Wyden’s core request is straightforward. He asks the recipients to issue clear public guidance directing businesses to recognize and honor GPC signals from their residents regardless of the user’s temporary physical location or IP address, and to form a bipartisan multistate task force focused on joint enforcement of universal opt-out requirements.
How GPC Works and Why States Have Recognized It
Global Privacy Control is a technical mechanism that allows a user’s browser or extension to automatically transmit an opt-out preference to websites the user visits. The signal indicates that the individual does not want their personal information sold or shared. It functions as a universal opt-out mechanism, relieving consumers of the need to locate and complete separate opt-out forms on every site.
At least fifteen states now permit consumers to exercise sale-or-sharing opt-out rights through universal mechanisms such as GPC. Several state regulators—including California, Colorado, Connecticut, Oregon, and New Jersey—have publicly identified GPC as a valid method. California and Colorado have issued detailed regulations governing how businesses must process these signals. California further requires businesses to display whether a GPC signal has been honored, for example through an “Opt-Out Request Honored” indicator.
Enforcement has already produced notable settlements. California has resolved cases against Sephora, Healthline, and Disney that included failures to process GPC signals properly, resulting in multimillion-dollar penalties and mandated compliance programs. In September 2025, California, Colorado, and Connecticut launched a joint investigative sweep targeting businesses that appeared not to honor GPC requests.
The Core Problem: Selective Honoring Based on GeoIP Data
Despite these legal requirements, many companies configure their systems—or rely on consent management platforms—to honor GPC signals only when commercial GeoIP databases indicate the user’s IP address is located in a state that mandates compliance. Wyden argues this practice systematically undermines the rights the state laws were designed to create.
GeoIP databases are widely acknowledged to be inaccurate. Even when the location data is correct, a user’s temporary physical presence in another state does not change their legal residency or extinguish rights granted by their home state’s privacy statute. College students studying out of state, business travelers, interstate commuters, and military personnel stationed or deployed away from their home states all retain their statutory protections. Relying solely on IP-derived location data effectively strips these individuals of rights they are entitled to exercise.
The same filtering also disadvantages privacy-conscious users who employ virtual private networks. Because a VPN routes traffic through a server that may be located in a different jurisdiction, the IP address visible to websites often does not reflect the user’s actual residence. Consumers who take extra steps to protect their privacy online are therefore more likely to have their GPC signals ignored—the opposite of the outcome privacy laws intend.
Wyden notes that California Privacy Protection Agency staff have confirmed to his office that California residents retain their CCPA/CPRA rights, including the right to opt out via GPC, regardless of physical location. California regulations also prohibit businesses from requiring identity verification for opt-out requests, increasing the compliance risk of any system that silently discards signals based on geolocation guesses.
Dark Patterns in Status Disclosure
The letter further criticizes the way many sites handle transparency around GPC processing. California rules require businesses to indicate whether an opt-out preference signal has been processed as a valid request. In practice, some companies display an “honored” badge only when they accept the signal and remain silent when they reject it. Users therefore have no affirmative notice that their preference was disregarded. Wyden describes this asymmetric disclosure as a dark pattern that leaves consumers unaware their rights have been violated.
Consent Management Platforms and Emerging Technical Fixes
Wyden’s office has engaged directly with major consent management platforms that many websites rely on to handle privacy signals. The letter reports mixed but improving practices:
- Osano, Usercentrics, and Transcend already honor GPC signals from all users regardless of IP address. Transcend additionally agreed to develop an optional feature that automatically treats traffic from U.S. government and military IP ranges as high-sensitivity and applies stronger privacy defaults.
- OneTrust committed to providing a clear visual notification when a GPC signal is rejected and, when it suspects a user is out-of-state, to prompt the user to affirm residency rather than silently discarding the signal.
- Ketch, which currently honors GPC by default for IP addresses associated with required states, agreed to roll out default-enabled features that display a visual indicator when a signal is disregarded and allow users to correct an inferred location or manually assert their state of residency.
- TrustArc agreed to update default configurations for clients operating in GPC-enforcing states or using a nationwide banner so that GPC is properly set up and honored. It also committed to treating U.S. government and military IP traffic as if it originated in California and to develop optional tools for residency self-certification and status indicators.
These technical commitments, Wyden argues, demonstrate that commercially reasonable alternatives to pure GeoIP filtering already exist. Platforms that can prompt users to self-certify residency or display clear status indicators undermine any claim that more accurate handling of GPC signals is technically or commercially infeasible.
Call for Clear Guidance and Coordinated Enforcement
The senator urges the addressed attorneys general and the CPPA to issue public guidance making three points explicit:
- Businesses are expected to respect GPC signals sent by residents of the relevant state regardless of the user’s current physical location or the IP address observed.
- Selectively ignoring GPC signals based solely on IP geolocation is impermissible unless the business clearly notifies the user and provides a simple, frictionless method for the individual to self-certify true residency.
- VPN use does not extinguish a resident’s opt-out rights.
He further recommends formation of a bipartisan, multistate Attorney General task force dedicated to joint investigation and enforcement of GPC compliance. Coordinated investigative demands and compliance notices, he contends, would make clear that geographic filtering is an enforcement priority rather than a permissible workaround.
Wyden’s Remarks on Privacy
State privacy laws generally condition the obligation to honor universal opt-out signals on the business’s ability to determine, through commercially reasonable efforts, that the signal comes from a resident of the state. Some statutes explicitly reference the use of IP addresses as one possible method; others are silent or focus on the UOOM technology’s ability to support accurate determination of residency. California’s framework is comparatively silent on residency verification for opt-outs and prohibits identity verification requirements for those requests.
Edge cases—travelers, military personnel, students, VPN users, and individuals whose wireless carriers issue IP addresses across state lines—have not yet featured prominently in published enforcement actions. Existing settlements have largely turned on whether companies processed investigators’ GPC signals at all. As enforcement matures, however, reliance on inaccurate or incomplete location data is likely to attract greater scrutiny, particularly when simple self-certification or status-notification tools are readily available.
For businesses and the consent management platforms that serve them, the practical takeaway is that silent, GeoIP-only filtering of GPC signals carries increasing legal and reputational risk. Implementing clear user notification when a signal is not honored, offering an easy residency affirmation mechanism, and treating government and military traffic with elevated privacy defaults are emerging as baseline expectations among platforms that have engaged with congressional oversight.
Wyden closes by offering staff contacts for further discussion and reiterating that the goal is partnership with state enforcers to ensure the privacy rights already written into state law are actually delivered to the residents those laws were enacted to protect. The letter arrives as the Consortium of Privacy Regulators continues to expand, with the Vermont Attorney General’s Office recently joining the group—another signal that state-level coordination on privacy enforcement is deepening.
Organizations that operate websites or digital services reaching residents of GPC-recognizing states should review how their systems and vendors currently handle opt-out preference signals. Mapping the decision logic that determines whether a GPC signal is accepted or discarded, documenting the accuracy limitations of any geolocation tools in use, and testing the user experience when a signal is rejected will help identify gaps before they become the subject of investigative demands or public guidance from state regulators.