Only 45% of the 11,708 US websites Wesleyan University researchers tracked actually honored Global Privacy Control opt-out signals as of April 2024, the largest direct measurement available of whether businesses meet a state privacy law's core opt-out requirement, according to research presented at USENIX Security 2025. That figure has barely moved since researchers started tracking sites in December 2023. No single audited number covers every clause of every state privacy law at once, so the studies below all measure the one requirement that is actually testable at scale: does a website stop selling or sharing personal data when a visitor tells it to.

What percentage of US companies actually honor a state privacy opt-out signal?

45% of tracked websites honored a Global Privacy Control (GPC) opt-out signal as of April 2024, according to Sebastian Zimmeck's research team at Wesleyan University, whose findings were presented at USENIX Security 2025 after tracking 11,708 US websites continuously since December 2023. GPC is the browser-level signal that California, Colorado, Connecticut, and nine other states now require covered businesses to recognize as a valid opt-out of the sale or sharing of personal information.

Less than half of websites honor state privacy opt-out signals 45% of tracked US websites honoredGlobal Privacy Control opt-outs

The remaining 55% of tracked sites either ignored the signal entirely or kept sharing data with third parties after receiving it. Zimmeck's team built its methodology directly from what regulators check: does the site's server detect the signal, does it stop selling or sharing data for that visitor, and do third-party ad tags stop firing within a reasonable window. A site that passes only one or two of those three tests still counts as non-compliant in the study's tally.

GPC opt-out compliance among 11,708 tracked websites, April 2024 45%55%Honored the opt-out45%Ignored the opt-out55%

Figure 1: Fewer than half of tracked sites passed the full opt-out test. Source: Sebastian Zimmeck, Wesleyan University, presented at USENIX Security 2025.

A near-even split like this is a hard number for any single business to hide behind. If a company's own compliance is a coin flip against a stat this well documented, a customer, a journalist, or a state attorney general checking the same signal has roughly even odds of catching the gap.

Is opt-out compliance getting better or worse over time?

Compliance has held almost flat rather than trending in either direction. Zimmeck's team recorded 44% compliance in December 2023, a slight dip to 43% in February 2024, then a recovery to 45% by April 2024, the most recent measurement published from that tracking run as of this post's writing.

GPC opt-out compliance rate over time, 11,708 tracked websites 012.52537.550%Dec 2023Feb 2024Apr 202445%

Figure 2: Compliance moved two points in either direction across five months rather than climbing steadily. Source: Sebastian Zimmeck, Wesleyan University, USENIX Security 2025.

A flat trend line across a period when several new state laws took effect suggests most of the businesses now covered by an opt-out mandate had not meaningfully changed their systems by the time each new law started. Zimmeck's own assessment matches the data: "There is some compliance, but there's also a long way to go." Enforcement pressure, not a new law's effective date alone, appears to be what eventually moves this number.

How many top retailers ignore an opt-out after a shopper submits it?

12 of 40 major online retailers, 30%, kept serving retargeted advertisements to shoppers on other publisher websites after those shoppers had opted out using GPC, according to an April 2025 study Consumer Reports ran jointly with Wesleyan University. Researchers used a VPN to browse from Los Angeles and Denver IP addresses, enabled GPC on each retailer's site, added items to a cart, then visited ten publisher sites to check for retargeted ads tied to that cart.

That means 70% of the 40 retailers tested did pass the retargeting portion of the test, a notably higher pass rate than the 45% figure covering all site types and all data-sharing categories, which suggests large, recognizable retail brands may be further along on this specific requirement than the broader website population. Matt Schwartz, a Consumer Reports policy analyst involved in the study, argued the gap points to an enforcement resourcing problem rather than a technical one: "State attorneys general need more resources to enforce these laws, and individuals harmed by privacy violations should have the right to action."

Which industries fail state privacy compliance tests most often?

Finance had the worst opt-out failure rate of any industry tested, at 74%, according to InfoTrust's State of Consent Compliance 2025 report, which audited 450 US websites across five industries for whether they kept loading advertising or targeting tags after a visitor opted out. Media followed at 71%, and eCommerce and CPG sites combined came in at 57%. Healthcare had the best record by a wide margin, though its 21% failure rate still means roughly one in five healthcare sites tested failed to suppress tracking on request.

