Sec-GPC Header
The Sec-GPC header is a small piece of information sent by a web browser or extension with a user's web requests to tell a website that the user does not want their personal information sold or shared. It is one part of the broader Global Privacy Control (GPC) mechanism, which is designed to let people express a privacy preference automatically rather than site by site. Whether a website is legally required to honor this signal depends on the applicable law and jurisdiction.
The Sec-GPC header field is an HTTP request header that forms part of the Global Privacy Control (GPC) mechanism for expressing a person's general, universal preference regarding a do-not-sell-or-share interaction. When enabled at the browser or extension level, the header communicates the user's opt-out preference to servers as part of outgoing HTTP requests, allowing the preference to be signaled without per-site interaction. GPC is described in the referenced sources as a proposed specification and set of web technologies; the legal effect of receiving the Sec-GPC signal is not established by the header itself but by applicable privacy regimes. Notably, several US state privacy frameworks operate on an opt-out model under which such signals may be relevant, whereas the technical presence of the header does not, on its own, determine obligations under any particular jurisdiction. This definition covers the header as a signaling mechanism; the specific enforcement obligations, the scope of covered businesses, and the required server-side response are governed by law and applicable regulatory guidance not detailed in the evidence provided.
Why it matters
The Sec-GPC header addresses a practical problem in privacy compliance: without an automated mechanism, users would need to express their preferences site by site, which is impractical across the number of websites a person visits. As part of the broader Global Privacy Control mechanism, the header allows a do-not-sell-or-share preference to travel with a user's web requests, so that a single browser or extension setting can communicate that preference to many sites at once. For businesses, this shifts part of the compliance burden from asking users repeatedly to detecting and responding to a signal already present in incoming requests.
The legal significance of the signal varies by jurisdiction, and this distinction is central to understanding its relevance. Several US state privacy frameworks operate on an opt-out model under which a signal such as GPC may be relevant to a business's obligations, but the presence of the Sec-GPC header does not, on its own, determine what any particular law requires. Whether a business must honor the signal, which businesses are covered, and what the required server-side response looks like are questions governed by applicable law and regulatory guidance rather than by the header itself. Organizations should treat detection of the signal as one input into a compliance program, not as a self-contained legal answer.
Because GPC is described in its underlying sources as a proposed specification and a set of web technologies, its technical form and its adoption continue to evolve. Teams evaluating how to respond to the Sec-GPC header should confirm the obligations that apply in each jurisdiction where they operate, since enforcement positions and guidance can differ and may change over time. Relying solely on the technical presence or absence of the header to assess legal exposure risks conflating a signaling mechanism with a legal determination.
Who it's relevant to
Inside Sec-GPC Header
Common questions
Answers to the questions practitioners most commonly ask about Sec-GPC Header.

