Artifact GuideUSDo Not Sell Share Implementation

US CCPA Do Not Sell Share Implementation

Connect the public Do Not Sell or Share control and GPC detection to consent state, ad-tech suppression, recipient instructions, testing, and evidence that the choice persists across relevant surfaces.

A cookie banner alone is not an opt-out method. The control must address sale and sharing, require minimal steps, avoid dark patterns, and reach every covered transfer.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Under the California Consumer Privacy Act (CCPA), a business engaged in of personal information must give consumers usable opt-out methods and honor qualifying opt-out preference signals. The implementation is complete only when the choice stops covered transfers, persists for the required identity scope, reaches relevant recipients, can be confirmed by the consumer, and matches the privacy policy and notice. The statute and regulations control the result; the inventory and end-to-end tests below are practical evidence controls.

Section 1

What does a compliant do-not-sell/share setup include?

Provide two or more designated methods suited to how the business interacts with consumers. An online business must accept a qualifying and at least one additional route: an interactive form linked from "Do Not Sell or Share My Personal Information," the Alternative Opt-out Link, or the privacy policy when the business satisfies every condition for frictionless signal processing. The form must let the consumer opt out of all sale and sharing even if it also offers narrower choices. A cookie banner or cookie control is not enough by itself because it may address collection rather than .

Stop as soon as feasibly possible and no later than 15 business days. If a third party received the consumer's personal information after the request arrived but before compliance, notify that third party, direct it to comply, and require it to forward the request to another person to whom it made the information available during that period. The rule does not require a notice to every historical recipient regardless of timing.

  • Entry point: conspicuous link or permitted alternative, minimal and symmetrical steps, no account requirement, and a method matching the primary consumer interaction.
  • Signal handling: detect a qualifying signal and apply it to the browser or device, associated profiles, and the known consumer.
  • Suppression: stop covered client-side and server-side transfers, batch exports, audience uploads, and applicable offline disclosures.
  • Confirmation: let the consumer see that the business processed the opt-out.
Section 2

What should teams decide about Do Not Sell Share Implementation under the US CCPA?

Inventory every transfer of personal information to another person and record the recipient, consideration, purpose, consumer context, and contract. Sale can involve money or other valuable consideration. Sharing covers making personal information available to a third party for cross-context behavioral advertising, whether or not money changes hands. A recipient providing cross-context behavioral advertising is a third party for that service.

Test statutory exclusions separately. A consumer-directed disclosure requires an intentional direction or interaction; a qualifying merger or acquisition transfer remains subject to consistency and notice limits; and an identifier may be sent to communicate an opt-out or limit request. Removing money from a transaction does not avoid sale when the recipient still provides something of value or use.

Do not assume a tag is outside the opt-out because it is called analytics, measurement, or a service provider. Test the recipient's actual use and the section 7051 contract. If the relationship does not meet the service-provider or contractor rules, assess and connect the flow to the opt-out.

  • Map web tags, SDKs, APIs, pixels, server events, real-time bidding, clean rooms, audience lists, data feeds, loyalty and co-marketing programs, and offline transfers.
  • Classify the recipient separately for each service and document the contract relied on.
  • Record whether the flow is sale, sharing, a business-purpose disclosure, or outside scope, with the facts supporting the result.
  • Block unclassified or unsupported transfers until the owner completes the role and opt-out analysis.
Section 3

Who should own Do Not Sell Share Implementation, and what evidence should prove the decision?

Assign an accountable product or engineering owner who can stop the data flow, a privacy owner who controls the legal classification and request logic, and procurement or legal owners for recipient contracts. Marketing and analytics teams should confirm business purposes and destinations; they should not approve their own role classifications without privacy review.

Evidence should connect a test request to the resulting technical state. Keep the request time and method, browser or device scope, profile and account matches, suppression state, network or event evidence, downstream notices, consumer confirmation, privacy-policy disclosure, exception analysis, and remediation.

  • Engineering: prevent covered requests from firing and persist the choice across the identity scope.
  • Privacy: approve flow classifications, request logic, conflict handling, notices, and evidence criteria.
  • Vendor owner: issue required downstream instructions and verify contract and suppression controls.
  • Quality or assurance: test clean-browser, pseudonymous, logged-in, cross-device, and offline scenarios.
Section 4

Which edge cases should teams check before relying on a Do Not Sell Share Implementation decision?

A signal that conflicts with a business-specific setting allowing still controls unless the consumer later gives compliant consent. A financial-incentive conflict follows the separate section 7025 branch. A business cannot treat a later absence of the signal as consent for a known consumer who previously sent one.

Consumers under 16 have opt-in rules for : a consumer aged 13 to 15 may authorize the practice, while a parent or guardian must authorize it for a child under 13. Actual knowledge and willful disregard of age control the statutory branch. Sensitive personal information has a distinct right to limit, with statutory and regulatory exceptions. These controls may share an interface, but the workflow should preserve the different trigger, choice, and legal effect.

