In development, not yet available to install
Global Privacy Control, read before anything runs.
ConsentAlly is being built to read the browser's Global Privacy Control signal before any script runs and before the banner shows, and to apply what it means under the rules of the visitor's region: denying marketing, denying everything that is not necessary, or, where the rules do not recognise the signal, nothing.
What the signal is
Global Privacy Control is a browser setting. When it is on, the browser sends a Sec-GPC header with every request and exposes navigator.globalPrivacyControl to the page. It says: do not sell or share my data.
How ConsentAlly will apply it
- The signal will be read in the synchronous script, before the Consent Mode defaults are set and before any tracker could run. Reading it later would be too late.
- What it means will be set per jurisdiction in the store's configuration: ignore it, deny the marketing category, or deny every category that is not necessary. A new store's configuration will honour it in every jurisdiction it starts with.
- The visitor's consent record will carry whether the signal was present and whether it made the decision, so the store can show why marketing was denied.
What the visitor sees
Where the signal answers only part of the question, the banner will still appear for the rest, and the preference centre will show the categories the signal has already denied. The visitor will always be able to open the preference centre and change their mind.
What it cannot do
The signal is only what the browser sends. A browser without the setting sends nothing, and ConsentAlly will then fall back to the region's default rules.