Websites' Global Privacy Control Compliance at Scale and over Time
Katherine Hausladen
34th USENIX Security Symposium (USENIX Security '25) · Day 3 · Privacy 2: Consent, Compliance, and Provable Privacy
Overview
In an era dominated by the "data for content" business model, where users often exchange personal information for access to online services, the right to opt out of data sharing and sales has become a critical privacy safeguard. However, exercising this right is frequently hampered by overly complex and opaque consent interfaces, leaving many users frustrated and their privacy preferences unheeded. This talk, presented by Sebastian Zc from Wesleyan University, introduces and rigorously evaluates the real-world adoption and effectiveness of Global Privacy Control (GPC), a standardized mechanism designed to simplify and automate the process of opting out.

Key moments
- 0:00 Introduction to GPC and the opt-out problem
- 2:00 Understanding Global Privacy Control (GPC) mechanism
- 3:00 GPC technical implementation and varying legal interpretations
- 6:00 Driving GPC adoption: CMPs, browsers, regulators
- 8:00 Methodology for detecting GPC compliance
- 9:30 Key findings: GPC compliance rates over time
- 11:36 Transition to Global Privacy Platform (GPP)
Websites' Global Privacy Control Compliance at Scale and over Time
Speakers: Sebastian Zc, Professor, Wesleyan University
Conference: USENIX Security
YouTube: https://www.youtube.com/watch?v=JgKA5Ra5WfM
Overview
In an era dominated by the "data for content" business model, where users often exchange personal information for access to online services, the right to opt out of data sharing and sales has become a critical privacy safeguard. However, exercising this right is frequently hampered by overly complex and opaque consent interfaces, leaving many users frustrated and their privacy preferences unheeded. This talk, presented by Sebastian Zc from Wesleyan University, introduces and rigorously evaluates the real-world adoption and effectiveness of Global Privacy Control (GPC), a standardized mechanism designed to simplify and automate the process of opting out.
GPC aims to empower users by allowing their browsers or operating systems to automatically signal their opt-out preference to websites and applications, effectively acting as a "little robot" that pushes the opt-out button on their behalf. Zc's research provides a comprehensive, large-scale, and longitudinal analysis of GPC compliance across over 11,000 websites, offering crucial insights into the current state of privacy regulation adherence. The findings are vital for understanding the practical impact of privacy laws like the California Consumer Privacy Act (CCPA) and similar statutes, highlighting both the progress made and the significant challenges that remain in ensuring robust user privacy online.
The study’s methodology involves systematically observing website behavior with and without GPC enabled, tracking how sites propagate opt-out signals through various privacy flags to third parties. By quantifying the compliance rates and monitoring their evolution over time, Zc and his team provide actionable data for regulators, policymakers, and website operators. This research not only illuminates the technical intricacies of GPC implementation but also underscores the broader implications for user trust, regulatory enforcement, and the future of privacy-respecting web design.
Background
▶ Watch: Introduction to GPC and the opt-out problem (0:00)
The pervasive "data for content" business model underpins much of the modern internet, where users implicitly trade their personal data for access to free services, social media, and digital content. While this model has fueled innovation and accessibility, it has also raised significant privacy concerns regarding the collection, sharing, and sale of personal information. In response, a growing number of privacy laws, such as the California Consumer Privacy Act (CCPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CDPA), and the New Jersey Data Privacy Act (NJDPA), have granted consumers the statutory right to opt out of these data practices.
However, the practical exercise of these rights has proven to be a significant hurdle for the average user. Websites commonly present users with intricate and often confusing consent management interfaces, replete with multi-layered options, ambiguous language, and dark patterns designed to encourage consent rather than facilitate opt-out. These screens, ranging from cookie banners to granular data preference settings, demand considerable cognitive load and time from users, making effective privacy management a daunting task. The complexity of these interfaces, often featuring elements like the IAB's Transparency and Consent Framework (TCF), renders them largely incomprehensible to non-technical users, undermining the very intent of privacy legislation.
