Universal opt-out: which states require an opt-out preference signal to be honored?
Eleven states now require a business to honor an opt-out preference signal: California, Colorado, Connecticut, Delaware, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas. Texas and Nebraska reach that result through authorized-agent rules rather than a standalone duty. Colorado recognizes Global Privacy Control by name. Virginia and Utah require nothing.
Applies to: Businesses subject to more than one US state privacy law that sell personal data or process it for targeted advertising, and need to know where a browser-level opt-out signal must be honored.
Find out what applies to you
Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.
Run the free 2-minute Obligation ScanA universal opt-out signal is the one privacy obligation you cannot satisfy by waiting for a request. The signal arrives with the page load, and either your site reads it or it does not.
The list of states where this is an explicit duty grew on January 1, 2026, when Oregon's requirement began and California's updated regulations took effect. Guidance written before that date is now short by two states.
Where the duty is explicit
Colorado. The Department of Law states that beginning July 1, 2024, businesses within the CPA's application thresholds must allow consumers to opt out of the sale of personal data or use of personal data for targeted advertising using GPC, citing C.R.S. section 6-1-1306(1)(a)(IV). Colorado is the only one of these states that names a mechanism: GPC was the first recognized and remains the only one the Department considers valid, under a public list maintained per CPA Rule 5.07.
California. The CCPA Regulations are the most prescriptive of the group. Section 7025(b) requires a business that sells or shares personal information to process any opt-out preference signal meeting two conditions as a valid request to opt out: the signal must be in a format commonly used and recognized by businesses, such as an HTTP header field or a JavaScript object, and the mechanism sending it must make clear that its use is meant to opt the consumer out of sale and sharing. Section 7025(c)(1) then requires the business to treat the signal as a valid opt-out under Civil Code section 1798.120 for that browser or device and any consumer profile associated with it, including pseudonymous profiles.
Oregon. As of January 1, 2026, Oregon controllers must accept opt-out requests sent through a universal opt-out mechanism. The Oregon Department of Justice states the start date plainly, and the duty sits at ORS 646A.578(5)(c), inside the list of methods a controller has to offer for submitting requests. Before that date the signal was optional in Oregon, which is why older guidance leaves the state off this list.
Minnesota. Section 325M.14, subdivision 3(a) requires a controller to allow a consumer to opt out of processing for targeted advertising, or any sale, through an opt-out preference signal sent with the consumer's consent by a platform, technology, or mechanism.
New Jersey. Section 56:8-166.11(b)(1) requires that, beginning not later than six months following the effective date, a controller processing personal data for targeted advertising or the sale of personal data shall allow consumers to exercise the opt-out right through a user-selected universal opt-out mechanism.
Connecticut. Conn. Gen. Stat. section 42-520(e)(1)(A)(ii) required that, not later than January 1, 2025, a controller allow a consumer to opt out through an opt-out preference signal sent by a platform, technology or mechanism. Connecticut is routinely left off universal opt-out lists because the duty sits inside the general list of opt-out methods rather than under a heading with the words "universal opt-out" in it.
Montana. MCA section 30-14-2809(3)(b) says opt-out methods must, by no later than January 1, 2025, allow a consumer to opt out through an opt-out preference signal. Same date as Connecticut, same drafting pattern.
New Hampshire. RSA 507-H:6, V(a)(1)(B) uses near-identical wording: not later than January 1, 2025, allowing a consumer to opt out through an opt-out preference signal.
Delaware. 6 Del. C. section 12D-106(e)(1)a.2. provides that any such means shall include, not later than January 1, 2026, allowing a consumer to opt out through an opt-out preference signal. Delaware and Oregon are the two most recent additions, both landing on January 1, 2026.
The dates in one place
The duty and the date it started, by state:
Colorado, July 1, 2024. Connecticut, Montana, Nebraska, New Hampshire and Texas, January 1, 2025. Minnesota, July 31, 2025. Delaware and Oregon, January 1, 2026. California's duty comes from the CCPA regulations rather than a dated statutory clause and has been in force since the CPPA's regulations took effect. New Jersey's statute sets the duty at not later than six months following the effective date of P.L.2023, c.266 rather than printing a calendar date, so the safe planning assumption is that it is already live.
Minnesota carries one carve-out worth noting: postsecondary institutions are not required to comply until July 31, 2029.
Where there is no duty at all
Two of the enacted state laws impose nothing here, and confirming that is as useful as confirming the positives, because it tells you where not to spend engineering time.
Virginia. The VCDPA, Va. Code sections 59.1-575 to 59.1-585, contains no opt-out preference signal duty, no universal opt-out mechanism, and no provision letting a consumer designate an authorized agent by browser setting. Section 59.1-577 requires a controller to comply with an authenticated consumer request, and that is the whole of it. The only signal language anywhere in the chapter concerns minors and known-child geolocation, which is a different obligation.
Utah. The UCPA, Utah Code chapter 13-61, contains no reference to a signal, a browser, a global device setting, a universal opt-out or an authorized agent.
