Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Tracking Technologies

W3C Tracking Preference Expression

Also known as: DNT, Tracking Preference Expression (DNT), Do Not Track, DNT header
Simply put

The W3C Tracking Preference Expression is a technical specification, developed by the World Wide Web Consortium, that defines how a user's browser can signal a preference not to be tracked across websites. In practice, this is usually done through a "Do Not Track" (DNT) signal sent by the browser. The specification was designed so that the signal is transmitted only when it reflects a deliberate choice by the user.

Formal definition

The W3C Tracking Preference Expression is a Working Draft specification from the World Wide Web Consortium that defines technical mechanisms for expressing a user's cross-site tracking preference, principally via the DNT request header field in HTTP, and, as noted in later drafts, via mechanisms such as an HTML DOM property. The specification's stated basic principle is that a tracking preference expression is transmitted only when it reflects a deliberate choice by the user, distinguishing an explicit preference from a default state. It should be understood as a signaling and expression mechanism rather than a consent management framework: it standardizes how a preference is communicated, while questions of what receiving parties must do in response were addressed separately (for example in companion work on tracking compliance and scope) and were the subject of ongoing working-group discussion, including a Patent Advisory Group. Practitioners should note this is a technical standard and does not by itself establish legal obligations; whether and how a DNT or similar signal must be honored depends on the applicable legal regime, which is outside the scope of this specification.

Why it matters

The W3C Tracking Preference Expression matters because it represented an early, standards-based attempt to give users a simple, machine-readable way to communicate a preference not to be tracked across websites. Rather than requiring users to configure settings site by site, the specification aimed to let a browser transmit a single signal, principally through the DNT request header field in HTTP, that any receiving party could read. For privacy officers and web developers, it is a foundational reference point in the broader conversation about how user preferences can be expressed technically rather than only through on-page consent interfaces.

A central design commitment of the specification is that a tracking preference is transmitted only when it reflects a deliberate choice by the user, distinguishing an explicit preference from a default state. This principle is significant because it addresses a recurring compliance concern: a signal that is on by default, or that does not represent a genuine user decision, is of limited value as evidence of what the user actually wanted. Practitioners evaluating any preference signal should keep this distinction in mind when considering whether a signal can be treated as meaningful.

Equally important is what the specification does not do. It is a signaling and expression mechanism, not a consent management framework, and it does not by itself establish legal obligations. The specification standardizes how a preference is communicated; the separate question of what receiving parties must do in response was addressed in companion work on tracking compliance and scope and remained the subject of ongoing working-group discussion, including a Patent Advisory Group. Whether and how a DNT or similar signal must be honored depends on the applicable legal regime, which is outside the scope of the specification itself. Readers should therefore treat DNT as a technical standard whose real-world effect has depended heavily on voluntary adoption and on external legal requirements rather than on the standard alone.

Who it's relevant to

Privacy and data protection officers
Privacy officers may encounter DNT as an early example of a standardized user preference signal and should understand both its intent and its limits. The specification's principle that a preference is transmitted only when it reflects a deliberate choice is useful when assessing whether any signal can be treated as a genuine expression of user intent. However, because the specification does not itself establish legal obligations, whether a DNT or similar signal must be honored depends on the applicable legal regime, which is outside the standard's scope.
Web developers and engineers
Developers benefit from understanding the technical mechanisms the specification defines, principally the DNT request header field in HTTP and, in later drafts, mechanisms such as an HTML DOM property. This context helps when reading incoming request headers, interpreting whether a preference has been expressed, and appreciating that the standard defines how a preference is communicated rather than what a receiving party must do in response.
Legal counsel and compliance teams
Legal and compliance professionals should note that DNT is a technical standard, not a consent management framework, and does not by itself create legal duties. The separate question of what receiving parties must do was addressed in companion work on tracking compliance and scope and remained subject to working-group discussion, including a Patent Advisory Group. Counsel should therefore assess any obligation to honor such signals against the specific legal regime that applies, rather than relying on the specification alone.
Standards and industry participants
Those following web standards work will recognize the Tracking Preference Expression as a W3C Working Draft whose development involved ongoing discussion, including issues studied by a chartered Patent Advisory Group. This audience is well placed to understand the specification's status as a signaling mechanism and the distinction between expressing a preference and defining compliance obligations.

Inside DNT

Do Not Track (DNT) header
The core mechanism of the specification, expressed as an HTTP header field (DNT) that a user's browser sends with requests to signal a user's tracking preference. A value of 1 generally indicated a preference not to be tracked, 0 indicated consent to tracking, and the absence of the header meant no preference had been expressed.
Tracking preference values
The defined set of signals (typically 1, 0, or unset) intended to communicate a user's stated preference regarding cross-site tracking to servers and third parties. The specification did not itself define enforcement; it described how the preference was to be represented and transmitted.
Server response mechanisms
Elements allowing a server to communicate its compliance status back to the user agent, for example via a tracking status resource or response header indicating how the site intended to honor the expressed preference. This was designed to make a site's handling of the signal discoverable.
Site-specific and web-wide exceptions
A framework by which a user could grant exceptions permitting tracking by particular parties or across the web, intended to allow more granular preferences beyond a single global signal.
Standardization context (W3C)
The specification was developed within the World Wide Web Consortium's Tracking Protection Working Group as a proposed technical standard. Its status as a widely adopted or legally binding mechanism was limited, and it did not by itself impose compliance obligations on websites.

Common questions

Answers to the questions practitioners most commonly ask about DNT.