Global Privacy Control (GPC) emerged as a proposed solution to this systemic problem. The fundamental idea behind GPC is to standardize a simple, automated mechanism for users to convey their privacy preferences across the web. Instead of manually navigating complex opt-out forms on every website, GPC allows a user's browser, operating system, or platform software to send a clear signal to websites and integrated third parties, instructing them to refrain from selling or sharing the user's personal information. This "push-button" automation aims to drastically reduce the friction associated with exercising privacy rights, making it a more accessible and effective tool for consumers.
The GPC specification is currently under consideration at the W3C (World Wide Web Consortium), the main international standards organization for the World Wide Web. Its details are publicly available on globalprivacycontrol.org, providing resources for both users and implementers. A crucial aspect of GPC is its flexibility: while the mechanism for sending the signal is standardized, the precise meaning of that signal can vary depending on the local jurisdiction. For instance, in California, GPC might signify an opt-out from both the selling and sharing of personal information, whereas under the GDPR in Europe, it might be interpreted as an objection to data processing for advertising purposes. This adaptability allows GPC to serve as a universal technical signal that can be mapped to diverse legal requirements and regulatory interpretations.
Driving the adoption of GPC are various stakeholders. Consent Management Platforms (CMPs), such as OneTrust and Didomi, have integrated GPC support, offering website operators a streamlined way to comply with privacy regulations. Several popular browsers, including Firefox and Brave.go, now include native GPC settings, and browser extensions are available for those using other browsers. Non-profit organizations like Consumer Reports and governmental regulators in states such as California, Colorado, and Connecticut are also actively promoting and enforcing GPC compliance, recognizing its potential to significantly improve the privacy landscape for internet users.
Key Findings
▶ Watch: GPC technical implementation and varying legal interpretations (3:00)
The research undertaken by Sebastian Zc and his team provides a critical empirical assessment of GPC compliance, employing a robust methodology to track adoption and effectiveness over time. The core of their approach involved a two-step process for each website analyzed: first, visiting the site without GPC enabled to establish a baseline; second, enabling GPC and observing the site's reaction, specifically looking for changes in widely used privacy flags. These flags, which include the IAB US Privacy String, Google's Restricted Data Processing (RDP), and Meta's Limited Data Use (LDU), are mechanisms used by first-party websites to propagate user opt-out preferences to integrated third parties. The study focused on analyzing this propagation as a key indicator of GPC compliance.
The study analyzed over 11,000 websites, with a particular focus on those that implemented the US privacy string, totaling 1,687 sites. The findings revealed a mixed picture of GPC adoption and compliance, with a significant proportion of sites failing to respect the signal.
Compliance with IAB US Privacy String:
- December 2023: Out of 1,687 sites that had implemented the US privacy string, 663 (approximately 39.3%) opted users out after receiving the GPC signal. Conversely, a substantial 871 sites still did not respect the opt-out, while 157 did not opt users out even without GPC, and 31 opted users out regardless of the GPC signal. Another 132 indicated the opt-out right was not applicable.
- February 2024: A modest improvement was observed, with 777 sites opting users out after GPC was sent, an increase from 663.
- April 2024: The compliance rate largely stabilized, with 770 sites opting users out.
These figures indicate a slow but positive trend towards increased GPC compliance over time, though more than half of the sites analyzed still failed to honor the opt-out signal. Zc noted that this longitudinal data collection would be crucial for assessing the effectiveness of future regulatory enforcement actions, expecting to see a more pronounced increase in opt-outs following such interventions.
Compliance with Global Privacy Platform (GPP):
During the study period, the IAB US Privacy String was deprecated and replaced by the Global Privacy Platform (GPP). The research tracked the adoption of this newer standard, revealing an even slower uptake:
- December 2023: Only 44 sites demonstrated GPP-based compliance by opting users out.
- April 2024: This number increased to 131 sites.
This transition highlights the challenges of evolving privacy standards and the lagging pace of adoption for new compliance technologies, further contributing to the overall slow level of compliance observed.
Strategies for Increasing Impact:
The research identified two key areas where efforts could yield significant improvements in GPC compliance:
- Big Publishers: Many large publishers operate hundreds or even thousands of websites under a unified data management infrastructure. Non-compliance or incorrect GPC implementation by these entities can have a disproportionately large impact on user privacy. Zc emphasized that notifying such publishers, whose non-compliance is often due to technical misconfiguration rather than malicious intent, can lead to dramatic improvements across a vast number of sites.
