GPC and Do-Not-Track explained: the privacy signals your browser can send
Global Privacy Control and Do-Not-Track are browser signals that tell websites you do not want to be tracked or have your data sold. Here is what they actually do — and what they do not.
What GPC and DNT are
Global Privacy Control (GPC) is a browser signal that communicates your preference not to have personal data sold or shared. It is a legally recognized signal in some jurisdictions, including under the CCPA in California and the GDPR in the European Union.
Do-Not-Track (DNT) is an older, simpler signal that requests websites not to track your browsing. Unlike GPC, DNT has no legal backing and most websites ignore it entirely.
What they actually do
GPC is designed to trigger legal obligations. In regions with strong privacy laws, websites that receive a GPC signal are required to honor it — meaning they must not sell or share your personal data.
DNT is a request, not a requirement. Most websites and advertisers do not honor it, and there is no enforcement mechanism. Some browsers have stopped supporting DNT because it created a false sense of privacy.
- GPC: legally enforceable in some regions, supported by major browsers
- DNT: voluntary request, largely ignored by websites
- Both signals are sent automatically by your browser — no extension needed
How to turn them on
Firefox sends GPC by default in standard mode. Brave and some other privacy-focused browsers also support it. You can check whether your browser sends GPC by visiting a testing site or checking your browser's privacy settings.
DNT can be enabled in most browsers through the privacy settings, but given its limited effectiveness, enabling GPC is the more meaningful step. The most effective privacy protection remains blocking trackers directly with a content blocker.