Appearance
Global Privacy Control
Some browsers and extensions send Global Privacy Control — a header and a JavaScript flag that say, once, for every site: do not sell or share my data. Under a dozen US state laws it is a legally binding opt-out. CookieWave honours it everywhere, not only in those states: over-honouring an opt-out is never a breach, and a list of states that keeps growing is a liability.
What it does
Before the visitor decides, on every site: nothing non-essential runs. GPC forces the opt-in behaviour regardless of region, so scripts stay blocked and Consent Mode starts denied. The banner still appears — GPC is an opt-out, not an answer to your specific question, and a visitor may still want to accept.
After the visitor decides, it depends on which template the site runs.
| US state laws | GDPR | |
|---|---|---|
| Consent given before GPC was turned on | Void. Cleared, cookies deleted, banner returns | Kept |
| Consent given while GPC was on | Kept | Kept |
The difference is what the signal means in each place. Under the US laws it is a binding request that arrives later than the click, and a later instruction from the same person wins. Under GDPR a global browser preference does not withdraw an explicit, informed consent given for one site — but nothing non-essential runs before that consent either way, which is the EEA default regardless of GPC.
On a site running both templates, the visitor's country decides which row applies.
What your visitors will notice
On a US or both-templates site, a visitor who accepted before turning GPC on is asked once more. Their previous answer is cleared, along with the cookies it had allowed, exactly as if they had withdrawn it. Whatever they answer this time is kept, and they are not asked again.
That one extra prompt also happens on the first visit after this behaviour shipped, for anyone already running GPC: consents stored before then carry no record of the conditions they were given under, so they are treated as predating the signal.
Checking it
In the console of a browser that sends it:
js
navigator.globalPrivacyControl // → trueFirefox has it under Settings → Privacy & Security → Website Privacy Preferences; Brave and DuckDuckGo send it by default; Chrome needs an extension. The matching Sec-GPC: 1 request header is what your server sees.
Every consent record CookieWave stores includes whether GPC was being signalled at the moment of the decision, so a disputed record can show which conditions applied.