Does implementing the W3C Tracking Preference Expression (the Do Not Track standard) satisfy cookie consent obligations under EU law?
No. The Tracking Preference Expression (TPE), commonly known through the Do Not Track (DNT) header, is a technical specification for expressing a user's tracking preference; it is not a consent mechanism recognised by the ePrivacy Directive or the GDPR. In most EU jurisdictions, placing or accessing non-essential cookies and processing the resulting personal data generally require prior, freely given, specific, informed, and unambiguous consent obtained through a clear affirmative action. A DNT signal does not, on its own, provide that. Organisations relying on TPE alone would typically still need a separate, compliant consent mechanism. Whether and how such signals should be honoured can also depend on national implementations and evolving regulatory guidance, which are outside the scope of this entry.
Is the W3C Tracking Preference Expression the same thing as Global Privacy Control (GPC)?
They are related in purpose but distinct. TPE (the DNT standard) is an earlier W3C effort to standardise how browsers communicate a user's tracking preference, and its recommendation-track work was ultimately discontinued without becoming a widely enforced standard. Global Privacy Control is a separate, more recent signal that has gained particular relevance in the context of certain US state privacy laws, where opt-out signals may be given legal effect. Conflating the two can lead to incorrect assumptions about legal recognition. The specific status of GPC and any obligation to honour it depend on the applicable jurisdiction and current guidance, and a full treatment of GPC falls outside this entry.
How does a web server detect a Tracking Preference Expression signal from a browser?
The TPE specification defines a mechanism whereby a user agent can transmit a tracking preference to a server, historically expressed through an HTTP request header. A server-side application can read that header value to determine the expressed preference. In practice, browser support for sending the signal has been inconsistent and, in some cases, removed or deprecated, so relying on its presence is not dependable. Detecting the signal is a technical step only and does not by itself establish or replace a legally valid consent record. How you should respond to a detected signal is a legal question that varies by jurisdiction.
Should our consent management platform (CMP) treat a DNT signal as an opt-out?
Whether a CMP is configured to interpret a DNT-style signal as an opt-out is a policy and legal decision rather than a purely technical one. Some organisations choose to honour such signals as part of a broader privacy posture, but the TPE signal does not carry the legal recognition that certain other opt-out signals may have in specific frameworks. In most EU jurisdictions, opt-in consent for non-essential cookies is generally required regardless of any DNT signal, so a signal indicating no objection would not substitute for affirmative consent. Configuration choices should be reviewed against the requirements of each jurisdiction you operate in and documented, but the tool does not replace legal judgement on how the signal is treated.
If a browser sends no Tracking Preference Expression signal, can we infer that tracking is permitted?
No. The absence of a TPE or DNT signal should not be read as consent. Valid consent in most EU jurisdictions requires a clear affirmative action, and silence, inactivity, or the absence of a preference signal does not meet that standard. Implied consent from continued browsing is widely regarded as non-compliant in the EU. Under opt-out frameworks in some US states, the analysis differs, but even there the absence of a signal does not automatically establish a compliant basis for all processing. Treat a missing signal as no expressed preference, not as permission, and rely on your separate consent or opt-out mechanism as required by the applicable regime.
Do we still need to maintain consent logs if we detect and act on Tracking Preference Expression signals?
Generally yes, where consent or opt-out record-keeping obligations apply. Detecting a TPE signal is not a substitute for the consent logging and record-keeping practices expected under frameworks such as the GDPR, where being able to demonstrate that valid consent was obtained is typically important. If you honour a signal, you may also wish to record how and when it was received and actioned. The specifics of what must be logged, for how long, and in what form depend on the applicable jurisdiction and on facts not covered by this entry, so the retention and documentation approach should be determined with reference to current guidance and legal advice.

Common misconceptions

Sending a Do Not Track signal legally required websites to stop tracking users.
The Tracking Preference Expression specification defined only how a preference is expressed and transmitted; it did not compel any server to honor it. Whether honoring such a signal is required depends on separate legal regimes rather than on the technical standard itself, and honoring DNT was generally voluntary in practice.
A DNT signal is equivalent to, or satisfies, valid consent under EU law.
DNT expresses a preference not to be tracked, which is conceptually different from the affirmative opt-in consent that is generally required under the ePrivacy Directive and GDPR for non-essential cookies and similar technologies. The technical signal does not, on its own, establish consent that is freely given, specific, informed, and unambiguous, and it does not replace the separate obligations governing the placing of and access to information on a device versus the processing of personal data that follows.
The W3C Tracking Preference Expression is the same as newer opt-out signals like Global Privacy Control.
They are distinct mechanisms developed in different contexts. Global Privacy Control is a separate signal that has been referenced in connection with certain US state privacy frameworks that rely on opt-out, whereas the W3C DNT specification is an earlier, broader proposal whose legal recognition and adoption were limited. Practitioners should not treat one as interchangeable with the other.

Best practices

Treat an incoming DNT signal as a user-expressed preference to document and consider, but do not assume it alone satisfies or replaces the specific consent or opt-out obligations that may apply under the relevant EU, UK, or US state frameworks.
Determine the geographic and legal scope of your users before deciding how to respond to a DNT signal, since obligations differ between opt-in regimes (such as those under the ePrivacy Directive and GDPR in the EU) and opt-out oriented regimes (such as certain US state laws).
Do not rely on DNT as your primary consent mechanism for non-essential cookies, pixels, SDKs, local storage, or fingerprinting in EU jurisdictions, where prior affirmative consent is generally required; use a properly configured consent management platform for those purposes instead.
If your servers respond to DNT, clearly document and, where appropriate, publish your tracking status so that your handling of the signal is transparent and consistent with what you tell users.
Distinguish DNT from newer opt-out signals such as Global Privacy Control in your internal documentation, and configure your systems to handle each according to its own applicable requirements rather than treating them as interchangeable.
Seek legal review when interpreting how DNT signals interact with your obligations, since the standard's limited adoption and the evolving positions of data protection authorities mean technical handling alone does not determine compliance.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.