Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy states that Target processes Global Privacy Control browser signals as valid opt-out requests from consumers for the sale or sharing of personal information.
This analysis describes what Target's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Recognition of GPC signals as valid opt-out requests is required under CPRA regulations for businesses subject to CCPA/CPRA; this provision creates an operational obligation to implement technical GPC signal recognition consistently across all digital surfaces and to honor those signals within the 15-business-day response period.
This provision establishes that consumers using GPC-compatible browsers can automatically signal an opt-out of the sale or sharing of personal information to Target without submitting a separate privacy request; the opt-out applies to data sale and sharing for advertising purposes as described in the policy.
How other platforms handle this
You may make a verifiable consumer request related to your personal information twice per 12-month period.
You can choose to what extent we will use your personal information to personalize your Discord experience.
where the EU GDPR or UK GDPR applies, we will respond within one calendar month of receiving a verifiable request, and where your request is complex...we may extend that period by up to a further two months.
Monitoring
Target has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We process Global Privacy Control signals as opt-out requests for the sale or sharing of personal information.Excerpt from Target's Privacy Policy
1. REGULATORY LANDSCAPE: CPRA regulations require businesses subject to CCPA to recognize and process GPC signals as valid opt-out requests for the sale or sharing of personal information. The California Privacy Protection Agency (CPPA) has cited GPC non-compliance in enforcement actions. The FTC Act may apply to deceptive representations about opt-out mechanism availability and functionality. 2. GOVERNANCE EXPOSURE: Medium. While the policy states GPC signals are processed, the technical implementation must ensure that GPC signals are recognized at the point of data collection (including advertising tags and analytics scripts) rather than only post-collection. If advertising tags fire before GPC signals are evaluated, the opt-out is not operationally effective. The CPPA has identified this implementation gap in prior enforcement contexts. 3. JURISDICTION FLAGS: California creates the most defined obligation under CPRA. Colorado's CPA also references browser-based opt-out signals. Other state statutes are developing analogous requirements. The GPC requirement applies to California residents regardless of whether they use a California IP address. 4. CONTRACT AND VENDOR IMPLICATIONS: GPC signal processing requires that advertising and analytics vendors integrated into Target's digital properties receive the GPC signal and suppress data collection or sharing accordingly. Vendor tag management systems must be configured to evaluate GPC status before firing any data-sharing tags. 5. COMPLIANCE CONSIDERATIONS: Compliance teams should audit whether: GPC signals are evaluated at page load before advertising and analytics tags are initiated; GPC signal recognition is implemented across all Target digital properties including mobile web; the technical implementation is documented and auditable; and the policy's representation that GPC is processed is verified against actual tag management configuration.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Recognition of GPC signals as valid opt-out requests is required under CPRA regulations for businesses subject to CCPA/CPRA; this provision creates an operational obligation to implement technical GPC signal recognition consistently across all digital surfaces and to honor those signals within the 15-business-day response period.
This provision establishes that consumers using GPC-compatible browsers can automatically signal an opt-out of the sale or sharing of personal information to Target without submitting a separate privacy request; the opt-out applies to data sale and sharing for advertising purposes as described in the policy.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Target.