Opt-Out Preference Signals: What the Law Requires of Consent Management
Key Takeaways
- California's statute lets a business elect between opt-out links and honouring a preference signal, but the CCPA regulations at 11 CCR 7025(b) require processing a conforming signal as a valid opt-out request
- The Colorado Attorney General maintains a public list of recognised universal opt-out mechanisms under CPA Rule 5.07, and Global Privacy Control is currently the only entry on it
- Several statutes impose conditions on the mechanism rather than on the business, most consistently a bar on default settings and a requirement that the choice be affirmative, freely given and unambiguous
- The California Attorney General's Sephora settlement in 2022 rested in part on failure to process opt-outs sent by a global privacy control, and carried $1.2 million in penalties
- The CPPA fined Todd Snyder $345,178 after a misconfigured privacy portal failed to process opt-out requests for 40 days, stating that using a consent management platform does not shift responsibility
Moving the Choice Out of the Page
A universal opt-out mechanism inverts the usual arrangement. Instead of each website presenting its own interface and each visitor deciding site by site, the browser or device transmits a standing preference, and every site that receives it is expected to act on it. Global Privacy Control is the specification that implementation has settled on.
The Colorado Attorney General's published explanation states the purpose plainly: to let consumers “automatically exercise their opt-out rights with all Controllers they interact with without having to make individuals requests with each controller.” The California regulations use nearly the same framing, describing the signal as a way to opt out “with all businesses they interact with online without having to make individualized requests with each business.”
That design has a consequence worth stating at the outset: the obligation attaches to a signal a business receives passively, not to a request a consumer submits through an interface the business built. A site that never displays a banner can still be receiving opt-out requests on every page load.
California: Statute and Regulation Say Different Things
The California statute treats the signal as an alternative. Civil Code section 1798.135(a) requires a business that sells or shares personal information to post a “Do Not Sell or Share My Personal Information” link and a “Limit the Use of My Sensitive Personal Information” link, or a single combined link. Subdivision (b)(1) then relieves a business of that duty where it instead allows opt-out and limitation through an opt-out preference signal meeting technical specifications set by regulation. Subdivision (b)(3) is explicit: “a business may elect whether to comply with subdivision (a) or subdivision (b).”
The regulations do not read the same way. Section 7025(b) of the CCPA regulations provides that a business that sells or shares personal information “shall process any opt-out preference signal that meets the following requirements as a valid request to opt-out of sale/sharing.” The requirements are two, and neither names a particular product: the signal must be in a format commonly used and recognised by businesses — the rule gives an HTTP header field or a JavaScript object as examples — and the platform sending it must make clear, in its configuration or public disclosures, that the signal is meant to opt the consumer out. The rule adds that the disclosure “does not need to be tailored only to California or to refer to California.”
So the statutory election governs whether the links are required; the regulation governs whether the signal is honoured. Reading them together, the links are optional for a business that supports the signal, and the signal is not optional for a business that sells or shares.
Section 7025(c) then works through the collisions. Where a signal conflicts with a business-specific setting permitting sale, the business processes the signal but may notify the consumer of the conflict and seek consent. Where it conflicts with participation in a financial incentive programme, the business may ask the consumer to affirm an intent to withdraw — and if it does not ask, it processes the signal anyway. Subsection (c)(5) closes a loop that would otherwise swallow the rule: where the consumer is known to the business, the absence of a signal after one was previously sent may not be treated as consent to opt back in.
Colorado Runs a List
Colorado took a different route: rather than specify a format, the Attorney General recognises particular mechanisms and publishes them. CPA Rule 5.07 directs the Attorney General to “maintain a public list of Universal Opt-Out Mechanisms that have been recognized to meet the standards of this subsection,” with the list to be released no later than January 1, 2024 and updated periodically.
The Department's page records the current state of that list. Global Privacy Control was the first mechanism recognised, and the page states that it “is currently the only UOOM considered valid by The Department.” The underlying duty is at C.R.S. section 6-1-1306(1)(a)(IV): from July 1, 2024, businesses within the CPA's thresholds must allow consumers to opt out of sale and of targeted advertising using GPC. A separate rule, 4 CCR 904-3 Rule 6.03(4)(e), requires the privacy policy to explain how requests made through such mechanisms will be processed.
