Table of Contents [TOC]

{tocindex article="current"}

Privacy laws

Menu

  • Pricing
  • Features
    • Regulation compliance
    • GDPR (EU)
    • CCPA (California)
    • PIPEDA (Canada)
    • LGPD (Brasil)
    • KVKK (Turkey)
    • POPIA (South Africa)
    • The basics
    • 42 languages
    • User consents recording
    • Third-party cookie blocking
    • Geo targeting
    • Cookie Banner
    • Google Consent Mode v2
    • Automation
    • Automatic monthly scans
    • Automatic script blocking
    • Advanced reporting
    • Cookie Banner sharing
    • IAB TCF 2.3 integration
    • Google-certified CMP
  • Resources
    • Cookie Scanner
    • Privacy Policy Generator
    • System status
    • Roadmap
    • Changelog
  • Blog
    • Guides
    • News
    • GDPR & CCPA
    • Privacy laws
    • Compare
    • Knowledge base
  • Support
    • Help Center
    • Integrations
    • Contact us
    • Feature request
  • For partners
    • Agencies
    • Affiliates
  • separator
  • Language switcher
    • Profile
    • Billing
    • My plan
  • Sign in
  • Try now
 
  • Guides
  • News
  • GDPR & CCPA
  • Privacy laws
  • Compare
  • Knowledge base
Details
15 September 2026

California Opt Me Out Act: What Changes in 2027

ON THIS PAGE

  • What Is the California Opt Me Out Act and What Changes in 2027?
  • What Is an Opt-Out Preference Signal?
  • Is OOPS the Same as Global Privacy Control?
  • Do Websites Already Have to Honor Opt-Out Preference Signals?
  • What Does OOPS Mean for Cookies, Pixels, and Advertising Trackers?
  • How Should a Website Process an OOPS or GPC Signal?
    • What About Logged-In Users?
    • What If the Browser Signal Conflicts With Website Privacy Settings?
  • Does OOPS Replace “Do Not Sell or Share My Personal Information”?
  • What Should Websites Do Before January 2027?
  • How to Test Your Website’s OOPS/GPC Implementation
  • How Is California’s Browser Rule Different From Other State Privacy Laws?
  • Using a CMP for California OOPS and GPC Requirements
  • Conclusion
  • Frequently Asked Questions

For websites, the underlying sale-and-sharing opt-out obligation is not new. CCPA-covered businesses that sell or share Personal Information may already need to process qualifying signals such as Global Privacy Control.

What changes in 2027 is the availability of those signals at the browser level, which could make them much more common across websites using advertising, remarketing, audience-building and other tracking technologies.

!

What Is the California Opt Me Out Act and What Changes in 2027?

The California Opt Me Out Act is AB 566, authored by Assemblymember Josh Lowenthal and chaptered as Chapter 465, Statutes of 2025. Governor Gavin Newsom approved it on October 8, 2025.

The Act adds Civil Code §1798.136 to the CCPA. The provision is already part of California’s current CCPA statutory text, but it expressly becomes operative on January 1, 2027. “Operative” is therefore more precise than describing that date as when the provision becomes effective.

From that date, the mandate applies to a CCPA “business” that develops or maintains a browser, defined as interactive software consumers use to locate, access and navigate internet websites.

Covered browser businesses must provide functionality that:

  • Can be configured by the consumer to send an opt-out preference signal.
  • Communicates that signal to businesses the consumer interacts with through the browser.
  • Is easy to locate and configure for a reasonable person.
  • Is publicly explained, including how the functionality works and its intended effect.

The final AB 566 does not directly impose this mandate on mobile operating systems or browser engines. Earlier versions of the bill were broader.

What Is an Opt-Out Preference Signal?

California uses “opt-out preference signal,” or OOPS, for a signal communicating a consumer’s choice to opt out of the sale and sharing of Personal Information.

Under the CCPA, a sale generally involves making personal information available to a third party for monetary or other valuable consideration, subject to statutory exclusions. Sharing refers specifically to making personal information available for cross-context behavioral advertising, whether or not money changes hands.

An OOPS communicates that legal preference. It is also different from Cookie Consent: Cookie Consent addresses permission for cookies or similar technologies where consent is required, while an OOPS communicates a CCPA sale-and-sharing opt-out. It is not a cookie category, cookie blocker, deletion request or command to stop all data collection.

Is OOPS the Same as Global Privacy Control?

