Artifact GuideUSDo not sell or share

US CCPA Do not sell or share

Classify disclosures by the statutory sale and sharing definitions, provide the required opt-out path, honor qualifying preference signals, and notify downstream third parties of the consumer choice.

Ground decisions in the consolidated CCPA statute and the regulations effective through January 1, 2026; preserve the trigger, owner, evidence, deadline, and reassessment condition for each control.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Under the CCPA, a California consumer can direct a business to stop the of the consumer's personal information. The business must offer valid request methods, honor qualifying opt-out preference signals, stop covered disclosures as soon as feasible and no later than 15 business days after receipt, and notify affected downstream third parties.

Section 1

What does "do not sell or share" actually mean?

The CCPA gives a consumer the right to direct a business to stop selling or sharing their personal information. "Sell" means disclosing a consumer's personal information to a third party for monetary or other valuable consideration. "Share" is narrower and specific to advertising: it means disclosing personal information to a third party for cross-context behavioral advertising, whether or not any money changes hands. A common example of sharing is letting an ad-tech vendor use a site visitor's identifiers to target ads across other sites and apps.

In practice, a business that sells or shares personal information must give consumers a clear way to opt out, most commonly a "Do Not Sell or Share My Personal Information" link, and must treat an such as as a valid opt-out request. Once a consumer opts out, the business must stop selling or sharing that person's personal information and must notify third parties that received the information during the interval between the request and compliance, directing them to honor and forward the opt-out. A consumer can also authorize someone else to opt out on their behalf.

  • Opt out applies to two things: selling personal information for value, and sharing it for cross-context behavioral advertising.
  • If the business sells or shares, it must offer an opt-out link and honor opt-out preference signals like .
  • After an opt-out, stop selling or sharing that consumer's data and tell downstream recipients to do the same.
  • If the business does not sell or share personal information, it does not need the notice or link only if its privacy policy states that it does not sell or share; retain the disclosure map and contracts supporting that statement.
Section 2

Classify every disclosure before choosing the control

Create a recipient-by-recipient disclosure map. Record the personal information, purpose, consideration, use for cross-context behavioral advertising, recipient role, contract, onward disclosures, and whether an exception to applies.

A service-provider or contractor label is not enough. The recipient's actual use and written contract must satisfy the CCPA restrictions. A disclosure can be sharing without money, and a disclosure for valuable consideration can be a sale even when it is not advertising.

  • Inventory web, app, SDK, server-to-server, offline, enrichment, audience, and data-broker disclosures.
  • Test sale, sharing, and statutory exceptions separately for each disclosure.
  • Confirm the notice at collection and privacy policy describe the applicable categories and purposes.
  • For consumers under 16, apply the CCPA opt-in rules before selling or sharing personal information.
Section 3

Offer valid opt-out methods and honor GPC

A business that sells or shares personal information must offer two or more designated opt-out methods, with at least one reflecting how it primarily interacts with consumers. An online business must support a qualifying and at least one regulatory method, subject to the frictionless-processing alternative.

Do not require identity verification or account creation. Collect only information needed to complete the opt-out. A signal applies to the browser or device and associated profiles; when the consumer is known, it also applies to the consumer, including the known account and applicable offline .

  • Product owns the public method and confirmation; engineering owns signal detection, preference storage, suppression, and propagation.
  • Test logged-in and logged-out states, known and pseudonymous profiles, multiple devices, browsers, apps, and offline records.
  • Do not treat the absence of a signal on a later visit as consent to reverse an existing opt-out.
  • A cookie banner alone is not an adequate sale-or-sharing opt-out unless it controls the legal disclosure, not only cookie collection.
Section 4

Meet the deadline and propagate the choice

Stop selling or sharing as soon as feasibly possible and no later than 15 business days after receipt. Notify every third party that received the consumer's personal information between receipt and compliance; direct it to honor the request and forward it to anyone to whom it made the information available during that interval.

Provide a way for the consumer to confirm that the request was processed. Except where the regulations allow otherwise, wait at least 12 months before asking the consumer to consent again. Keep financial-incentive conflicts and business-specific consent paths within the regulatory conditions.

  • Timestamp receipt, system suppression, downstream notice, and confirmation.
  • Maintain the recipient list needed to identify disclosures during the receipt-to-compliance interval.
  • Document a good-faith, reasonable belief before denying a request as fraudulent and explain the denial.
  • Keep any data collected for the opt-out limited to processing that request.
Section 5

Evidence and change control

Keep the disclosure classification, notice, interface, GPC tests, request log, suppression evidence, recipient notices, exceptions, and re-consent date together.

Reopen the analysis when a tag, SDK, recipient, purpose, consideration, contract, identity graph, or advertising use changes.

  • Run automated signal tests and periodic manual end-to-end tests.
  • Compare deployed tags and recipients against the approved disclosure inventory.
  • Verify that third parties and service providers act on forwarded instructions.
  • Escalate any flow whose role, consideration, or advertising purpose is unresolved before launch.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • California statutory source for operationalizing do-not-sell-or-share links and opt-out preference signal handling.
"Do Not Sell or Share My Personal Information"
leginfo.legislature.ca.gov
Referenced sections
  • Binding definitions of sale, sharing, service provider, contractor, and third party.
"for monetary or other valuable consideration"
cppa.ca.gov
Referenced sections
  • CPPA consumer-facing source for enforcement and complaint context around do-not-sell-or-share rights.
"You cannot sue businesses for most CCPA violations"
cppa.ca.gov
Referenced sections
  • Current binding rules for opt-out preference signals, request processing, confirmation, and downstream notice.
"A business must provide a means by which the consumer can confirm that their request to opt-out of sale/sharing has been processed by the business."
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share: Implementation and Testing
Implement CCPA sale-or-sharing opt-outs across links, GPC, consent state, ad tech, recipients, confirmation, privacy disclosures, and evidence.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.