Skip to content

California Opt Me Out Act: A Guide for Website Owners

Resources / Blog / California Opt Me Out Act: A Guide for Website Owners

  • As of January 1, 2027, the California Opt Me Out Act requires businesses subject to the CPRA to honor opt-out preference signals, such as Global Privacy Control (GPC), as legally valid “Do Not Sell or Share” requests.
  • Under CPPA regulations that took effect January 1, 2026, California businesses must display a visual indicator confirming when a GPC signal has been recognized and processed.
  • The California Privacy Protection Agency (CPPA) has conducted joint enforcement sweeps targeting GPC non-compliance, coordinating with regulators in Colorado and Connecticut.
  • Failing to honor GPC signals was among the earliest and most common enforcement triggers under the CPRA; the Opt Me Out Act reinforces and extends these obligations.
  • Businesses cannot require consumers to re-confirm or override their GPC signal through a consent banner or pop-up.
  • A consent management platform (CMP) that detects and acts on opt-out preference signals is the most reliable way to support compliance at scale.

California’s Opt Me Out Act extends existing CPRA opt-out requirements. It mandates that businesses recognize browser-based opt-out preference signals, including Global Privacy Control (GPC), as legally valid consumer opt-out requests. This article covers what the law requires, who it applies to, enforcement risk, and how businesses can prepare before the January 1, 2027 effective date.

California has long been the leading edge of U.S. consumer privacy law. The California Opt-Out Preference Signal Act, commonly called the Opt Me Out Act, builds on the California Privacy Rights Act (CPRA) by requiring businesses to recognize automated browser-based signals as legally valid opt-out requests. 

For any business that collects personal data from California consumers and relies on digital advertising or analytics, this legislation represents a meaningful and enforceable compliance obligation.

This article explains what the Opt Me Out Act requires, which businesses it applies to, how California regulators are approaching enforcement, and what practical steps organizations should take to prepare.

What Is the California Opt Me Out Act?

The California Opt-Out Preference Signal Act, referred to in shorthand as the Opt Me Out Act, is a California law that formalizes and strengthens the obligation for businesses to honor automated privacy signals transmitted by consumers’ browsers or devices. 

It builds directly on the framework established by the California Consumer Privacy Act (CCPA) and expanded under the California Privacy Rights Act (CPRA).

Under CPRA, California consumers have the right to opt out of the sale or sharing of their personal information. The Opt Me Out Act goes further by requiring that this right can be exercised not just through manual controls on a website, but automatically through browser-based opt-out preference signals, most prominently Global Privacy Control (GPC).

The law is administered by the California Privacy Protection Agency (CPPA), also known as CalPrivacy, the independent regulatory body established under the CPRA with the authority to investigate, enforce, and issue binding regulations on California privacy law.

How the Opt Me Out Act Relates to Existing California Privacy Law

The Opt Me Out Act does not stand alone. It operates within California’s layered privacy framework. The CCPA, which came into effect in 2020, established the original right to opt out of data sales. 

The CPRA, which took effect in January 2023, expanded that right to cover “sharing” of personal information for cross-context behavioral advertising, not just outright sales. The Opt Me Out Act comes into effect January 1, 2027.

CPRA regulations adopted by the CPPA subsequently established that opt-out preference signals, including GPC, must be treated as valid opt-out requests when transmitted by California consumers. 

The Opt Me Out Act codifies and reinforces this requirement at the statutory level, reducing the risk that a change in regulatory interpretation could dilute the obligation.

What Is Global Privacy Control (GPC)?

GPC is a technical specification that enables consumers to communicate a “Do Not Sell or Share” preference automatically, at the browser or device level, without needing to interact with each website individually. When a consumer enables GPC in a supported browser or extension, the signal is transmitted to every website they visit before the page loads.

GPC was developed collaboratively by privacy researchers, technologists, and civil society organizations, and has been recognized by the CPPA as a valid legal opt-out mechanism under the CPRA. As of 2026, browsers including Firefox, Brave, and DuckDuckGo support GPC natively, and adoption is growing.

How GPC Works Technically

When a visitor with GPC enabled arrives at a website, the signal is transmitted in the HTTP request header. A properly configured consent management platform reads this signal before any tracking scripts are loaded or personal data is processed for advertising purposes. 

If the signal is present, the site must honor it immediately, without prompting the visitor to confirm their preference or presenting a separate opt-out flow, for example, by displaying a consent banner.

