Geofencers Beware: IP Address May Not Be Sufficient Basis for Offering Privacy Choices

A recent letter from Senator Ron Wyden to the Attorneys General of ten states with universal opt-out mechanism (UOOM) requirements and to the Chair of the California Privacy Protection Agency Board highlights the potential issues with geofencing by IP address when configuring compliance with opt-out choices and state privacy laws. The letter urged the regulators to issue guidance that businesses should honor Global Privacy Control (GPC) signals sent by their residents and not rely on “flawed geolocation data to selectively ignore consumer opt-out requests.”[1] The letter also asks the offices to take collective action to address the issue.

We note that the letter is not law and does not change any existing legal obligation. It is, however, a useful signal of where regulator expectations may be heading, and it discloses specific product commitments from several major consent management platforms (CMPs). Those commitments are the most immediately actionable part of the letter because they may affect how the “commercially reasonable" standard in several state privacy statutes is interpreted over time. In addition, while this is currently limited to GPC, it may very well broaden to considerations of all privacy choices and rights under the state statutes.

Background: The Practice at Issue

Many businesses configure their CMP to honor GPC signals only for visitors whose IP address appears to be located in a state that requires UOOM compliance. Senator Wyden's position is that this approach can silently deny opt-out rights to residents of covered states who are (1) temporarily out of state (including college students, business travelers, interstate commuters, and deployed military personnel) or (2) using a VPN, whose traffic appears to originate from the VPN server's location. He also notes that if a business displays an "Opt-Out Request Honored" style indicator only when the signal is accepted, the consumer has no way of knowing when a signal has been disregarded, which “effectively morphs a transparency rule into a cloaking device for non-compliance.”

CMP Response

The letter reports that the Senator’s office has conducted oversight into the CMPs, which come with pre-configured settings that “respect or selectively ignore GPC based on the user’s IP address.”

According to the letter, three CPMs (Osano, Usercentrics and Transcend) already honor GPC signals from all users regardless of IP address, and Transcend agreed to add a “new, optional feature allowing customers to automatically classify visitors from U.S. government and military IP address as high-sensitivity users, instantly applying their most privacy-preserving protections” by the end of 2026.

OneTrust and Ketch have agreed to develop and display a visual indicator when the CMP ignores a GPC signal and will provide a mechanism for the consumer to change their state of residence. TrustArc will “update the default configuration for clients who operate in states that enforce GPC or deploy a nationwide CMP banner,…include a GPC setup process that will honor GPC preferences,…develop capabilities to automatically treat traffic from U.S. government and military IP addresses as if they come from California,…[and create both] a state of residency selector to allow consumers to manually correct a misidentified location and…a visual indicator to inform users that a site honors GPC but the user has not enabled it.”

The letter also states that CalPrivacy staff confirmed to the Senator's office that California consumers retain their rights under California law, including the right to opt out via GPC, regardless of their physical location. We note that this is a staff-level statement rather than formal guidance or a regulation. Privacy scholars have challenged the interpretation attributed to agency staff as legally dubious and as potentially in conflict with the constitutional principle that generally prevents states from regulating out-of-state activity.

Two Approaches to Consider

Option 1: Honor GPC nationwide. Configure the CMP to honor GPC from all visitors regardless of IP address. This is the lowest-risk position from a compliance standpoint, removes residency determination from the analysis, and is easier to document and audit rather than having different approaches by state. This change will impact the business as it reduces the addressable audience for targeted advertising and negatively impacts measurement, attribution, analytics and personalization.

Option 2: Retain geolocation-based logic, but notify users their GPC signal is being ignored and allow users to change their state of residency. This preserves most of the marketing and analytics value while addressing the transparency concern that drives the letter. This approach adds a user-experience element to the banner flow, requires the vendor features described above to be available and correctly configured, and creates a standard that must actually work end-to-end.

Recommended Next Steps

  1. Confirm with your CMP vendor what your current configuration actually does with GPC signals, including by IP address, and how VPN traffic is treated.

  2. Understand the vendor's roadmap. Verify whether any vendor default changes will alter your configuration automatically and decide in advance whether you want that outcome.

  3. Meet with internal teams to communicate these potential changes to the CMP due to the letter and recent CalPrivacy enforcement actions (i.e., updating CMP configurations and only requiring verifiable requests for deletion, right to know and right to correct).

  4. Address GPC handling in your data protection assessment for targeted advertising, which most state privacy laws already require.

  5. Monitor for future AG guidance in the covered states.

  6. Consider your other privacy controls, use of geofencing, and your privacy policy, banner and notices to consumers as a whole and determine whether adjustments should be made to those as well. Your notices and options should be consumer friendly!

  7. Train your employees on any new changes.

See our Practical Lessons for All Businesses from a Recent CalPrivacy Action article: https://www.infolawgroup.com/insights/2026/8/24/practical-lessons-for-all-businesses-from-a-recent-calprivacy-action

 [1] https://www.wyden.senate.gov/imo/media/doc/wyden_letter_to_ags_on_gpc.pdf

Originally published by InfoLawGroup LLP. If you would like to receive regular emails from us, in which we share updates and our take on current legal news, please subscribe to InfoLawGroup’s Insights HERE. This summary does not constitute legal advice.