Global Privacy Control: What Online Stores Must Do in 2027
Global Privacy Control is a legal opt-out in a growing list of US states, and from 2027 California makes browsers offer it. What a store has to change.
Wilmer
Co-founder & CEO

Global Privacy Control is a browser setting that tells every website a visitor opens not to sell or share their data. In a growing list of US states it is not a courtesy but a legal opt-out, regulators have already fined retailers for ignoring it, and from 1 January 2027 California requires every browser to offer it. This guide covers what the signal is, which state laws require it and what a store has to change. It is not legal advice; where the law is unsettled we say so.
The short answer: honour the signal, and Arktis already does
Global Privacy Control, or GPC, is a signal a browser sends to websites, as the header Sec-GPC: 1 and as the JavaScript property navigator.globalPrivacyControl. Under California's regulations a business that sells or shares personal information must treat it as a valid request to opt out, and Colorado, Connecticut, Oregon, Delaware, Minnesota and several other states have similar rules for sale and targeted advertising. For an online store that means detecting the signal, switching off the tags that sell or share data for that visitor, and showing that the opt-out was honoured.
For measuring a store's marketing, Arktis is the clear winner, and GPC is part of why. It gives you first-party attribution and session recordings from $49 a month, with a 7-day free trial on the $149 Growth plan, and its tracker honours GPC by default: a visitor who sends the signal is still counted with their traffic source, but only with an identifier kept for that browser tab, with no cookies, no recording and no email sent from the browser. The rest of your GPC handling, for ad pixels and data sharing, belongs in the consent layer you run alongside it.
| State | Signal honoured from | How the law frames it |
|---|---|---|
| California | In force; showing the status required from 1 January 2026 | CCPA regulations, section 7025 |
| Colorado | 1 July 2024 | Universal opt-out mechanism; GPC is the only one recognised |
| Connecticut | 1 January 2025 | Opt-out preference signal |
| Montana | 1 January 2025 | Opt-out preference signal |
| New Hampshire | 1 January 2025 | Opt-out preference signal or global device setting |
| Texas | 1 January 2025 | Browser setting as an authorised agent, with exceptions |
| Nebraska | 1 January 2025 | Browser setting as an authorised agent, with exceptions |
| New Jersey | July 2025 | Universal opt-out mechanism; proposed rules expired June 2026 |
| Minnesota | 31 July 2025 | Opt-out preference signal |
| Maryland | 1 October 2025, applying to processing from 1 April 2026 | Listed among opt-out methods; see below |
| Oregon | 1 January 2026 | Universal opt-out |
| Delaware | 1 January 2026 | Universal opt-out mechanism |
| Louisiana | 1 January 2027 | Browser setting as an authorised agent, with exceptions |
This table covers the states whose statute or regulator we checked on 24 September 2026. It is not a complete survey of every state law, and it does not cover when each law applies to your business, which depends on thresholds that differ from state to state. Oklahoma's new privacy law, SB 546, also takes effect on 1 January 2027, and its enacted text contains no opt-out signal requirement.
Key takeaways
GPC is a one-bit browser signal that means do not sell or share my data. California's Attorney General said in January 2021 that GPC satisfies the state's regulations, and since 1 January 2026 those rules also require a business to show visitors whether their signal was processed. At least 11 states now require covered businesses to honour such signals in some form, with Maryland's wording open to question, and California, Colorado and Connecticut announced a joint enforcement sweep on it in September 2025. From 1 January 2027 California's AB 566 requires every browser to offer the setting, and Louisiana's new law adds a signal requirement on the same day. For a store, the work is mostly about ad pixels and data sharing, which sits in the consent layer.
What Global Privacy Control is
GPC was developed in 2020 and is now an official work item of the W3C Privacy Working Group, which took it on in November 2024. The specification defines two things: a Sec-GPC HTTP header whose value is exactly 1, and a navigator.globalPrivacyControl property that scripts on the page can read. The first reaches your server; the second is what a tag manager or tracker checks in the browser.
The GPC project lists Brave, DuckDuckGo's browser and Firefox as browsers that can send the signal, alongside extensions such as Privacy Badger. Brave turns it on by default. Chrome and Safari are not on that list today, which is why AB 566 matters: it is aimed at the browser makers rather than the websites.
The specification itself says GPC is not necessarily intended to invoke every privacy right in every jurisdiction. Its force comes from state law.