This creates a specific and testable technical requirement: the CMP must intercept the GPC header and suppress or modify data processing accordingly, before any tags, pixels, or third-party scripts fire. A visual indicator must also be displayed confirming that the GPC signal has been honored.

Who Does the Opt Me Out Act Apply To?

The Opt Me Out Act applies to businesses that are already subject to the CPRA. Specifically, a for-profit business that operates in California and meets any of the following thresholds is covered:

  • Annual gross revenues exceeding USD 25 million (adjusted periodically to the Consumer Price Index)
  • Buying, selling, receiving for commercial purposes, or sharing the personal information of 100,000 or more consumers or households per year
  • Deriving 50 percent or more of annual revenues from selling or sharing consumers’ personal information

It is worth noting that “operates in California” is interpreted broadly. A business does not need to be physically located in California. If it collects personal information from California residents, it is likely within scope.

Exemptions and Edge Cases

Certain entities are exempt from the CPRA framework and therefore fall outside the scope of the Opt Me Out Act. These include nonprofit organizations, government agencies, and businesses that fall below all three CPRA thresholds. 

However, these exemptions are narrow in practice. Any digital business of meaningful scale that runs advertising or analytics in the U.S. is likely to meet at least one threshold.

Businesses that have previously treated their operations as out of scope purely on the basis of size should review their data processing volumes carefully. The 100,000-consumer threshold is based on data processed per year, not revenue, and many mid-sized businesses exceed this figure without realizing it.

What Does the Opt Me Out Act Require?

The core requirements under the Opt Me Out Act, as reinforced by CPPA rulemaking, cover both the technical mechanisms businesses must support and the operational steps they must take to honor consumer opt-out requests within prescribed time frames.

Automatic Recognition of Opt-Out Signals 

When a California consumer transmits a GPC signal or another recognized opt-out preference signal, the business must honor it as a valid “Do Not Sell or Share” request. No additional action from the consumer is required.

No Counter-Prompts or Confirmation Flows 

A business cannot ask a consumer to re-confirm their GPC preference or override it via a cookie banner. Displaying a consent prompt that contradicts or re-litigates a GPC signal is a regulatory violation.

Visual Confirmation 

Under CPPA requirements that took effect January 1, 2026, California businesses must display a visual indicator when a GPC signal has been recognized and processed. This is a new implementation requirement that adds an observable layer to signal handling.

Consistent Treatment Across the Website 

Honoring GPC for one category of processing but not others, for example, suppressing advertising trackers while continuing to operate analytics, does not satisfy the requirement where all processing falls under “sharing” as defined by the CPRA.

No Financial Incentives to Override Opt-Out Preferences 

Businesses cannot offer benefits, discounts, or other incentives in exchange for a consumer agreeing to override their GPC signal.

Enforcement: What the CPPA Has Done and What Comes Next

California’s approach to GPC enforcement has moved from guidance to active investigation. Businesses treating this as a theoretical risk are behind the curve.

Early Enforcement Action: Sephora

The CPPA’s enforcement record on opt-out signals dates back to 2022, when the California Attorney General reached a settlement with Sephora for USD 1.2 million over violations that included failure to process GPC opt-out signals. 

While the enforcement predated the CPPA’s full enforcement authority, it established a clear precedent: GPC non-compliance is not a technical oversight but a substantive legal violation.

The Consortium of Privacy Regulators and Joint Sweeps

In April 2025, privacy regulators from seven U.S. states — California, Colorado, Connecticut, Delaware, Indiana, New Jersey, and Oregon — formed the Consortium of Privacy Regulators to coordinate enforcement of state privacy laws. 

In September 2025, California, Colorado, and Connecticut launched a joint investigative sweep targeting businesses that failed to honor GPC signals. This was the Consortium’s first major coordinated enforcement action.

The sweep sent a clear signal to the market: multi-state enforcement is not a future scenario. It is already underway. Businesses operating across multiple states cannot treat GPC compliance as a California-only concern.

What Enforcement Looks Like

CPPA investigations have focused on a number of common failure patterns. These include:

  • Consent banners that appear after tracking has already begun
  • CMPs that read the GPC header but do not suppress third-party tags before they fire
  • Businesses that honor GPC for advertising but not for analytics or data broker sharing

Civil penalties under the CPRA can reach USD 2,500 per unintentional violation and USD 7,500 per intentional violation (periodically adjusted for the Consumer Price Index). Given that GPC signals are transmitted per visit, per consumer, a systemic failure to honor them can accumulate into material liability quickly.

