Growth Marketing Glossary

Global Privacy Control (GPC)

G·P·Cnoun

Do Not Track, with consequences — the one-setting opt-out the state laws made enforceable.

Sec-GPC: 1one browser setting= opt-out at every siteenforceable (Sephora, 2022)mandatory in CO, CA + morethe privacy signal with legal teeth
Schematic — one signal, every site, with teeth
Term
Global Privacy Control
Is
A browser header (Sec-GPC: 1) = opt-out
Enforced
Sephora settlement (CA, 2022)
Mandatory
CA, CO, CT-family state laws

Forms & parts of speech

GPC · noun
The enforceable opt-out signal.
"The audit's first test was simple - send GPC, watch the tags. Half kept firing. That's the Sephora fact pattern."

Definition in plain terms

Global Privacy Control (GPC) is the browser-level universal opt-out: a setting (sent as the Sec-GPC header and a JavaScript property) that tells every site the user opts out of the sale and sharing of their personal information — once, globally, instead of footer-link by footer-link. It is DO-NOT-TRACK's successor built on that failure's lesson: GPC launched in 2020 with law waiting for it — the CCPA/CPRA regime requires honoring it, the Sephora settlement (2022) enforced exactly that, and Colorado's rules made recognition mandatory from July 2024, with the CTDPA-family laws following the template.

The mechanics

Technically trivial, operationally demanding: the browser (or extension) sends the signal; the site must treat it as a valid opt-out of sale/sharing for that visitor — which means the consent stack reads it and the TAG-MANAGER honors it: audience-sharing pixels suppressed, CRM-RETARGETING syncs gated, the same DATA-LAYER consent state the footer link sets, set automatically (the CCPA entry's wiring, triggered by header instead of click). The jurisdictional map matters: California requires honoring GPC as a CCPA opt-out (the AG's Sephora action turned ignoring it into a settlement with terms), Colorado's universal-opt-out rules made it mandatory there, Connecticut and successors wrote recognition into statute — so national stacks build it once, to the strictest standard (the recurring architecture lesson). The implementation honesty points: GPC expresses opt-out of sale/sharing (not a consent withdrawal for everything — scope it correctly per law), conflicts resolve user-protectively (a logged-in preference saying 'share' against a GPC saying 'don't' is the edge case the regulations address — when in doubt, honor the signal), and testing is exactly the audit the CCPA entry runs: send the header, watch what fires. The strategic read: GPC adoption shifts opt-out from per-site friction to ambient default — plan for opted-out shares of EEA-style magnitude in privacy-forward segments, with CONVERSION-MODELING absorbing the measurement gap.

When it matters

GPC matters to any US-market stack with sharing-grade data flows — it is the enforcement surface regulators test first, precisely because testing it is trivial. It matters at consent-stack selection (does the CMP read it natively?), at tag-manager wiring, and in measurement planning as adoption grows. The discipline is the Sephora test run on yourself quarterly: send the signal, watch the tags, and make the header and the footer link land on the same suppression state.

Worked example. A national retailer's privacy program looks finished - footer link, CMP, the CCPA paperwork - until the quarterly self-audit adds the simplest test: a browser sending Sec-GPC: 1, and a network tab watching. The result is the Sephora fact pattern in miniature: the footer link suppresses sharing, but the GPC signal goes unread - the CMP's default config ignored it - so opted-out Californians' data kept flowing to three ad platforms. The fix is configuration, not construction: the CMP's GPC recognition enables, the signal maps to the same do-not-sell state the link sets, conflict rules resolve protectively, and the audit joins the quarterly calendar alongside its CCPA sibling. Six months later Colorado's mandatory date passes without a project, because the wiring was already to the strictest standard - one header, one suppression state, every jurisdiction.
Failure modes to watch. CMPs shipping with GPC recognition off; the header and the footer link landing on different suppression states; signal scope misread as universal consent withdrawal; conflict edge cases resolved by whichever system answered last; and the trivial self-test - send the signal, watch the tags - never run until a regulator runs it.

Synonyms & antonyms

Synonyms

Global Privacy ControlGPCuniversal opt-out signal

Antonyms

Do Not Track (the failed ancestor)per-site opt-out links

Origin & history

GPC launched in 2020 from a coalition of privacy researchers and publishers, designed against DNT's failure: a signal the CCPA's regulations could require honoring. California's Sephora settlement (2022) supplied the enforcement precedent, Colorado's rules the first mandatory-recognition date (July 2024), and the state-law wave keeps writing it into statute.

Etymology: source.

Usage trends

Search interest for this term over the last five years:

View interest-over-time on Google Trends →

Common questions

What is Global Privacy Control?
A browser-level signal (Sec-GPC: 1) expressing opt-out of the sale and sharing of personal information to every site — Do Not Track's idea, rebuilt with legal enforceability.
Is honoring GPC legally required?
In California (the Sephora settlement enforced it), Colorado (mandatory universal-opt-out recognition since July 2024), Connecticut, and the growing CCPA-family — national stacks build to the strictest standard.
How is GPC implemented?
The consent stack reads the signal and maps it to the same do-not-sell/share suppression state the footer link sets — gating tags and audience syncs — verified by sending the header and watching what fires.

Related tools & calculators

Resources & people to follow

Curated, non-competitor resources verified per term.

Related training

Disciplines

Areas of marketing where global privacy control (gpc) is a core concern:

Sources

  1. trendsGoogle Trends — "global privacy control"