Do Not Track
Do Not Track (DNT) is a browser setting that, when enabled by a user, sends a signal to the websites they visit expressing a preference not to be tracked across their web browsing. Because it communicates only a request, websites and advertising companies have generally not been required to honor it, and support for the feature has declined over time.
Do Not Track (DNT) is a non-standard HTTP header field, typically transmitted as 'DNT: 1', through which a browser communicates a user's expressed preference to opt out of tracking by websites and third-party services. It functions as a unilateral signal rather than an enforcement mechanism: the standard was never finalized and is now widely regarded as deprecated, so recipients are generally under no technical obligation to act on it. Whether a site must respond to DNT depends on the applicable legal regime and any voluntary commitments a site makes; DNT should be distinguished from later opt-out signals such as Global Privacy Control, which some US state privacy frameworks may treat as a legally recognized opt-out request. The scope of any legal effect is jurisdiction-dependent and not addressed by this definition.
Why it matters
Do Not Track represents an early attempt to give users a simple, browser-level way to express a preference against being tracked across the web. For privacy and compliance teams, understanding DNT matters because it illustrates a recurring challenge in the industry: a technical signal can communicate a user's wishes, but it carries weight only if recipients are willing or legally obligated to honor it. Because DNT was a unilateral request rather than an enforcement mechanism, websites and advertising companies have generally not been required to act on it, and support for the standard has declined over time. The standard was never finalized and is now widely regarded as deprecated.
The practical significance of DNT today lies largely in what it teaches about its successors. Compliance professionals should not assume that the presence of a DNT header creates any obligation on its own; whether a site must respond depends on the applicable legal regime and any voluntary commitments the site has made. This is an important distinction to draw when advising on how automated browser signals fit into a consent strategy, because treating DNT as a binding opt-out could create a false sense of compliance.
DNT should be carefully distinguished from later opt-out signals such as Global Privacy Control, which some US state privacy frameworks may treat as a legally recognized opt-out request. Whether any particular signal carries legal effect is jurisdiction-dependent, and enforcement positions continue to evolve. Teams operating across the EU, the UK, and individual US states should evaluate each signal against the specific requirements of the relevant regime rather than assume a uniform treatment.
Who it's relevant to
Inside DNT
Common questions
Answers to the questions practitioners most commonly ask about DNT.

