Universal Opt-Out Mechanisms, State by State

California gets the attention, and California is not the only state involved. Colorado, Connecticut, and Texas already require businesses to recognize a browser-level opt-out. Vermont has the requirement written down with a future start date. Virginia, which is often listed alongside the rest, reads differently in the sections tracked here, and that difference is the most useful thing in this article.

Below is what each statute asks for, when it started asking, and what the practical scope question looks like for a site that serves visitors from more than one of these states.

What a universal opt-out mechanism is

A universal opt-out mechanism is a preference a person sets once, in their browser or on their device, that then travels with every request they make. Instead of finding and clicking a link on each site individually, the visitor configures the setting one time and every site they visit receives it. State statutes describe this in deliberately protocol-neutral language: a "universal opt-out mechanism", an "opt-out preference signal", or a technology used to designate an agent. Legislatures avoided naming a specification so that the duty would survive changes in how the signal is carried.

Global Privacy Control is the implementation with traction. It travels as a Sec-GPC: 1 request header and as a navigator.globalPrivacyControl boolean that any script on the page can read. Keeping the concept and the protocol separate is worth the effort: the statutes create a duty toward a category of signal, and GPC is the member of that category your visitors are sending today. Handling GPC correctly is how the duty gets discharged in practice, but the statutory wording is what defines the duty, and no two states word it the same way.

Those differences decide which date applies to you, which legal construct the signal fits inside, and, in one case, whether a signal-recognition duty appears in the tracked sections at all.

California: the reference implementation

The CCPA and its implementing regulations set the pattern the other states borrow from. Section 7025 requires a business to treat a qualifying opt-out preference signal as a valid request to opt out of sale and sharing for that browser or device, along with any consumer profile associated with it. The statute behind the regulation, Civil Code section 1798.135, handles the relationship between the signal and the posted opt-out links, exempting a business that lets consumers opt out through an opt-out preference signal from the two-link requirement.

California also supplies the enforcement anchor for the whole category. In August 2022 the California Attorney General announced a $1,200,000 settlement with Sephora, the state's first public CCPA settlement, which included a finding that the company did not honor Global Privacy Control opt-out signals and did not cure the violations within the thirty-day cure period then available. That case is why "we support the signal in the consent tool" and "the signal is honored on the live site" are treated as separate claims.

The California detail runs deeper than one section of this article can carry, so the rest of this piece stays on the other states.

Colorado: recognition required since July 1, 2024

The Colorado Privacy Act puts the mechanism inside the consumer rights section. Section 6-1-1306 grants consumers the rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising, the sale of personal data, and profiling. The same section mandates honoring technical universal opt-out signals, GPC among them, since July 1, 2024. That date has now been live long enough that a site still ignoring the signal for Colorado traffic has been out of step for two years rather than two months.

The obligations that surround the right sit in section 6-1-1308, the controller duties: specify processing purposes, minimize collection, secure the data, and publish a transparent privacy notice. Colorado also added a distinct duty through SB 25-276, which bars selling a consumer's sensitive data, now including precise geolocation, without consent. The signal work and the notice work are separate projects, and a compliance program that only does the notice half leaves the signal half undone.

Connecticut: recognition required since January 1, 2025

The Connecticut Data Privacy Act follows the same structural choice. Section 42-518 grants the rights to access, correct, delete, and obtain a portable copy of personal data, and mandates honoring technical universal opt-out signals since January 1, 2025. Connecticut has kept legislating around that core: effective July 1, 2026, Public Act No. 25-113 adds profiling-related rights for consumers subject to solely automated decisions, and effective October 1, 2026, Public Act No. 26-64 broadens the deletion right to reach publicly available information that has been collated into a consumer profile.

Controller duties live in section 42-520, also amended by both acts. Those amendments add a privacy-notice disclosure about using or selling personal data to train large language models, a consent requirement before selling sensitive data, a prohibition on selling precise geolocation data, and signage and policy requirements for facial-recognition use. None of that changes the signal duty, which has been in force since the start of 2025 and is unaffected by the later amendment dates.

Texas: the signal as an authorized agent

Texas is the state worth reading closely, because the Texas Data Privacy and Security Act arrives at the same outcome through a different legal construct. Instead of naming a universal opt-out mechanism directly, Texas puts it inside the authorized-agent provision of section 541.055, which governs the methods a controller must offer for submitting consumer requests. Subsection (e) lets a consumer designate an agent using a technology: a link to a website, a browser setting or extension, or a global setting on a device. GPC fits that description exactly.

The framing has a consequence. In Texas the signal is not a special category of communication, it is an ordinary opt-out request arriving from an agent the consumer designated by technical means, which the controller may verify with commercially reasonable effort. The rights being exercised through that agent are the targeted advertising and sale opt-outs in section 541.051, subsection (b)(5). Controllers must honor such a signal starting January 1, 2025, six months after the Act's general July 1, 2024 effective date. Two statutes, two constructions, one behavior on the wire: the tracker has to stop.

