If you're managing CCPA compliance, you've likely deployed a "Do Not Sell or Share My Personal Information" link on your site. But simply having the link isn't enough. This checklist guides you through what a compliant "Do Not Sell" implementation truly requires. It goes beyond what looks good to your legal team and focuses on what withstands regulatory scrutiny.
We'll cover technical placement, request handling, record-keeping, and the operational systems that transform a static link into a functioning consumer right. If you can't check every box below with documentation, you're carrying compliance debt.
Prerequisites
Before starting this audit, confirm you have:
- Access to your privacy notice and website footer code to verify exact link placement and wording.
- Documentation of all data sharing arrangements including sales, rentals, and disclosures for cross-context Behavioural Advertising.
- Your DSAR intake and tracking system to ensure "Do Not Sell" requests flow into the same workflow as other consumer rights.
- A list of all third-party data recipients such as vendors, ad networks, and analytics providers.
If you're missing any of these, stop here. You can't audit what you can't see.
Checklist Items
1. Link Placement Meets CCPA Visibility Standards
Requirement: Cal. Civ. Code § 1798.135(a)(1) requires a "clear and conspicuous" link titled "Do Not Sell or Share My Personal Information."
Check:
- Link appears in your website footer on every page.
- Link uses the exact statutory language (not "Opt Out" or "Privacy Choices").
- Link is the same size and visual weight as other footer links.
- Link is functional on mobile devices without requiring zoom or horizontal scroll.
What good looks like: A user lands on any page, scrolls to the footer, and immediately sees "Do Not Sell or Share My Personal Information" in readable type. Clicking it works on the first try.
2. Request Intake Doesn't Require Account Creation
Requirement: § 1798.135(a)(2) prohibits requiring account creation to submit a "Do Not Sell" request.
Check:
- The link directs to a form that accepts requests without login.
- Form fields are limited to what you need for verification (typically email or a device identifier).
- You're not asking for information you don't already have about the consumer.
What good looks like: An anonymous visitor can submit a valid "Do Not Sell" request using only the information you'd use to match them to existing records, no registration wall, no password creation.
3. You Process Requests Within 15 Business Days
Requirement: CCPA regulations require action on "Do Not Sell" requests within 15 business days of receipt.
Check:
- Your DSAR system logs receipt timestamps for "Do Not Sell" requests.
- You have an automated or manual process that flags requests approaching the 15-day deadline.
- You've documented your verification method for matching requests to consumer records.
- You send confirmation to the consumer once you've honored the request.
What good looks like: Every "Do Not Sell" request gets a unique ticket number, a timestamp, and a status that moves from "received" to "verified" to "actioned" within 15 business days. You can pull a report showing compliance with this timeline.
4. Opt-Out Applies to All Covered Data Sharing
Requirement: The opt-out must stop all sales and sharing as defined under CCPA, not just a subset.
Check:
- You've mapped every third party that receives personal information for monetary or other valuable consideration.
- Your "Do Not Sell" suppression list is distributed to all those third parties.
- You've confirmed that ad networks, data brokers, and analytics vendors stop receiving opted-out consumers' data.
- You have a technical mechanism (suppression file, API call, or manual notification) that propagates opt-outs.
What good looks like: When a consumer opts out, you can trace the suppression through your data pipeline to every downstream recipient. If you're using a Consent Management Platform for cookie-based tracking, the opt-out also triggers withdrawal of non-essential third-party cookies.
5. You Don't Discriminate Against Opt-Out Users
Requirement: § 1798.125(a)(1) prohibits denying goods or services, charging different prices, or providing a different level of quality to consumers who exercise their "Do Not Sell" right.
Check:
- Opt-out users still access the same content and features as other visitors.
- You're not serving a degraded experience (slower load times, fewer articles, restricted functionality).
- If you offer a financial incentive for allowing sales, it's documented under a separate CCPA-compliant program with its own notice.
What good looks like: An opted-out consumer and a non-opted-out consumer see identical site functionality. If you're running a loyalty program tied to data use, it's disclosed in a separate notice and consumers can opt in affirmatively.
6. Records Prove Compliance Over Time
Requirement: While CCPA doesn't specify retention periods for "Do Not Sell" records, you need proof of compliance if the California Attorney General or a consumer brings a claim.
Check:
- You retain logs of "Do Not Sell" requests for at least 24 months.
- Logs include request date, verification method, and action taken.
- You document when and how you notified third parties of each opt-out.
- You can produce this documentation in response to a regulatory inquiry.
What good looks like: You can pull a CSV of all "Do Not Sell" requests from the past two years, showing receipt date, consumer identifier, and the date you stopped sharing their data with named third parties.
7. Your Privacy Notice Discloses the Right Accurately
Requirement: § 1798.130(a)(5) requires your privacy notice to describe the consumer's right to opt out of sales.
Check:
- Your privacy notice includes a section on "Do Not Sell" rights.
- It explains what constitutes a "sale" under your business model.
- It lists the categories of third parties who receive personal information.
- It includes a direct link to your "Do Not Sell" submission page.
What good looks like: A consumer reading your privacy notice understands exactly what data sharing will stop if they opt out, and they can navigate to the opt-out form in one click.
Common Mistakes
Treating "Do Not Sell" as a Consent Notice setting. The CCPA opt-out covers all sales and sharing, not just browser-based tracking. If you're only suppressing cookies but still sharing hashed email identifiers with data brokers, you're non-compliant.
Requiring re-verification on every visit. Once a consumer opts out, that preference should persist. Don't ask them to opt out again unless you've genuinely lost their record (and even then, you need a defensible data retention policy).
Conflating "Do Not Sell" with GDPR withdrawal of consent. These are distinct rights under different laws. A CCPA opt-out doesn't necessarily mean the consumer is withdrawing GDPR consent for processing, and vice versa. Track them separately.
Ignoring mobile app obligations. If you operate a mobile app, CCPA requires an equivalent opt-out mechanism. A website-only link isn't sufficient if you're collecting personal information through iOS or Android applications.
Next Steps
If you found gaps in this audit, prioritize items 1-4. These are the elements most likely to surface in a regulatory investigation or consumer complaint. Items 5-7 focus on proving you've built a sustainable compliance program, not just a one-time fix.
Document what you've checked and what you've remediated. The California Attorney General has enforcement authority under CCPA, and your ability to show good-faith compliance efforts matters if you're ever in their crosshairs. A completed checklist with timestamps is evidence. An unaudited link in your footer is a liability.





