An opt-out signal is a machine-readable message, sent automatically by a browser or a device, telling every business it reaches that the person behind it refuses the sale or sharing of their personal information and its use for targeted advertising. California regulation calls it an opt-out preference signal. Colorado calls it a universal opt-out mechanism. Practitioners shorten the first to OOPS. All three name the same construct: a standing instruction, set once, that substitutes for clicking a link on each site.

The category exists because a right and the labour of exercising it grew apart. Roughly a dozen state privacy laws give residents the right to refuse data sales and cross-context advertising, but the default method is a per-site request. Section 7025 of the California Consumer Privacy Act regulations states the purpose plainly: a consumer can opt out of sale and sharing with all businesses they interact with online without making individualised requests to each one.

How the signal travels

The law does not name a technology. Section 7025(b) requires only that the signal arrive in a format commonly used and recognised by businesses, offering an HTTP header field or a JavaScript object as examples, and that whatever sends it makes the intent clear to the user. In practice one implementation dominates: Global Privacy Control, which travels as a request header reading Sec-GPC with the value 1, and as a browser property that a page script can read directly. Sites prefer the property, which resolves marginally faster.

That header stops at the first server it touches. Everything downstream of the publisher runs on encoded strings, so a consent management platform has to translate the refusal into something an exchange can parse.

The first translation layer was the US Privacy String, published by the IAB Tech Lab in final form in November 2019 with a clarification in March 2020. Four characters carried the whole state: specification version, whether notice was given, whether the person opted out of sale, and whether the publisher signed the Limited Service Provider Agreement. A string of 1YNN meant notice given and no opt-out; the third character did the legal work. The Tech Lab deprecated the signal on 31 January 2024.

Its replacement, the Global Privacy Platform, splits the payload into sections keyed to jurisdictions. The US National section carries named fields including SaleOptOut, SharingOptOut and TargetedAdvertisingOptOut, each holding 0 for not applicable, 1 for opted out and 2 for did not opt out, alongside notice fields and the MSPA flags that record which contractual mode the publisher operates under. State sections reserve a subsection named Gpc whose only job is to relay the browser value onward. The IAB's signalling guidelines of 26 January 2024 leave signatories free to use that subsection, the opt-out fields, or both. Six further state sections arrived in August 2024 for Delaware, Iowa, Nebraska, New Hampshire, New Jersey and Tennessee, and the framework gained state-specific extensions designed to absorb new laws without breaking existing parsers.

Inside the auction, OpenRTB 2.6 moves the container in regs.gpp with an array of applicable section identifiers in regs.gpp_sid. Receiving platforms then change behaviour. Google's restricted data processing mode stops using prior behaviour for targeting and sends non-personalised requests to bidders. AdSense added support for the national string in its second version from 6 October 2025.

Two operational rules matter more than the plumbing. The signal applies to the browser or device and to any profile associated with it, including pseudonymous ones, and to the identified person where the business knows who that is. And where a business relies on signal processing instead of posting opt-out links, the handling must be frictionless: no fee, no degraded experience, no pop-up or interstitial thrown up in response.

Origin and evolution

The idea predates the enforcement. The Platform for Privacy Preferences was standardised at the World Wide Web Consortium in 2002 and abandoned. Do Not Track shipped in browsers from 2011 and failed for a structural reason: honouring it was voluntary, and the working group never agreed what tracking meant.

California inverted the order. The right arrived first, in the Consumer Privacy Act of 2018, and the signal was built afterwards to exercise it. A coalition including Wesleyan University researcher Sebastian Zimmeck, later California Privacy Protection Agency director Ashkan Soltani, the Electronic Frontier Foundation, Mozilla, Brave and DuckDuckGo proposed Global Privacy Control in April 2020, and California began requiring businesses to honour it in January 2021.

Colorado added the registry model. Its attorney general published a list of recognised mechanisms on 1 January 2024, binding from 1 July that year, and Global Privacy Control remains the only entry.

The browser mandate took two attempts. Assembly Bill 3048 would have required browsers and mobile operating systems to carry the setting, and passed the legislature on 28 August 2024. Governor Gavin Newsom vetoed it on 20 September 2024, arguing that most browsers already offered the option or a plug-in while no major mobile operating system did. The California Opt Me Out Act, Assembly Bill 566, was signed on 8 October 2025 and takes effect on 1 January 2027, putting Chrome, Safari and Edge in scope.

Why it matters for advertising

Every layer of the supply chain is now expected to carry a refusal it did not originate. Google has rolled restricted data processing across states in tranches: eight added on 30 June 2025, then Indiana, Kentucky and Rhode Island ahead of their January 2026 effective dates, followed by further additions with automatic coverage for future states. The commercial stake sits in the gap between personalised and non-personalised inventory, which industry figures place at 50 to 70 per cent of revenue.

Verification has become its own product category. The IAB Tech Lab's Accountability Platform samples transactions to check whether preference strings survive the hops between vendors, an admission that transmission cannot be assumed.

Limitations and disputes

Measured compliance is poor. A peer-reviewed study led by Katherine Hausladen and presented at USENIX Security in August 2025 crawled 11,708 sites and found 45 per cent honouring California opt-outs in April 2024. Downstream encoding fared worse: across the privacy strings examined, 44 per cent accurately reflected a refusal, while 80 to 85 per cent of observed values reported that the person had not opted out. Only 12 per cent of sites used the Global Privacy Platform at that point.