No. OOPS is California’s broader legal concept; Global Privacy Control (GPC) is a specific technical signal that can qualify as an OOPS.

California regulators have treated GPC as a qualifying opt-out preference signal. The current W3C GPC Working Draft describes mechanisms including the Sec-GPC: 1 header and navigator.globalPrivacyControl property. AB 566 does not require GPC by name, and GPC is distinct from legacy Do Not Track (DNT).

As of September 15, 2026, CalPrivacy lists OOPS as preliminary rulemaking and says it has no formal proposed regulation packages at this time. In August 2026, Agency staff presented recommendations for possible OOPS rules, including expressly identifying GPC as an OOPS and adding examples involving pseudonymous profiles and sale/share tracking. Those recommendations are not current law.

Do Websites Already Have to Honor Opt-Out Preference Signals?

Yes—where the business is covered by the CCPA and sells or shares personal information.

The current CCPA regulations, effective January 1, 2026, require such businesses to process a qualifying opt-out preference signal as a valid request to opt out.

Enforcement is already happening. In February 2026, California’s Attorney General announced a $2.75 million Disney settlement resolving allegations that opt-outs, including GPC from logged-in users, were not fully applied across linked devices and services.

CCPA penalties: AB 566 does not establish a separate fine schedule. Under Civil Code §1798.155(a) and Civil Code §1798.199.90(a), administrative fines and civil penalties are subject to inflation adjustment. As of 2026, the adjusted maximums are $2,663 per violation, or $7,988 for each intentional violation and certain violations involving personal information of consumers known to be under 16. These amounts are adjusted every odd-numbered year and may change in 2027.

What Does OOPS Mean for Cookies, Pixels, and Advertising Trackers?

OOPS does not map directly to CMP categories such as “Marketing” or “Analytics.”

Third-party cookies, tracking pixels such as Meta Pixel, Google advertising tags, remarketing technologies, affiliate tools, customer matching and audience-building systems may involve sale or sharing, but their legal treatment depends on the data, purpose, recipient, contracts and configuration. Analytics is neither automatically covered nor automatically exempt.

The review should extend beyond browser cookies. Server-side tagging, conversion APIs, customer-data platforms and backend audience integrations may continue sending data after a client-side tag is disabled.

Google Consent Mode may form part of an implementation, but its consent types differ from California’s statutory sale/sharing categories. A value such as ad_storage=denied does not by itself establish CCPA compliance.

How Should a Website Process an OOPS or GPC Signal?

Under §7025 of the current CCPA regulations, a qualifying signal generally applies to the browser or device and associated consumer profiles, including pseudonymous profiles.

A business cannot require unnecessary additional information merely to process the browser/device-level request. Where the consumer is not already identified, it may offer an optional way to provide identifying information if that would extend the request.

The resulting privacy state must affect processing covered by the sale/sharing opt-out. Depending on the website, that can mean suppressing advertising tags, stopping audience-building, updating vendor states or changing other applicable processing.

Under §7026, the request must be effectuated as soon as feasibly possible and no later than 15 business days. Where real-time sale or sharing can feasibly be stopped immediately—as in the regulations’ programmatic-advertising example—it must be stopped immediately.

The regulations also require businesses to provide a way for consumers to confirm that the opt-out was processed. “Opt-Out Request Honored” is one regulatory example under §7025 and §7026(g).

What About Logged-In Users?

Under §7025, where the business already knows who the consumer is—for example, because they are logged in—the signal must be applied to the associated consumer or account profile as required by the regulations, including applicable offline sale or sharing.

If the browser cannot be connected to an identified account, the request applies to the browser or device and associated pseudonymous profiles, rather than information the business cannot reasonably link to it.

What If the Browser Signal Conflicts With Website Privacy Settings?

Under §7025, if an OOPS conflicts with a prior site-specific setting allowing sale or sharing, the business must process the signal.

It may notify the consumer of the conflict and provide a compliant way for the consumer to change the choice on their own initiative. That is different from proactively asking an opted-out consumer to opt back in.

Under §7026(k), a business generally must wait at least 12 months before asking an opted-out consumer to consent to sale or sharing again, subject to regulatory exceptions. The later absence of a signal is not affirmative consent to reverse an earlier opt-out.

Does OOPS Replace “Do Not Sell or Share My Personal Information”?

Not automatically.

