- Short answer
- Colorado yes — honour GPC if you sell data or run targeted ads inside CPA thresholds; no such duty in Virginia's Chapter 53 on September 10, 2026.
- Who Colorado's duty reaches
- A Colorado nexus AND a volume test, and only where you sell personal data or run targeted advertising.
- Virginia: what we read, and when
- No opt-out-signal duty in §§ 59.1-576, 59.1-577 or the full Chapter 53 text, read September 10, 2026.
- Shopify's side names no state
- GPC acts only for visitors in regions where you use a data sharing opt-out page.
- No per-visitor override
- In configured regions GPC is honoured automatically and cannot be adjusted through setTrackingConsent.
Does Colorado or Virginia require you to honour the signal?
Colorado does, and the duty is live. C.R.S. § 6-1-1306 requires a controller that runs targeted advertising or sells personal data to offer an opt-out through a user-selected universal opt-out mechanism, and the Colorado Attorney General dates it to July 1, 2024 for businesses inside the CPA thresholds.
Those thresholds are an AND: a Colorado nexus — doing business there or directing goods at its residents — plus one volume test, more than 100,000 individuals in a calendar year, or 25,000 individuals plus revenue or a discount from selling personal data. Miss either half — or sell no data and run no targeted ads — and Colorado's duty is not yours: honouring GPC stays a choice.
Virginia does not say the same. The phrases "opt-out preference signal" and "universal opt-out" appear nowhere in §§ 59.1-576 and 59.1-577, or in the full text of Chapter 53, read on September 10, 2026.
The right itself exists — § 59.1-577(A)(5) — but a Virginia consumer exercises it by sending you a request you answer by hand, not a browser signal.
What counts as a recognised opt-out signal?
Only one mechanism counts today. The Colorado Attorney General keeps the list of valid mechanisms, and Global Privacy Control (GPC) is its only entry.
Currently, the only UOOM considered valid by The Department is GPC.
GPC is a browser setting a shopper turns on: it arrives as a Sec-GPC request header set to "1", mirrored by navigator.globalPrivacyControl. It has been a W3C Privacy Working Group work item since November 2024, still being standardised, and the Colorado Department of Law updates its list of valid mechanisms periodically.
What do you switch on in your Shopify admin?
You switch on a data sharing opt-out page — Shopify requires a published privacy policy first. Shopify says the GPC header activates opting out of data sale, sharing and targeted advertising for visitors in regions where you use a data sharing opt-out page. Shopify's own Customer Privacy API names Virginia — its userDataCanBeSold() method covers visitors located in California or Virginia — but no Shopify page we read ties either state to GPC.
In a configured region the signal is honoured automatically, sale_of_data is set to false, and it cannot be adjusted through setTrackingConsent.
This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.
Editorial Policy