California asks a different question
European storage-and-access rules and California privacy law ask different questions. The CCPA focuses in part on whether a covered business sells or shares personal information and gives consumers a right to opt out. It does not impose a general prior-consent rule on all cookies; accurate notice, a usable opt-out mechanism and purpose-specific handling of special cases are a common baseline.
The CPRA amendments define “sharing” to cover disclosure for cross-context behavioural advertising, even without payment. Advertising pixels can fall within that definition, but the result depends on the data flow, purpose, contracts and statutory exceptions rather than the vendor name alone.
- Right to opt out of sale and sharing
- Right to limit use and disclosure of sensitive personal information
- Right to know, delete and correct
- No discrimination for exercising a right
Global Privacy Control is not optional in California
California requires businesses to treat an opt-out preference signal as a valid request from that consumer. Global Privacy Control is the signal in practice: the browser sets `navigator.globalPrivacyControl` and sends a `Sec-GPC` header, and the Attorney General’s 2022 settlement with Sephora made clear that ignoring it is an enforcement matter rather than a technicality.
StrongPrivacy honours it where the resolved model is opt-out. When the runtime computes default preferences, a GPC signal of `true` (or the string `"1"`) conservatively disables every optional category before anything loads. The signal is legally directed at sale and sharing rather than all processing, but a category label alone cannot prove which technologies participate in those uses; failing closed avoids letting a sale/share integration run merely because it was filed under analytics, functional, media or a custom category.
The model has to be opt-out for GPC to apply
A property on Global strict resolves every visitor to opt-in, which means nothing optional loads anyway and there is no default to suppress. GPC changes the outcome under Regional defaults and Global balanced, which are the profiles that give a California visitor an opt-out experience.
What each region profile resolves to
| Region profile | Resolved model | What the visitor sees |
|---|---|---|
| Regional defaults | opt-out | Optional technologies load, with a visible way to refuse |
| Global strict | opt-in | Nothing optional loads until a choice is made, everywhere |
| Global balanced | opt-out | Optional technologies load, with a visible way to refuse |
| EU and UK opt-in | none | No banner |
Watch the last row
On the "EU and UK opt-in" profile, a California visitor gets no banner and no opt-out control at all. That profile is for properties with no US-regulated audience. If you serve California, choose Regional defaults or Global balanced.
The other US states are not detected for you
This is the most important operational fact on the page. `detectedJurisdiction()` maps US + CA to CCPA and every other US state to no built-in regime. Other states have comprehensive privacy laws with differing definitions, exemptions, sensitive-data rules, appeal processes and universal opt-out requirements. The runtime does not infer those laws; maintain a dated, counsel-reviewed state matrix and express the resulting treatment with region rules.
Express them yourself with region rules. A rule is a country code, an optional region code and a consent model, and a property may carry up to 100 of them. They are evaluated before the profile, so a rule always wins.
Region rules, as stored in a published configuration
"regionRules": [
{ "country": "US", "region": "CA", "model": "opt-out" },
{ "country": "US", "region": "CO", "model": "opt-out" },
{ "country": "US", "region": "CT", "model": "opt-out" },
{ "country": "US", "region": "VA", "model": "opt-out" },
{ "country": "US", "region": "TX", "model": "opt-out" }
]A single US-wide opt-out rule can simplify the interface, but it is not a substitute for a state-law analysis. An opt-out model does not by itself address differences in sensitive-data consent, children’s data, profiling, notices, appeals or the definition of sale and targeted advertising.
This is a product reference, not legal advice
It describes how StrongPrivacy behaves and summarises published law so you can configure the product deliberately. Whether a particular configuration satisfies your obligations is a question for your own counsel, who knows your data flows and your risk position.
Common questions
Does the CCPA require a cookie banner?
The CCPA generally uses notice and opt-out rather than prior consent for sale or sharing, although other duties and special cases may apply. A covered business needs the prescribed link or a legally valid alternative, must honour recognised opt-out preference signals such as GPC, avoid friction and keep its notices accurate. A reopenable preference centre can support that mechanism, but its existence alone does not establish compliance.
Do advertising pixels count as a sale?
They can constitute sharing when personal information is disclosed for cross-context behavioural advertising, with or without payment. The result depends on the data flow, purpose, contracts and exceptions. StrongPrivacy therefore applies GPC to every optional category under an opt-out model instead of assuming that only items labelled marketing can participate in sale or sharing.
How does StrongPrivacy detect a California visitor?
From the country and region resolved at configuration-fetch time: country US with region CA. The consent record stores that resolved location as `US-CA`, alongside the configuration version that was live, so you can show later both where the visitor was and which published rules applied to them.
What happens if the region cannot be determined?
The runtime fails closed rather than open. With no country, Regional defaults resolves to opt-in and the record is marked as matched by fallback. A visitor whose location is unknown is never given the weaker of the two treatments.
Sources and verification
Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.
- California Department of Justice: CCPA
Regulator guidance
Checked
- Global Privacy Control specification
Official documentation
Checked
See what your own site is loading
A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.