Two regulatory models
California defines conforming characteristics and honours anything that meets them. Colorado names specific mechanisms and honours what is on the list. A signal can therefore be valid in one state and not yet recognised in the other, and the two approaches answer different questions: California's asks what a signal must look like, Colorado's asks which signals have been vetted.
What the Signal Carries, and What It Reaches
The regulations describe the transport in a single clause and decline to standardise beyond it. Section 7025(b)(1) requires only that the signal be “in a format commonly used and recognized by businesses,” offering an HTTP header field or a JavaScript object as examples. There is no prescribed field name, no registry of conforming implementations, and no certification step — the test is recognisability in practice.
Its reach is defined more precisely than its format. Under section 7025(c)(1), a business receiving a conforming signal treats it as a valid opt-out request “for that browser or device and any consumer profile associated with that browser or device, including pseudonymous profiles,” and, if the consumer is known, for the consumer as well. Three things follow from that wording:
- The unit is the browser, not the person. A consumer using two browsers sends two signals, and the Colorado page says the same in plain terms: a consumer with multiple devices or browsers turns the setting on for each one separately.
- Pseudonymous profiles are named. The obligation does not wait on identification; a profile keyed to a device identifier rather than to a person is within it by the regulation's own terms.
- Extension to the identified consumer is conditional. The regulation reaches the consumer where known to the business, and permits — but does not require — offering an option to supply identifying information so the request can extend to offline sale or sharing. Anything the consumer provides for that purpose may not be used, disclosed or retained for any other.
What the signal does not reach is equally definite. It communicates an opt-out from sale and sharing, and in California a request to limit the use of sensitive personal information. It is not a deletion request, not an access request, and not a withdrawal of consent to processing generally. Those rights run through the ordinary request channels, and the statutes discussed here keep them separate.
That separation explains why a business can support a preference signal fully and still owe a conventional request interface. The signal answers one question, standing and automatically; the remaining consumer rights are exercised one at a time.
Conditions on the Mechanism, Not on the Business
A cluster of later statutes borrows a common template that regulates the signal itself. New Jersey's is representative. Section 8(b) of P.L.2023, c.266 requires a controller processing personal data for targeted advertising or sale to allow the opt-out right to be exercised through a user-selected universal opt-out mechanism, beginning not later than six months after the Act's effective date. Paragraph (2) then sets five conditions on the platform, technology or mechanism:
- It may not permit its manufacturer to unfairly disadvantage another controller.
- It may not use a default setting that opts a consumer in, unless the controller has determined that the consumer selected that default and the selection clearly represents an affirmative, freely given and unambiguous choice to opt in.
- It must be consumer-friendly, clearly described and easy for the average consumer to use.
- It must be as consistent as possible with any similar mechanism required by other federal or state law.
- It must enable the controller to accurately determine whether the consumer is a resident of the state and whether the request is legitimate.
Delaware's version at 6 Del. C. section 12D-104(e)(1)a.2 is nearly identical in substance, with the duty attaching not later than January 1, 2026, and the same five-part list — no unfair disadvantage, no default setting but an affirmative, freely given and unambiguous choice, consumer friendly, consistent with other regimes, and permitting residency and legitimacy determination. Delaware pairs it with a link requirement rather than treating the two as alternatives, and subparagraph b. addresses conflicts with a controller-specific setting or with participation in a bona fide loyalty, rewards, premium features, discounts or club card programme.
The recurring condition across these statutes is the bar on default settings. It is what distinguishes a preference the consumer chose from one a browser vendor chose on the consumer's behalf, and it is drafted as a constraint the mechanism must satisfy rather than as something the receiving business controls.
New Jersey also grants rulemaking authority for the technical specifications, allowing the Division of Consumer Affairs to adopt rules for one or more mechanisms, including rules permitting a controller to authenticate the consumer as a state resident and to determine that the request is legitimate.
Not Every State Requires One
Recognition is a genuine point of divergence rather than a settled national baseline, and the honest description of the map is that it is partly unmapped. Our comparison of the state comprehensive statutes records that of twenty-four state records, eight document the treatment of opt-out preference signals against a primary source, and declines to infer the rest. That remains the position; the research behind this guide did not extend the count.
Among the states that are documented, three comprehensive statutes contain no opt-out preference signal requirement at all — Indiana, Kentucky and Rhode Island — and each of those chapters also lacks rulemaking authority through which one could be added administratively. The distinction matters more than a missing feature usually would: where the statute is silent and no agency can write a rule, the absence is durable rather than pending.