Later audits found little improvement. A webXray scan of more than 7,000 popular sites run from a California address in 2026 found advertising cookies set despite an active signal on 55 per cent of them, with Google failing 86 per cent of the time. Enforcement has followed the same fault line: Healthline settled for $1.55 million in July 2025 after investigators watched 118 advertising cookies fire following a triple opt-out, Jam City for $1.4 million in November 2025 over missing opt-out methods in 21 mobile apps, and Disney for $2.75 million in February 2026 over streaming privacy controls.

Coverage is uneven by design. Laws modelled on Virginia's mostly omit the mandate, published tallies of covered states range from eight to twelve depending on how phase-ins are counted, and mobile applications sit largely outside the mechanism because no major operating system emits a signal. A federal bill, the SECURE Data Act introduced on 21 April 2026, proposes to replace the patchwork entirely.

Europe reached a different answer. The Digital Omnibus proposal of November 2025 included an automated browser-level signal, and the Council of the European Union removed it from its position on 18 June 2026.

Not the same as

consent signal records permission granted, usually under an opt-in regime such as IAB Europe's Transparency and Consent Framework, and is produced by a consent management platform. An opt-out signal records refusal and originates with the user.

Global Privacy Control is one implementation of the category, not a synonym for it. Colorado's list has room for others; none has qualified.

App Tracking Transparency is a per-app permission prompt enforced by Apple's platform rules rather than a standing signal enforced by statute, which is why its opt-in rate, measured by Adjust at 38 per cent in the first quarter of 2026, is a measure of persuasion rather than compliance.

AI crawler opt-outs carried in robots.txt or content-signal headers, such as the no-training preferences Cloudflare writes for customers, express a site owner's position on machine use of published content. The refusing party is the publisher, not the reader, and no US privacy statute compels compliance.

Recent developments

California has moved from requiring the signal to be honoured towards requiring proof. Since 1 January 2026, amended section 7025(c)(6) obliges businesses to display that a signal was processed, with wording such as "Opt-Out Request Honored" given as an example, part of a wider set of amendments effective that date.

The agency, now operating as CalPrivacy, invited preliminary comments between 6 March and 6 April 2026 on reducing friction in privacy rights and on opt-out preference signals, asking how businesses apply a signal across browsers, devices and identifiers. At its meeting on 6 and 7 August 2026 the board voted to open formal rulemaking on the subject, including codifying Global Privacy Control as an example of a valid signal, according to a summary published by law firm Alston and Bird. Deputy Attorney General Stacy Schesser used the session to argue that opt-out rights attach to people rather than to individual browsers.

Adjacent controls keep appearing under litigation pressure rather than product strategy. A new interface limiting personalised advertising across Google's publisher network surfaced in 2026 because a settlement required it, days after the audit that measured how often the existing signal was ignored.

Timeline

  • 2002: The Platform for Privacy Preferences is standardised at the World Wide Web Consortium, then abandoned
  • 2011: Do Not Track ships in major browsers as a voluntary header
  • 28 June 2018: California enacts the Consumer Privacy Act, creating the right to opt out of sale
  • November 2019: IAB Tech Lab publishes the final US Privacy String, with a clarification in March 2020
  • April 2020: Global Privacy Control is proposed to the W3C Privacy Community Group
  • January 2021: California begins requiring businesses to honour opt-out preference signals
  • August 2022: California settles with Sephora for $1.2 million over ignored signals
  • 1 January 2024: Colorado publishes its list of recognised universal opt-out mechanisms
  • 26 January 2024: IAB publishes MSPA technical signalling guidelines covering the Gpc subsection
  • 31 January 2024: The US Privacy String is deprecated in favour of the Global Privacy Platform
  • 1 July 2024: Colorado's recognition requirement becomes binding
  • 20 September 2024: Governor Newsom vetoes Assembly Bill 3048
  • 9 September 2025: California, Colorado and Connecticut announce a joint investigative sweep
  • 8 October 2025: The California Opt Me Out Act is signed, operative 1 January 2027
  • 1 January 2026: Amended California regulations require businesses to display that a signal was processed
  • 6 March to 6 April 2026: CalPrivacy accepts preliminary comments on opt-out preference signals
  • 18 June 2026: The Council of the European Union drops the automated consent signal from its ePrivacy position
  • 6 August 2026: California's privacy board votes to open formal rulemaking on opt-out preference signals

Summary

Who. Browsers and extensions emit the signal; publishers and consent management platforms detect and translate it; supply-side platforms, exchanges and demand-side platforms are expected to honour it downstream. State attorneys general and CalPrivacy enforce it, and the IAB Tech Lab defines the formats that carry it.

What. A machine-readable refusal of the sale or sharing of personal information and of targeted advertising, sent automatically rather than per site, expressed today as the Sec-GPC header and relayed through Global Privacy Platform sections inside the bid request.

When. Rooted in the 2018 California statute, implemented from 2020, binding in Colorado from July 2024, subject to a display requirement from January 2026, and reaching mainstream browsers when the California Opt Me Out Act takes effect on 1 January 2027.

Where. Roughly a dozen US states with comprehensive privacy laws, principally California, Colorado and Connecticut. Virginia-model states largely omit the requirement, and the European Council removed the equivalent mechanism from its ePrivacy position in June 2026.

Why. It converts a legal right into an automated instruction, which is why enforcement now targets whether the instruction survives the technical chain rather than whether businesses claim to accept it.