检查清单

How do you prove a storefront honored GPC?

开始免费审计

Keep Sec-GPC proof, a GPC-on versus GPC-off cookie and request diff, and a banner screenshot. A free US-baseline scan is not a California GPC conclusion.

In brief

To prove a storefront honored GPC, keep three artifacts from a paired GPC-off and GPC-on run on the same URL: Sec-GPC header proof, a network and cookie diff, and a screenshot of the banner under GPC-on. A detected line on the CMP is a separate claim. ConsentProbe can label a GPC scenario and tie findings to those surfaces. A free US-baseline scan is not a California GPC conclusion. This page is a test checklist, not legal advice.

Not legal advice

This article explains observable artifacts that show a storefront reacted to a Global Privacy Control signal in a test. It is not legal advice, not a CPRA compliance certificate, and not a guarantee that honoring GPC in one run meets California or any other rule. ConsentProbe reports are technical observations. They do not replace counsel.

Last updated September 24, 2026. The general file list lives on the cookie consent evidence pack guide. What GPC is, and how to turn the signal on, lives on the Global Privacy Control test guide. This page is the proof checklist for a paired run.

Short answer

To prove a storefront honored GPC in a test, keep three artifact types from a paired GPC-off versus GPC-on run on the same URL: (1) request header proof that Sec-GPC: 1 was present on the GPC-on navigation, (2) a network and cookie diff that shows which marketing or sale-or-share hosts and cookies dropped or stayed, and (3) a screenshot of the CMP or banner state under GPC-on, and under GPC-off if you claim the UI changed.

GPC detected in the banner is not enough when Network still matches the GPC-off run. Read that case on the GPC versus CMP claims guide. Package the three surfaces the same way as a general cookie consent evidence pack. ConsentProbe can produce a labeled GPC scenario with findings tied to those surfaces. A free US-baseline scan is not a California GPC conclusion. This page is testing guidance, not legal advice and not a compliance certificate.

What honored means in a test

On this page, honored means the files show a behavior change after the signal arrived. You enabled GPC, and you confirmed the signal reached the page. Sec-GPC: 1 on the document request is the header proof. navigator.globalPrivacyControl in the console is optional. Keep the header in the pack. That is the value on the request many tags and the server can see.

Compare the same URL with GPC off and with GPC on, and record cookies and third-party requests. Keep the CMP sentence beside the network file. The sentence is a claim about the UI. The request list is the check on behavior.

A quieter network on one URL, in one region, on one day, is a test result. This page does not set a legal threshold for honored. A browser language, or a clock set to Los Angeles, does not turn a non-California network into a California result. The free versus paid guide draws that line for ConsentProbe scans. The same line applies to a pack you build by hand.

Evidence checklist

Fill one row per artifact before you write honored on a ticket. The evidence pack guide still owns how any consent file is named, redacted, and handed off. The rows below are the GPC-specific items.

GPC proof items from a paired run. Observable signals only.
ArtifactWhat to captureObservable pass signalWeak signal
Request header proofDevTools, Network, document request headers on the GPC-on run.Sec-GPC: 1 is present on the run you label GPC-on.The file is labeled GPC-on and the header is missing.
Network diffThird-party ad, analytics, or sale-or-share hosts, GPC-off versus GPC-on.A drop or a gate on hosts you expected to react.The host list matches the GPC-off run.
Cookie and storage diffCookies and relevant storage keys after one navigation.Marketing cookies that appear on GPC-off stay absent or gated on GPC-on.The same new cookies appear under both runs.
Screenshot of stateBanner or CMP UI under GPC-on, and under GPC-off when the UI differs.The UI sentence matches what Network shows.The banner says GPC detected while Network matches GPC-off. See the claims guide.
Finding sentenceOne line with the host, the state, and the artifact IDs.Someone else can replay the check without guessing which file.GPC broken, with no host and no header proof.

Capture the header, then the diff

In Chrome DevTools, open Network and reload. Select the document row and open Request Headers. Sec-GPC with a value of 1 is the proof for that load. Save a screenshot, or a HAR line, after you remove cookies, query tokens, and request bodies. The evidence pack guide uses that redaction rule for every consent state.

