Does the CCPA require honoring Global Privacy Control?
Yes. Under the CCPA, a business that sells or shares personal information and collects it online must treat an opt-out preference signal, such as Global Privacy Control, as a valid request to opt out of sale or sharing. It has 15 business days to comply, and must let the consumer confirm the request was processed.
Applies to: Any business that must comply with the CCPA, collects California consumers' personal information online, and sells or shares that information; such a business must process opt-out preference signals like Global Privacy Control as valid opt-out requests.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanMost CCPA opt-out advice stops at the "Do Not Sell or Share My Personal Information" link. The link is only half the rule. If a browser sends your site an opt-out preference signal, California treats that as the consumer opting out, and you have to honor it whether or not the person ever clicks your link. Global Privacy Control is the signal that makes this real, and ignoring it is exactly what recent enforcement has gone after.
What is an opt-out preference signal?
An opt-out preference signal is a message a browser, extension, or device sends automatically to every site a consumer visits, telling each business the consumer wants to opt out of the sale or sharing of their personal information. Global Privacy Control, or GPC, is the leading example. It travels as an HTTP header field or a JavaScript object, so the business receives it in the background without the consumer filling in a form or hunting for a link. California Civil Code section 1798.135(b) recognizes the signal, and the CCPA regulations at 11 C.C.R. section 7025 spell out how a business must respond to it.
Which businesses have to honor it?
The duty is not universal. Under the CCPA regulations, a business must treat GPC as a valid opt-out if three things are true: it is a "business" that must comply with the CCPA, it collects personal information from consumers online, and it sells or shares that personal information. "Share" here means disclosing personal information for cross-context behavioral advertising, which sweeps in a lot of ordinary ad-tech and analytics setups that companies do not think of as selling data. If you do not sell or share, you do not have to process the signal, but you still owe the rest of the CCPA.
What do you have to do when a signal arrives?
Section 1798.135(b) lets a business use the signal as its opt-out method instead of the two homepage links, or alongside them. When GPC arrives, you stop selling and sharing the personal information tied to that browser or device, including any pseudonymous profile connected to it. If the consumer is logged in and therefore known to you, you apply the opt-out to their whole account. The California Privacy Protection Agency's guidance sets the outer limit at 15 business days from receiving the request. You cannot charge a fee for using the signal or degrade the consumer's experience because they sent it.
How the consumer knows the signal is being honored
This is the part that changed on January 1, 2026, and it is the question most people actually arrive with: how do I tell whether a site is honoring my opt-out signal, or, from the other side, how do I show that mine is?
The answer is now a duty rather than a courtesy. Under 11 C.C.R. section 7026(g), a business must provide a means by which the consumer can confirm that their request to opt out of sale/sharing has been processed. The regulation supplies its own example: displaying "Opt-Out Request Honored" on the website, and displaying in the consumer's privacy settings, through a toggle or radio button, that the consumer has opted out of the sale and sharing of their personal information.
Two details are worth pinning down because older write-ups get them wrong. Before the amendment the display was permissive, the text said a business may display it, and the suggested wording was "Opt-Out Preference Signal Honored". The current text is mandatory and the suggested string is "Opt-Out Request Honored". If your site shows the old phrase, it is not wrong so much as dated, but if your site shows nothing at all, that is now a gap.
The same duty is what makes the two exception paths workable. Where a known consumer has previously consented to the sale of their information, or where a controller-specific setting conflicts with the signal, the regulations let the business resolve the conflict a particular way, but in either case the business must display the status of the consumer's choice. The consumer is never left guessing.
What happens when the scoping is too narrow
The clearest illustration of getting this wrong is the Disney settlement, announced in February 2026 with $2.75 million in civil penalties.
Disney did detect GPC. The finding against it was that when a consumer opted out through GPC, Disney limited the request to the specific device the consumer was using, even when that consumer was logged into their account. The signal was received, acknowledged and then applied to a fraction of what it should have covered.
That maps directly onto section 7025(c)(1), which requires the business to treat the signal as a valid opt-out for that browser or device and any consumer profile associated with it, including pseudonymous profiles, and then adds that if the consumer is known, the business shall also treat it as a valid opt-out for the consumer. Known means account-wide.
The frictionless option
A business that processes GPC in a "frictionless" manner, meaning it does not charge the consumer, change their experience, or throw up an interstitial, can skip posting the "Do Not Sell or Share My Personal Information" link entirely. That is the trade the regulations offer: honor the signal cleanly and you lose the link obligation. You still have to describe the opt-out right and the signal in your privacy policy. For the link-based route, see CCPA Do Not Sell or Share, and pair this with your CCPA notice at collection.
Next step
If your site runs advertising or analytics that count as selling or sharing under the CCPA, the free 2-minute Obligation Scan checks whether you are required to honor Global Privacy Control and lists the opt-out, link, and privacy-policy steps that go with it, so a background signal does not turn into an enforcement action. The US state privacy laws hub shows how this sits inside your wider CCPA duties.
Compliance checklist
- Confirm you are covered: you meet a CCPA threshold, you collect personal information online, and you sell or share it. If all three are true, you must honor opt-out preference signals.
- Configure your site to detect an opt-out preference signal such as Global Privacy Control, sent as an HTTP header field or a JavaScript object.
- Treat the signal as a valid request to opt out of sale and sharing, and stop selling or sharing that browser's or device's personal information no later than 15 business days after receiving it.
- Apply the opt-out to any pseudonymous profile tied to that browser or device, and to the logged-in consumer's whole account if they are known to you, which is the exact scoping failure California penalized Disney for.
- Give the consumer a way to confirm the request was processed, which section 7026(g) has required since January 1, 2026.
- Do not require the consumer to supply extra information to make the signal work; section 7025(c)(2) forbids asking for more than is needed to send it.
- If you process the signal in a frictionless way, you may drop the Do Not Sell or Share link, but you must still describe the signal and the opt-out right in your privacy policy.
Sources
- Cal. Civ. Code § 1798.135 (Methods of limiting sale, sharing, and use; opt-out preference signal), California Legislative Information
- CCPA Updates, Cyber, Risk, ADMT and Insurance Regulations, approved text (11 C.C.R. §§ 7025, 7026), effective January 1, 2026, California Privacy Protection Agency
- Global Privacy Control, Office of the Attorney General of California
- California Won't Let It Go: Attorney General Bonta Announces $2.75 Million Settlement with Disney (February 11, 2026), California Department of Justice
Last verified: 2026-09-10
Informational, not legal advice.