  • Do not request identity information when the browser, device, or associated profile can be suppressed without it.
  • Do not omit the opt-out links under the frictionless exception if a signal cannot fully reach applicable offline .
  • Do not offer granular choices without also offering one choice to opt out of all sale and sharing.
  • Wait at least 12 months before asking an opted-out consumer to consent again, except where the regulations allow otherwise.
Section 5

How should teams operationalize Do Not Sell Share Implementation with proportionate controls?

Test from the consumer action to the last covered recipient. Use both interface requests and qualifying opt-out preference signals. Test before consent state exists, after identifiers are assigned, while logged in, after logout, on another device for a known account, and against online and offline transfers. A successful interface state is not enough if network requests, server events, exports, or recipient-side use continue.

Re-run the test when tags, SDKs, destinations, identity graphs, consent tools, account logic, contracts, data uses, or privacy text change. Record failures as control defects with the affected flow, interim block, owner, due date, retest, and closure evidence.

  • Confirm a request is accepted without an account and with no unnecessary information.
  • Confirm covered network and server events stop as soon as feasible, rather than defaulting to the 15-business-day maximum.
  • Confirm third-party notices cover only the period between receipt and compliance and require forwarding during that period.
  • Confirm the privacy policy, notice, link text, status display, and system state all describe the same choice.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding statute for opt-out links or permitted alternatives, preference signals, privacy-policy disclosures, and consumer choices.
leginfo.legislature.ca.gov
Referenced sections
  • Binding definitions of sale, sharing, cross-context behavioral advertising, service provider, contractor, and third party.
Related guides