The current CCPA regulations still address “Do Not Sell or Share My Personal Information,” “Your Privacy Choices” and related interfaces.

An exception to certain link requirements is available under Civil Code §1798.135(b)(1) only where the business satisfies the implementing conditions in §7025(f)–(g), including frictionless processing, fully effectuating the opt-out and making the required OOPS disclosures in its Privacy Policy.

Frictionless handling also restricts practices such as charging a fee, degrading the consumer’s experience or presenting impermissible responsive pop-ups or interstitials.

OOPS also does not replace a CMP, which may perform separate functions such as privacy-state management, script control, regional configuration and consent management.

What Should Websites Do Before January 2027?

  • Start by establishing whether the business is subject to the CCPA and mapping the data flows that may constitute sale or sharing.
  • Inventory the technologies and parties involved in those flows, including cookies, advertising tags, SDKs, vendors, server-side integrations and backend systems. The goal is to understand what data moves, where it goes and for what purpose.
  • Define how a qualifying browser signal should propagate through the systems and profiles affected by the opt-out, and document the controls responsible for applying that state.
  • Review privacy interfaces and disclosures. Make sure the Privacy Policy contains the disclosures required for the implementation, and keep any Cookie Policy aligned with the cookies and tracking technologies actually used. Vendor arrangements should likewise reflect the business’s real data flows.
  • Assign ownership for the implementation, preserve configuration and remediation records, and monitor CalPrivacy’s OOPS rulemaking before the browser mandate becomes operative.

How to Test Your Website’s OOPS/GPC Implementation

  • Establish a baseline with GPC disabled, then enable it and reload the site. Confirm the signal is present through Sec-GPC: 1 or the relevant JavaScript exposure where applicable.
  • Compare network requests and browser storage before and after the opt-out. Check whether applicable advertising, remarketing and audience-building activity changes, while remembering that some identifiers may legitimately remain.
  • Test both a pseudonymous visitor and a logged-in account. Confirm the appropriate profile is updated, the consumer can see that the request was honored, the state persists across navigation and reloads, and conflicting site-specific preferences are handled correctly.
  • Repeat the test on a second device and on mobile browsers without assuming that the preference automatically propagates across devices.
  • Inspect downstream vendor states, server-side tags, conversion APIs and audience integrations, then repeat the test against the live production configuration.

Seeing Sec-GPC: 1 confirms that the browser sent the GPC header with that request. It does not prove that the website or its downstream systems processed the preference correctly.

How Is California’s Browser Rule Different From Other State Privacy Laws?

Several U.S. states already require covered businesses to honor universal opt-out mechanisms. The examples below are selected to show how those receiving-business requirements differ from California’s new browser-side mandate; they are not an exhaustive list.

State lawUniversal opt-out requirementWhy it is relevant
California — California Consumer Privacy Act (CCPA), as amended by AB 566 Covered businesses that sell or share personal information must process qualifying OOPS. From January 1, 2027, covered businesses that develop or maintain browsers must also provide configurable opt-out functionality. Adds a separate browser-provider requirement.
Colorado — Colorado Privacy Act (CPA) Since July 1, 2024, covered controllers must honor recognized universal opt-out mechanisms for sale and targeted advertising. Colorado currently recognizes GPC. An established universal opt-out mechanism model.
Connecticut — Connecticut Data Privacy Act (CTDPA) Since January 1, 2025, covered controllers must recognize qualifying opt-out preference signals for applicable sale and targeted-advertising rights. Uses browser-based preference signals without California’s browser-provider mandate.
Oregon — Oregon Consumer Privacy Act (OCPA) Since January 1, 2026, covered controllers must accept qualifying universal opt-out mechanisms for sale and targeted advertising. A current receiving-controller model for browser-generated signals.
Minnesota — Minnesota Consumer Data Privacy Act (MCDPA) Covered controllers must honor qualifying opt-out requests submitted through universal opt-out mechanisms. Illustrates the broader spread of universal opt-out requirements.

Businesses operating nationally should still treat each state separately because covered rights, definitions, implementation requirements and operative dates vary.

Using a CMP for California OOPS and GPC Requirements

A Consent Management Platform (CMP) with support for browser privacy signals provides the website-side layer for handling those preferences: detecting supported opt-out preference signals, updating the corresponding privacy state and controlling configured website technologies according to that state.