If the header is missing, stop and fix the profile before you diff cookies. A GPC-off visit filed under a GPC-on label looks like the storefront ignored a signal it never received.

Export cookies from the Application panel for the shop host and for third parties set on that navigation, and save the third-party request list under the same label as the header shot. A host on the GPC-off file and absent or gated on GPC-on is the pass signal for that host. A host on both files, with a similar spread, did not use the signal. Name that host in the finding sentence. An illustrative line, with a stand-in host: GPC-on, ads.example still requested /collect after Sec-GPC: 1 (header shot H1, request R14). Substitute the host and the IDs from your run.

Paired mini protocol

Change only the signal between the two runs. Keep the URL and how far you navigate the same. A missing Sec-GPC header means that file cannot support a GPC-on claim.

  1. Use two clean profiles, or an equivalent isolated context. Open the same storefront URL. Write the region you actually used. A locale or a timezone is not an IP.
  2. Run A, GPC off. Record cookies, third-party requests, and a banner screenshot.
  3. Run B, GPC on. Confirm Sec-GPC: 1 on the navigation request. Record the same surfaces.
  4. Diff hosts and cookies. Write one finding sentence per distinct failure, with the artifact IDs from that run.
  5. If the shop is Shopify, follow the Shopify GPC honor test for theme, app, and pixel steps. Keep this checklist for the proof pack itself.
  6. For what GPC is and how to enable it, use the Global Privacy Control test guide. If the UI says detected and Network is unchanged, use the GPC versus CMP claims guide.

The badge, the header, and the network

A CMP badge that says GPC was detected is the UI claim. Header proof shows this navigation sent the signal. The network and cookie diffs show whether behavior changed. When the pack says honored, keep all three. The GPC versus CMP claims guide walks a badge that is up while the request list still matches GPC-off. The CMP claims versus runtime guide covers the same kind of check for Reject All and Accept All.

On Shopify, follow the Shopify GPC honor test for theme Liquid, app embeds, customer events, and pixels, and bring these three artifacts back from that run. If you are still choosing among GPC, Reject All, and a pre-consent pass, start from the testing hub.

After the DIY checklist

After you have run the checklist by hand, use ConsentProbe when you want a labeled GPC scenario with findings already linked to a request, a cookie, or a screenshot. A free US-baseline visit shows the report format on one non-California pass. It is not a California or GPC conclusion. Paid California or GPC scenarios are the regional pair. The free versus paid guide states that split.

ConsentProbe does not install a CMP or a banner. The CMP still collects the click choice. The audit records what the browser did under the scenario name.

FAQ

How do you prove a storefront honored GPC?

Run GPC-off and GPC-on on the same URL. Keep header proof that Sec-GPC: 1 was sent, a network and cookie diff, and a screenshot of the banner state.

Is GPC detected in the CMP enough?

No. Keep the header proof and a network and cookie diff. The GPC versus CMP claims guide covers a detected badge with an unchanged network.

What goes in the GPC evidence pack?

The three surfaces above, packaged like the cookie consent evidence pack, plus a finding sentence that names the host, the state, and the artifact IDs.

Does ConsentProbe replace the pack?

No. It can supply a labeled GPC scenario with findings linked to a request, a cookie, or a screenshot. You still hand the pack to engineering or counsel. ConsentProbe does not install a CMP.

Does a free US-baseline scan prove California GPC behavior?

No. A free US-baseline visit is not a California or GPC conclusion. See the free versus paid guide, and use paid California or GPC scenarios when that is the claim.

Is this legal advice or a CPRA certificate?

No. These are technical observations from labeled visits. They are not a compliance certificate and not a substitute for counsel.

Limits of this page

This page explains how to prove, in a test, that a storefront reacted to Global Privacy Control. It is not legal advice, not a CPRA compliance certificate, and not a guarantee that three files mean a shop meets California or any other rule. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan remains a format pass, not a GPC conclusion.

Related guides

Open the evidence pack guide for the file rules, the GPC test guide to enable the signal, the claims guide when the badge and the network disagree, and the Shopify GPC honor test when the shop is Shopify.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

如何证明店面兑现了 GPC | ConsentProbe