Summarize this article with
Global Privacy Control (GPC) is a browser-level signal that tells a business to stop selling or sharing a person's data, and honoring an opt-out signal such as GPC has been a legal requirement under the CCPA for years. Ketch's own research found that 40% of trackers ignore consumer opt-outs, and the CPPA voted in August 2026 to begin formal rulemaking expressly recognizing GPC in the CCPA regulations and tighten how opt-out signals must be honored across devices. Most consent management platforms were built for a different regulatory model and were never architected to close that gap.
Global Privacy Control (GPC) is a signal a browser or extension sends to every website a person visits, telling that business to stop selling or sharing their personal information. It works automatically, in the background, without the person filling out a form or hunting for a link. Under the California Consumer Privacy Act (CCPA), a business that detects a GPC signal is legally required to treat it as a valid opt-out request.
That requirement is not new and it is not proposed. California has required businesses to honor qualifying opt-out preference signals for years, and the current CCPA regulations expressly require businesses to process them. What is new is how much regulatory and enforcement weight is now sitting behind it, and how uneven the actual compliance record looks once you go check it.
This post walks through four things: what the CCPA already requires, what happens when businesses get GPC wrong, where the California Privacy Protection Agency (CPPA) is taking the rule next, and how Ketch closes the gap between saying you honor GPC and proving it.
What honoring GPC actually requires
11 Cal. Code Regs. § 7026(a)(4) states plainly that a cookie banner or cookie control tool, by itself, is not an acceptable way to process an opt-out of sale or sharing. Cookies govern collection. GPC governs sale and sharing, a different question entirely, and one a consent banner alone was never built to answer.
Once a business receives a GPC signal, three obligations follow:
- Stop selling and sharing "as soon as feasibly possible," and no later than 15 business days (11 Cal. Code Regs. § 7026(f)(1)). This is not a preference toggle. Cal. Civ. Code § 1798.120(d) makes it a legal prohibition once the signal is received.
- Honor it beyond new collection. The opt-out has to reach data already collected and already flowing to third parties, not just stop the tap going forward.
- Honor it beyond the device it arrived on, when the consumer is known. Under 11 Cal. Code Regs. § 7025(c)(1), if a business can associate a person's devices, accounts, or pseudonymous profiles by any reasonable means, the opt-out has to follow that person across all of them, not just the browser where the signal showed up.
Every one of those three points has already been tested in enforcement, and businesses have lost. You can see the full pattern across dozens of cases in Ketch's enforcement analysis.
The compliance gap, in numbers
Ketch's own research across 134 major websites found that 40% of all trackers ignore consumer opt-outs, generating an estimated 215 billion "dirty data" events every month, personal information collected or shared after a person already said no. That is not a hypothetical risk sitting in a regulatory filing. It is a website tag firing anyway.
The pattern shows up the same way inside individual privacy programs once someone actually looks. In one client environment Ketch audited, only 43% of trackers and data collection events were found to be respecting opt-out signals at all, and 76% of the data collection events on the site were not authorized in the first place.
The gap exists because most consent management platforms (CMPs) were designed for a different job. They were built around the EU's cookie-consent model: ask permission before a cookie loads, record the answer, move on. GPC asks a different, harder question: once someone says stop, does that choice reach every system, every device, and every piece of data already collected, not just the cookie on the browser where the signal arrived. A cookie-scoped tool answers the first question well and the second one barely at all.
What enforcement has already established
The CPPA and the California Attorney General have both brought cases that turn specifically on GPC and opt-out signal failures.
Sephora set the template for everything that followed: the California AG found that pixel-based sharing with ad-tech partners counted as a sale under the CCPA, and that Sephora's systems never treated GPC signals as a valid opt-out at all.
Disney is the clearest illustration of the cross-device problem. Disney's opt-out webform stopped data sharing through Disney's own advertising platform, but the company kept sharing the same consumer's data with third-party ad-tech partners embedded in its apps.
California Attorney General Rob Bonta's office was direct about it in its announcement of the settlement: a consumer's opt-out right applies wherever and however a business sells data, and businesses cannot force people to submit a new request device by device or service by service.
The final judgment goes further, requiring Disney to honor an opt-out across every service tied to a consumer's account once that person is logged in, and to extend the same protection to pseudonymous profiles for people who never log in at all.
