In the US, businesses face a new compliance requirement: automatically recognizing consumers’ privacy choices. Instead of requiring people to visit every website and manually click a “Do Not Sell or Share My Personal Information” link, several state privacy laws now require businesses to recognize universal opt-out mechanisms (UOOMs).
Global Privacy Control (GPC) is the best-known technical implementation of UOOM. GPC is a browser-based signal that sends consumer’s requests to websites not to sell, share, or use their personal data for certain types of targeted advertising.
States with comprehensive privacy laws fall into two groups: states that legally require businesses to detect and honor an opt-out preference signal, and states whose laws grant residents an opt-out right but do not require automatic recognition of a browser-level signal.
For businesses operating across multiple US states, understanding the relationship between UOOMs, GPC, and individual state privacy laws is an important part of privacy compliance.
This guide explains universal opt-out mechanisms in the US and the GPC requirements by state.
What Are Universal Opt-Out Mechanisms (UOOMs)?
A Universal Opt-Out Mechanism (UOOM) is a browser, device, or software-level signal that automatically communicates a consumer’s preference to opt out of the sale, sharing, and targeted advertising of their personal data across websites without requiring manual opt-outs on every website.
Without UOOM, individuals who want to prevent businesses from selling their personal data or using it for targeted advertising need to visit individual websites, find each company’s privacy controls, and submit separate opt-out requests.
A universal opt-out mechanism is designed to reduce that burden. Individuals can enable a browser-level signal, automatically signaling their choice over personal data management. Once enabled, the mechanism sends the consumer’s preference to all websites that the consumer visits.
The main benefit of UOOM is scalability. Instead of requiring a consumer to communicate the same privacy choice individually to many businesses, a UOOM can express the preference across numerous websites.
For businesses, this means placing an opt-out link in a website footer is not enough for privacy compliance. In 2026, businesses need technical systems that can detect users’ location under applicable state privacy laws and a qualifying privacy signal from browsers. After detecting an opt-out preference signal, businesses must ensure the preference carries through advertising, analytics, identity, and data-sharing systems.
CookieScript supports the universal opt-out preference signal through its Consent Management Platform (CMP). If a user has enabled UOOM, your website can automatically honor the opt-out preference signal (where required) and adjust data sharing and ad/analytics behavior accordingly.
What Is Global Privacy Control (GPC) and How Does It Work?
Global Privacy Control (GPC) is the best-known technical implementation of a universal opt-out mechanism. GPC is a browser-based signal that sends consumer’s requests to websites not to sell, share, or use for certain types of targeted advertising their personal data.
The main purpose of GPC is to signal businesses in a single and scalable way consumers’ opt-out preference not to sell, share, or use for certain types of targeted advertising their personal data.
These privacy preferences are then transmitted as a signal to every website the user visits. So, consumers do not need to press the ‘Do not sell or share my personal data’ link on every website.
Once enabled, businesses must transmit this opt-out preference signal to third-party vendors, used for advertising, analytics, identity, and other data-sharing systems.
Note that the GPC differs from the older Do Not Track (DNT) browser signals. Do Not Track generally depends on voluntary website participation and is not regulated by state laws. As a result, businesses often neglected it. GPC, by contrast, can trigger legally enforceable obligations when an applicable privacy law requires a business to recognize the signal.
Thus, GPC is not just a browser preference. In states where recognition is required, it is a legal requirement, which action is equal as opting out of sell or sharing of personal data manually through privacy preferences.
GPC vs. Universal Opt-Out Mechanisms: What’s the Difference?
Although GPC and universal opt-out mechanisms are often used interchangeably, they do not mean the same thing. UOOM is the broader category, describing technology that allows consumers to communicate their privacy choices automatically across multiple websites. GPC is one of the most widely recognized examples of UOOM and is expressly recognized by regulators in United States.
This distinction matters because most state privacy statutes are written to accept technological development. Rather than requiring one opt-out mechanism forever, legislatures often describe the characteristics that future qualifying opt-out mechanisms must possess.
GPC has become well known because regulators have specifically recognized it. California identifies GPC as a valid opt-out request, Colorado currently lists GPC as its recognized UOOM, and Connecticut also expressly requires respecting the GPC signal.
However, that does not mean GPC will always be the only relevant technology. State laws are generally designed to qualify other mechanisms that satisfy applicable legal and technical standards.
Not sure if your website uses cookies that could be used in the sale, sharing, or targeted advertising of customers’ personal data by third parties? CookieScript Cookie Scanner scans all website cookies and trackers and automatically blocks all third-party scripts:
Universal Opt-Out and GPC Requirements by State
Universal Opt-Out Mechanism requirements depend on the state privacy law. Some states legally require businesses to detect and honor an opt-out preference signal, universal opt-out mechanism, or a GPC signal. Other states grant residents an opt-out right, but they do not require automatic recognition of an opt-out preference signal.
