Summary

  • W3C published a Global Privacy Control Working Draft on 24 September 2026. It is a work in progress, not a final Recommendation or W3C endorsement; a prior draft appeared on 17 September.
  • The specification distinguishes the navigation-time preference carried in Sec-GPC: 1 and the DOM from an origin’s optional /.well-known/gpc.json statement. The latter does not attest to the treatment of a particular request.
  • An operator’s evidence of actual processing would be a third record. A request, a declared intention and observed conduct should not be collapsed into one compliance claim.

A person turns on Global Privacy Control in a browser while a shopping tab is open. The preference shown in the browser may have changed, but the tab’s GPC value has not yet caught up. The W3C draft requires the user agent to cache the preference when a top-level document begins loading; a later change takes effect on the next navigation. It says the browser should warn about inconsistent tabs and offer a reload. That small timing rule is a reminder that a privacy choice has an event history, not merely an on/off icon.

The Privacy Working Group’s 24 September Working Draft defines how a person can ask websites and services not to sell or share personal information with third parties or use it for cross-context ad targeting. When the cached preference is true, a user agent sends Sec-GPC: 1; otherwise it sends no such header. A script can read navigator.globalPrivacyControl, whose value reflects the cached state for that navigation. These mechanisms carry the request. They do not report how every recipient or third party ultimately handled data.

The document offers a second, quite different signal. An origin may publish /.well-known/gpc.json to describe its awareness and support. A gpc: true entry says the server intends to abide by GPC requests at least insofar as legally obligated; lastUpdate dates the declaration. W3C explicitly says this resource is not meant to say whether the origin abided by a request from the user agent reading it. Support is unknown by default. Absence of the optional file therefore cannot be translated automatically into noncompliance, just as its presence cannot be treated as a per-visitor compliance certificate.

This is the governance seam. One record describes the browser’s request at navigation time. Another describes an origin’s general declared posture. The question readers and reviewers are likely to care about—whether relevant processing and onward sharing followed the applicable rule—requires evidence of conduct, not a comparison of two visible labels. The draft specifies neither a universal audit receipt nor a measurement of how websites currently respond. It does not certify any named implementation.

GPC’s scope also matters. The draft says it does not exercise every privacy right: it is not a deletion request, nor a blanket opt-out from all advertising or same-context data use. Its legal consequences may differ with jurisdiction, the individual’s location, applicable law and separate agreements. Treating a received header as one universal legal outcome would overstate the document as much as treating a support file as proof of actual compliance.

The distinction does not diminish the value of a portable request. It gives the request a fairer test. If a site can show which navigation-time signal it received, how its decision rule interpreted that signal, and where relevant data was or was not routed afterward, a reviewer has a basis to examine behavior. That evidence trail is Daniel Kade’s editorial operating proposal, not a W3C-mandated schema. The Working Draft remains open to change and its publication does not imply W3C or member endorsement.

Sources