Does the CCPA require honoring Global Privacy Control?
Yes. Under the CCPA, a business that sells or shares personal information and collects it online must treat an opt-out preference signal, such as Global Privacy Control, as a valid request to opt out of sale or sharing. The CCPA regulations (11 C.C.R. sections 7025 and 7026) require honoring it within 15 business days.
Applies to: Any business that must comply with the CCPA, collects California consumers' personal information online, and sells or shares that information; such a business must process opt-out preference signals like Global Privacy Control as valid opt-out requests.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanFounding 30% off with code FOUNDING until 15 August 2026
Most CCPA opt-out advice stops at the "Do Not Sell or Share My Personal Information" link. The link is only half the rule. If a browser sends your site an opt-out preference signal, California treats that as the consumer opting out, and you have to honor it whether or not the person ever clicks your link. Global Privacy Control is the signal that makes this real, and ignoring it is exactly what recent enforcement has gone after.
What is an opt-out preference signal?
An opt-out preference signal is a message a browser, extension, or device sends automatically to every site a consumer visits, telling each business the consumer wants to opt out of the sale or sharing of their personal information. Global Privacy Control, or GPC, is the leading example. It travels as an HTTP header field or a JavaScript object, so the business receives it in the background without the consumer filling in a form or hunting for a link. California Civil Code section 1798.135(b) recognizes the signal, and the CCPA regulations at 11 C.C.R. section 7025 spell out how a business must respond to it.
Which businesses have to honor it?
The duty is not universal. Under the CCPA regulations, a business must treat GPC as a valid opt-out if three things are true: it is a "business" that must comply with the CCPA, it collects personal information from consumers online, and it sells or shares that personal information. "Share" here means disclosing personal information for cross-context behavioral advertising, which sweeps in a lot of ordinary ad-tech and analytics setups that companies do not think of as selling data. If you do not sell or share, you do not have to process the signal, but you still owe the rest of the CCPA.
What do you have to do when a signal arrives?
Section 1798.135(b) lets a business use the signal as its opt-out method instead of the two homepage links, or alongside them. When GPC arrives, you stop selling and sharing the personal information tied to that browser or device, including any pseudonymous profile connected to it. If the consumer is logged in and therefore known to you, you apply the opt-out to their whole account. The California Privacy Protection Agency's guidance sets the outer limit at 15 business days from receiving the request. You cannot charge a fee for using the signal or degrade the consumer's experience because they sent it.
The frictionless option
A business that processes GPC in a "frictionless" manner, meaning it does not charge the consumer, change their experience, or throw up an interstitial, can skip posting the "Do Not Sell or Share My Personal Information" link entirely. That is the trade the regulations offer: honor the signal cleanly and you lose the link obligation. You still have to describe the opt-out right and the signal in your privacy policy. For the link-based route, see CCPA Do Not Sell or Share, and pair this with your CCPA notice at collection.
Next step
If your site runs advertising or analytics that count as selling or sharing under the CCPA, the free 2-minute Obligation Scan checks whether you are required to honor Global Privacy Control and lists the opt-out, link, and privacy-policy steps that go with it, so a background signal does not turn into an enforcement action. The US state privacy laws hub shows how this sits inside your wider CCPA duties.
Compliance checklist
- Confirm you are covered: you meet a CCPA threshold, you collect personal information online, and you sell or share it. If all three are true, you must honor opt-out preference signals.
- Configure your site to detect an opt-out preference signal such as Global Privacy Control, sent as an HTTP header field or a JavaScript object.
- Treat the signal as a valid request to opt out of sale and sharing, and stop selling or sharing that browser's or device's personal information no later than 15 business days after receiving it.
- Apply the opt-out to any pseudonymous profile tied to that browser or device, and to the logged-in consumer's whole account if they are known to you.
- If you process the signal in a frictionless way, you may drop the Do Not Sell or Share link, but you must still describe the signal and the opt-out right in your privacy policy.
Sources
- Cal. Civ. Code § 1798.135 (Methods of limiting sale, sharing, and use; opt-out preference signal), California Legislative Information
- California Privacy Protection Agency, What Is OOPS and How Does a Business Respond? (Civ. Code § 1798.135(b),(e); 11 C.C.R. §§ 7025, 7026)
Last verified: 2026-08-12
Informational, not legal advice.