Thus, Global Privacy Control requirements and state privacy laws opt-out requirements regarding the scope, effective dates, exceptions, and technical requirements vary by state.
States that require UOOM recognition
As of September 2026, the following states have comprehensive privacy laws that legally require covered businesses to detect and honor a universal opt-out mechanism or opt-out preference signals such as GPC:
- California (CCPA/CPRA)
- Colorado (CPA)
- Connecticut (CTDPA)
- Montana (MTCDPA)
- New Hampshire (NHDPA)
- Texas (TDPSA)
- Nebraska (NDPA)
- New Jersey (NJDPA)
- Minnesota (MCDPA)
- Delaware (DPDPA)
- Oregon (OCPA)
- Maryland (MODPA)
Find out more details about state privacy laws, opt-out requirements, and GPC requirements by state:
California
CCPA/CPRA require processing GPC as a valid consumer request to opt-out of sale, sharing, and cross-context behavioral advertising. The GPC signal must be treated as a valid Do Not Sell or Share request- consumers do not have to activate a separate Do Not Sell or Share signal. California has also demonstrated that universal opt-out compliance is enforced.
Colorado
Colorado has one of the country's most developed UOOM frameworks.
The Colorado Attorney General has published binding universal opt-out mechanism technical specifications that a signal must meet to qualify. The Attorney General maintains an official list of recognized UOOMs. GPC is on the list.
Colorado privacy notices must also explain how businesses process requests submitted through universal opt-out mechanisms.
Connecticut
The Connecticut Data Privacy Act requires businesses to detect and honor opt-out preference signals for targeted advertising and sale of personal data.
In Connecticut, honoring universal opt-out mechanisms is an enforcement priority. Connecticut's Attorney General specifically identifies GPC as an example of an opt-out preference signal and has emphasized that businesses should recognize qualifying signals across website-based activities.
Montana
Controllers must allow consumers to opt out of targeted advertising and sales through qualifying opt-out preference signals.
The opt-out signal must be consumer-friendly and represent an affirmative and unambiguous consumer choice.
New Hampshire
Controllers must allow consumers to opt out of targeted advertising and sales through qualifying opt-out preference signals.
The UOOM technology cannot simply use an automatic default. The consumer must make an affirmative, freely given, and unambiguous choice.
Texas
In Texas, UOOM is mandatory. Businesses must honor opt-out preference signals sent via qualifying technology (a platform, technology, or mechanism).
The statute contains important verification and controller exceptions. Among other conditions, a controller is not obliged to process a technology-based request where it cannot verify Texas residency, lacks the ability to process the request, or does not process similar requests for compliance with comparable state laws.
Nebraska
In Nebraska, respecting UOOM is mandatory. Consumers can use browser and device technologies, such as browser settings, browser extensions, website links, or global device settings, to communicate their opt-outs from targeted advertising or personal-data sales.
Nebraska follows a framework similar to Texas, including significant exceptions.
For example, a controller may not be required to honor the technology-based request if it cannot reasonably verify Nebraska residency, cannot process the request, or does not process similar requests to comply with comparable laws in other states.
New Jersey
Controllers processing data for targeted advertising or sale must support a user-selected universal opt-out mechanism.
To honor the opt-out signal, businesses should be able to determine whether the consumer is a New Jersey resident.
Minnesota
Covered controllers must honor manual and qualifying automatic opt-out requests for targeted advertising and personal-data sales.
Delaware
Controllers must recognize universal opt-out mechanisms as valid consumer requests.
Oregon
Oregon's universal opt-out requirement became mandatory January 1, 2026.
Covered businesses and nonprofits must honor qualifying universal opt-out signals for data sales and targeted advertising.
Oregon specifically identifies GPC as an example. However, businesses must still provide an appropriate website opt-out mechanism as well; recognizing the universal signal does not replace other methods for consumer requests.
Maryland
Maryland uses a different statutory structure.
The Maryland Online Data Privacy Act permits controllers to provide a mechanism for opting out of targeted advertising and data sales by providing a clear website link or by allowing consumers to use a qualifying opt-out preference signal, rather than establishing the same straightforward mandatory UOOM-recognition rule found in states such as Colorado or Connecticut.
A controller may use a qualifying opt-out preference signal to enable opt-outs; recognizing signals approved by other states can satisfy the relevant statutory provision.
Maryland consumers may additionally designate an authorized agent using technologies such as browser settings, browser extensions, global device settings, or similar technologies.
States that do not require UOOM recognition
Data privacy laws of these states grant residents the right to opt out of sale, targeted advertising, or profiling. Still, their statutes do not require businesses to automatically recognize a universal opt-out mechanism or opt-out preference signal, such as GPC. In these states, targeted advertising opt-out and personal data sale opt-out can be exercised through a manual “Do Not Sell or Share My Personal Information” request mechanism instead.
Thus, state privacy laws opt-out requirements can vary.
