Skip to content
optoutwatch

CCPA/CPRA · Global Privacy Control · CIPA

Your banner makes a promise. Does your site keep it?

optoutwatch clicks “Reject” on your consent banner, sends the Global Privacy Control signal, and records which third parties still load. Then it keeps watching — and tells you the day something changes.

Automated first assessment from a US location. Not legal advice.

Why this exists

The letter nobody saw coming

A manufacturer’s banner offered “Reject tracking”. After visitors clicked it, LinkedIn and ZoomInfo still set cookies. The demand letter did not allege a privacy lapse. It alleged deception — $10,000 per violation under the federal wiretap statute, as a class action.

The marketing team had added the tags. Nobody had checked what the banner actually did afterwards.

Two things we measure

What your visitors are promised, compared with what loads

Pillar 1

Banner effectiveness: reject, then measure

Most scanners look at what happens before consent. We look at what happens after a visitor says no.

  1. 1We click the reject option your visitors see.
  2. 2We reload and record every third-party host and cookie.
  3. 3We list what still loads — by service, not by request.

Pillar 2

Global Privacy Control is enforced now

Since September 2025, California, Colorado and Connecticut run a joint, automated sweep for sites that ignore the GPC signal. Settlements so far:

Sephora
$1.2M
Tractor Supply
$1.35M
Disney
$2.75M
General Motors
$12.75M

From January 1, 2027, AB 566 requires browsers to ship GPC. The signal will arrive with a large share of your traffic, not just a few privacy-minded visitors.

We load your site with and without the signal, several times, and compare which hosts disappear entirely — request counts fluctuate on their own and prove nothing.

Continuous monitoring

The value is in noticing

A single scan finds today’s problem — if someone happens to run it today. Sites change every week: a new tag, a swapped consent tool, an agency update. optoutwatch scans daily and tells you when something changes.

Only changes are reported, compared with the previous scan — not the same finding every day. A service that loads on one run and not the next is loading jitter, not a change; we alert once a difference persists across runs.

What triggers an alert

  • A third-party service appears that wasn’t there before
  • A check gets worse than in the previous scan
  • GPC stops working, for example after a consent tool swap
  • The banner promises something the site no longer keeps
  • The privacy policy changes while data flows stay the same — or the other way round

How you hear about it

  • E-mail to the addresses you choose
  • Webhook, Slack-compatible, for your own systems

What we check

Five groups, ordered by how actively they are enforced

  1. A

    Opt-out mechanics

    Whether the GPC signal is honored, a status indicator is shown, no extra pop-up appears, and the opt-out link works without an account.

  2. B

    Banner effectiveness

    Which trackers still load after “Reject”, and whether accept and reject are presented with equal prominence.

  3. C

    Required links

    “Do Not Sell or Share”, “Limit the Use of My Sensitive Personal Information” and the privacy policy link — recognizing all four permitted variants, and telling “missing” apart from “present but named or placed differently”.

  4. D

    Privacy policy (11 CCR § 7011)

    Last-updated date, categories, sources, purposes, recipients, retention per category, the six consumer rights, two ways to submit requests, and how opt-out signals are handled.

  5. E

    CIPA litigation risk

    Form and search input sent to third parties, session recording, chat widgets with third-party backends. Shown as a litigation risk, not as a violation.

The report

A work list, not a legal opinion

Reports are grouped by service, not by statute. Marketing sees which tags to fix; leadership sees what is at stake.

3 things to review, involving 2 of 14 third-party services.
Each entry shows what we measured and, separately, what it may mean — and under which conditions.

Thresholds can’t be measured from outside

The CCPA applies above revenue and data-volume thresholds that no scanner can see. You tell us once per site. Until you do, findings read “applies if thresholds are met” — never as a hard violation. CIPA has no threshold, so litigation risks are always shown.

What a report is — and isn’t

An automated first assessment of what we observed from a US location on a given date. It keeps measurement and conclusion apart. It is not legal advice, and it never declares a site to be in conformity with any law or issues a seal.

Find out what your banner actually does

Free for one site. No credit card.

Start free