Private Pierce

Global Privacy Control and where it is binding

Global Privacy Control sends a technical preference signal, but its legal effect depends on the authority, covered processing, conditions, and effective date. Colorado expressly recognizes GPC; California requires conforming opt-out preference signals; ten other captured states recognize qualifying signals, mechanisms, or agent technologies.

Updated

Not legal advice. This page is research, not compliance guidance.

What is Global Privacy Control?

Global Privacy Control is a technical signal for expressing a general preference not to have personal information sold or shared; the technical specification does not itself create one national legal consequence.

The current technical record is W3C Working Draft 24 September 2026; Sec-GPC: 1; navigator.globalPrivacyControl. (source) The World Wide Web Consortium working draft describes an HTTP `Sec-GPC` header and a `navigator.globalPrivacyControl` property. Its stated semantics are a general universal preference for a do-not-sell-or-share interaction. That description defines the signal and its transport; it does not identify the businesses covered by a law, the processing a law reaches, or the response a particular authority requires.

A legal recognition record supplies those missing parts. The useful comparison asks five separate questions: which authority issued the rule, which entity is covered, which processing or right is at issue, what response is required, and which conditions limit that response. A technical signal can remain the same while those legal answers change.

The distinction matters because the phrase universal preference describes how the signal communicates a preference, not universal legal coverage. The captured records do not establish a federal GPC mandate. They also do not establish that the signal is a deletion request, an access request, a direction to erase public records, or a command that reaches every controller, broker, website, application, or downstream recipient.

Where does a captured record expressly recognize Global Privacy Control?

Colorado expressly names Global Privacy Control as a recognized universal opt-out mechanism, while the captured California record supports a conforming opt-out preference signal rule without naming GPC.

  • Colorado — GPC is a recognized Colorado universal opt-out mechanism. (source) The Colorado Department of Law record says covered businesses must allow consumers to use GPC to opt out of sale of personal data or targeted advertising beginning July 1, 2024. Recognition remains subject to the Colorado Privacy Act and the state's universal opt-out mechanism rules.
  • California — Conforming opt-out preference signals are valid requests to opt out of sale or sharing. (source) The controlling California Privacy Protection Agency regulation requires a business that sells or shares personal information to process a conforming opt-out preference signal as a valid opt-out request, subject to the regulation's format and intent conditions.

These two records support different formulations. Colorado's official mechanism page expressly calls GPC a valid universal opt-out mechanism. California's controlling regulation states a rule for conforming opt-out preference signals, but the cell does not support a GPC-specific California claim. The two authorities should not be collapsed into one national sentence or treated as if their covered processing and conditions were identical.

Express recognition also does not prove that every transmission reached a covered business, matched the required format, reflected the consumer's intent, or was processed correctly. Those are event- and entity-specific questions beyond the authority records. The records establish the rule and its boundary, not compliance by a particular recipient.

Which captured states require a qualifying signal or universal opt-out mechanism?

Connecticut, Delaware, Montana, New Hampshire, Minnesota, Maryland, New Jersey, and Oregon require covered controllers to recognize specified opt-out signals or mechanisms; none of these eight operative records names GPC.

  • Connecticut — Controllers must allow opt-out preference signals for targeted advertising and sale. (source) The captured rule applies not later than January 1, 2025, and includes consent, resident, and legitimate-request conditions.
  • Delaware — Controllers must allow opt-out preference signals for targeted advertising and sale. (source) The captured rule applies not later than January 1, 2026, and requires an affirmative, freely given, and unambiguous choice plus reasonable resident and request checks.
  • Montana — Controllers must allow opt-out preference signals for targeted advertising and sale. (source) The captured rule applies by January 1, 2025, and keeps consumer consent and request-validation conditions attached.
  • New Hampshire — Controllers must allow opt-out preference signals for targeted advertising and sale. (source) The captured statute requires the signal path not later than January 1, 2025, subject to its stated choice and request conditions.
  • Minnesota — Controllers must allow opt-out preference signals for targeted advertising and sale. (source) The captured statute is effective July 31, 2025, with a later compliance date noted for regulated postsecondary institutions.
  • Maryland — Controllers must allow opt-out preference signals for targeted advertising and sale on or before October 1, 2025. (source) The captured rule requires the signal path on or before October 1, 2025, and states choice, residency, request, and no-default-setting limits.
  • New Jersey — Controllers must allow a user-selected universal opt-out mechanism for targeted advertising and sale. (source) The captured enacted law uses a relative implementation period rather than a calculated calendar date and requires a user-selected universal opt-out mechanism.
  • Oregon — Controllers must accept a platform, technology, or mechanism carrying an opt-out signal for sale or targeted advertising. (source) The current-code capture requires an opt-out signal path but does not assign an effective date from that record.

These records establish duties for qualifying opt-out preference signals, universal opt-out mechanisms, or similar technology. They do not support rewriting every rule as GPC-specific. Whether GPC satisfies each authority's format, consent, residency, request, and technical conditions requires the authority's own rule and the actual implementation.

The processing scope is also narrower than a general privacy command. These captured rules concern sale, targeted advertising, or both. They do not establish a deletion right, access right, correction right, profiling opt-out, or public-record change unless the cited authority says so separately.

How do Nebraska and Texas treat browser or device settings?

