California is changing how consumers can communicate their privacy choices online. Beginning January 1, 2027, web browsers operating in California will be required to give users an easy way to send an opt-out preference signal.
For businesses, this is worth paying attention to before the requirement takes effect. Browser-based privacy signals already exist, and California already requires certain businesses to recognize them. Making the option easier to access could mean more website visitors begin using them.
For companies using cookie consent platforms, Google Tag Manager, GA4 and advertising tags, now is a good time to understand how those systems respond when a visitor arrives with a privacy preference already enabled.
What is an opt-out preference signal?
An opt-out preference signal allows someone to communicate a privacy choice through their browser or other software instead of making the same choice individually on every website.
Global Privacy Control, or GPC, is one example. When GPC is enabled, the browser sends a signal that communicates the user’s privacy preference to the websites they visit.
Under the California Consumer Privacy Act, businesses subject to the applicable requirements must process GPC as a valid request to opt out of the sale or sharing of personal information.
GPC itself isn’t new. What changes in 2027 is its accessibility. California’s Opt Me Out Act will require browsers operating in the state to provide an easy-to-use setting that allows consumers to send an opt-out preference signal.
That could make these signals much more common than they are today.
How this affects your website
Most business websites have quite a bit happening in the background. GA4 may be measuring website activity while Google Tag Manager manages conversion tracking and advertising tags. A company might also use Meta, LinkedIn, Microsoft Advertising, HubSpot, heatmapping software, chat tools, and other third-party technology.
A consent management platform may sit in the middle of all of this, controlling what can happen based on the visitor’s privacy choices.
Browser privacy signals add another consideration. When an applicable signal is detected, the website’s consent and tracking systems need to respond according to the rules the business has established.
This can get complicated quickly, especially on websites where tracking has been added or changed over several years.
The cookie banner is only part of the setup
Seeing a cookie banner load doesn’t tell you much about what the website is actually doing.
A consent platform could correctly recognize an opt-out while a marketing tag inside Google Tag Manager continues to behave differently than expected. A script added directly to the website might not be connected to the consent platform at all. Regional settings can also affect how visitors in different locations experience the site.
There can be measurement problems in the other direction as well. An overly restrictive configuration can prevent analytics or conversion tracking from working when it should.
This is why testing the implementation matters. You need to look at the consent platform and the technology connected to it.
California is already paying attention to opt-outs
Businesses don’t have to wait until 2027 to think about browser privacy signals.
California already requires businesses subject to the applicable CCPA requirements to recognize GPC for sale and sharing opt-outs. In 2025, regulators in California, Colorado and Connecticut also announced a coordinated investigative sweep focused on businesses that may not have properly honored consumers’ opt-out requests.
The new California browser requirement could increase how often businesses encounter these signals simply because the controls will be easier for consumers to find and use.
What can businesses check now?
Start with your existing consent setup.
If you use a consent management platform, check whether it recognizes GPC and how the website responds when the signal is present. Then look at the systems connected to it, including Google Tag Manager, GA4 and any advertising or marketing tags running on the site.
It’s also useful to test the website under several different conditions. See what happens before a visitor makes a consent choice, after accepting, after rejecting, after changing preferences and while GPC is enabled.
During those tests, look at more than cookies. Check which GTM tags fire, which third-party requests are made, what consent states are passed to Google and whether advertising platforms behave as expected.
You may also need to test different geographic regions if your consent platform uses regional rules.
Don’t forget about tags added outside GTM
This is an easy one to miss.
Companies often have a well-organized Google Tag Manager container but still have tracking scripts installed directly on the website. A developer may have added a script years ago. A WordPress plugin might inject one automatically. A marketing platform could have been installed through a CMS integration.
Those scripts may not follow the same consent controls as tags managed through GTM.
A consent review should account for the website itself, not just what’s visible inside the tag manager.
Consent and marketing measurement are becoming more connected
For marketing teams, consent is increasingly part of the normal tracking conversation.
A change to a consent platform can affect GA4 traffic. A GTM configuration issue can affect Google Ads conversions. A new marketing tag can change what happens before or after a visitor makes a privacy choice.
This is especially important when different people manage different parts of the setup. Marketing may own GA4 and advertising. A developer may manage the website. Another team may manage the consent platform. An outside agency may have access to GTM.
Over time, it’s easy for those pieces to stop lining up.
Use 2026 to find the gaps
California’s new browser requirement takes effect January 1, 2027. Businesses have time to understand their current setup and address problems before then.
For companies with a consent platform, GTM, GA4 and several advertising or marketing integrations, a technical review can help identify issues that aren’t obvious from looking at the website.
Sometimes the problem is a complicated consent configuration. Sometimes it’s one old tag nobody realized was still running.
Finding it now is a lot easier than trying to sort it out later.
Need a closer look at your consent setup?
Steel Sparrow reviews the technical side of website consent, including consent platforms, Google Tag Manager, Google Consent Mode, GA4, and advertising tags.
We test how the website behaves under different consent conditions, document our findings, and identify areas that need attention.
This article provides general information about website technology and privacy developments. It is not legal advice. Consult qualified privacy counsel to determine which privacy laws apply to your business and what they require.
This article provides general information about website technology and privacy developments. It is not legal advice. Consult qualified privacy counsel to determine which privacy laws apply to your business and what they require.