- Individual High-Profile Sites: Beyond large publishers, individual websites with exceptionally high user traffic also represent critical targets for compliance efforts. Ensuring these sites respect GPC can significantly enhance privacy protections for a large user base.
Regulators are encouraged to focus their enforcement efforts on these high-leverage targets—big publishers and high-profile individual sites—to maximize the impact of GPC and accelerate its adoption.
Data Availability for Further Research:
A significant contribution of this work is the commitment to open science. All software used in the analysis, along with the collected data, is made publicly available at privacysurvey.org. The team plans to continue their crawls every three months, extending the longitudinal analysis beyond the initial California-focused data points (December 2023, February 2024, April 2024) to include later periods in 2024 and 2025. Furthermore, data for additional states—Colorado, Connecticut, and New Jersey—will also be released, providing a rich resource for other researchers, privacy advocates, and regulators to conduct their own analyses and monitor the evolving landscape of GPC compliance.
Technical Deep Dive
▶ Watch: Driving GPC adoption: CMPs, browsers, regulators (6:00)
The Global Privacy Control (GPC) mechanism is designed to provide a lightweight yet unambiguous signal from a user agent (e.g., browser, operating system) to a website or application, indicating the user's preference to opt out of the sale or sharing of their personal information. The technical specification for GPC outlines two primary methods for transmitting this signal: an HTTP header and a DOM (Document Object Model) property.
- HTTP
Sec-GPCHeader: When a GPC-enabled browser makes an HTTP request to a website, it includes a specific header:Sec-GPC: 1. The value1signifies that the user has enabled GPC and wishes to exercise their privacy opt-out rights. This header is sent with every request, allowing server-side applications to detect the GPC signal before any client-side JavaScript executes. This is particularly important for initial page loads and interactions that primarily involve server-side logic. The server can then process this signal and adjust its data handling practices accordingly.
- DOM Property: For client-side detection, GPC also specifies a JavaScript-accessible property on the
navigatorobject:navigator.globalPrivacyControl. This property will returntrueif GPC is enabled andfalseotherwise. Websites can query this DOM property using JavaScript to dynamically adjust their behavior, interact with embedded third-party scripts, or display relevant privacy information to the user. This client-side mechanism allows for greater flexibility and responsiveness in handling the GPC signal within the browser environment.
The specification for GPC is hosted at the W3C, ensuring a standardized approach that can be widely adopted across different platforms and technologies. A critical aspect highlighted in the talk is the jurisdictional flexibility of GPC. While the technical signal is consistent, its legal interpretation and the specific data practices it prohibits can vary based on local privacy laws (e.g., CCPA in California, GDPR in Europe). This means implementers must map the GPC signal to the relevant legal obligations in the user's jurisdiction.
The research methodology for detecting GPC compliance hinges on how websites, particularly first parties, propagate the GPC signal to their integrated third-party services. This propagation is typically achieved through the modification of specific privacy flags or strings that third-party scripts are designed to read. The study focused on three prominent examples:
- IAB US Privacy String: This string, part of the IAB Tech Lab's US Privacy framework, provides a standardized way for websites to communicate consumer privacy choices, including opt-out signals, to advertising and data partners. When a GPC signal is received, a compliant website would update this string to reflect the user's opt-out preference.
- Google's Restricted Data Processing (RDP): Google offers mechanisms for advertisers and publishers to limit how user data is used, particularly in response to privacy regulations. A GPC-compliant site would trigger Google's RDP settings to ensure that data shared with Google's advertising platforms adheres to the user's opt-out.
- Meta's Limited Data Use (LDU): Similar to Google's RDP, Meta (Facebook) provides a Limited Data Use mode that restricts how certain data is processed for users who have exercised their opt-out rights. A compliant website would activate LDU when a GPC signal is present.
The research's automated crawling system first visited a target website without sending the Sec-GPC header or setting the navigator.globalPrivacyControl property. This established a baseline of the site's default data practices. Subsequently, the system re-visited the same site with GPC enabled. By comparing the state of the IAB US Privacy String, Google RDP, and Meta LDU before and after GPC activation, the researchers could determine if the website acknowledged and propagated the opt-out signal. This comparative analysis, conducted at scale across 11,000+ sites and over multiple time points (December 2023, February 2024, April 2024), allowed for a robust, longitudinal assessment of compliance trends.
