Only 45% of websites that sell or share personal data honored Global Privacy Control (GPC) opt-out signals when researchers tested them in April 2024, according to a Wesleyan University and Princeton University study published at USENIX Security 2025. The study tracked 11,708 US websites across three separate crawls and found compliance stuck in the mid-40s the entire time. Most sites that are legally required to respect a GPC signal are still not doing it.
What is Global Privacy Control and how many companies honor it?
Global Privacy Control is a browser setting or extension that automatically tells a website a visitor wants to opt out of the sale or sharing of their personal data, replacing the need to hunt down a "Do Not Sell My Personal Information" link on every site. Under the CCPA, California residents have had the right to send this signal since a 2021 regulation amendment, and the California Attorney General's office requires businesses to treat it as a valid opt-out request.
Despite that legal backing, honoring the signal remains inconsistent. Researchers Katherine Hausladen, Sebastian Zimmeck, and colleagues crawled 11,708 sites in December 2023, February 2024, and April 2024, checking whether each site actually stopped selling or sharing data after receiving a GPC signal.
Figure 1: Compliance nearly quadrupled from an earlier 2022 baseline but has plateaued in the mid-40s since late 2023. Source: Hausladen et al., "Websites' Global Privacy Control Compliance at Scale and over Time," USENIX Security 2025, citing an earlier August 2022 Wesleyan study for the baseline figure.
The plateau is the real story. Compliance was 44% in December 2023, dipped to 43% in February 2024, and only climbed to 45% by April 2024, meaning the improvement over that five-month window was within the study's own margin of noise. A site that ignored GPC in December 2023 had roughly the same odds of still ignoring it four months later.
Which sites are covered by the GPC opt-out requirement in the first place?
A site only owes visitors a GPC opt-out if it sells or shares personal data with a third party and meets the CCPA's business thresholds. The researchers found this describes almost all of the sites in their crawl set. About 90% of the 11,708 sites integrated at least one advertising, analytics, or fingerprinting service the study classified as capable of buying, selling, or collecting personal information, in every one of the three crawls.
Not every one of those sites met the CCPA's traffic-based business threshold, but the researchers estimated that roughly 3,200 to 3,600 sites per crawl both integrated a data-sharing service and implemented at least one of the four technical mechanisms, USPS, the GPP String, an OptanonConsent cookie, or a .well-known/gpc.json file, that a site uses to signal its opt-out status. That is the population the 43 to 45% compliance figures are measured against, not the full 11,708-site crawl.
| Crawl date | Sites with a data-sharing service and a privacy string | Sites that opted out via every implemented string | Compliance rate |
|---|---|---|---|
| December 2023 | 3,226 | 1,411 | 44% |
| February 2024 | 3,402 | 1,473 | 43% |
| April 2024 | 3,566 | 1,620 | 45% |
Table 1: Sites had to opt users out via every privacy string they implemented to count as fully compliant. A site that honored GPC through one mechanism but not another still counted as non-compliant. Source: Hausladen et al., USENIX Security 2025.
Which opt-out mechanism actually works best?
Not all four technical signals perform the same. The OptanonConsent cookie, set by OneTrust's consent management platform and the most widely deployed of the four mechanisms studied, produced the highest opt-out rate of any single signal: 66% in December 2023, 67% in February 2024, and 68% in April 2024.
Figure 2: The OptanonConsent cookie outperformed every other privacy string the study measured, but nearly a third of sites using it still did not flip to opted-out after a GPC signal. Source: Hausladen et al., USENIX Security 2025.
The US Privacy String (USPS) told a different story. In the study's 100-site accuracy test set, USPS was implemented on 54% of sites, more than any other single mechanism, but only 46% of those sites (25 of 54) actually changed their opt-out value after receiving a GPC signal. USPS was also being phased out during the study window: the Interactive Advertising Bureau deprecated it on January 31, 2024, in favor of the Global Privacy Platform (GPP) String, whose adoption jumped from 7% of sites in December 2023 to 12% by February 2024 before slowing down again.
Figure 3: The vast majority of sites the study crawled were confirmed to integrate at least one third-party service that buys, sells, or collects personal data, making the GPC opt-out requirement apply to almost the whole crawl set. Source: Hausladen et al., USENIX Security 2025.
Which US states legally require businesses to honor GPC?