Maryland is genuinely ambiguous and should not be put in either column without care. MODPA section 14-4606(b) says a controller shall comply with an opt-out request received from an authorized agent, where the agent may be designated by a browser setting, browser extension or global device setting, which reads as mandatory. But section 14-4607(f)(3) says a controller may utilize either a clear and conspicuous link or, on or before October 1, 2025, an opt-out preference signal, which reads as a permissive alternative. Until that tension is resolved, treat Maryland as a state where honoring the signal is the prudent course rather than a settled requirement.
Where the duty arrives by another route
Texas and Nebraska do not impose a standalone universal opt-out duty. They run the same outcome through authorized agents.
Nebraska's section 87-1111(5) lets a consumer designate an authorized agent using a technology including a link to a website, a browser setting or extension, or a global setting on an electronic device, and requires the controller to comply where it can verify the consumer's identity and the agent's authority with commercially reasonable effort.
The practical effect is similar, but the framing differs, and Nebraska attaches four express grounds for declining an agent request. One of those grounds matters here: a controller need not comply where it does not process similar or identical requests received for the purpose of complying with similar or identical laws of another state. Read plainly, that means a business already honoring GPC for Colorado cannot decline it in Nebraska on capability grounds.
The criteria are near-identical
Minnesota, New Jersey and Nebraska each attach requirements to the mechanism, and they converge:
It must not unfairly disadvantage another controller. It must not use a default setting, but require the consumer to make an affirmative, freely given, and unambiguous choice. It must be consumer-friendly and easy to use by the average consumer.
Minnesota and New Jersey add two more: the mechanism should be as consistent as possible with any similar mechanism required by other federal or state law, and it must let the controller determine whether the consumer is a resident of that state and whether the request is legitimate. Minnesota adds that using an IP address to estimate the consumer's location is sufficient for the residency determination.
That convergence is deliberate, and it is why one implementation generally serves all of them.
Minnesota's reciprocity clause
Subdivision 3(d) is worth quoting for planning purposes: a controller that recognizes opt-out preference signals that have been approved by other state laws or regulations is in compliance with this subdivision.
That is an explicit safe harbor. Build to Colorado's recognized mechanism and Minnesota accepts it.
The conflict case nobody builds for
Minnesota's subdivision 3(b) addresses what happens when a universal signal contradicts something the consumer set earlier: a controller-specific privacy setting, or voluntary participation in a loyalty, rewards, premium features, discounts, or club card program.
The rule is that the controller must comply with the opt-out preference signal, but may also notify the consumer of the conflict and offer them a choice to confirm the controller-specific setting or their participation in the program.
Signal wins by default. The consumer can then reinstate their prior choice, but only after being told.
What Colorado requires beyond the signal
Honoring GPC is not the whole Colorado obligation. Businesses must also include, in their privacy policy, an explanation of how requests made through universal opt-out mechanisms including GPC will be processed, under Rule 6.03(4)(e) of the CPA Rules.
This is the visible half. A regulator or a prospective customer can read your privacy policy and see immediately whether you have addressed universal opt-outs at all.
Universal opt-out, opt-out preference signal, GPC: three names, one mechanism
The vocabulary is inconsistent across states, and searching for the wrong term hides half the obligation.
"Universal opt-out mechanism" is the phrase Colorado and Oregon use. "Opt-out preference signal" is California's regulatory phrasing. "Global Privacy Control", or GPC, is the name of a specific implementation of the signal rather than a legal category. All three describe the same thing: a setting a consumer turns on once, in a browser or on a device, that communicates a refusal to every site they visit.
Texas does not use any of those phrases in its statute, which is why Texas is often left off lists like this one. Section 541.055(e) of the Texas Business and Commerce Code gets there by a different mechanism. A consumer may designate another person as an authorized agent to opt out on the consumer's behalf, and may make that designation "using a technology, including a link to an Internet website, an Internet browser setting or extension, or a global setting on an electronic device, that allows the consumer to indicate the consumer's intent to opt out of the processing".
A controller must comply with an opt-out request received from such an agent if it can verify, with commercially reasonable effort, the identity of the consumer and the agent's authority. So the browser signal is honored in Texas as an agent designation rather than as a named universal opt-out.
Section 541.055(e) also sets out four grounds on which a controller is not required to comply: the agent does not communicate the request clearly and unambiguously, the controller cannot verify with commercially reasonable effort that the consumer is a Texas resident, the controller does not possess the ability to process the request, or the controller does not process similar or identical requests received for the purpose of complying with similar laws of another state.
That last one repays attention. If you already honor GPC to satisfy California or Colorado, the fourth ground falls away and the Texas duty attaches.
What the signal itself has to look like in Texas
Section 541.055(f) sets three requirements for the technology. It may not unfairly disadvantage another controller. It may not make use of a default setting, and must instead require the consumer to make an affirmative, freely given and unambiguous choice to indicate the intent to opt out. And it must be consumer-friendly and easy to use by the average consumer.
