California regulators specify that businesses must demonstrate end-to-end processing of opt-out signals like GPC, intensifying compliance efforts and expanding enforcement amid new privacy legislation and oversight measures.
California privacy regulators are tightening the rules on how companies handle opt-out preference signals, as the California Privacy Protection Agency pushes ahead with formal rulemaking on the Global Privacy Control and related compliance obligations. At meetings on 6 and 7 August, the agency signalled that businesses must do more than recognise a signal in theory: they must show that it is processed end-to-end across the systems that collect, share and sell data.
The move comes as California expands enforcement under the Consumer Privacy Act and the Opt Me Out Act begins to reshape browser-level privacy controls. According to the CPPA, web browsers now have to support opt-out preference signals such as GPC, which gives consumers a single mechanism to tell companies not to sell or share their personal information. The agency is now seeking to codify GPC as a valid signal under its broader rules, while also exploring whether linkages between cookies, device identifiers and IP addresses should be treated as part of the same consumer request.
Enforcement officials used the meeting to sharpen that message. California Deputy Attorney General Stacy Schesser said businesses must accept and process GPC signals, verify that their technical systems work in practice, and treat opt-out rights as belonging to the consumer rather than to a single browser or device. That stance suggests regulators are unlikely to accept arguments that implementation is too complex, particularly where ad-tech and analytics tools can start collecting data before privacy settings are fully applied.
The pressure is even higher for data brokers. The CPPA’s Delete Request and Opt-Out Platform, known as DROP, launched on 1 January 2026, and broker processing duties took effect on 1 August 2026. The agency says more than 600 data brokers have registered and roughly 450,000 Californians have already submitted requests. Data brokers must now access DROP at least once every 45 days to download, match and process deletion requests, apply exceptions and report back through the system. The CPPA has also moved to raise the annual registration fee from $6,000 to $9,500 from 2027 and to require independent third-party audits every three years from 1 January 2028.
The agency is building the enforcement machinery to match. Its Audits Division has outlined future attention on automated decision-making technology, cybersecurity, risk assessments and sector-specific audits, while the CPPA’s proposed 2026-27 budget stands at about $19.7 million, an increase of roughly $3 million. It is also backing or monitoring several bills in Sacramento, including measures to broaden deletion rights, restrict the sale or sharing of sensitive data and strengthen protections for precise geolocation information. For businesses, the immediate task is clear: test whether opt-out signals are actually honoured across platforms, document the process, and prepare for a more evidence-driven compliance regime.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