Share of sites still tracking visitors after they opt out, by industry 020406080%74Finance71Media57eCommerce and CPG21Healthcare

Figure 3: Finance sites were more than three times as likely to keep tracking after opt-out as healthcare sites. Source: InfoTrust, State of Consent Compliance 2025, audit of 450 US websites.

Across the full 450-site sample, InfoTrust found 79% of sites kept loading at least one targeting or advertising tag after a user explicitly opted out, and nearly a quarter of sites made no measurable change at all to their tracking behavior. The median non-compliant site in the audit kept sharing data with five separate advertising or analytics vendors after opt-out, and the worst individual case reached 139 platforms. Regulators have started following up on exactly this pattern: the California Privacy Protection Agency fined Tractor Supply $1.35 million on September 30, 2025, its largest penalty to date, for several violations including failing to provide an effective opt-out mechanism such as Global Privacy Control.

Do companies think they are compliant, even when they aren't?

91% of respondents said they were at least somewhat confident in their organization's ability to comply with privacy regulatory requirements, and 21% reported total confidence, according to the IAPP-EY Annual Privacy Governance Report, a self-reported survey of privacy professionals whose page was most recently updated in November 2024 and does not publish a disclosed sample size in its public summary. That confidence figure sits far above the roughly 45% compliance rate researchers actually measured when they tested real websites against a state privacy law's opt-out requirement.

Figure 4: The three-step test researchers actually run before counting a site as compliant. Source: methodology described by Sebastian Zimmeck, Wesleyan University, and InfoTrust's State of Consent Compliance 2025.

The gap between confidence and measured behavior is not necessarily dishonesty. A privacy team can reasonably believe its policy language, its consent banner, and its documented processes are correct while a specific third-party ad tag, set up by a marketing team using a different vendor, keeps firing regardless of what the signal says. That gap between what a company's privacy team believes and what a browser signal actually finds is exactly what these audits are built to expose.

How many states require an opt-out signal like GPC right now?

12 states will require covered businesses to recognize an opt-out preference signal such as GPC as of January 1, 2026: California, Colorado, Connecticut, Montana, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Delaware, Oregon, and Texas, according to compliance vendor Didomi's December 2025 tracker of the requirement. That sits inside a wider group of 20 states with a comprehensive consumer privacy law in effect as of January 2026; see our full state-by-state list and effective-date tracker for the other eight, which give consumers an opt-out right but have not yet mandated recognition of a browser-level signal specifically.

Figure 5: Three years of independent measurement all point to the same gap between what state law requires and what most sites actually do. Source: Wesleyan University, InfoTrust, California Privacy Protection Agency, Didomi.

A site is far more likely to get tested against this specific requirement than against most other clauses in a state privacy law, since checking whether a signal is honored takes a researcher, a journalist, or a regulator only a browser extension and a few minutes. Businesses building or refreshing a policy for these states can generate a privacy policy that names the opt-out mechanisms it actually supports, which is a cheaper first step than a six-figure fine and a public enforcement notice.

How the leading studies compare

SourceSample sizeResultYear
Wesleyan University, USENIX Security 202511,708 websites, measured45% honored GPC opt-out (Apr 2024)2025
Consumer Reports and Wesleyan University40 online retailers, measured30% kept serving retargeted ads after opt-out2025
InfoTrust, State of Consent Compliance 2025450 US websites, measured79% still loaded a tracking tag after opt-out2025
IAPP-EY Annual Privacy Governance ReportSample size not disclosed, self-reported91% at least somewhat confident in compliance ability2024

Source: Wesleyan University (Zimmeck), Consumer Reports, InfoTrust, and IAPP-EY, as cited throughout this post and listed in full below.

Where opt-out failures cluster by industry

IndustryOpt-out failure rate
Finance74%
Media71%
eCommerce and CPG57%
Healthcare21%

Source: InfoTrust, State of Consent Compliance 2025, audit of 450 US websites across five industries.

