Glossary

Global Privacy Control

A browser-level signal that communicates an opt-out of sale and sharing, legally binding in California and honoured automatically where the resolved model is opt-out.

Signal
navigator.globalPrivacyControl; Sec-GPC header
Binding in
California, among others
Effect here
Disables every optional category under opt-out

What it is

GPC is a specification for expressing an opt-out once, in the browser, instead of on every site. A browser or extension that supports it exposes `navigator.globalPrivacyControl` as true and sends a `Sec-GPC: 1` header with requests.

Unlike Do Not Track, which preceded it and failed for want of anyone being obliged to listen, GPC has legal backing. California requires businesses to treat an opt-out preference signal as a valid request from that consumer, and enforcement has followed.

Exactly what StrongPrivacy does with it

When the runtime computes default preferences, it applies GPC before optional loaders are created. If the resolved model is opt-out and the signal is `true` or the string `"1"`, every optional category is disabled. This is deliberately conservative: GPC concerns sale and sharing, but a category label cannot prove whether a technology participates in those uses.

  • Only applies where the model is opt-out: under opt-in nothing optional loads anyway
  • Disables analytics, marketing, functional, media and custom optional categories rather than guessing which labels contain sale/share uses
  • Happens before the first optional loader is created, not after the banner renders
  • The visitor can still make an explicit choice in the preference centre

Common questions

Is honouring GPC mandatory?

In California, treating an opt-out preference signal as a valid request is required, and the Attorney General has enforced it. Several other US state laws include universal opt-out mechanism requirements. Honouring it is also simply the low-cost option.

Does GPC turn off analytics too?

Yes, under this implementation’s opt-out model. The legal signal targets sale and sharing, not all analytics, but the runtime conservatively disables every optional category because it cannot infer sale/share status safely from a category name. Customers should still classify purposes accurately and honour explicit later choices where the applicable law permits them.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.