Tech Giants Sidestep Privacy Opt-Outs

Tech firms are accused of ignoring Global Privacy Control opt-out signals in California, raising compliance questions under consumer privacy law.

Cuneyd Erdogan ·

Tech Giants Sidestep Privacy Opt-Outs

Several large technology companies are accused of not consistently honoring Global Privacy Control (GPC) signals , a mechanism meant to let users opt out of certain data tracking and related data-sharing practices. Researchers said this behavior could conflict with California consumer privacy requirements, which recognize GPC as a legally valid way for consumers to communicate opt-out choices.

The findings stem from an audit of California web traffic conducted in March. Researchers reported identifying 194 online advertising services that allegedly disregard GPC signals, despite the signals being designed to communicate a user’s preference to opt out. The research also cited major firms among the services reviewed, alleging that one company ignored opt-out requests 86% of the time, another did so 50% of the time, and a third 69% of the time.

At the center of the dispute is California law, including the California Consumer Privacy Act, which gives consumers the right to decline the sale of their personal data. GPC is intended to streamline that process by allowing a browser or device setting to transmit an opt-out signal automatically, rather than requiring users to navigate individual site settings repeatedly.

Researchers said the audit results suggest that, in practice, some advertising-related services may continue operating in ways that do not reflect those opt-out preferences.

California regulators have previously taken enforcement action tied to GPC compliance. Officials have issued penalties to companies for failing to honor these signals, including a $1.2 million fine against a beauty retailer in 2022 and a $2.75 million fine against an entertainment company in February. Those cases underscore that regulators view GPC as more than a voluntary standard and that non-compliance can carry financial consequences.

Company representatives disputed the research conclusions. Spokespersons said the study misreads how their products function or emphasized that consumer privacy is a priority. Some companies also argued that certain cookies are necessary for operational purposes, suggesting that not all data-related activity should be treated as optional tracking.

For markets and policy stakeholders, the allegations highlight ongoing friction between digital advertising practices and privacy rules in a major US state with outsized influence on compliance strategies. The audit’s claims also raise questions about how consistently opt-out signals are implemented across the advertising ecosystem, and how regulators may interpret “necessary” cookies versus tracking-related activity.

The research itself is contested by the companies involved, leaving uncertainty over how much of the reported behavior reflects non-compliance versus measurement or classification differences.

More stories