A significant technical shift observed during the study was the deprecation of the IAB US Privacy String and the introduction of the Global Privacy Platform (GPP). GPP is a newer, more comprehensive framework by the IAB Tech Lab designed to manage consent and privacy signals across various global privacy regulations. The study's ability to track the adoption of GPP alongside the older US Privacy String provides valuable insights into the industry's transition to new privacy standards, highlighting the slow and gradual nature of such shifts. The availability of the researchers' software and data at privacysurvey.org underscores their commitment to transparency and reproducibility, offering a valuable resource for the wider security and privacy research community.
Demo / Proof of Concept
▶ Watch: Key findings: GPC compliance rates over time (9:30)
While the talk itself did not feature a live demonstration of a specific tool or a real-time proof of concept, the entire research presented can be considered a large-scale, automated proof of concept for assessing GPC compliance. The speaker described a sophisticated methodology involving automated web crawls and the programmatic detection of privacy signal propagation.
The research team developed and utilized software to systematically visit over 11,000 websites, first without GPC enabled and then with the signal activated. This automated system was designed to detect changes in specific privacy flags, such as the IAB US Privacy String, Google's Restricted Data Processing (RDP), and Meta's Limited Data Use (LDU), which serve as indicators of a website's response to the GPC signal. The findings, presented through detailed graphs and statistics across multiple time periods, effectively demonstrate the real-world impact and current limitations of GPC. Furthermore, the speaker explicitly mentioned that all the software used for their analysis, along with the comprehensive dataset collected, is publicly available on privacysurvey.org. This allows other researchers and interested parties to replicate their findings, conduct independent analyses, and even extend the monitoring of GPC compliance, effectively serving as a distributed, ongoing proof of concept.
Defensive Implications
▶ Watch: Transition to Global Privacy Platform (GPP) (11:36)
The findings from this extensive research on Global Privacy Control compliance carry significant implications for various stakeholders involved in the digital ecosystem, ranging from website operators and developers to privacy advocates and regulatory bodies.
For Website Operators and Publishers:
The most direct implication is the imperative to implement and respect GPC signals correctly. Many websites, particularly those falling under the purview of privacy laws like CCPA, are legally required to honor these opt-out requests. Publishers should:
- Integrate GPC detection: Implement server-side detection for the
Sec-GPCHTTP header and client-side detection via thenavigator.globalPrivacyControlDOM property. - Utilize Consent Management Platforms (CMPs): Leverage GPC-compliant CMPs like OneTrust or Didomi, which can simplify the technical implementation and ensure proper propagation of the GPC signal.
- Ensure Third-Party Propagation: Critically, the GPC signal must be effectively propagated to all integrated third-party services and ad networks. This involves correctly updating privacy flags such as the Global Privacy Platform (GPP) (which superseded the IAB US Privacy String), Google's Restricted Data Processing (RDP), and Meta's Limited Data Use (LDU). Failure to propagate these signals means that even if a first party acknowledges GPC, third parties may still process data against user preferences.
- Regular Compliance Audits: Conduct periodic self-audits or engage third-party services to verify GPC compliance. The research highlights that non-compliance is often due to "incorrect implementation," not malicious intent, making technical oversight crucial.
- Focus on High-Impact Sites: Large publishers and individual high-traffic websites have a greater responsibility and opportunity to make a significant impact on user privacy. Prioritizing correct GPC implementation on these platforms is essential.
For Developers and Privacy Engineers:
- Stay Updated on Standards: Keep abreast of evolving privacy standards, such as the transition from the IAB US Privacy String to GPP. Implementing deprecated standards can lead to non-compliance.
- Robust Implementation: Develop robust, jurisdiction-aware GPC handling logic. The GPC signal's meaning can vary, requiring careful mapping to specific legal obligations.
- Testing and Validation: Thoroughly test GPC implementations across different browsers, device types, and integrated third-party services to ensure consistent and accurate signal propagation.
For Users:
- Enable GPC: Users should be encouraged to enable GPC in their browsers (e.g., Firefox, Brave.go) or via browser extensions. This is the simplest way to exercise their opt-out rights automatically.
