What is a Sec-GPC header?
"Global Privacy Control" - signals that the user does not consent to their data being sold or shared.
Sec-GPC is the modern, more legally-backed successor to DNT - in several jurisdictions (including under California's CCPA), a website receiving this header is required to actually treat it as a valid opt-out request rather than just a polite suggestion, which makes it worth taking seriously if your site handles any user data covered by that kind of regulation.
Common use case
A site operating under CCPA checks for Sec-GPC: 1 and automatically treats the visitor as having opted out of having their personal data sold or shared, without requiring them to click through a separate opt-out form.
Example
Sec-GPC: 1History
Developed by a coalition including the Electronic Frontier Foundation and Mozilla, first implemented in Brave and Firefox around 2021, and given specific legal weight under California's CCPA regulations shortly after.
Did you know?
Unlike DNT, which was purely voluntary, this one has real regulatory teeth in some jurisdictions - a site covered by CCPA that ignores it can face genuine enforcement action, not just bad PR.