Methodology and known limitations
This page explains how our free tools test a website's response to Global Privacy Control (GPC), what the results mean, and what they cannot show. Results are technical observations, not legal conclusions.
For the difference between an ongoing GPC opt-out and California's data-broker deletion program, read GPC vs. DROP: California's two privacy tools explained.
How the test works
- GPC off. The page is loaded without the GPC signal. The extension reloads the tab; the scanner uses a fresh automated Chromium session and also visits up to two internal pages.
- GPC on. The same pages are loaded again with the
Sec-GPC: 1request header andnavigator.globalPrivacyControlset to true, the two forms of the signal defined by the GPC specification. - Observation. In each run, the tool scrolls the page and waits several seconds for tags to load, then records requests to a built-in list of known advertising and analytics vendors.
- Comparison. Requests that send data to advertising vendors are compared between the two runs. Tag or script loads alone are not counted, because loading a tag doesn't by itself send data.
What the results mean
| Result | Meaning |
|---|---|
| No ad-vendor requests seen with GPC on | No requests to known ad vendors were observed after GPC was sent (restricted-flag requests aside). |
| Fewer ad-vendor requests with GPC on | Some vendors' requests stopped and some continued, or ad-related cookies were present with GPC on. Review recommended. |
| Ad-vendor requests continued with GPC on | Requests to the same known vendors were observed with GPC on at similar levels to GPC off. This may or may not indicate a compliance issue. |
| Ad-vendor requests seen with GPC on: review recommended | Extension only: a single page load with GPC already on. Run the before/after test for a comparison. |
| No known ad vendors observed | None of the vendors on our list were seen. |
Restricted-processing flags
Some vendors let sites send requests in a mode that limits how data is used. Requests carrying these flags are reported separately and not counted:
- Google Ads:
npa=1(non-personalized ads),rdp=1(restricted data processing), or a Consent Modegcsvalue indicating ad storage denied. - Meta:
dpo=LDU(Limited Data Use).
Other vendors may offer restricted modes that aren't visible in request addresses. Those requests are counted, which can produce false positives.
Known limitations
- Client-side only. Data a site shares from its own servers, contracts with vendors, and vendor account settings are not visible.
- Location and consent. Many sites change behavior based on the visitor's location, prior consent choices stored in cookies, device, or timing. Results reflect the tester's network location and browser state.
- Variation between runs. Ad rotation, A/B tests, and tag timing can change results from one run to the next.
- Incomplete vendor list. Vendors not on our list are not detected (false negatives). Some requests to listed vendors may serve purposes other than advertising (false positives).
- Not a legal determination. Whether any law applies to a site, or was violated, depends on facts these tools cannot see.
Request a review of a result
If you operate a website and believe a result about it is wrong or misleading, email sales@digibiz360.com with the subject "GPC result review request." Include the site, the date of the result you saw, and what you believe is inaccurate. We review every request, respond within five business days, and correct our tools, vendor list, or published materials when we find an error. We keep a record of each request and outcome. There is no charge, and requesting a review has no connection to our paid services.
Independence
DigiBiz360 is an independent company. We are not affiliated with, endorsed by, or acting on behalf of any regulator, the Global Privacy Control project, Google, or any vendor named in results.