Universal Opt-Out Mechanism
A Universal Opt-Out Mechanism is a tool or setting on a consumer's desktop or mobile device that automatically tells businesses the consumer wants to opt out of certain uses of their personal data, such as the sale or sharing of that data. Instead of clicking an opt-out link on every website, the consumer configures the preference once and the signal is communicated automatically. The Global Privacy Control (GPC) is a commonly cited example of such a signal.
A Universal Opt-Out Mechanism (UOOM) is a standardized, device- or browser-based signal that enables a consumer to communicate an opt-out preference automatically to controllers or businesses, typically covering the sale or sharing of personal data and processing for targeted advertising. The Global Privacy Control (GPC) is a widely referenced implementation designed to let consumers exercise opt-out rights automatically rather than on a site-by-site basis. UOOM obligations arise under U.S. state privacy regimes, such as the Colorado Privacy Act, where controllers are generally required to recognize an approved UOOM; the specific scope, list of approved mechanisms, and effective dates of these obligations vary by jurisdiction and are established through each state's statute and implementing regulations. This entry does not specify the operative compliance dates, technical conformance requirements, or the set of approved signals for any given jurisdiction, and it does not address the EU or UK GDPR, which do not use this mechanism as a defined concept. It also does not cover enforcement, penalties, cross-border transfer, or retention.
Why it matters
Universal Opt-Out Mechanisms shift the burden of exercising privacy choices away from the consumer and onto the business. Rather than requiring individuals to locate and click an opt-out link on each website they visit, a UOOM lets a consumer configure a single preference on their device or browser that is then communicated automatically. For businesses subject to U.S. state privacy regimes that recognize such mechanisms, this creates a compliance obligation that operates continuously and at scale, because an approved signal must be honored wherever it is received rather than treated as an isolated request.
The significance for compliance teams is that a UOOM is a machine-readable signal, not a manual form submission, so recognizing it generally requires deliberate technical implementation across web properties and, in some cases, mobile experiences. Failing to detect or act on an approved signal can constitute a failure to honor a validly exercised opt-out right under the relevant state statute. Because the specific list of approved mechanisms, the scope of covered processing, and the operative compliance dates vary by jurisdiction and are set through each state's statute and implementing regulations, organizations should confirm the requirements applicable to each state in which they do business rather than assuming a single uniform standard.
This entry does not address enforcement, penalties, cross-border transfer, or retention, and it does not cover the EU or UK GDPR, which do not use a Universal Opt-Out Mechanism as a defined concept. Organizations should treat the recognition of a UOOM as one component of a broader opt-out rights program and confirm the precise obligations, approved signals, and effective dates against the current text of each applicable state law and its regulations.
Who it's relevant to
Inside UOOM
Common questions
Answers to the questions practitioners most commonly ask about UOOM.