Home / BlogYour banner ignores the global privacy signal: consent and the opt-out broadcastYour banner ignores the global privacy signal: consent and the opt-out broadcast

Your banner ignores the global privacy signal: consent and the opt-out broadcast

Published 2026-10-06

Modern browsers and privacy extensions can broadcast a user's choice: do not sell my data. The Global Privacy Control signal is sent with every request, a standing instruction from the visitor that applies before your banner even renders. Most consent setups never check it.

That is a gap with teeth. Privacy regulations in several US states treat an honored GPC signal as a valid opt-out request. Ignoring it while displaying a friendly privacy banner is exactly the kind of mismatch that turns a routine complaint into an enforcement letter.

The signal you are probably ignoring

GPC works at the browser level. When enabled, every HTTP request from that browser carries a flag saying the user has opted out of data selling and sharing. Unlike cookie banners, which need to be seen and clicked, the signal arrives automatically and applies to every page on your site.

Privacy extensions enable it by default for millions of users, and several mainstream browsers ship it as a built-in toggle. The share of your traffic carrying the signal is not a rounding error. It is growing, and regulators in California and elsewhere have said explicitly that businesses must honor it as an opt-out of sale and sharing.

What most consent setups get wrong

The typical failure is architectural. The banner asks the visitor to choose, and the tag blocking waits for that choice. But GPC is a choice the visitor already made, in their browser settings, before they ever reached your site. A setup that only reacts to banner clicks treats that prior choice as nonexistent.

The second failure is procedural. Teams audit their banner's buttons and their tag blocking rules but never check what happens when the signal arrives. There is no test case for it, no monitoring, and no documentation. When asked whether they honor GPC, most teams cannot answer from evidence, only from optimism.

What honoring the signal actually requires

Start by treating GPC as consent denied for any processing that counts as a sale or sharing under applicable state laws. That means when the signal is present, data-sale trackers stay blocked exactly as if the visitor had rejected everything in the banner. This is not a new consent category. It is an existing input to the logic you already have.

The detection itself is simple: the browser exposes the signal both as an HTTP header and through JavaScript. Your consent code reads it on page load, folds it into the consent state, and logs it the same way it logs banner choices. The complexity is not technical. It is making sure the blocked-until-consent rules apply to the GPC-derived state with the same rigor they apply to banner choices.

One edge case to handle deliberately: visitors who send GPC and then explicitly consent through the banner. A fresh, clear, banner consent can override the browser-level opt-out, since it is a more specific and recent expression of choice. Your consent records should capture that sequence so the override is auditable.

Testing it before a regulator does

Add GPC to your verification checklist. Enable the signal in a test browser, visit the site with a clean profile, and confirm the data-sale trackers stay blocked without any banner interaction. Then check the consent log: it should record that the opt-out came from the signal, not from a default-deny assumption.

Include it in the reject-all test you already run. The pattern is the same one this blog keeps returning to: do not trust the banner's appearance, watch the network requests. With GPC on and no clicks, your site should look identical in the network tab to a full reject.

The bottom line

GPC is the visitor telling you their answer before you ask the question. A consent setup that ignores it is not neutral. It is actively overriding a stated privacy choice with its own default. Read the signal, treat it as a deny for sale and sharing, and log it. The implementation is a day's work. Explaining why you ignored it is much harder.

Common questions

Do all browsers send the GPC signal?

No. It is available in Firefox, Brave, DuckDuckGo's browsers, and through many privacy extensions, but not in Chrome or Safari by default. The signal's coverage comes from the installed base of extensions and privacy browsers, which keeps growing among privacy-aware visitors.

Does GPC apply outside the US?

The GPC specification is a general mechanism, but its legal force comes from regulations like the CCPA that explicitly recognize it as an opt-out request. Treat it as an opt-out of sale and sharing for visitors in states where that recognition exists.

Can a banner consent override a GPC signal?

Yes, if the visitor then makes an explicit, informed choice through your banner. The later, more specific choice governs. Your consent log should record the sequence: signal received, then explicit consent given, so the override is defensible.

Get a free consent audit of your website

Free consent audit