States that do not require UOOM recognition include:
- Virginia (VCDPA)
- Utah (UCPA)
- Iowa (ICDPA)
- Indiana (INCDPA)
- Kentucky (KCDPA)
- Tennessee (TIPA)
- Rhode Island (RIDTPPA).
Businesses operating only in non-mandate states like Virginia or Tennessee are not currently required to detect or honor the GPC signal automatically. But this comes with a risk.
First, state privacy laws change frequently, so a state without a UOOM requirement today may introduce the honoring requirement in a future amendment,
Second, state data privacy laws have extraterritorial reach: even if your company is headquartered in a state that does not require UOOM recognition, your website may be accessed by individuals located in California or other states, honoring UOOM. Thus, you must honor UOOM provided by these individuals.
Third, honoring the signal uniformly avoids the operational complexity and makes compliance much easier and more reliable.
How CookieScript Can Help Honor Automated Opt-Out Signals
CookieScript CMP is an advanced tool that helps businesses fully comply with state privacy laws.
CookieScript offers the following functionalities:
- geo-targeting
geo-targeting identifies a visitor's exact location and applies UOOM based on the relevant state's legal requirements. When a state privacy law is updated, honoring the GPC signals updates automatically, so you don’t need to track changes in state privacy laws yourself. - GPC detection
CookieScript detects UOOM signals, such as GPC and other legally qualifying opt-out signals automatically, so you can pass the signal to third-party vendors and partners. - Google Tag Manager integration
for easier integration of Google Products. - Third-party cookie blocking
CookieScript CMP automatically blocks all non-essential scripts until consent is given. No cookies or other website trackers will be set on customers’ devices before consent. - Certification by Google
It allows the use of Google Ads, Google AdSense, Google Analytics, and other products. - Granular Cookie Banner
It lets users choose between different cookie types (e.g., strictly necessary, analytics, marketing, and security) rather than only allowing them to accept or reject all cookies. - Strong consent logging
CookieScript CMP lets you track banner versions, export consent logs, and keep them long-term. - Easy integration with your stack
CookieScript CMP is integrated with GTM, has many automatic CMS integration options, and allows custom scripts. - Google Consent Mode v2 integration
It enables privacy-safe marketing and analytics for businesses without exposing personal data. - Automatic cookie scanning
The CMP automatically scans your website for cookies, local storage, session storage, and other tracking technologies. - CookieScript API
CookieScript API to customize the behavior of cookie banners, manage Cookie Consent and scans, retrieve and update cookie declarations, and control individual cookies automatically. - 40+ language support
The CMP ensures consent banners display in each patient’s language, essential for international providers. - Cookie banner sharing to allow web agencies to share their banners with multiple users.
- Cross-domain cookie consent sharing to enable both sub-domain and cross-domain Cookie Consent sharing from a single user across multiple domains.

Frequently Asked Questions
What is a universal opt-out mechanism under US privacy laws?
A Universal Opt-Out Mechanism (UOOM) is a browser, device, or software-level signal that automatically communicates a consumer’s preference to opt out of the sale, sharing, and targeted advertising of their personal data across websites without requiring manual opt-outs on every website. To honor UOOM, you need a CMP like CookieScript that can detect it.
Is Global Privacy Control the same as a Universal Opt-Out Mechanism?
Not exactly. A Universal Opt-Out Mechanism (UOOM) is the broader category, describing technology that lets consumers communicate their privacy choices automatically across multiple websites. GPC is one of the most widely recognized examples of UOOM and is expressly recognized by regulators in the United States. Use CookieScript CMP which can detect UOOM and GPC.
Which states require businesses to honor GPC or universal opt-out signals?
States that require businesses or controllers to recognize GPC or qualifying universal opt-out preference signals include California, Colorado, Connecticut, Delaware, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. However, the scope, exceptions, and technical requirements vary by state. Maryland also recognizes opt-out preference signals, but its statutory framework differs from states that impose a direct universal signal-recognition requirement.
Do businesses still need a “Do Not Sell or Share” link if they honor GPC?
In many cases, yes. Honoring GPC does not automatically eliminate other consumer-rights requirements. Some state privacy laws still require businesses to provide a clear website-based method for exercising opt-out rights manually in addition to recognizing universal opt-out signals. Businesses should therefore offer both methods to express user opt-out preferences. Use CookieScript CMP, which can detect automatic opt-out signals.
Does Maryland data privacy law require businesses to honor GPC or universal opt-out signals?
Maryland recognizes opt-out preference signals, but its statutory framework differs from other states. The Maryland Online Data Privacy Act permits controllers to provide a mechanism for opting out of targeted advertising and data sales by providing a clear website link or by allowing consumers to use a qualifying opt-out preference signal, rather than requiring the direct UOOM-recognition rule found in other states. Use CookieScript CMP, which can detect automatic opt-out signals.