Nebraska and Texas allow browser settings, extensions, or global device settings to operate as authorized-agent technology for specified opt-outs, subject to verification and processing conditions.

  • Nebraska — A browser or global-device setting may act as an authorized agent for sale and targeted-advertising opt-outs, subject to statutory conditions. (source) The current statute capture does not print an effective date, so none is inferred here.
  • Texas — A browser or global-device setting may act as an authorized agent for sale and targeted-advertising opt-outs, subject to statutory conditions. (source) The captured enrolled-law record assigns January 1, 2025, to this mechanism.

Both records preserve conditions: the request must be clear and unambiguous, the controller may make a commercially reasonable effort to verify identity and agent authority, and the captured rules include residency, processing-capability, and comparable-request limits. The technology can carry an authorized request; its presence does not establish that every controller received, could process, or was legally required to honor every setting.

These rows should not be summarized as unconditional GPC mandates. They recognize a technology pathway for an authorized agent and identify the rights at issue. A conclusion about GPC in a particular transaction would need the technical signal, the statutory conditions, the controller's coverage, and the event-specific facts to align.

Are signal recognition, broker registration, and deletion the same mechanism?

No. Signal recognition governs a covered opt-out path, broker registration identifies entities within a registry rule, and deletion follows a separate right and request process.

The three mechanisms answer different questions. A recognition rule asks whether a covered entity must respond to a qualifying preference signal or mechanism for specified processing. A data-broker registry asks which entities a statute defines and requires to register. A deletion process asks whether a person has a right to request deletion, which entity receives the request, and what scope, exception, or confirmation applies.

What Is a Data Broker? owns the data-broker definition and registry-population boundary. Get Your Business Data Deleted, State by State — What's Actually Possible owns state deletion rights, portals, eligibility, and request-process limits. Neither page turns registration into GPC recognition, and this page does not turn a transmitted signal into a completed deletion request.

A registry entry does not establish that an entity received or honored a signal. A transmitted signal does not establish that the recipient is a registered broker. A submitted deletion request does not establish that deletion was completed. Keeping those states separate prevents one observable event from being used as evidence for another.

What does a control signal establish across other systems?

A control signal establishes no change to a public filing, deed index, assessor portal, tax roll, or separate commercial profile unless evidence from that named system shows the change.

A signal and its legal recognition remain bounded to the processing and entity the rule covers. An opt-out mechanism on one commercial system does not establish that another commercial system changed. It also does not establish that a public filing or government index was altered, suppressed, or deleted.

This boundary is why the page uses authority-specific narrative records instead of a fifty-state matrix. The records behind this page are one technical specification and twelve state rules. They do not contain a result for every state, and absence from this page is not a finding that another state rejects GPC. The page names only accepted records and leaves unsupported jurisdictions unclassified.

The authority records also do not establish compliance or enforcement outcomes for a named business. They do not show that a particular signal was sent, received, interpreted, or honored. They do not establish a cure period, penalty, private right of action, or enforcement result unless the individual record states that fact. A source-mapped rule is not an event log.

What are the limits of this Global Privacy Control map?

This map identifies one technical specification and twelve captured state rules; it does not establish universal recognition, deletion, cross-system change, a complete state count, or compliance by any named business.

The technical record is a World Wide Web Consortium working draft dated September 24, 2026. The authority records were checked on October 6, 2026. Those dates matter because specifications, statutes, regulations, and official guidance can change. A later decision should return to the cited primary source and its current status.

Only Colorado's captured official mechanism page expressly labels GPC as a recognized universal opt-out mechanism. California's captured controlling regulation addresses conforming opt-out preference signals without naming GPC. The other ten captured state records establish signal, mechanism, or authorized-agent pathways; none of those ten operative records names GPC. No broader GPC-specific claim is inferred from similar wording.

The page does not establish that any unlisted jurisdiction accepts or rejects GPC. It does not establish that GPC deletes data, changes a public record, reaches every data broker, or substitutes for a jurisdiction-specific deletion request. It does not establish that a signal default reflects an affirmative consumer choice where an authority requires one. It does not establish that a particular controller falls within an authority's coverage or that a particular request was legitimate.

This is a sourced explanation of captured rules, not legal advice or a compliance verdict. The Private Pierce methodology explains how the site binds claims to dated sources, preserves unknowns, and states what the evidence does not establish.

Frequently asked questions

What is Global Privacy Control?

Global Privacy Control is a technical signal for expressing a general preference not to have personal information sold or shared. The technical specification does not itself create one national legal consequence.

Where is Global Privacy Control legally recognized?

In the captured records, Colorado expressly recognizes GPC as a valid universal opt-out mechanism. California requires conforming opt-out preference signals without naming GPC. Ten additional captured states recognize qualifying signals, mechanisms, or authorized-agent technology; none of those ten operative records names GPC.

Does Global Privacy Control delete data?

No deletion result follows from the signal alone. The captured recognition rules concern specified opt-outs, while deletion rights, request procedures, exceptions, and confirmation are separate questions.

Is Global Privacy Control the same as a data-broker deletion request?

No. A qualifying control signal can carry an opt-out preference for covered processing, while a data-broker deletion request follows a separate jurisdiction-specific right and process.

Related research

Submit a correction