Three states could not be checked for this guide. Connecticut's legislative site was unreachable throughout, Texas publishes its codes through a client-rendered application that returns no statutory text to a fetch, and the sections of the Montana Consumer Data Privacy Act examined here did not contain a signal provision without establishing that no other section does. Nothing is asserted about those three.
Where the Interface and the Backend Diverge
The enforcement record on this subject is not about businesses that refused to offer an opt-out. It is about opt-outs that existed on the page and did not work underneath it.
In May 2025 the California Privacy Protection Agency Board ordered the clothing retailer Todd Snyder, Inc. to pay a $345,178 fine and change its practices. The Enforcement Division's allegations were three: failing to oversee and properly configure the technical infrastructure of its privacy portal, with the result that consumer opt-out requests went unprocessed for 40 days; requiring consumers to submit more information than necessary to process privacy requests; and requiring identity verification before a consumer could opt out of sale or sharing at all.
Businesses should scrutinize their privacy management solutions to ensure they comply with the law and work as intended, because the buck stops with the businesses that use them. Using a consent management platform doesn't get you off the hook for compliance.
Michael Macko, head of the CPPA Enforcement Division, May 6, 2025
Two of the three allegations concern friction rather than refusal. The regulations bear that out: section 7025(c)(2) provides that a business shall not require a consumer to provide additional information beyond what is necessary to send the signal, and that where a consumer offers no further information the business processes the signal for that browser or device and any associated profile, including pseudonymous profiles.
The First Enforcement Action Was About This
The pattern is not new. In August 2022 the California Attorney General announced a settlement with Sephora, Inc. resolving allegations under the CCPA. Two of the three allegations went to the mechanics of opting out: that Sephora failed to disclose that it was selling personal information, that it “failed to process user requests to opt out of sale via user-enabled global privacy controls,” and that it did not cure within the thirty-day period the CCPA then allowed.
The settlement required $1.2 million in penalties along with injunctive terms, among them providing mechanisms to opt out of sale including via the Global Privacy Control, and reporting to the Attorney General on its efforts to honour that signal. The same announcement disclosed a broader sweep: notices sent to a number of businesses alleging failure to process opt-out requests made via user-enabled global privacy controls, each with thirty days to cure.
The release states the operative reading directly — that under the CCPA, businesses must treat opt-out requests made by user-enabled global privacy controls the same as requests made by users who clicked the “Do Not Sell My Personal Information” link. That equivalence, asserted by the enforcing agency in 2022 and codified in the regulations since, is the whole of the obligation in one sentence.
What This Guide Does Not Cover
The European cookie consent regime under the ePrivacy Directive and the consent conditions in the General Data Protection Regulation are not described here. The consolidated text of the Directive could not be retrieved during this research, and a regime of that consequence is not worth reporting from memory or from secondary summaries.
Nor does this guide cover record-keeping standards for proof of consent, which the state statutes discussed above largely do not specify, or the design rules governing how a consent interface may be presented. Those design rules are a separate body of law, and are treated in our guide to deceptive design regulation.
Background
For the underlying law rather than this development: California privacy law, Colorado privacy law, Delaware privacy law, New Jersey privacy law, Retail & E-Commerce privacy law.
Frequently Asked Questions
Does a business have to honour Global Privacy Control in California?
Which universal opt-out mechanisms does Colorado recognise?
Can a browser turn an opt-out signal on by default?
Does using a consent management platform transfer responsibility for opt-outs?
Can a business require identity verification before honouring an opt-out signal?
Sources
Everything above is reported from these documents. Follow them to verify.
- Cal. Civ. Code § 1798.135, Methods of limiting sale, sharing, and use of personal information statute
- CCPA Regulations § 7025, Opt-out Preference Signals (final text) (March 29, 2023) regulation
- Colorado Attorney General, Universal Opt-Out and the Colorado Privacy Act registry
- 6 Del. C. ch. 12D, Delaware Personal Data Privacy Act statute
- N.J. P.L.2023, c.266, New Jersey Data Privacy Act statute
- California Attorney General, Settlement with Sephora, Inc. (August 24, 2022) agency release
- CPPA, Order against Todd Snyder, Inc. (May 6, 2025) agency release
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.