How to test Global Privacy Control (GPC) response
Test GPC by comparing equivalent fresh browser sessions with and without the signal. Verify that the signal reached the loaded page, then compare requests, storage, and consent behavior. A configured browser flag or a completed scan alone does not establish that a site honored GPC.
By CertScore.ai · Updated
Run a free website behavior scan
Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.
1. Define a comparable test
Record the exact HTTPS page, UTC time, browser version, region, and observation window. Use fresh sessions with the same conditions; do not compare a previously accepted visitor with a new visitor. Keep Accept and Reject experiments separate from the passive GPC comparison.
A public-page observation covers the page and window tested. It does not establish account-wide preferences, downstream data use, or behavior in every jurisdiction.
2. Verify delivery before judging response
In the GPC-enabled session, inspect the actual main-document request for Sec-GPC: 1 and verify navigator.globalPrivacyControl in the loaded document. Retain the request and document identity. Merely configuring injection is weaker than observing delivery.
If the document navigates, a worker fails, or delivery cannot be verified, record the limitation. Do not treat a blocked request as if it contained a transmitted header.
Primary sources:Global Privacy Control specification
3. Compare behavior, not just cookie totals
Compare exact cookie identities, storage keys, classified vendor requests, advertising or measurement activity, and relevant CMP state. Preserve the baseline and GPC observations so another reviewer can reproduce the comparison.
An unrelated timestamp, random identifier, or CMP storage change is not enough to show a privacy response. Different totals can also reflect incomplete captures, auctions, or page variation.
4. Interpret the three possible outcomes
GPC response: verified, comparable evidence supports an observable response. This describes behavior; it is not a legal compliance determination.
No observable GPC response: the comparable retained evidence did not show a response within the tested scope. This is not proof of every downstream use of data.
Indeterminate: signal delivery, comparability, or coverage was insufficient. Missing proof must not become a finding that the site ignored the signal.
5. Hand the result to the right owner
For delivery failures, ask the browser or test owner to resolve the measurement problem. For a comparable no-response result, ask the CMP and tag owners to inspect opt-out mappings, vendor configuration, and regional rules. Preserve the original evidence before making changes.
Use the CCPA review guide for legal context, and the annotated historical report to see why contract version matters when reading older GPC records.
Related CertScore.ai pages
Run a free website behavior scan
Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.