That is the "known consumer" standard in practice: if a business can link a browser, device, or profile back to a person by any reasonable means, whether it built that linkage itself or gets it through an ad platform it uses, the opt-out has to follow.
Where the CPPA is taking this next
On August 6 and 7, 2026, the CPPA board voted unanimously to direct staff to begin formal rulemaking that would name Global Privacy Control by name inside the CCPA regulations, codifying what has so far been agency guidance rather than explicit statutory text, according to Wilson Sonsini Goodrich & Rosati's client alert on the board's action. Alston & Bird's own analysis notes the anticipated rule would also make GPC easier to recognize across the 13 other states that already require some form of universal opt-out mechanism.
This follows a separate step already in motion: the California Opt Me Out Act, signed into law in October 2025, will require browsers operating in California to build in an opt-out preference signal option directly, with the requirement taking effect in January 2027. Combined with the CPPA's rulemaking, the direction is consistent.
GPC is moving from a signal regulators expect a business to honor toward a signal named explicitly in the statute, built into browsers by default, and expected to work across every device a consumer touches.
For a business still treating its cookie banner as its GPC compliance program, that direction of travel is worth taking seriously now rather than after the next enforcement sweep.
Why "we honor GPC" often isn't true in practice
Most teams that get asked "do we honor GPC" answer honestly based on what their CMP dashboard shows: a toggle is set, a script is installed, the signal is technically detected. The Disney case shows why that answer can still be wrong.
Two disconnected systems, one handling the cookie banner and one handling the offline opt-out form, can each work correctly in isolation and still leave a gap between them. A consumer who submits one does not automatically complete the other.
Closing that gap requires two things a browser-scoped CMP does not do on its own:
- Coupling the opt-out to identity, not to a cookie. When a rights request or an opt-out is tied to a resolved identity rather than a single browser cookie, the choice can follow that person to CTV, mobile, and any pseudonymous profile the business can otherwise link back to them, exactly what §7025(c)(1) requires. This is what cross-device identity resolution is for.
- Coupling the consent record to the rights-request form. A cookie toggle only ever governs what happens in that browser, on that visit. A rights-request form captures something durable, usually an email address or account identifier, that reaches into the offline systems a cookie can never touch: CRM records, purchase history, loyalty profiles. When the two are connected, one submission updates both, instead of requiring a second manual step that enforcement has now penalized more than once.
That is the architectural difference between a consent banner and full Do Not Sell enforcement, and it is the difference the Disney and Sling/Dish cases both turned on. It is worth saying plainly: this is not a knock on any one vendor's intentions.
Most CMPs on the market today were genuinely built to solve GDPR-style cookie consent well, and they do that job. The gap only shows up once the compliance question shifts from "did we ask" to "does the opt-out actually reach every system," which is a different engineering problem than the one most CMPs were originally built to solve.

How Ketch honors GPC
Ketch Consent Management treats GPC as one of several opt-out preference signals it recognizes automatically, alongside IAB TCF and state-specific mechanisms, and enforces the resulting choice from the same identity record used everywhere else in the platform. That last part is the point: the signal does not just get logged, it gets propagated.
Once a GPC signal or any other opt-out is captured, Opt-Out Sync is the piece that carries it everywhere the person's data actually lives, not just the browser where the signal arrived: across browser configurations, backend systems, and downstream partners including CRM platforms, CDPs, advertising systems, identity resolution providers, and demand-side platforms.
Every one of those enforcement actions is logged with an identity-based audit trail, so a business has documentation ready if a regulator ever asks how a specific opt-out was applied, rather than reconstructing it after the fact.
That still leaves one honest question: how does a privacy or marketing team know the signal is actually being honored, not just configured. Data Sentry answers that by inspecting real network traffic leaving a site, the actual data packets, not just whether a tag fired, so a team can see directly which trackers are still collecting or sharing data after a person opts out.
Put together, that is the full loop the Disney and Sephora cases exposed as broken elsewhere: detect the signal, propagate it identity-wide instead of cookie-wide, and verify in production that it actually held.
Read more: Privacy frameworks
Where to go from here
The honest starting point for most privacy or marketing teams is not "do we say we honor GPC," it is "can we prove it, on every device, across every system that touches this person's data." If you're weighing that question against what your current CMP can actually demonstrate, it's worth checking how the leading consent management platforms compare on exactly this point before assuming the gap doesn't apply to you.




