Technical guide
GPC vs CMP Claims: How to Spot a Mismatch
Check whether Global Privacy Control and CMP honor claims match browser behavior with paired GPC-off and GPC-on California-facing storefront visits.
In brief
To check whether GPC and your CMP claims match, run two clean visits to the same storefront: one with Global Privacy Control off, one with GPC on. Do not touch the banner unless your test plan says so. Compare cookies and third-party ad or analytics requests. If the CMP claims to honor GPC but GPC-on traffic still looks like a sale-or-share-style load, capture both runs as evidence. Marketing pages that say we honor GPC are not proof.
Hard boundary
This page is a technical checklist for California-facing storefronts. It is not a CPRA legal memo, not a browser-extension encyclopedia, and not a CMP feature matrix. Do not name-attack CMP vendors. Locale and timezone do not replace California IP evidence. A free US-baseline audit is not a California GPC conclusion.
Claims versus behavior
Policy text and CMP UI copy are not network reality. Common mismatches include a UI that acknowledges GPC while pixels already fired, or only partial categories suppressed while ad and analytics fan-out continues.
Describe what you observed. Do not turn a mismatch into a legal determination about whether sale or sharing applies to the business.
What GPC is
Global Privacy Control is a browser signal that the user opts out of sale or sharing of personal information. Read the California Attorney General and Global Privacy Control publisher pages for authoritative wording. Do not invent statutory quotes from marketing copy.
Prep
Prepare two fresh profiles or equivalent isolation. Use a known GPC-on method for the browser you test with, and state uncertainty if DIY enablement varies. Keep the same URL and roughly the same timing. Skip logged-in accounts unless that path is the test target.
California conclusions need California-context runs. ConsentProbe lists the paid California baseline versus GPC product on pricing.
DIY paired test
Change only the GPC signal between runs. Leave the banner untouched unless your written plan requires a click.
- Run A — GPC off: load the site; record cookies and third-party requests; screenshot the banner or CMP if shown.
- Run B — GPC on: same URL in a new profile; verify
Sec-GPCon the document request andnavigator.globalPrivacyControlin the console; record the same surfaces. - Diff: vendors and cookies present in both; anything that should suppress on GPC-on but did not.
- Optional: note whether the CMP shows a GPC detected state. UI without a network change still counts as mismatch risk.
What aligned looks like
Use the table when marketing says the CMP honors GPC. Aligned means observable suppression relative to the matched off run, not a guarantee of every legal duty.
| Signal | Expect if claims hold | Mismatch red flag |
|---|---|---|
| GPC on | Non-essential sale-or-share-style requests drop versus GPC off | Same ad or analytics fan-out as GPC off |
| CMP UI | Optional detected notice after the signal is verified | Notice shown but pixels already sent |
| After navigation | Suppression holds on the next page | Tags return on product, cart, or checkout |
Evidence pack and soft CTA
Label every artifact GPC-off or GPC-on. Include cookie tables, key request URLs, timestamps, and screenshots. ConsentProbe maps findings to request, cookie, and screenshot IDs after a saved California run.
Need a repeatable California baseline versus GPC evidence pack? Use the California product on pricing. Free US-baseline remains a format check, not a GPC conclusion.
FAQ
What is GPC in one sentence?
A browser signal that the user wants to opt out of sale or sharing of personal information.
If the CMP says it honors GPC, am I done?
No. Verify with GPC-on versus GPC-off network and cookie diffs, and confirm the signal reached the page.
Can GPC and the banner disagree?
Yes. The UI may show respect while tags already loaded, or only some categories may suppress.
Does a US free scan prove GPC?
No. You need a GPC-on scenario on a California-facing path. ConsentProbe’s California product is the paid path for that comparison.
What do I send legal or engineering?
Paired evidence packs for GPC-off and GPC-on. Policy screenshots alone are not enough.
Related guides
Keep pre-consent, reject leftovers, and GPC storefront workflows linked so teams pick the right pack.
- Pre-Consent Cookie Audit: A Storefront Checklist
- Reject All Still Tracking: What to Check After You Say No
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Testing Global Privacy Control on a California Storefront
- Runtime Audit vs CMP: What Each One Measures
- Reject All vs Accept vs GPC: A Scenario Matrix for Shopify Stores
- ConsentProbe methodology
- Sample report
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.