Global Privacy Control & DNT What We Honour
Cookie Control honours Global Privacy Control in CCPA mode and does not respond to Do Not Track. The exact scope, and the reasons.
How Cookie Control handles Global Privacy Control and Do Not Track browser signals
Cookie Control honours the Global Privacy Control signal in CCPA mode: a visitor sending GPC is treated as objecting to tracking and all categories default to off. It does not respond to Do Not Track, because the W3C disbanded the DNT working group in 2019 and browser support was never consistent, though your privacy policy may still need to say where you stand on DNT.
Browser privacy signals are an area where vendors tend to be vaguest exactly where they should be clearest — "respects user privacy signals" can mean almost anything. Here is our position, stated precisely, with the reasoning. It is short because the truthful version is short.
Global Privacy Control: honoured, in CCPA mode
Since v9.8, when Cookie Control runs in CCPA mode and a visitor’s browser or extension sends a Global Privacy Control signal, the platform accepts it as an intent not to be tracked and prevents automatic tracking from occurring. The effect is deliberately strong: all categories default to off — even though CCPA is an opt-out regime where categories would otherwise start enabled — unless the visitor has overridden the signal by explicitly opting in to a category on your site. The visitor has expressed a preference through their browser, and the banner respects it before they touch anything.
The scope is equally deliberate: CCPA mode. GPC was created as a mechanism for exercising opt-out rights under California law, and California’s regulator has confirmed businesses must honour it. We implement it where it has defined legal meaning, rather than sprinkling it decoratively across regimes that define consent differently. Under UK GDPR and PECR, consent is opt-in from the start — every optional category is already off until the visitor acts, which is a stronger default than GPC requests. It is also a different mechanism from Consent Mode v2, which carries the visitor’s decision to Google’s tags after it has been made; GPC shapes the default before any decision.
One scope note for Premium customers: the GPC behaviour described here is documented for the current edition’s CCPA mode. Premium’s documentation does not yet describe GPC handling, so if you run Premium and serve California traffic, ask us before relying on it.
Cookie Control in CCPA mode defaulting all categories off for a visitor sending a Global Privacy Control signal.
Do Not Track: not honoured, and here is why
Cookie Control does not respond to Do Not Track. The reason is the signal’s history, not indifference: browser support was insufficient and varied throughout DNT’s life, and the W3C disbanded the DNT working group in January 2019. A signal with no maintained specification and inconsistent emission is a poor foundation for a compliance decision — a site could "honour" it and still behave differently from what any given visitor’s browser intended.
There is a footnote sites routinely miss: some regimes expect you to state your DNT position in your privacy policy even when — especially when — you do not respond to it. Not honouring DNT does not remove it from your paperwork. One sentence in the policy does the job.
The historical wrinkle we may as well own: Cookie Control v7 supported DNT back in November 2015, running in explicit mode when the header was present — at a time the signal still looked like it had a future. We removed reliance on it as the standard collapsed. Positions should track reality.
What should you do on your own site?
- If you serve California traffic, run CCPA mode for those visitors — GPC handling then comes built in, defaulting every category off for signal-sending visitors. Our 2027 guide has a short section on US traffic alongside the UK and EU rules.
- State your DNT position in your privacy policy, whichever position it is.
- Do not claim signal support your stack does not deliver — "we respect GPC" on a site whose CMP ignores it is exactly the kind of gap regulators and researchers go looking for.
Frequently asked questions
Sources
- Cookie Control documentation — Optional categories CCPA mode and Global Privacy Contro
- Cookie Control documentation — v9 overview Do Not Track statement
- Cookie Control documentation — Version changelog (v9.8, 2 December 2022)
- Cookie Control — v7 released (27 November 2015) DNT header support
- Global Privacy Control — specification and adoption
- California Attorney General — CCPA and Global Privacy Control