- Understand Limitations: Be aware that GPC compliance is not universal. The research shows that over 50% of sites still do not respect the signal, meaning GPC is a valuable tool but not a complete solution for privacy protection.
- Advocacy: Support organizations like Consumer Reports that advocate for stronger privacy controls and GPC adoption.
For Regulators and Policy Makers:
- Targeted Enforcement: The research provides clear evidence for targeted enforcement actions. Focusing regulatory pressure on large publishers and high-profile non-compliant sites can yield the greatest impact on overall compliance rates.
- Monitor Compliance: Utilize research like this, including the publicly available data and software, to continuously monitor GPC adoption and compliance trends. This data can inform policy effectiveness and identify areas requiring further intervention.
- Promote Standard Adoption: Encourage the adoption of standardized mechanisms like GPC to simplify compliance for businesses and enhance privacy for users, moving away from fragmented and confusing consent interfaces.
- Clarify Interpretations: Provide clear guidance on how GPC signals should be interpreted and acted upon under specific privacy laws in their respective jurisdictions.
Overall, the defensive implications underscore a collective responsibility to improve the privacy landscape. While GPC offers a powerful technical solution, its effectiveness hinges on widespread and accurate implementation by website operators, supported by consistent monitoring and enforcement by regulatory bodies, ultimately empowering users to exercise their fundamental privacy rights more effectively.
Key Takeaways
- GPC Simplifies Opt-Out, but Adoption is Slow: Global Privacy Control (GPC) offers a crucial, automated mechanism to simplify user opt-out rights under privacy laws, but its real-world adoption by websites is progressing slowly.
- Significant Non-Compliance Persists: In December 2023, only about 39.3% of sites using the IAB US Privacy String honored the GPC signal, with over 50% failing to respect the opt-out. While compliance saw a slight increase by April 2024, a large proportion of websites still do not properly implement GPC.
- Evolving Standards Challenge Adoption: The transition from the IAB US Privacy String to the Global Privacy Platform (GPP) highlighted slow adoption of new compliance technologies, with GPP compliance starting at only 44 sites in December 2023 and slowly rising to 131 by April 2024.
- Propagation to Third Parties is Key: GPC's effectiveness relies on websites correctly propagating the user's opt-out signal to third parties through privacy flags like Google's RDP and Meta's LDU; simply receiving the GPC header isn't enough if the signal isn't cascaded.
- Targeted Efforts Can Maximize Impact: Focusing regulatory and advocacy efforts on large publishers (who manage thousands of sites) and individual high-profile websites can significantly accelerate GPC compliance and improve privacy for a vast number of users.
- Open Data for Ongoing Monitoring: The research team provides all software and extensive longitudinal data for California, Colorado, Connecticut, and New Jersey at
privacysurvey.org, enabling continuous monitoring and further research into GPC compliance trends.
About the Speaker(s)
Sebastian Zc is a faculty member at Wesleyan University, where his research interests lie in the intersection of technology and privacy, particularly focusing on mechanisms that empower users to control their personal data online. His work, supported by organizations such as the National Science Foundation under the Secure and Trustworthy Cyberspace program, Wesleyan University, and the Anil Fernando Endowment, aims to analyze and improve the effectiveness of privacy-enhancing technologies. Zc is dedicated to understanding the practical challenges of implementing privacy laws and developing scalable solutions to enhance the opt-out situation on the internet. He can be contacted for further discussion about his work via privacytechlab.org.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Competent empirical privacy research with genuine value for regulators and policy researchers — it's rigorous, longitudinal, and open-access. But this is measurement science, not security research in any meaningful offensive or defensive sense, and the findings (roughly half the web ignores a voluntary opt-out signal) won't surprise anyone who's spent five minutes thinking about adtech incentives.
Heather Calloway (CISO) — SOLID
Rigorous empirical work on GPC compliance with genuine policy utility — the open dataset and longitudinal methodology are real contributions. But the talk stays at the measurement layer and never quite becomes a governance document, leaving the institutional accountability question underexplored.
→ Top-rated talks at 34th USENIX Security Symposium (USENIX Security '25)
All talks from 34th USENIX Security Symposium (USENIX Security '25)