For Windows users and IT teams, the immediate change is not a new Edge setting or an enforceable new technical specification. California Assembly Bill 566 already requires businesses that develop or maintain browsers to provide a consumer-configurable opt-out preference signal that is easy for a reasonable person to find and configure. What CalPrivacy’s reported vote opens is the regulatory process that can decide how the agency interprets and administers that mandate.
The important finding is that the agency’s public rulemaking pages had not yet caught up as of August 8. CalPrivacy still described opt-out preference signals as a preliminary rulemaking topic, with no proposed regulation package listed, while its public motions summary did not yet show an August 7 action. That does not disprove MLex’s account of the board vote; agency sites and meeting records often lag a meeting. But it does mean the public still lacks the documents that will determine what browser makers actually have to ship and how much discretion they retain.
AB 566 requires a function, not a named protocol
The law does not say “Chrome, Edge, Firefox, and every other browser must implement Global Privacy Control by name.” It defines an opt-out preference signal functionally: it must communicate a consumer’s choice to opt out of the sale and sharing of personal information. A “browser” is broadly defined as interactive software consumers use to locate, access, and navigate websites.
That wording matters. GPC is the obvious implementation because it already exists, is recognized under California’s CCPA rules, and is supported by privacy-oriented browsers and extensions. But the statute leaves technical room for browser companies to implement a compatible signal in their own way, provided the result qualifies under California privacy law.
CalPrivacy itself has used GPC as the central example. The California Attorney General’s office says a user-enabled global privacy control is a valid method for online consumers to opt out, and that covered businesses must honor it. CalPrivacy’s own consumer guidance says users can look for “Global Privacy Control” or “GPC” in browser privacy settings or extension stores.
The regulations therefore matter less as a mandate to invent a new browser feature than as a decision about interoperability. A poor rule could allow nominal compliance through a hard-to-find control or a signal that downstream advertising systems cannot consistently recognize. A strong rule could establish disclosure, usability, and compatibility expectations that make the existing GPC approach far harder to evade.
The published statute provides two concrete obligations for browser developers:
- Browsers must include a consumer-configurable function that sends an opt-out preference signal to businesses a user interacts with through that browser.
- Browser developers must publicly explain how the signal works and what effect it is intended to have.
The law also gives a browser business immunity from liability for another business’s CCPA violation after receiving the signal. That is a consequential allocation of responsibility: Microsoft, Google, Mozilla, Apple, Brave, and other browser providers must provide the control, but the website or advertising recipient remains responsible for processing the request lawfully.
The January 1, 2027 deadline does not wait for a polished rulebook
AB 566 becomes operative on January 1, 2027. That date is statutory, not something CalPrivacy can casually move by publishing regulations later. The agency has authority to adopt rules necessary to implement and administer the requirement, but the browser obligation is already on the books.
This creates a compressed timeline. California’s regular Administrative Procedure Act process formally begins when the agency publishes a Notice of Proposed Action in the California Regulatory Notice Register, posts the notice and proposed text, and provides its initial statement of reasons. The public comment period must run for at least 45 days. If the proposal changes after comments, a further 15-day comment period is typical for related modifications; a substantially different proposal can require a fresh 45-day notice.
In other words, a board vote to start the process is an important threshold, but it is not the same thing as a final regulation. Until CalPrivacy publishes a notice, express regulatory text, and an explanation of its rationale, neither browser vendors nor enterprise web teams can assess the agency’s final technical and compliance expectations.
That distinction is not pedantic. The Opt Me Out Act is written in unusually broad product terms: it does not specify a header name, browser UI placement, default setting, mobile browser treatment, or how the function should behave when a user signs into a browser profile and syncs settings across devices. It also does not say whether a browser must apply the feature only for California users, offer it globally, or identify a user’s state at all.
A regulation could clarify some of those points. Or it could leave them to vendors. The latter outcome would make national rollout more likely, since maintaining a California-only privacy branch is expensive and potentially confusing, but it would also preserve wide variation in implementation.
The hard problem is enforcement after the browser sends the signal
California already requires covered businesses that sell or share personal information to honor qualifying opt-out preference signals. The missing consumer tool has been widespread browser availability. AB 566 attempts to close that gap by making a signal a browser feature instead of a privacy add-on for technically confident users.
But getting more users to send GPC-like signals will expose a second problem: many recipients appear not to honor them reliably.
