TL;DR: Researchers at webXray audited over 7,000 popular websites and found that Google, Meta, and Microsoft are flat-out ignoring California’s legally required privacy opt-out signal. Google kept tracking users 86% of the time they sent the “stop tracking me” signal. Meta’s trackers didn’t even bother checking for the signal, failing 69% of the time. Microsoft ignored it half the time. One third-party ad tool failed 90%+ of the time. The California Consumer Privacy Act says businesses must honor the Global Privacy Control signal. Potential fines run into the billions. Actual fines levied against these three companies for GPC violations: zero.

7,000 Websites. Three Tech Giants. One Conclusion: They Don’t Care.

On April 21, The Markup published an investigation based on research from webXray, a firm run by Tim Libert , a former Google privacy engineer who led cookie policy there from 2021 to 2023. Libert’s team visited over 7,000 of the most popular websites from a California IP address with the Global Privacy Control (GPC) signal enabled [1][2].

The GPC signal is simple. Your browser sends a one-line header that says: “Don’t sell or share my personal data.” Under the CCPA, as amended by the California Privacy Rights Act, websites must treat this signal as a legally binding opt-out request [3].

Here’s what they found:

  • Google: Continued tracking in 86% of cases. Sites still set a Google cookie to follow visitors around the web, even after receiving the signal [1][2].
  • Meta: Failed 69% of the time. Meta’s tracking code doesn’t even check whether the signal exists , it just fires regardless [1][2].
  • Microsoft: Ignored the signal in 50% of instances [1][2].
  • One third-party advertising tool: Failed to honor the opt-out more than 90% of the time [1].

“They don’t make any substantive effort to comply,” Libert told The Markup [1].

That’s a guy who literally ran Google’s cookie policy. He knows how this works from the inside.

The Privacy Signal They Promised to Respect

Quick primer. The Global Privacy Control signal is a browser-level setting. Firefox, Brave, and DuckDuckGo support it natively. Chrome users can enable it through extensions. When you visit a website, your browser sends an HTTP header , Sec-GPC: 1 , telling the site not to sell or share your data [3].

California passed the CCPA in 2018 and strengthened it with the California Privacy Rights Act (CPRA) in 2020. The law requires businesses to treat GPC signals as valid opt-out requests. It’s not optional. It’s not a suggestion. It’s a legal obligation backed by fines of $2,500 per violation , or $7,500 per intentional violation [3][4].

The California Privacy Protection Agency confirmed this in its enforcement guidelines. Attorney General Rob Bonta has publicly said GPC is legally binding [4].

And yet. Here we are. Three of the largest advertising companies on the planet ignoring it on thousands of websites.

The Companies Have Thoughts. None of Them Are Convincing.

Google told The Markup the audit was “based on a fundamental misunderstanding” of how its ad tools work [1]. Google didn’t elaborate on what exactly was misunderstood about “we keep tracking you 86% of the time you tell us to stop.”

Microsoft spokesperson Courtney Ramirez said their advertising systems “are designed to reflect that choice” when they receive a GPC signal, and claimed certain cookies were placed for “operational necessity” [2]. The audit found Microsoft failed 50% of the time. Operational necessity covers a lot of ground apparently.

Meta called the entire report “a blatant marketing ploy” [5]. Libert called Meta’s response “farcical,” pointing out that Meta’s tracking pixel doesn’t even check for the GPC signal , it can’t honor a request it never reads [5].

Engineers interviewed by The Markup and KQED said implementing GPC compliance requires minor changes to tracking code , a few lines of JavaScript to check the signal before firing trackers [1][5]. Google, Meta, and Microsoft employ some of the best engineers on the planet. This isn’t a technical limitation. It’s a business decision.

Billions in Fines. On Paper.

Here’s where it gets interesting. The CCPA sets fines at $2,500 per violation, or $7,500 if the violation is intentional [3][4]. WebXray estimates that if the California Privacy Protection Agency fined every non-compliant site its researchers found, the total could reach into the billions [1].

The math: 7,000+ websites, each receiving thousands of California visitors per day with GPC enabled, each visit generating a separate violation. The numbers compound fast.

For context, the largest CCPA settlement to date was $2.75 million , against Walt Disney Company in February 2026 [5]. Disney. Two-point-seven-five million. That’s a rounding error on Google’s Q1 ad revenue.

