On a site that shows commercial signals (a cart or checkout flow, a pricing page, or an embedded payment provider), we check whether it offers a “Do Not Sell or Share My Personal Information” or “Your Privacy Choices” opt-out link (the clear-and-conspicuous link CPRA §1798.135 requires) and flag the finding for California. The scan still does not score opt-out preference signals such as Global Privacy Control, or consumer request flows. Our free cookie consent checker does send a GPC signal and reports what loaded with it set, which is an observation of one page load rather than a finding: it cannot certify that a site honours the signal, because answering that needs a second load to compare against.
Read the official source for the California Consumer Privacy Act →