Vermont: on the books, effective January 1, 2028

The Vermont Data Privacy and Online Surveillance Act belongs on this list for planning purposes and not for this quarter's remediation list. Its controller duties section, section 2415e, requires a non-default opt-out preference signal mechanism alongside data minimization, consent for sensitive-data processing and sale, a detailed privacy notice, and an extension of the ban on targeted advertising and sale to any consumer known to be under 18. The consumer rights it pairs with are in section 2415d, which consolidates access, correction, deletion, portability, the opt-outs, and a right to obtain a list of third parties that purchased the consumer's data.

The effective date is January 1, 2028. Say that out loud before putting Vermont in a status report, because a control that is not yet a live obligation should not be tracked as an open finding. The useful planning point is that Vermont asks for the same machinery Colorado, Connecticut, and Texas already ask for, so a site that honors the signal today has already built most of what 2028 will want.

Virginia: an opt-out right without a signal mandate in the sections we track

Virginia is on nearly every list of state privacy laws, which is why it is worth being precise about what the Virginia Consumer Data Protection Act actually says here. Section 59.1-577 grants Virginia consumers the rights to confirm processing and access their data, correct inaccuracies, delete personal data, obtain a portable copy, and opt out of targeted advertising, the sale of personal data, and profiling. The section describes those rights as invoked by submitting a request to a controller.

The Virginia sections tracked here grant an opt-out right exercised by request and do not impose a duty to recognize a universal opt-out signal. Controller duties in section 59.1-578 cover data minimization, reasonable security, opt-in consent for sensitive data, and a clear privacy notice that explains how to exercise those rights. That makes Virginia the instructive contrast in this set: an opt-out regime built entirely around the request path, where the posted mechanism carries the whole burden.

The practical reading is narrow. It means a request-handling process has to exist and work in Virginia, and it does not mean a site operating nationally can skip signal handling, because Colorado, Connecticut, and Texas visitors are hitting the same pages.

Others

Other states, including Oregon, have their own universal opt-out requirements that this regulation library does not yet track section by section.

What this means if you operate in more than one state

The technical failure mode is identical in every one of these states: a tracker that keeps firing after the signal arrives. A free GPC check answers that question once for all of them. The legal wrapper varies, the dates vary, the vocabulary varies, and the network trace looks the same in each case: a request to an advertising or social endpoint that left the page after the browser said not to.

StateSignal recognition dutyWhere it lives
CaliforniaYes, opt-out preference signal treated as a valid opt-out11 CCR § 7025, Civil Code § 1798.135
ColoradoYes, since July 1, 2024§ 6-1-1306, with controller duties in § 6-1-1308
ConnecticutYes, since January 1, 2025§ 42-518, with controller duties in § 42-520
TexasYes, from January 1, 2025, as an authorized-agent designation§ 541.055(e), with the rights in § 541.051(b)(5)
VermontNot yet, effective January 1, 2028§ 2415e, with consumer rights in § 2415d
VirginiaNo signal duty in the sections tracked here; opt-out by request§ 59.1-577, with controller duties in § 59.1-578

A multi-state program usually resolves this in one of two ways. The first is geographic gating: detect the visitor's state and apply the matching rule set. That approach inherits every weakness of IP-based geolocation, and it multiplies the number of code paths that need testing, since each state's variant is a configuration that can drift on its own schedule. The second is a single national posture: honor the signal for every visitor, everywhere, and keep the request-path mechanisms working alongside it. The second is fewer moving parts, and fewer moving parts is the whole game in a control that has to keep working through theme changes and tag additions.

One implementation, several statutes

Read together, the tracked statutes ask a site to do one thing on the wire: notice the signal and stop the sale and sharing that follows. That is why one correct implementation satisfies all of them. Read the signal on both the header path and the JavaScript path, map your tag categories to what counts as sale or sharing, and enforce that mapping at a point every tag routes through. The Colorado date, the Connecticut date, and the Texas authorized-agent construction change what you would tell a regulator about why you did it. They do not change the code.

The obligations that do not collapse into the signal are the posted mechanisms. Virginia's request path has to work on its own, and California layers California's separate posted-link duties on top of the signal duty, with a frictionless-processing path that changes what has to be posted without changing the duty to honor the signal. Treat those as a second workstream rather than a substitute for the first.

One last thing about all six jurisdictions at once: signal handling is a control that decays. A configuration that passed in Colorado in 2024 and in Connecticut in 2025 can stop passing after a template change, a newly hardcoded pixel, or a vendor swap, and nothing in the deploy pipeline announces it. The date a state's requirement started is a fact about the calendar. Whether the tracker stopped firing this week is a fact about your site, and it is worth checking on a schedule rather than at a launch.

Check this on your own site

Our free GPC checker loads one URL with the Global Privacy Control signal set and reports whether third-party trackers still fire.

Run a free GPC check