Google made $66.9 billion in advertising revenue in Q4 2025 alone. An 86% non-compliance rate across thousands of websites suggests the company calculated that ignoring the law is cheaper than obeying it. Until the fines change that math, nothing else will.

The Cop on the Beat Is Taking a Very Long Lunch

Tom Kemp, executive director of the California Privacy Protection Agency, gave the most telling response: “While we don’t have comment on the finding of this specific report, we do appreciate that the report brings visibility to the importance of opt out rights” [2].

Read that again. The agency responsible for enforcing the CCPA “appreciates the visibility” that companies are violating the law at industrial scale. That’s not enforcement. That’s a press release.

Libert put it bluntly: “Ask the average Californian if they feel they have more privacy now than before the CCPA was passed. I think the answer’s going to be no” [5].

He’s right. California was supposed to be the model for US privacy law. The state passed the CCPA in 2018, strengthened it in 2020, created a dedicated enforcement agency, and defined the GPC signal as a legally binding opt-out. On paper, it’s one of the strongest privacy frameworks in the country.

In practice, the three companies that control most of the web’s advertising infrastructure just... don’t comply. And the enforcement agency appreciates the visibility.

Why This Matters Beyond California

If you don’t live in California, this still hits you. Google, Meta, and Microsoft don’t run separate tracking systems for each state. Their infrastructure is global. If they’re ignoring GPC signals from California , where the legal consequences are strongest , they’re almost certainly ignoring them everywhere.

Colorado and Connecticut have similar GPC requirements under their own privacy laws [3]. More states are adding them. Federal privacy legislation like the Secure Data Act is actively debating whether to include opt-out signal requirements.

But laws only matter if someone enforces them. Right now, the enforcement picture looks like this:

  • Biggest CCPA fine ever: $2.75 million (Disney, Feb 2026)
  • Google Q4 2025 ad revenue: $66.9 billion
  • GPC enforcement actions against Google for non-compliance: Zero

State Senator Josh Becker (D-Menlo Park) has authored SB 923, the Expanding Privacy Rights Act, and pushed through the Delete Act (effective August 1, 2026, for data brokers) [5]. California keeps passing laws. Companies keep ignoring them. The gap between legislation and enforcement is where your privacy goes to die.

What You Can Do Right Now

The GPC signal won’t stop Google from tracking you. But there are layers you can add:

  • Enable GPC anyway. Firefox and Brave have it built in. For Chrome, install the “OptMeowt” or “Privacy Badger” extension. It may not work 86% of the time, but it creates a legal paper trail.
  • Use uBlock Origin. Block third-party trackers at the network level. If Meta’s pixel never loads, it can’t track you regardless of GPC.
  • Switch browsers. Firefox with Enhanced Tracking Protection blocks most of these trackers by default. Brave does the same.
  • File complaints. The California Privacy Protection Agency accepts complaints at cppa.ca.gov. Every complaint is a data point. Enough data points force investigations.
  • Check the California Delete Act tools when they go live in August 2026 to request data brokers delete your information.

The uncomfortable truth: privacy law in America is an honor system, and the biggest companies have decided not to honor it. Your browser settings are a legal shield that nobody’s enforcing. The real protection comes from blocking the trackers yourself.

The Bottom Line

A former Google privacy engineer audited 7,000 websites and found that Google, Meta, and Microsoft are ignoring California’s privacy law at industrial scale. Google tracks you 86% of the time you tell it to stop. Meta doesn’t even check whether you asked. The law says this is illegal. The fines could be in the billions. The actual enforcement is a polite thank-you note from the agency.

California wrote the playbook for US privacy regulation. Six years later, the three companies that run most of the web’s ad infrastructure treat it as optional. Until the fines match the revenue, they’re right to.

References

  1. The Markup , Websites break California privacy law at ‘industrial scale,’ survey finds (April 21, 2026)
  2. CalMatters , Websites break California privacy law at ‘industrial scale,’ survey finds (April 2026)
  3. Global Privacy Control , Official specification and legal framework
  4. California Attorney General , California Consumer Privacy Act (CCPA)
  5. KQED , What Is the Point of California’s Privacy Laws if Big Tech Ignores Them? (April 2026)