United States · California
CCPA/CPRA: cookies, sharing and Global Privacy Control
Why a European opt-in banner is not a complete California workflow and where GPC fits.
7 min read · 1 August 2026
Start with the business practice
California analysis turns on what data is collected and whether it is sold or shared for cross-context behavioural advertising, not on the word “cookie” alone. Map each advertising and analytics vendor to the actual data flow and contract.
The CPRA amended the CCPA and the current framework gives eligible consumers rights including deletion, correction and opting out of sale or sharing.
Opt-out is a separate product requirement
A generic cookie settings panel may not satisfy a request to opt out of sale or sharing. California enforcement examples stress that businesses must provide an effective mechanism and honour the resulting choice across relevant technologies.
- Expose a clear “Do Not Sell or Share My Personal Information” path where required.
- Apply the choice to server-side and downstream sharing, not only browser cookies.
- Avoid dark patterns and unnecessary account creation.
- Keep the privacy notice aligned with the actual mechanism.
Recognise GPC
Global Privacy Control is a browser-level signal. Covered businesses should detect it and apply the relevant opt-out without forcing the visitor through an additional form.
Decide how GPC interacts with an existing logged-in preference and document the precedence rule. A privacy signal should not be overwritten by an unrelated consent banner action.
Operational test
Run a California test profile with and without GPC. Inspect browser and server events, advertising destinations and preference persistence. Capture evidence that the signal was received and enforced.