California was the first state to give GPC legal teeth, but it is no longer the only one. State privacy laws that followed California, including Colorado's Privacy Act and Connecticut's Data Privacy Act, also require covered businesses to recognize a universal opt-out signal like GPC rather than only accepting a site-specific opt-out link. For a full state-by-state breakdown of which comprehensive privacy laws are in effect and when they took effect, see the full 2026 state privacy law tracker.
Figure 4: GPC moved from a voluntary browser feature to a jointly enforced legal requirement across three states within five years. Source: California Privacy Protection Agency; Hausladen et al., USENIX Security 2025.
This trend connects directly to how many Americans a comprehensive privacy law actually reaches; see how many Americans are covered by a privacy law for the population-level view behind these state requirements.
What happens if a company ignores a GPC signal?
Ignoring GPC is no longer just a compliance gap, it is an active enforcement target. On September 9, 2025, the California Privacy Protection Agency announced a joint investigative sweep with the California, Colorado, and Connecticut Attorneys General focused specifically on businesses that refuse to honor GPC opt-out requests.
Figure 5: A site is only fully compliant if it updates every privacy signal it implements, not just one. Source: Hausladen et al., USENIX Security 2025.
Two settlements from that September 2025 sweep show what enforcement looks like in practice. American Honda Motor Co. was fined $632,500, described by the CPPA as one of the largest penalties in the CCPA's history, and clothing retailer Todd Snyder was fined $345,178. Both cases centered on failing to honor consumers' opt-out preference signals. The researchers' own recommendation to regulators points at the same pattern the CPPA acted on: enforcement has more impact when it targets large publishers, because a handful of big sites tend to roll out the same (non-compliant) privacy string configuration across many properties at once.
The Bottom Line
Global Privacy Control has gone from a niche browser feature that 12% of sites respected in 2022 to a legally enforced right that a bit less than half of covered sites actually honor today. That gap between "legally required" and "actually implemented" is exactly where CCPA enforcement is now focused, and the September 2025 fines against Honda and Todd Snyder show regulators are willing to act on it. If your business collects, sells, or shares visitor data and does not yet have a compliant, regularly updated privacy policy that documents how it handles GPC and other opt-out preference signals, you can generate a CCPA-ready privacy policy that covers this requirement directly rather than risk being the next enforcement target.
Frequently Asked Questions
What percentage of websites honor Global Privacy Control? 45% of websites that sell or share personal data honored Global Privacy Control opt-out signals when researchers tested them in April 2024, according to Hausladen et al.'s longitudinal study of 11,708 US websites published at USENIX Security 2025.
Is honoring Global Privacy Control legally required? Yes, for businesses covered by the CCPA. The California Attorney General's office has treated GPC as a valid opt-out request since a 2021 CCPA regulation amendment, and the California Privacy Protection Agency actively enforces it, including a September 2025 joint sweep with the Colorado and Connecticut Attorneys General.
What happens if a company ignores a GPC signal? It can trigger a CCPA enforcement action. In September 2025, the California Privacy Protection Agency fined American Honda Motor Co. 632,500 dollars and clothing retailer Todd Snyder 345,178 dollars for failing to honor consumers' Global Privacy Control opt-out requests.
Which browsers support Global Privacy Control? Brave, DuckDuckGo, and Firefox all natively support Global Privacy Control as of 2026, according to Hausladen et al.'s USENIX Security 2025 study, alongside dedicated browser extensions from Disconnect, Privacy Badger, and Ghostery.
Where the Numbers Come From
- Hausladen, Wang, Eng, Wang, Wijaya, May, and Zimmeck: Websites' Global Privacy Control Compliance at Scale and over Time (USENIX Security 2025). Wesleyan University and Princeton University. Longitudinal crawl of 11,708 US websites in December 2023, February 2024, and April 2024, with a 100-site manually verified accuracy test set.
- Wesleyan University: Study, Majority of Websites Don't Honor Opt-Outs (July 2025). Research summary covering Sebastian Zimmeck's team's findings, including the August 2022 baseline compliance figure.
- California Privacy Protection Agency: Joint Investigative Sweep Announcement (September 9, 2025). Details of the American Honda ($632,500) and Todd Snyder ($345,178) settlements for failing to honor Global Privacy Control opt-out requests.
Note: All figures verified as of August 2026. The underlying compliance crawl data runs through April 2024, the most recent published snapshot as of this post's publication; state privacy law recognition of universal opt-out signals continues to expand and should be checked against each state's current statute before relying on it for legal compliance decisions.