Global Privacy Control (GPC)
Was ist Global Privacy Control (GPC)?
Global Privacy Control (GPC)A browser-level signal — an HTTP header and a JavaScript property — by which a user expresses a 'do not sell or share' opt-out, given binding legal force in California (CCPA/CPRA) and Colorado (CPA) regulations.
Global Privacy Control (GPC) is a browser-level privacy signal developed by a coalition of privacy advocates, publishers, and browser vendors (DuckDuckGo, Mozilla, Brave, EFF, NYT, WaPo, Disconnect) and first deployed in 2021. It is both an HTTP request header (`Sec-GPC: 1`) and a JavaScript property (`navigator.globalPrivacyControl`) which, when present, communicates that the user does not want their personal data sold or shared for cross-context behavioural advertising. Unlike the failed earlier Do-Not-Track signal, GPC has explicit regulatory force: the California AG and CPPA require businesses subject to CCPA/CPRA to treat GPC as a valid opt-out of sale and sharing; Colorado's CPA requires similar handling; other U.S. state laws (Connecticut, Delaware, New Jersey, Oregon) have followed. Major browsers (Firefox, Brave, DuckDuckGo, Safari via add-ons) send GPC by default or by toggle; Chrome and Edge currently do not. From a compliance perspective, sites serving U.S. users must implement server-side handling of GPC, link consent records to the signal, and update opt-out states accordingly.
● Beispiele
- 01
A retailer's web stack reads `Sec-GPC: 1` on incoming requests and disables third-party advertising scripts for California, Colorado, and Connecticut users on that request.
- 02
A CMP (consent management platform) integrates GPC handling so that the IAB TCF consent string is set to opt-out when the GPC header is present.
● Häufige Fragen
Was ist Global Privacy Control (GPC)?
A browser-level signal — an HTTP header and a JavaScript property — by which a user expresses a 'do not sell or share' opt-out, given binding legal force in California (CCPA/CPRA) and Colorado (CPA) regulations. Es gehört zur Kategorie Datenschutz der Cybersicherheit.
Was bedeutet Global Privacy Control (GPC)?
A browser-level signal — an HTTP header and a JavaScript property — by which a user expresses a 'do not sell or share' opt-out, given binding legal force in California (CCPA/CPRA) and Colorado (CPA) regulations.
Wie funktioniert Global Privacy Control (GPC)?
Global Privacy Control (GPC) is a browser-level privacy signal developed by a coalition of privacy advocates, publishers, and browser vendors (DuckDuckGo, Mozilla, Brave, EFF, NYT, WaPo, Disconnect) and first deployed in 2021. It is both an HTTP request header (`Sec-GPC: 1`) and a JavaScript property (`navigator.globalPrivacyControl`) which, when present, communicates that the user does not want their personal data sold or shared for cross-context behavioural advertising. Unlike the failed earlier Do-Not-Track signal, GPC has explicit regulatory force: the California AG and CPPA require businesses subject to CCPA/CPRA to treat GPC as a valid opt-out of sale and sharing; Colorado's CPA requires similar handling; other U.S. state laws (Connecticut, Delaware, New Jersey, Oregon) have followed. Major browsers (Firefox, Brave, DuckDuckGo, Safari via add-ons) send GPC by default or by toggle; Chrome and Edge currently do not. From a compliance perspective, sites serving U.S. users must implement server-side handling of GPC, link consent records to the signal, and update opt-out states accordingly.
Wie schützt man sich gegen Global Privacy Control (GPC)?
Schutzmaßnahmen gegen Global Privacy Control (GPC) kombinieren typischerweise technische Kontrollen und operative Praktiken, wie in der Definition oben beschrieben.
Welche anderen Bezeichnungen gibt es für Global Privacy Control (GPC)?
Übliche alternative Bezeichnungen: GPC, Sec-GPC header.
● Verwandte Begriffe
- compliance№ 167
CCPA
California Consumer Privacy Act — US-Datenschutzgesetz des Bundesstaates Kalifornien, das Kalifornierinnen und Kaliforniern Rechte über ihre personenbezogenen Daten gewährt.
- compliance№ 251
CPRA
California Privacy Rights Act von 2020, der den CCPA aendert und erweitert und am 1. Januar 2023 vollstaendig in Kraft trat.
- privacy№ 233
Consent Management
Prozesse und Werkzeuge zur Erhebung, Dokumentation, Aktualisierung und Durchsetzung von Nutzerzustimmungen für die Verarbeitung personenbezogener Daten und das Setzen von Cookies gemäß Datenschutzrecht.
- privacy№ 560
IAB TCF (Transparency and Consent Framework)
The Interactive Advertising Bureau Europe's framework for capturing, encoding, and propagating user consent for advertising and analytics data uses under GDPR — controversial, partly invalidated by Belgian DPA in 2022, then revised as TCF v2.2.
- privacy№ 1039
Recht auf Vergessenwerden
Recht einer Person, die Löschung der sie betreffenden personenbezogenen Daten zu verlangen, wenn keine überwiegenden rechtlichen Gründe für die weitere Verarbeitung bestehen (Art. 17 DSGVO).
- privacy№ 1263
Drittanbieter-Cookie
Cookie, das von einer anderen Domain als der in der Adresszeile gesetzt wird und historisch zur seitenübergreifenden Verfolgung von Nutzern dient.
● Siehe auch
- № 299Dark Patterns