Growth Marketing Glossary

Do Not Track (DNT)

D·N·Tnoun

The header everyone sent and no one honored — privacy's politest failure, and the ancestor of the signal laws now enforce.

DNT: 1the header sites ignoredGPC signalthe successor laws enforcethe polite request that failed, and what replaced it
Schematic — the ignored request and its successor
Term
Do Not Track (DNT)
Was
A voluntary browser header (DNT: 1)
Failed because
No enforcement, no agreed meaning
Successor
Global Privacy Control, with legal teeth

Forms & parts of speech

DNT · noun
The failed privacy header.
"Do Not Track proved the lesson GPC was built on - voluntary signals get ignored; enforceable ones get honored."

Definition in plain terms

Do Not Track (DNT) was the browser privacy signal of the 2010s: a simple header (DNT: 1) users could enable, requesting that sites not track them. Proposed in 2009, adopted by every major browser, and standardized at the W3C in name — it failed almost completely, because nothing required anyone to honor it, and almost no one did. Its history is the cautionary tale behind the privacy signals that work today: GLOBAL PRIVACY CONTROL (GPC) carries DNT's idea with what DNT lacked — laws that make ignoring it a violation.

The mechanics

DNT's failure was structural and instructive. The signal had no agreed meaning (no tracking? no targeting? no analytics?), no enforcement (honoring it was voluntary, and the adtech economy declined), and a credibility collapse with a date: when Microsoft enabled DNT by default in IE10 (2012), the industry argued defaults didn't express user choice and dismissed the signal wholesale. The W3C working group dissolved without a binding standard; Apple removed DNT from Safari in 2019 — by then it served mainly as a fingerprinting bit that made users more identifiable, privacy's bitterest irony. The successor learned each lesson: GPC, launched 2020, is technically the same idea — a browser-level opt-out header — but it arrived after the law: the CCPA-family statutes and regulations (and the CTDPA-grade state laws explicitly) require honoring universal opt-out preference signals, California's AG enforced exactly that in the Sephora settlement (2022), and the COLORADO-style rules formalized GPC as a recognized mechanism. For marketers the operational meaning today: DNT headers still arrive and can be safely treated as historical (no major regime mandates them), while GPC signals are compliance surface — the consent stack must read them and gate the SHARING flows the CCPA/CPRA entries describe.

When it matters

DNT matters now mostly as the lesson embedded in modern compliance: voluntary privacy mechanisms fail, enforceable ones get honored, and the difference is law, not technology. It matters operationally only at the boundary — auditing which signals your consent stack reads, retiring DNT-era logic, and wiring GPC properly where state laws require it. The discipline is the modern one: treat browser privacy signals as legal inputs with jurisdictions attached, and remember, when the next voluntary standard is proposed, why the last one became a fingerprinting bit.

Worked example. A privacy-stack audit at a national retailer finds three generations of signal handling in the codebase: a 2014-era module that reads DNT headers and does nothing with them (a comment promises a policy decision that never came), a consent platform that ignores GPC entirely, and a tag manager whose opt-out logic only fires from the footer link. The cleanup is a history lesson implemented: DNT handling retires with a comment explaining why (no mandate, fingerprinting surface), GPC parsing wires into the consent platform as a CCPA/CPRA opt-out equivalent - gating the audience-sharing tags exactly as the Sephora settlement expects - and the footer link and browser signal converge on one suppression state. Legal signs off on the jurisdictional map: GPC honored for the states that require it, documented for the audit trail. The retailer's stack now distinguishes what DNT never had - signals the law enforces from signals history ignored.
Failure modes to watch. Consent stacks still reading DNT while ignoring the GPC signals law enforces; opt-out logic living only in the footer link while browser signals go unparsed; treating signal-honoring as optional after Sephora made it a settlement; and proposing voluntary industry signals as if DNT's decade hadn't answered the question.

Synonyms & antonyms

Synonyms

Do Not TrackDNTDNT header

Antonyms

Global Privacy Control (GPC)enforceable opt-out signals

Origin & history

Do Not Track was proposed in 2009 and briefly looked like privacy's universal switch — every browser shipped it — before collapsing through the 2010s for want of enforcement and agreed meaning; Apple removed it from Safari in 2019, and GPC (2020) rebuilt the idea on the legal foundations DNT never had.

Etymology: source.

Usage trends

Search interest for this term over the last five years:

View interest-over-time on Google Trends →

Common questions

What was Do Not Track?
A voluntary browser header (DNT: 1) requesting sites not track the user — adopted by every browser in the 2010s, honored by almost no one, and abandoned without ever gaining enforcement or agreed meaning.
Why did DNT fail?
No law required honoring it, the industry never agreed what it meant, and the IE10 default-on episode gave cover to dismiss it — it ended as a fingerprinting bit that made users more identifiable.
What replaced DNT?
Global Privacy Control — the same browser-signal idea backed by CCPA-family law, with California's Sephora settlement establishing that ignoring it is an enforcement matter, not a preference.

Related tools & calculators

Resources & people to follow

Curated, non-competitor resources verified per term.

Related training

Disciplines

Areas of marketing where do not track (dnt) is a core concern:

Sources

  1. trendsGoogle Trends — "global privacy control"