The Bottom Line

Every independent study measuring actual website behavior, rather than self-reported confidence, lands in a similar place: somewhere between 21% and 55% of tested businesses fail a state privacy law's most testable requirement, honoring an opt-out signal. That is a wide enough gap that it cannot be explained away as a handful of laggards. It reflects a genuine, well documented shortfall between what state privacy laws require and what most covered businesses have actually implemented, even at large, well resourced retailers. The confidence gap matters too: 91% of privacy professionals report feeling at least somewhat prepared, which means most of the businesses failing these tests do not know they are failing until a researcher, a journalist, or a regulator checks. A current privacy policy that accurately names the opt-out mechanisms a business actually supports, paired with an ad-tag audit to confirm those mechanisms work in practice, addresses the exact gap every study above measured.

Frequently Asked Questions

What percentage of US companies actually honor state privacy opt-out signals? 45% of the 11,708 US websites tracked by Wesleyan University researchers honored Global Privacy Control opt-out signals as of April 2024, according to research presented at USENIX Security 2025. The rate held in a narrow 43% to 45% band from December 2023 through April 2024, the full period the researchers tracked.

Do most companies believe they comply with privacy law, even if they don't? 91% of respondents said they were at least somewhat confident in their organization's ability to comply with privacy regulatory requirements, and 21% reported total confidence, according to the IAPP-EY Annual Privacy Governance Report. That self-reported confidence sits far above the roughly 45% measured compliance rate researchers actually found when they tested real websites.

Which industries fail state privacy compliance tests most often? Finance had the worst opt-out failure rate at 74%, followed by media at 71% and eCommerce and CPG at 57%, according to InfoTrust's audit of 450 US websites in its State of Consent Compliance 2025 report. Healthcare performed best at a 21% failure rate, meaning roughly one in five healthcare sites still failed the test.

Has any company been fined specifically for ignoring Global Privacy Control? Yes. The California Privacy Protection Agency fined Tractor Supply 1.35 million dollars on September 30, 2025, its largest penalty to date, for several violations including failing to provide an effective opt-out mechanism such as Global Privacy Control.

Where the Numbers Come From

  1. Wesleyan University. (2025). "Study: Majority of Websites Don't Honor Opt-Outs." Sebastian Zimmeck's research, presented at USENIX Security 2025, tracking 11,708 US websites since December 2023; 44% compliant December 2023, 43% February 2024, 45% April 2024.
  2. Wesleyan University and Consumer Reports. (2025). "New Study Probes If Online Retailers Follow Privacy Opt Outs." 40 online retailers tested; 12 (30%) served retargeted ads after a GPC opt-out. Published April 11, 2025.
  3. InfoTrust. (2025). "The State of Consent Compliance 2025." Audit of 450 US websites across five industries; 79% kept loading a tracking tag after opt-out, with failure rates from 21% (healthcare) to 74% (finance).
  4. IAPP. "Privacy Governance Report." 91% of respondents at least somewhat confident in their organization's ability to comply with privacy regulatory requirements, 21% totally confident; page last updated November 12, 2024, no public sample size disclosed.
  5. California Privacy Protection Agency. (2025). Enforcement action against Tractor Supply. $1,350,000 fine, September 30, 2025, for failing to provide an effective opt-out mechanism including Global Privacy Control, among other violations.
  6. Didomi. (2025). "Global Privacy Control (GPC) in 2026." Twelve states requiring recognition of an opt-out preference signal by January 1, 2026. Published December 4, 2025; a compliance-vendor compiled tracker rather than a primary regulatory source.
  7. IAPP. "US State Privacy Legislation Tracker." 20 states with a comprehensive consumer privacy law in effect as of January 2026.

Note: All figures verified as of August 2026. The Wesleyan University tracking figures reflect an April 2024 snapshot, the most recent published from that specific research run at the time of writing, and the Didomi state count is a compliance-vendor tracker rather than a primary regulatory source. Figures are refreshed at least twice a year as new studies, audits, and enforcement actions are published.