The Markup reported in April that a WebXray audit of more than 7,000 popular sites tested from a California connection found widespread tracking despite GPC being enabled. The outlet reported that Google trackers continued operating in 86% of the tested instances, Microsoft in 50%, and Meta in 69%, according to the researchers’ methodology. Google and Microsoft disputed the characterization; Microsoft said certain cookies are needed for operations and Google said the audit misunderstood how its products work.
Those claims should not be read as final legal findings against each company. They do show why CalPrivacy’s next rules need to be about more than the browser toggle itself. A user can enable a signal perfectly and still see their choice fail in the handoff among the first-party site, a consent management platform, tag manager, analytics provider, ad exchange, and downstream advertising partners.
Academic work has pointed in the same direction. A 2025 USENIX Security study measuring GPC compliance across 11,708 sites found that only about a third of sites with evidence of selling or sharing personal information implemented at least one of the measured signals or privacy strings indicating a visitor’s opt-out status. That study measured implementation indicators rather than adjudicating each website’s legal status, but it reinforces the operational gap between a privacy request being sent and a privacy request being respected.
CalPrivacy has already demonstrated that GPC compliance is an enforcement issue, not merely an academic one. California’s 2022 Sephora settlement included allegations that the retailer failed to process user-enabled global privacy control signals. The state’s earlier rules also made clear that an online business receiving a qualifying signal must treat it as a request to opt out for that browser or device and associated pseudonymous profiles, and, if known, for the consumer.
The coming regulation update could therefore become a framework for reducing friction on both sides: the friction of locating and enabling a browser setting, and the more commercially contentious friction of making advertising and analytics systems stop sharing data after the setting is received.
What Edge, Chrome, Firefox, and enterprise admins should watch for
Microsoft Edge is directly within the law’s broad browser definition, as are Chrome, Firefox, Brave, Opera, and mobile browsers used in California. The law does not distinguish between retail users, managed Windows devices, personal machines, or bring-your-own-device deployments.
For vendors, the baseline job is clear: provide a discoverable, configurable control and explain its effect. The unresolved details will matter to product and compliance teams:
- CalPrivacy could define what “easy for a reasonable person to locate and configure” means, including whether a setting buried under several layers of menus would satisfy the law.
- The agency could align its expectations explicitly with the established GPC signal, avoiding a proliferation of California-specific implementations that sites and privacy-management tools would need to detect.
- It could address whether a browser must preserve a user’s choice across updates, profiles, or synchronized devices, though the statute itself does not expressly answer those questions.
- It could set expectations for how browser vendors describe the limitation that GPC is an opt-out request, not a universal block on every cookie, every form of measurement, or every kind of data collection.
For Windows administrators, the likely near-term task is inventory rather than deployment. Organizations that standardize on Edge or Chrome should determine whether their chosen browser build already exposes a usable GPC-compatible setting, whether the setting can be controlled by policy, and whether enabling it changes web application behavior that internal support desks will have to handle.
There is also a policy choice that many vendors will face before California’s deadline: restrict the setting to California, or offer it everywhere. The law is directed at browsers developed or maintained by businesses, but browser traffic is global and privacy signals are cheap to transmit. A broad rollout would reduce state detection and product-support complexity, while a California-only design could invite the question of how a browser determines which users receive a right that is supposed to be easy to find.
The board’s reported move into formal rulemaking is therefore the start of a technical compliance fight, not the end of one. On January 1, 2027, California will require browsers to offer the opt-out signal. Between now and then, CalPrivacy must publish the details—and browser vendors and web operators must prove that a privacy control is more than a switch that sends a request into an ad-tech system built to ignore it.
References
- Primary source: MLex
Published: August 7, 2026 at 10:50 PM UTC
CalPrivacy begins formal rulemaking update on Calif. opt-out preference signals | MLex | Specialist news and analysis on legal risk and regulation
CalPrivacy’s board voted to begin the formal process to update its enforcement regulations in advance of a state law that will take effect next year that mandates browser makers incorporate Global Privacy Control as a setting in their browsers.www.mlex.com - Related coverage: cppa.ca.gov
Loading…
www.cppa.ca.gov - Related coverage: boe.ca.gov
Rulemaking Protocol
The Program Department or Legal Division identifies the need for a new regulation/amendment based on new legislation, court decisions or changes in interpretation of existing law which have general taxpayer impact.boe.ca.gov - Related coverage: oal.ca.gov
- Related coverage: oal.ca.gov