Section 4(3) of Kentucky CDPA establishes the Universal Opt-Out Mechanism (UOOM) requirement + reflects converging US state privacy law standards for browser-level opt-out signals. (1) Section 4(3) UOOM Recognition: (a) Controller must honor a recognized universal opt-out mechanism; (b) Recognized via Attorney General published list (updated annually); (c) Currently includes GPC Global Privacy Control + emerging others; (d) Reflects Colorado CPA + California CCPA UOOM frameworks; (e) Convergence with multi-state privacy law standards. (2) GPC Global Privacy Control: (a) Browser-level signal (HTTP header Sec-GPC + JavaScript navigator.globalPrivacyControl); (b) Developed by Public Privacy + EFF + Disconnect + Brave + DuckDuckGo + Mozilla collaboration; (c) Indicates consumer opt-out preference; (d) Enabled by user in browser settings; (e) Must be honored when received; (f) Cannot require additional opt-out action after GPC. (3) Emerging Recognized Mechanisms: (a) Browser plugin opt-out; (b) Mobile device-level opt-out; (c) Connected TV (CTV) opt-out signal; (d) Privacy Sandbox attestation; (e) IAB Tech Lab Global Privacy Platform (GPP); (f) Future standards per AG annual review. (4) Section 4(3) UOOM Honor Requirements: (a) Browser/device-level GPC signal detection; (b) Backend opt-out processing; (c) Cookie consent management coordination; (d) Server-side opt-out application; (e) Vendor + processor flow-down; (f) Audit trail of opt-out signals received + honored; (g) Cannot dark pattern around UOOM. (5) UOOM Scope of Application: (a) Targeted advertising opt-out; (b) Sale of personal data opt-out; (c) Profiling for decisions with legal/significant effects (emerging); (d) Multi-state harmonization considerations. (6) UOOM vs Explicit Opt-Out: (a) UOOM is browser-level; (b) Explicit per-controller opt-out still required (e.g. via Privacy Notice link); (c) Some consumers prefer per-controller granular control; (d) Some consumers prefer universal browser-level; (e) Both must be honored. (7) Implementation Architecture: (a) Frontend - JavaScript snippet detecting GPC; (b) Cookie consent management + GPC integration; (c) Backend opt-out database; (d) Real-time advertising opt-out propagation; (e) Vendor + DSP/SSP coordination; (f) Email marketing opt-out coordination; (g) Cross-device coordination challenges. (8) Vendor + Processor Flow-Down: (a) Processor agreements must require UOOM honor; (b) Sub-processor flow-down; (c) Ad tech vendor coordination; (d) Marketing technology stack integration; (e) Attribution + measurement vendors; (f) Data broker + data clean room considerations. (9) Audit + Compliance Evidence: (a) GPC signal log + receipt tracking; (b) Opt-out processing record; (c) Vendor propagation evidence; (d) Customer service training; (e) Bug bounty considerations for UOOM bypass; (f) Periodic audit. (10) UOOM Effective Date Considerations: (a) Kentucky CDPA effective 1 January 2026; (b) UOOM list typically published by AG before effective date; (c) Transition period considerations; (d) Multi-state effective date staggering. (11) Multi-State UOOM Coordination: (a) Colorado CPA UOOM with state-specific list; (b) California CCPA UOOM with state-specific list; (c) Connecticut CTDPA UOOM; (d) Texas + Florida + Oregon emerging; (e) Common UOOM implementation strategy possible; (f) Per-state compliance evidence. (12) Penalties for UOOM Failures: (a) Section 9 AG enforcement; (b) 30-day cure period; (c) Civil penalty up to USD 7,500 per violation; (d) Significant exposure for systematic UOOM disregard. Coordinates with Colorado CPA UOOM + California CCPA UOOM + Connecticut CTDPA UOOM + Texas TDPSA + GPC Global Privacy Control (Public Privacy + EFF + Disconnect + Brave + DuckDuckGo + Mozilla) + IAB Tech Lab Global Privacy Platform (GPP) + IAB TCF v2.2 + W3C Privacy Standards + Browser vendors (Apple + Mozilla + Brave + DuckDuckGo). Kentucky CDPA UOOM + Section 4(3) applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.