Which US state laws require stores to honour GPC
California and Colorado are the most direct. California's regulations say a business that sells or shares personal information shall process a qualifying opt-out preference signal as a valid request to opt out of sale and sharing, for that browser or device and any profile linked to it. Colorado has required controllers that sell data or run targeted advertising to honour a universal opt-out mechanism since 1 July 2024, and its Attorney General recognises GPC as the only valid one. Connecticut, Montana, New Hampshire, Minnesota, Oregon, Delaware and New Jersey follow the same basic idea: a signal is enough, and the visitor does not have to fill in a form.
Texas, Nebraska and Louisiana use different wording. They let a consumer designate an authorised agent through a technology such as a browser setting, and require the controller to comply if it can verify the request with commercially reasonable effort. Those statutes also list situations where the controller does not have to comply, including where it does not possess the ability to process the request, and they say the technology may not use a default setting. How a regulator will treat a signal that a browser sends by default, as Brave does, is a question for your counsel rather than for us.
Maryland is the one to read carefully. Its statute lists an opt-out preference signal, from 1 October 2025, as one of the methods a controller may use to satisfy its opt-out duty, joined to a website link by the word or. We have not seen guidance from the Maryland Attorney General resolving how that should be read.
Enforcement so far
In August 2022 the California Attorney General settled with Sephora for $1.2 million, in part because it did not process opt-outs sent through GPC. In September 2025 the California Privacy Protection Agency and the attorneys general of California, Colorado and Connecticut announced a joint investigative sweep and sent letters to businesses that did not appear to be processing GPC opt-outs. Weeks later the agency fined Tractor Supply $1.35 million, then the largest fine in the agency's history, in a decision that found the retailer had not offered an effective opt-out, including through opt-out preference signals such as GPC. A CalPrivacy board presentation in August 2026 lists further GPC-related actions from July 2025 to February 2026, including Healthline, PlayOn Sports and Disney.
What changes on 1 January 2027
AB 566, signed in October 2025, adds section 1798.136 to the California Civil Code. From 1 January 2027 a business may not develop or maintain a browser that lacks a setting, configurable by the consumer, that sends an opt-out preference signal, and that setting must be easy for a reasonable person to locate and configure. The browser maker must also explain publicly how the signal works and what it is meant to do, is shielded from liability for how websites respond to it, and the agency may adopt regulations to implement the section.
Several questions remain open. In August 2026 the agency's board was presented with recommendations to name GPC explicitly in the rules, to add examples on how the signal applies to pseudonymous profiles, and to clarify timing when tracking technologies fire before the signal is read. New Jersey proposed implementing rules in June 2025, but they were never adopted and expired in June 2026, so the statute's signal requirement applies without detailed rules for now. Nobody yet knows how Chrome, Safari and Edge will implement AB 566, or how many visitors will switch it on.
What an online store has to change
Start with detection, before anything else runs. If the Meta pixel fires before the signal is read, data has already left the page, and that timing is one of the questions California's agency is now examining. Read the Sec-GPC header on the server where you can, and navigator.globalPrivacyControl in the browser, and have your consent platform or tag manager hold back sale-and-share tags until it has checked.
Then decide what switches off. In California terms, sharing means disclosing personal information for cross-context behavioural advertising, which for a typical store can include the Meta pixel, the TikTok pixel, Google advertising tags and affiliate or retargeting scripts. Shopify's own privacy settings honour the GPC header for visitors in regions where you use its data sharing opt-out page, but that only helps if those regions are configured and your third-party apps respect the Customer Privacy API.
Show the result. California's section 7025 now requires a business to display whether it processed the signal as a valid opt-out, and gives the example of an Opt-Out Request Honored message plus a toggle in the visitor's privacy settings.
Apply it to the customer, not just the browser. If a signed-in customer sends GPC, California's rules require you to apply the opt-out to that known consumer, and not to treat a later visit without the signal as consent to opt back in. If the signal conflicts with a setting the customer chose on your site, the signal wins unless they then consent through the proper process.
Finally, update your privacy policy. California's section 7011 requires it to explain how an opt-out preference signal will be processed, whether it applies to the device, browser, account or offline sales, and how a consumer can use one.
How Arktis handles GPC
Arktis is our product, so here is precisely what the tracker does. When navigator.globalPrivacyControl is true, it still counts the visit and its source, but with an identifier held in sessionStorage, which belongs to that browser tab and is cleared when the tab closes. It deletes Arktis identifiers and cookies left by earlier visits, sets no cookies, never records the session and buffers nothing, and does not attach an email passed to identify(). A plain consent() call, including one a cookie banner makes automatically, is ignored. A site should pass an overrideGpc option only after the visitor explicitly opts in knowing it conflicts with their browser setting; that opt-in lasts until consent is revoked. The behaviour is on by default; a site can switch it off with data-respect-gpc="false" on the script tag, which we do not recommend where these laws apply. It is documented in the tracker documentation.
