Opt-out Preference Signal: Browser Functionality
Reference only: This requirement is not currently tested by the Privisy scanner. It is included for reference. Consult a qualified attorney to assess your compliance posture.
What it requires
Added to the CCPA by AB 566, the California Opt Me Out Act, signed October 8, 2025 and operative January 1, 2027. A business that develops or maintains a browser must include functionality — configurable by the consumer and easy for a reasonable person to locate and configure — that sends an opt-out preference signal, and must publicly disclose how that signal works and what it is intended to do. The duty runs against browser developers only: it does not change a business’s own obligation to honor an opt-out preference signal it receives, which comes from § 1798.135 and 11 CCR § 7025 and has been in force since 2023. AB 566 is the successor to AB 3048, the 2024 browser-signal bill the Governor vetoed on September 20, 2024; AB 3048 never became law.
Legal text (excerpt)
A business shall not develop or maintain a browser that does not include functionality configurable by a consumer that enables the browser to send an opt-out preference signal to businesses with which the consumer interacts through the browser. [...] The functionality required by paragraph (1) shall be easy for a reasonable person to locate and configure.
Primary source
California Privacy Protection Agency (CalPrivacy): § 1798.136: Opt-out Preference Signal: Browser Functionality ↗Legal notice: This page is for informational purposes only and does not constitute legal advice. The legal text excerpt is reproduced from official public sources and is current as of the stated effective date. Laws change: verify against the authoritative source and consult a licensed attorney for compliance guidance.