Do Not Track asked companies to respect a user’s preference. Global Privacy Control can invoke a right that covered companies are legally required to honor. That difference, more than the technical signal itself, explains why the newer system has consequences the original never consistently produced.
The distinction is easy to miss because the two systems look similar from the browser. Both can transmit a header expressing a privacy preference to websites, but neither header physically prevents a remote server from receiving a request. The real question is what the recipient must do after receiving it.
The W3C’s Do Not Track specification defined a header that allowed users to express a preference about tracking. The document also acknowledged the mechanism’s central weakness: expressing a preference did not mean every recipient would comply, and the specification did not establish one universal set of conduct requirements for companies receiving the signal.
That gap followed Do Not Track throughout its development. In January 2019, the W3C concluded its work after finding insufficient deployment and no clear signs of broader planned support across browsers, third parties, and the wider online ecosystem.
Yahoo became one of the clearest examples of what voluntary compliance meant in practice. The company had described itself as the first major technology company to implement Do Not Track. On May 2, 2014, however, Yahoo announced that it had stopped recognizing browser Do Not Track settings, citing the absence of an effective standard adopted across the industry.
The conflict had surfaced earlier around Microsoft’s Internet Explorer. Yahoo said in October 2012 that it would not recognize signals automatically enabled by the browser because the setting did not necessarily reflect a deliberate user choice. That disagreement exposed a deeper problem: participants could not agree on what counted as a valid signal, much less what receiving one required them to stop doing.
A voluntary header therefore depended on company policy. A browser could transmit it perfectly, but a website or advertising company remained free to disregard it unless that company had made a separate commitment that regulators could enforce.
Global Privacy Control, or GPC, was designed around a narrower and more legally grounded request. Instead of expressing a general wish not to be tracked, it communicates that a user does not want personal information sold or shared in circumstances covered by applicable privacy law.
Calling GPC a literal replacement for Do Not Track goes too far. The Electronic Frontier Foundation explains that Privacy Badger can send GPC alongside the older DNT signal. The two can coexist because they express related but different preferences.
The technical standard has also continued to develop. The W3C’s June 2026 GPC working draft defines a signal that conveys a request not to sell or share personal information with third parties. Crucially, it is intended to work with legal frameworks that make such requests enforceable.
California provides the clearest example. The state Attorney General says that businesses covered by the California Consumer Privacy Act that sell or share personal information must treat a user-enabled GPC signal as a valid request. Under California law, covered businesses must honor that request to stop the sale or sharing of personal information.
That does not mean GPC stops every kind of online tracking. Its legal effect depends on the law, the user’s jurisdiction, the type of data processing involved, and whether the business falls within the statute’s scope. It is an enforceable opt-out mechanism, not a universal command that blocks every cookie, server request, or use of data.
Other states have adopted similar mechanisms. The Colorado Attorney General says GPC was the first universal opt-out mechanism recognized under the Colorado Privacy Act. Since July 1, 2024, covered businesses in Colorado have been required to let consumers use GPC to opt out of personal-data sales and targeted advertising.
Connecticut followed its own timetable. According to the state Attorney General, businesses covered by the Connecticut Data Privacy Act have been required to honor universal opt-out preference signals sent by Connecticut residents since January 1, 2025.
Browser-level blocking represents a different approach. Apple says Safari’s Intelligent Tracking Prevention is enabled by default and actively limits cross-site tracking. That is a technical intervention by the browser, while GPC is a request whose enforceability comes from the law that applies to the recipient.
This difference matters on pages assembled from many services. A single visit can involve the publisher, advertising exchanges, analytics providers, embedded media, and other third parties. Each participant may receive a signal, but its obligations depend on its role, its jurisdiction, and the law governing the data it processes.
Europe’s system follows another legal structure. Cookie consent requirements arise primarily from national laws implementing the ePrivacy Directive, while subsequent processing of personal data must also comply with the General Data Protection Regulation. The European Commission notes that essential cookies are exempt from consent, so it is inaccurate to describe every cookie or every European website visit as requiring affirmative permission.
None of these systems creates perfect privacy. Browser blocking can restrict certain technical behavior, while legal opt-out signals depend on companies correctly detecting and processing them. Enforcement still requires regulators to investigate noncompliance and establish that the business and activity fall within the relevant law.
What changed between Do Not Track and GPC was therefore not simply the header. Do Not Track expressed a broad preference without giving most recipients a binding legal obligation. GPC was shaped to invoke specific statutory rights in jurisdictions that recognize universal opt-out signals.
That is the lesson behind Yahoo’s reversal and the decade of privacy engineering that followed it. A preference can be withdrawn, reinterpreted, or ignored when company policy is the only enforcement mechanism. A legally recognized request gives regulators something concrete to compel.
Privacy on the open web is still not one switch. It remains a combination of browser protections, company practices, jurisdictional rules, and enforcement. GPC matters because, for covered businesses in places such as California, the signal is no longer merely something the user hopes a company will honor.