- Regulatory text requiring businesses to process opt-out preference signals as valid requests to opt out of sale or sharing.
"valid request to opt-out of sale/sharing"
Treat a qualifying browser or device privacy signal as a sale-or-sharing opt-out, stop covered disclosure as soon as feasibly possible, extend the opt-out to associated profiles, and preserve proof that downstream flows stopped.
The CCPA regulations require businesses that sell or share personal information to process the signal; a privacy link or cookie banner does not replace that duty.
Structured answer sets in this page tree.
Cited legal and guidance references.
An such as is a technical signal that clearly communicates a consumer's choice to stop sale or sharing of personal information. A business that sells or shares must treat a commonly used, recognized signal as a valid opt-out for the browser or device and every associated consumer profile, including pseudonymous profiles. Do not require identity verification, an account, or extra steps. The signal does not request deletion or stop collection and first-party use by itself.
Detect the signal at every consumer-facing domain, app, and relevant endpoint and stop sale or sharing as soon as feasibly possible. Confirm that the format is commonly used and recognized, such as an HTTP header or JavaScript object, and that the sending mechanism tells consumers the signal opts them out of sale and sharing. The regulations do not condition validity on a California-only disclosure.
Apply the signal to the browser or device and all associated profiles. If the consumer is known, apply it to that consumer, including offline sale or sharing. If the consumer is unknown, do not demand identifying information; optional information may be offered only to extend the request and may be used, disclosed, and retained only to process the opt-out.
A conflicting business-specific setting does not cancel the signal. Honor it, then the business may notify the consumer and seek CCPA-compliant consent. A financial-incentive program may use the regulation's separate confirmation branch. When the consumer is known, the later absence of a signal is not consent to opt back in.
Posting a Do Not Sell or Share link, Alternative Opt-out Link, or privacy-policy form does not excuse signal processing. A business may omit specified links only when it processes signals in a , makes the required privacy-policy disclosures, and the signal fully effectuates online and offline sale-or-sharing opt-outs.
The privacy engineering or consent owner should maintain evidence that the signal was detected, translated into a sale-or-sharing opt-out, applied to the correct scope, propagated downstream, and preserved where the business can recognize the consumer.
Run regression tests after changes to consent software, tag managers, advertising partners, domains, apps, login flows, or identity systems. Test signed-in and signed-out sessions, first visits, cleared storage, multiple browsers, delayed scripts, offline profile propagation, and known-consumer return visits. A visible privacy message does not prove that sale or sharing stopped.
This US CPRA guide turns GPC Handling Workflow into owners, evidence requests, review checkpoints, and reusable operating records in Sorena.
Turn GPC Handling Workflow into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with Sorena.
"valid request to opt-out of sale/sharing"
"On March 29, 2023, the Office of Administrative Law approved the California Privacy Protection Agency’s regulations and filed"
"Businesses must honor opt–out preference signals (“OOPS”) that meet certain requirements, such as the Global Privacy Control"
"GPC lets users signal their desired privacy, just by browsing"
"Organizations should not assume implementation of these Privacy Framework activities or outcomes means that they have met the"