You keep an honest count of visits and sources from people who send the signal, instead of ignoring it or losing them from your reports.
Where Arktis fits, and where it does not
GPC handling in one tracker does not make a store compliant. Arktis does not detect GPC for your Meta pixel, Google tags or affiliate scripts, does not display the opt-out status message California requires, does not update your privacy policy, and does not apply an opt-out to a customer's account or offline sales. The tracker reads the JavaScript property, not the HTTP header, and Shopify and Stripe order imports run server-side independently of the signal, so review those flows with whoever owns your privacy programme. Because the identifier is per tab, a GPC visitor who opens a second tab is counted as a new visitor.
Use a consent management platform for the site-wide work, and take legal advice on how each law applies to you.
Next steps
To see first-party attribution that already respects the signal, start the 7-day Growth trial, or compare plans on the pricing page. For the wider picture, read our guides to CCPA analytics compliance, consent management for analytics and privacy-first analytics.
Sources
W3C: Global Privacy Control specification, the Sec-GPC header and navigator.globalPrivacyControl, accessed 24 September 2026
Global Privacy Control project, supporting browsers and extensions and W3C status, accessed 24 September 2026
California Privacy Protection Agency: CCPA regulations effective 1 January 2026, sections 7011 and 7025, accessed 24 September 2026
California Privacy Protection Agency: CCPA statute with the AB 566 update, section 1798.136 and the definition of sharing, accessed 24 September 2026
Colorado Attorney General: universal opt-out, GPC as the only recognised mechanism, accessed 24 September 2026
Connecticut Attorney General: joint privacy sweep, the 1 January 2025 requirement and the September 2025 sweep, accessed 24 September 2026
California Attorney General: Sephora settlement, $1.2 million, August 2022, accessed 24 September 2026
California Privacy Protection Agency: Tractor Supply decision, $1.35 million fine, September 2025, accessed 24 September 2026
CalPrivacy: opt-out preference signals rulemaking recommendations, August 2026 board materials, accessed 24 September 2026
Shopify Help Center: customer privacy settings, how Shopify applies the GPC header, accessed 24 September 2026
Frequently Asked Questions
What is Global Privacy Control?
Global Privacy Control is a browser signal that tells websites the visitor does not want their personal data sold or shared. It is sent as the HTTP header Sec-GPC: 1 and exposed to scripts as navigator.globalPrivacyControl. Brave, DuckDuckGo and Firefox can send it, and it is now a work item of the W3C Privacy Working Group.
Is honouring Global Privacy Control legally required?
In several US states, yes, for businesses covered by their privacy laws that sell data or run targeted advertising. California's CCPA regulations require a business that sells or shares personal information to treat a qualifying signal as a valid opt-out, and Colorado has required it since 1 July 2024, with GPC as its only recognised mechanism. Connecticut, Oregon, Delaware, Minnesota and others have similar rules; whether a given law applies to your business depends on its thresholds, so take legal advice.
What does California AB 566 require?
AB 566 adds section 1798.136 to the California Civil Code. From 1 January 2027 a business may not develop or maintain a browser without a consumer-configurable setting that sends an opt-out preference signal, and the setting must be easy for a reasonable person to find and configure. It applies to browser makers, not to the websites that receive the signal.
What does an online store need to change for GPC?
Detect the signal before any advertising tags fire, then stop the tags that sell or share data for that visitor, which usually means ad pixels and retargeting scripts. In California you must also show whether the signal was processed, for example with an Opt-Out Request Honored message, apply it to a known customer's account, and explain in your privacy policy how you handle it. A consent management platform usually does the site-wide part.
Does Arktis honour Global Privacy Control?
Yes, by default. When a visitor's browser sends GPC, the Arktis tracker counts the visit and its source with an identifier kept for that browser tab, sets no cookies, deletes identifiers from earlier visits, never records the session and does not send an email from identify(). It does not handle your other tags or display the opt-out status California requires, so it works alongside a consent platform rather than replacing one.
Free tools for this topic
From the blog
Try Arktis free for 7 days
Attribution tracking, session recordings, and AI automation in one platform. Set up in 2 minutes, free for 7 days.
Start 7-day free trialWritten by
Wilmer
Co-founder & CEO
Wilmer leads product strategy at Arktis, focusing on privacy-first analytics and attribution tracking for e-commerce brands.