Practical testing guide

How to test Global Privacy Control (GPC) response

Test GPC by comparing equivalent fresh browser sessions with and without the signal. Verify that the signal reached the loaded page, then compare requests, storage, and consent behavior. A configured browser flag or a completed scan alone does not establish that a site honored GPC.

By CertScore.ai · Updated

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan

1. Define a comparable test

Record the exact HTTPS page, UTC time, browser version, region, and observation window. Use fresh sessions with the same conditions; do not compare a previously accepted visitor with a new visitor. Keep Accept and Reject experiments separate from the passive GPC comparison.

A public-page observation covers the page and window tested. It does not establish account-wide preferences, downstream data use, or behavior in every jurisdiction.

2. Verify delivery before judging response

In the GPC-enabled session, inspect the actual main-document request for Sec-GPC: 1 and verify navigator.globalPrivacyControl in the loaded document. Retain the request and document identity. Merely configuring injection is weaker than observing delivery.

If the document navigates, a worker fails, or delivery cannot be verified, record the limitation. Do not treat a blocked request as if it contained a transmitted header.

Primary sources:Global Privacy Control specification

3. Compare behavior, not just cookie totals

Compare exact cookie identities, storage keys, classified vendor requests, advertising or measurement activity, and relevant CMP state. Preserve the baseline and GPC observations so another reviewer can reproduce the comparison.

An unrelated timestamp, random identifier, or CMP storage change is not enough to show a privacy response. Different totals can also reflect incomplete captures, auctions, or page variation.

4. Interpret the three possible outcomes

GPC response: verified, comparable evidence supports an observable response. This describes behavior; it is not a legal compliance determination.

No observable GPC response: the comparable retained evidence did not show a response within the tested scope. This is not proof of every downstream use of data.

Indeterminate: signal delivery, comparability, or coverage was insufficient. Missing proof must not become a finding that the site ignored the signal.

5. Hand the result to the right owner

For delivery failures, ask the browser or test owner to resolve the measurement problem. For a comparable no-response result, ask the CMP and tag owners to inspect opt-out mappings, vendor configuration, and regional rules. Preserve the original evidence before making changes.

Use the CCPA review guide for legal context, and the annotated historical report to see why contract version matters when reading older GPC records.

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan
CertScore.ai automated findings may contain errors. Always review the underlying evidence. CertScore.ai does not provide legal advice, certification, or compliance determinations.