GPC Requirements Across the United States

California is the most prominent state to mandate recognition of GPC, but it is not alone. As of 2026, 12 U.S. states require businesses to honor opt-out preference signals, though the specific framing varies. Several more state-level privacy laws come into effect in 2027, and at least one will require honoring opt-out signals.

California, Colorado, and Connecticut explicitly require recognition of GPC by name, and New Jersey mentions it as an example, but doesn’t require recognizing it explicitly. 

A further eight states — Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, Oregon, and Texas — require recognition of a universal opt-out mechanism (UOOM), with GPC qualifying in practice.

This expanding footprint means that businesses operating nationally effectively face a de facto federal standard on opt-out signal recognition, even in the absence of a federal privacy law. Implementing GPC recognition once, at the platform level, supports obligations across all 12 jurisdictions simultaneously.

Practical Steps for Businesses

Meeting the obligations under the Opt Me Out Act requires both technical implementation and ongoing governance. A cookie banner alone is not sufficient. In fact, a banner that prompts visitors to override their GPC signal is itself a violation.

The following actions represent a reasonable operational framework for businesses subject to the law.

Audit Your Current Signal Handling

Determine whether your website currently reads GPC headers, and whether the CMP suppresses tracking before any scripts fire. This is a technical test, not a policy exercise, and requires reviewing tag manager configuration and script loading order.

Configure Your CMP to Detect and Honor GPC

A compliant CMP will read the GPC signal on arrival, treat it as a “Do Not Sell or Share” instruction, and suppress all downstream data processing accordingly, without requiring any visitor interaction.

Implement Visual Confirmation

Under the January 2026 CPPA requirement, your site must display a visual indicator when a GPC signal has been recognized. This is a UI requirement in addition to the underlying technical one.

If your banner asks visitors whether they want to override their GPC setting, that is a violation. Remove it.

Document Your Signal Handling

In the event of a CPPA investigation, businesses will need to demonstrate that their systems reliably honored GPC signals. Logging signal receipt alongside standard consent records supports this.

Extend the Audit to Server-Side Tracking

Server-side tagging and Meta Conversions API implementations are not exempt from opt-out signal requirements. If GPC is honored client-side but server-side tracking continues for opted-out consumers, the business remains in violation.

How Usercentrics Supports GPC and Opt-Out Signal Compliance

Managing opt-out preference signals manually introduces significant operational risk. This includes:

  • Monitoring every browser implementation
  • Updating tag configurations
  • Maintaining visual confirmation elements 

Usercentrics automates this process as part of a broader consent management infrastructure, supporting compliance with California’s Opt Me Out Act and equivalent requirements across all 12 states that mandate opt-out signal recognition.

Automatic GPC Detection and Honoring

The Usercentrics Web CMP detects GPC signals automatically when a visitor arrives at a website. When the signal is present and no prior consent interaction has been recorded, Usercentrics suppresses all non-essential data processing before any tracking scripts load, requiring no manual configuration per visit and no visitor interaction to trigger the opt-out. 

Where a visitor has previously interacted with the consent banner and a stored consent choice exists, that choice is respected in place of the GPC signal.

Visual Confirmation for California Compliance

To support the January 2026 CPPA requirement for visual confirmation of GPC signal recognition, Usercentrics provides configurable UI elements that display the appropriate indicator when a GPC opt-out has been processed. This addresses the new implementation layer without requiring custom development.

Consistent Signal Handling Across Jurisdictions

Because Usercentrics applies Universal Opt-Out Mechanisms (UOOM), including GPC recognition, at the platform level, businesses serving visitors from multiple states do not need to implement separate configurations per jurisdiction. 

A single deployment supports opt-out signal obligations across California, Colorado, Connecticut, and the broader group of states requiring UOOM recognition.

Usercentrics logs consent and opt-out decisions — including GPC signal receipt — in a centralized record. In the event of a CPPA investigation or audit, this documentation supports the business’s ability to demonstrate that signal handling operated as required.

Usercentrics operates across 2.4 million websites and applications globally, and supports businesses of all sizes in navigating the technical and operational demands of U.S. state privacy law.

Take control of CCPA privacy compliance

Usercentrics helps businesses manage consumer consent, meet opt-out requirements, and maintain privacy notice obligations under the CCPA. Try it for free.

William Newmark
Senior Legal Counsel, Usercentrics
Stay in the loop

Join our growing community of data privacy enthusiasts now. Subscribe to the Usercentrics newsletter and get the latest updates right in your inbox.