Explore more topics

California Data Brokers: CCPA, Registration, and DROP Duties
Decide whether a CCPA business is also a California data broker and track registration, privacy metrics, DROP deletion, vendor, and audit duties.
CCPA Consumer Rights Workflow: Requests, Clocks, and Evidence
Route CCPA requests by right, apply the correct verification and response rule, coordinate downstream action, and retain a clear decision record.
CCPA Contract Classification: Service Provider or Third Party?
Classify CCPA recipients from their actual processing and contracts, then document the clauses, restrictions, monitoring, and opt-out consequences.
CCPA Dark Patterns: Rules, Examples, and Review Checklist
Check a CCPA privacy interface for clear language, symmetrical choices, unnecessary steps, and other designs that can invalidate consent.
CCPA Deadlines and Compliance Calendar
Track CCPA request clocks, annual duties, DROP dates, and phased 2026-2030 deadlines for risk assessments, ADMT, and cybersecurity audits.
CCPA Do Not Sell or Share Guide
Classify CCPA sales and sharing, provide valid opt-out methods, honor preference signals, stop disclosures within 15 business days, and notify recipients.
CCPA Do Not Sell or Share: Scope and Implementation
Determine whether a transfer is a CCPA sale or sharing, provide the required opt-out path, honor preference signals, and propagate the choice.
CCPA DSAR Workflow: Intake, Verification, and Response
Run CCPA data-subject requests from intake through verification, search, exception review, downstream action, response, and retained evidence.
CCPA Financial Incentives: Notice, Consent, and Data Value
Assess a loyalty, discount, payment, or service program under the CCPA and document notice, opt-in, withdrawal, and data-value requirements.
CCPA Global Privacy Control (GPC): team obligations and technical implementation
Implement Global Privacy Control as a CCPA sale and sharing opt-out across browsers, devices, known accounts, and relevant downstream systems.
CCPA Minors: Opt-In Rules for Consumers Under 16
Apply the CCPA's under-13 parent authorization and age-13-to-15 consumer opt-in rules for sale or sharing of personal information.
CCPA Notice at Collection: Timing, Content, and Examples
Place a CCPA notice where consumers encounter it before collection and disclose categories, purposes, retention, sale or sharing, and required links.
CCPA Opt-Out Signal Workflow: Detect, Apply, and Test GPC
Process CCPA opt-out preference signals across browsers, devices, profiles, accounts, offline data, conflicts, recipients, and confirmation controls.
CCPA Penalties and Fines: Current Amounts
See current CCPA fines, civil penalties, security-breach damages, adjustment rules, and the facts needed before estimating exposure.
CCPA Personal and Sensitive Information Categories
Classify personal and sensitive personal information under the current CCPA, including exclusions and the duties each category can trigger.
CCPA Privacy Policy Template: Required Content and Review
Draft and maintain a CCPA privacy policy covering data practices, rights, request methods, GPC handling, minors, contacts, and the last-updated date.
CCPA Risk Assessments, Cybersecurity Audits, and ADMT
Apply California's regulations effective January 1, 2026 for risk-assessment triggers, phased cybersecurity audits, ADMT rights, evidence, reviews, and CPPA submissions.
CCPA vs CPRA: What Changed and Which Rules Apply
Compare the original CCPA with the CPRA amendments and learn why current California privacy work must use the CCPA as amended, not two separate laws.
CCPA vs GDPR: Scope, Rights, Duties, and Evidence
Compare the California CCPA and EU GDPR by scope, roles, legal basis, rights, advertising transfers, contracts, security, deadlines, and enforcement.
Does the CCPA apply to my business? Threshold guide
Apply the CCPA revenue, data-volume, and sale-or-sharing revenue thresholds, then check California nexus, control, joint ventures, roles, and exemptions.
US CCPA Applicability Test Guide
Apply the CCPA entity-by-entity: test California nexus, for-profit control, current thresholds, related-entity routes, exemptions, and processing roles.
US CCPA Compliance Checklist
A verifiable CCPA checklist for scope, data mapping, notices, rights, opt-outs, contracts, retention, security, risk assessments, audits, ADMT, and evidence.
US CCPA Compliance Guide
Build a CCPA operating model for entity scope, data mapping, notices, rights, opt-outs, contracts, retention, security, assessments, audits, ADMT, and evidence.
US CCPA Dark Patterns Guide
Review CCPA privacy interfaces for plain language, symmetry, minimal steps, neutral presentation, valid consent, and reliable opt-out operation.
US CCPA Data Broker Crossover Guide
Test whether a CCPA business is also a California data broker, then assign registration, metrics, DROP, deletion, downstream, and audit duties.
US CCPA DSAR Verification Guide
Verify CCPA know, delete, correct, and ADMT-access requests with request-specific, secure, minimized methods without adding friction to opt-outs.
US CCPA Enforcement and Penalties Guide
Understand CPPA investigations, Attorney General civil actions, CCPA administrative orders, current penalties, and the limited security-breach private action.
US CCPA Financial Incentives Guide
Decide whether a CCPA financial-incentive rule applies, then document the notice, data-value method, opt-in, withdrawal, and nondiscrimination checks.
US CCPA GPC Signal Guide
Implement Global Privacy Control under the CCPA across browsers, devices, accounts, ad technology, downstream recipients, and consumer notices.
US CCPA Minors Guide
Apply the CCPA opt-in rules for selling or sharing personal information of consumers under 16, including age bands, authorization, notices, and evidence.
US CCPA Notice at collection Guide
Build a CCPA Notice at Collection for online and offline collection points, including categories, purposes, sale or sharing, retention, links, and change control.
US CCPA Personal and Sensitive PI Categories Guide
Classify CCPA personal information and sensitive personal information, apply exclusions, and map each category to notices, rights, retention, security, sale, and sharing.
US CCPA Privacy Law FAQ
Direct answers on CCPA scope, rights, notices, opt-outs, GPC, minors, sensitive information, financial incentives, and data brokers.
US CCPA Privacy Notices and Disclosures Guide
Choose and maintain each CCPA consumer notice: privacy policy, collection, sale or sharing, sensitive-information limits, financial incentives, and ADMT.
US CCPA Privacy Policy Guide
Build and maintain a CCPA privacy policy covering online and offline practices, 12-month disclosures, consumer rights, request methods, and annual updates.
US CCPA Requirements Guide
Plain-language CCPA requirements covering scope, minimization, notices, rights, opt-outs, contracts, security, records, risk assessments, audits, and ADMT.
US CCPA Scope and Thresholds Guide
CCPA scope and threshold reference covering the current $26,625,000 revenue threshold, the 100,000-consumer-or-household test, related entities, and exemptions.
US CCPA Service Provider Contractor and Third Party Contracts Guide
Classify CCPA recipients and check the distinct contract terms for service providers, contractors, and third parties before disclosing personal information.
US CCPA Service Provider Contractor Contracts Guide
Check CCPA service-provider and contractor agreements for specific purposes, use restrictions, consumer-request support, subcontractors, and remediation.
US CCPA Thresholds Guide
Apply the CCPA business thresholds per legal entity, including the 2025 CPI-adjusted revenue amount, volume and sale-or-sharing tests, and control routes.
What must a CCPA privacy policy include?
A practical guide to CCPA privacy-policy content, placement, annual updates, consumer rights, request methods, and supporting evidence.
What must CCPA service-provider contracts include?
Required CCPA contract terms, role checks, subcontractor flow-downs, oversight rights, and evidence for service providers and contractors.
What should teams do about consumer request verification under the CCPA?
Choose a proportionate CCPA verification method for know, delete, and correct requests without collecting unnecessary identity data.
When does the CCPA require risk assessments or cyber audits?
CCPA triggers, deadlines, evidence, retention, and submission duties for risk assessments and annual cybersecurity audits.