For OOPS and GPC implementation, the most directly relevant CMP capabilities include:

  • Global Privacy Control support detects GPC, an established example of a CCPA opt-out preference signal, and applies the corresponding privacy state according to the website’s configuration.
  • A Cookie Scanner inventories cookies and scripts for review when mapping processing that may constitute sale or sharing.
  • Automatic script blocking and third-party cookie blocking prevent configured client-side scripts from executing when the applicable privacy state blocks them.
  • Geo targeting applies different privacy configurations according to detected location. Geographic detection does not establish a visitor’s legal residency.

Depending on the platform, CMPs also offer broader privacy and consent-management functionality, including:

  • Cookie Banner
  • Cookie Badge
  • Show cookie categories
  • Consent events
  • GTM events when users change Cookie Consent
  • Google Tag Manager integration
  • Google Consent Mode v2
  • IAB TCF 2.3 integration
  • Cross-domain cookie consent sharing
  • Remember Consent for Subdomains
  • User consents recording
  • SameSite consent-cookie configuration
  • Multilingual support
  • Automatic monthly scans
  • Advanced reporting
  • Cookie Banner sharing
  • Privacy Policy Generator

CookieScript is a Consent Management Platform that Google includes among the CMP partners available for Consent Mode setup. It is also a Google-certified CMP with GOLD Tier status in Google’s CMP tiering system. A 14-day free trial of the Plus plan is available without requiring a credit card.

A CMP does not determine whether processing legally constitutes sale or sharing or automatically control data flows outside its configured integrations. Businesses still need to map and test the implementation against their actual processing.

Conclusion

For website operators, the 2027 change is primarily about scale: browser-level opt-out choices are expected to become easier for consumers to use. Businesses already subject to the CCPA should therefore ensure that qualifying signals produce the correct result across the data flows subject to the consumer’s opt-out.

Frequently Asked Questions

When does the California Opt Me Out Act become operative?

The browser requirement added by AB 566 becomes operative on January 1, 2027. Existing CCPA obligations to process qualifying opt-out preference signals already apply before that date.

What actually changes in California in 2027?

From January 1, 2027, covered businesses that develop or maintain browsers must provide consumer-configurable functionality for sending opt-out preference signals and explain how that functionality works and its intended effect.

Do websites already have to honor GPC before 2027?

Yes. A business subject to the CCPA that sells or shares personal information may already be required to treat a qualifying Global Privacy Control signal as a valid opt-out request. The 2027 browser requirement does not create a grace period for websites.

Is OOPS the same as Global Privacy Control?

No. OOPS is California’s broader concept of an opt-out preference signal. GPC is a specific technical signal that can qualify as one. AB 566 does not require GPC by name.

Does an OOPS mean “reject all cookies”?

No. An OOPS communicates a consumer’s choice to opt out of sale and sharing of personal information under the CCPA. It is different from Cookie Consent, and its effect depends on what individual cookies, pixels, scripts and other data flows actually do.

What happens when the consumer is logged in?

Where the business already knows the consumer’s identity, the current CCPA regulations require the preference to be applied to the associated account or consumer profile as applicable, including relevant offline sale or sharing.

Does OOPS replace a “Do Not Sell or Share My Personal Information” link?

Not automatically. The exception to certain link requirements derives from Civil Code §1798.135(b)(1) and the implementing §7025(f)–(g) conditions, including frictionless processing of qualifying signals and required privacy-policy disclosures.

Does every website need a new California Cookie Banner in 2027?

No. AB 566 is not a cookie-banner or cookie-consent law. Websites should instead determine whether the CCPA applies, whether their processing involves sale or sharing, and whether qualifying privacy signals affect relevant technologies correctly. A cookie banner may form part of a broader privacy setup, but the law does not itself require a new California banner.

 
  • About CookieScript
  • Terms of Service
  • Privacy Policy
  • Pricing
  • Resources
  • Cookie Scanner
  • Privacy Policy Generator
  • System status
  • Sitemap
  • Changelog
  • Alternatives
  • CookieBot
  • Termly
  • OneTrust
  • Iubenda
  • Cookie Information
  • CookieFirst
  • Illow
  • Blog
  • Guides
  • News
  • GDPR & CCPA
  • Privacy laws
  • Knowledge base
  • Support
  • Help center
  • Contact us
  • Integrations
  • Request a feature
  • Roadmap
  • For Partners
  • For agencies
  • For Affiliates

Copyright ©2026 CookieScript


main version