Consent & Cookies

What is Do Not Sell or Share?

"Do Not Sell or Share My Personal Information" is the opt-out right California's CCPA/CPRA grants consumers — and the link businesses must post to honor it — covering both data sales and 'sharing' for cross-context behavioral advertising.

The original CCPA gave Californians the right to opt out of the 'sale' of personal information, defined broadly as disclosure to a third party for money 'or other valuable consideration.' Businesses argued that giving data to ad platforms was not a sale because no money changed hands. The CPRA closed that argument by adding 'sharing' — defined specifically as disclosing personal information for cross-context behavioral advertising, whether or not anything of value is exchanged. Routine ad-tech data flows are squarely covered.

The obligation is concrete: a business that sells or shares personal information must provide a clear and conspicuous 'Do Not Sell or Share My Personal Information' link on its homepage (commonly the footer), process opt-outs without requiring account creation, honor them across the data flows that constitute selling or sharing, and treat the Global Privacy Control browser signal as a valid opt-out request. Opt-outs must persist, and businesses must wait 12 months before asking an opted-out consumer to opt back in.

What actually has to stop: syncing visitor data to advertising platforms for targeting, retargeting pixels transmitting behavioral events, audience uploads, and server-side event forwarding for ad purposes — for that consumer. Analytics confined to your own use and disclosures to true service providers under contract are generally outside the definition.

Enforcement is real: the Sephora settlement ($1.2 million, 2022) targeted a missing sale disclosure and unprocessed GPC signals, and 'inspect the footer link, then test whether opting out actually stops the pixels' is now a standard regulator and plaintiff workflow.

Why it matters for eCommerce

If your store runs the Meta Pixel, Google Ads remarketing, or TikTok events for California visitors, you are 'sharing' under the CPRA and need the footer link, a working opt-out flow, and GPC handling. The common failure is cosmetic compliance — a link that files a request somewhere while the pixels keep firing. Test the flow end to end: opt out, reload, watch the network tab.

Frequently asked questions

Is using advertising pixels really 'selling' or 'sharing' data?
Under the CPRA, sending personal information to ad platforms for cross-context behavioral advertising is 'sharing' regardless of payment, and the Sephora action treated analytics-and-ads arrangements as a 'sale' under the original CCPA. Assume standard ad-tech integrations are covered.
Where does the Do Not Sell or Share link have to appear?
On the business's internet homepage in a clear and conspicuous manner — in practice, the site footer, and commonly every page. California also permits meeting the requirement through an opt-out preference signal; GPC must be honored either way.
Does opting out apply to data already collected?
The opt-out stops future selling and sharing of the consumer's personal information. Consumers who want data removed entirely can pair it with a deletion request, which is a separate CCPA right.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Check your CCPA opt-out implementation

← Back to all glossary terms