The no-default rule is the one that matters for anyone building or evaluating a signal. A browser that ships with the signal switched on has not captured an affirmative choice, which is the same objection Colorado and California regulators have raised about default-on implementations.
What makes a signal valid, in the California regulation's own words
The state rules differ on whether honouring a signal is mandatory, but they converge on what a signal has to be. California's formulation at 11 CCR 7025(b) is the most detailed, and it is only two conditions:
"(b) A business that sells or shares personal information shall process any opt-out preference signal that meets the following requirements as a valid request to opt-out of sale/sharing:
(1) The signal shall be in a format commonly used and recognized by businesses. An example would be an HTTP header field or JavaScript object.
(2) The platform, technology, or mechanism that sends the opt-out preference signal shall make clear to the consumer, whether in its configuration or in disclosures to the public, that the use of the signal is meant to have the effect of opting the consumer out of the sale and sharing of their personal information. The configuration or disclosure does not need to be tailored only to California or to refer to California."
The last sentence of (2) is the one that removes a common objection. A business cannot decline to honour Global Privacy Control on the ground that the signal is generic rather than California-specific. The regulation expressly says it need not refer to California at all.
Section 7025(c) then sets out what happens on receipt. Under (c)(1), the business must treat the signal as a valid request to opt out under Cal. Civ. Code Section 1798.120 "for that browser or device and any consumer profile associated with that browser or device, including pseudonymous profiles", and, if known, for the consumer as well. Under (c)(2), the business may not require additional information beyond what is necessary to send the signal, and anything a consumer does volunteer may not be used, disclosed or retained for any purpose other than processing the opt-out.
Two further rules close off workarounds. Under (c)(5), where the consumer is known to the business, the absence of a signal after one was previously sent cannot be interpreted as consent to opt back in. And under (c)(6) the business "must display whether it has processed the consumer's opt-out preference signal as a valid request to opt-out of sale/sharing on its website", with the regulation giving "Opt-Out Request Honored" as an example. Confirming the outcome to the consumer is an obligation, not a courtesy.
Next step
Universal opt-out is a site-wide engineering change rather than a policy edit, so it is worth knowing which of these laws actually reach you before scoping the work. The free 2-minute Obligation Scan checks your business against every US state privacy law and tells you which apply. See Colorado's universal opt-out rules for the most prescriptive version, Nebraska request methods for the authorized-agent route, and Texas browser opt-out signals for the Texas equivalent.
Compliance checklist
- Implement Global Privacy Control detection site-wide rather than only on privacy or cookie pages.
- Treat a received signal as covering both the sale of personal data and targeted advertising, which are the two purposes named across these laws.
- In Colorado, add an explanation to your privacy policy of how you process universal opt-out requests, which the CPA Rules require separately from honoring the signal itself.
- Do not require account creation or identity verification before honoring a universal opt-out; the point of the mechanism is that it works without an individual request.
- In Minnesota, handle the conflict case in subdivision 3(b): comply with the signal, then optionally notify the consumer of a conflict with a controller-specific setting or loyalty program and let them confirm.
- In Nebraska, remember the fourth refusal ground cuts against you if you already honor signals elsewhere, since it applies only where you do not process similar requests for other states' laws.
- Re-check Colorado's published mechanism list periodically, because Rule 5.07 commits the Department of Law to updating it.
- In California, apply the opt-out to the browser or device and to any profile associated with it, including pseudonymous profiles, which section 7025(c)(1) requires by name.
Sources
- Universal Opt-Out and the Colorado Privacy Act, Colorado Attorney General (C.R.S. 6-1-1306(1)(a)(IV))
- Minn. Stat. 325M.14, subd. 3, Universal opt-out mechanisms, 2025 Minnesota Statutes
- P.L. 2023, c.266 (C.56:8-166.11), New Jersey data privacy law, New Jersey Legislature
- Tex. Bus. & Com. Code Section 541.055, Methods for Submitting Consumer Requests (authorized agent designation by browser setting or global device setting), Texas Statutes
- Neb. Rev. Stat. 87-1111, Consumer right; method to submit request, Nebraska Legislature
- CCPA Regulations, 11 CCR section 7025 (opt-out preference signals), effective 1 January 2026, California Privacy Protection Agency
- ORS 646A.578(5)(c) as amended by Oregon Laws 2025, chapter 251 (HB 2008), effective January 1, 2026, Oregon State Legislature
- Conn. Gen. Stat. Chapter 743jj, Data Privacy (section 42-520), Connecticut General Assembly
- MCA 30-14-2809, Consumer Data Privacy Act, Montana Legislature
- RSA 507-H:6, Expectations of Controllers and Consumer Rights, New Hampshire General Court
- 6 Del. C. Chapter 12D, Delaware Personal Data Privacy Act (section 12D-106), Delaware Code
- Va. Code Chapter 53, Consumer Data Protection Act, Virginia Law Library
- Chapter 454 (HB 567), Maryland Online Data Privacy Act, 2024 Laws of Maryland
Last verified: 2026-09-16
Informational, not legal advice.