, browser or device, signal header or API value, capture time, and test owner.
  • Consent-platform state, tags or SDKs evaluated, sale-or-sharing classification and rationale, blocked and allowed recipients, network evidence, and 15-business-day completion deadline.
  • Profile association result, known or unknown consumer state, offline scope, account preference, local-state record, third-party instruction, and confirmation.
  • Business-setting or financial-incentive conflict, consent or affirmation record, frictionless-link eligibility, defect ticket, remediation deadline, regression result, reviewer, and next test date.
Section 3

How should teams review and improve the GPC Handling Workflow?

Run regression tests after changes to consent software, tag managers, advertising partners, domains, apps, login flows, or identity systems. Test signed-in and signed-out sessions, first visits, cleared storage, multiple browsers, delayed scripts, offline profile propagation, and known-consumer return visits. A visible privacy message does not prove that sale or sharing stopped.

  • Inventory every current recipient and retest its classification as sale, sharing, service-provider processing, contractor processing, or another disclosed use.
  • Compare page-load and server-side events with and without the signal; investigate any covered disclosure that occurs before or after the consent layer changes state.
  • Confirm a known consumer's opt-out survives a later session or device without a signal; do not treat signal absence as opt-in.
  • Recheck whether frictionless processing fully reaches offline activity before omitting any statutory opt-out link.
Primary sources

References and citations

cppa.ca.gov
Referenced sections
  • Review source for maintaining opt-out preference signal handling after regulatory or product changes.
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
cppa.ca.gov
Referenced sections
  • Confirms the consumer-facing GPC rule that businesses must honor qualifying opt-out preference signals for sale and sharing.
"Businesses must honor opt–out preference signals (“OOPS”) that meet certain requirements, such as the Global Privacy Control"
globalprivacycontrol.org
Referenced sections
  • Supports testing the technical signal sent by a browser or extension; the CPPA regulations control the California scope and response.
"GPC lets users signal their desired privacy, just by browsing"
nist.gov
Referenced sections
  • Optional, nonbinding crosswalk resource for mapping privacy engineering activities; it does not establish California GPC duties.
"Organizations should not assume implementation of these Privacy Framework activities or outcomes means that they have met the"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.