Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
CCPA "Do Not Sell or Share" Disclosure TemplateLaws and Regulations
4 min readFor Privacy Officers

CCPA "Do Not Sell or Share" Disclosure Template

California's updated CCPA regulations clarified the "Do Not Sell or Share My Personal Information" requirements three months before enforcement. If you're still drafting disclosure language from scratch each time a new category surfaces, you're wasting time and risking inconsistency.

This template provides defensible language for your CCPA disclosure notice, with customization fields for your specific data practices. It's built around the regulatory requirements for notice, transparency, and user-enabled privacy controls approved by the California Office of Administrative Law.

Purpose of the Template

Use this template to create the disclosure notice that must accompany your "Do Not Sell or Share" link under the updated CCPA regulations. It's not your full privacy policy. It's the specific notice explaining:

  • Which categories of personal information you sell or share
  • The business purposes for selling or sharing
  • How users can exercise their opt-out right
  • How you'll honor user-enabled privacy controls like Global Privacy Control

You need this disclosure when you collect personal information from California residents and either sell it to third parties or share it for cross-context Behavioural Advertising.

Prerequisites

Before customizing this template, document:

  1. Your data inventory: Which categories of personal information you actually sell or share (not just collect)
  2. Your third-party recipients: Who receives this information and what they do with it
  3. Your opt-out mechanism: Whether you support Global Privacy Control, browser signals, or only manual opt-out links
  4. Your verification process: How you'll confirm a user's identity when they submit an opt-out request

If you haven't mapped your data flows to CCPA's eleven statutory categories of personal information, do that first. This template won't fix an incomplete data inventory.

The Template

DO NOT SELL OR SHARE MY PERSONAL INFORMATION

We sell or share the following categories of personal information 
for business purposes:

[SELECT ALL THAT APPLY:]
☐ Identifiers (such as email addresses, device IDs, or cookie identifiers)
☐ Internet or network activity (such as browsing history, search history, 
  or interaction with advertisements)
☐ Geolocation data
☐ Inferences drawn from the above to create a profile about preferences 
  or behavior

We sell or share this information with:
[LIST RECIPIENT CATEGORIES:]
• Advertising networks
• Data analytics providers
• [Add other third-party categories]

Business purposes for selling or sharing:
[LIST SPECIFIC PURPOSES:]
• Delivering targeted advertising based on your browsing activity
• Measuring advertising campaign performance
• [Add other purposes]

YOUR OPT-OUT RIGHTS

You have the right to opt out of the sale or sharing of your personal 
information. To exercise this right:

1. Click the "Do Not Sell or Share My Personal Information" link 
   [LOCATION: in our website footer / at the bottom of this page]

2. Use a browser or extension that sends an opt-out preference signal, 
   such as Global Privacy Control. We recognize and honor these signals.
   [DELETE IF YOU DON'T SUPPORT GPC]

3. Email us at [PRIVACY EMAIL ADDRESS] with "CCPA Opt-Out Request" 
   in the subject line

We will process your opt-out request within [15] business days. You do 
not need to create an account to submit an opt-out request.

After you opt out, we will not sell or share your personal information 
unless you later provide authorization allowing us to do so again.

SENSITIVE PERSONAL INFORMATION

[INCLUDE ONLY IF YOU COLLECT SENSITIVE CATEGORIES:]
We [do / do not] use or disclose sensitive personal information for 
purposes other than those permitted under CCPA Section 7027(m). 

If we do, you have the right to limit our use of this information by 
[DESCRIBE OPT-OUT MECHANISM].

Last updated: [DATE]

Customization Instructions

Categories of information: Delete any checkbox you don't use. If you sell geolocation data, check that box. If you don't, remove it. Don't list categories you merely collect but never sell or share.

Recipient categories: Be specific. "Third-party partners" is vague. "Advertising networks that deliver personalized ads based on your browsing history" meets the transparency requirement.

Business purposes: Avoid vague terms like "marketing" or "analytics". Specify purposes, such as "Delivering ads for products you've viewed on other websites".

Opt-out mechanisms: If you support Global Privacy Control, state it clearly and explain how it works. If you only offer a manual link, remove the GPC paragraph but ensure your link is prominent.

Processing timeline: CCPA gives you 15 business days to honor opt-out requests. Don't promise faster processing unless you can deliver consistently.

Sensitive personal information: Include this section only if you collect data like precise geolocation or account credentials. If not, delete the paragraph.

Validation Steps

After customizing the template, verify compliance:

  1. Cross-check your privacy policy: Ensure this disclosure matches your full privacy notice. Contradictions create enforcement risk.

  2. Test your opt-out link: Click it. Does it work? Does it offer a clear choice without requiring account creation?

  3. Verify GPC implementation: If you claim to honor Global Privacy Control, test it with a GPC-enabled browser. Your CMP should detect the signal and apply the opt-out automatically.

  4. Review contract language: Ensure your service provider and contractor agreements include the required CCPA provisions. Your disclosure is ineffective if your vendors aren't contractually bound to respect opt-outs.

  5. Document your data flows: Be prepared to show records of which categories you sell or share if asked by the California Privacy Protection Agency.

The California Office of Administrative Law approved these regulations, but the California Privacy Protection Agency will continue rulemaking on cybersecurity audits, risk assessments, and automated decision-making. When those rules arrive, update this disclosure. Establish a review schedule now to avoid last-minute scrambles before enforcement dates.

Your disclosure notice isn't just a compliance tool. It's a transparency tool that works only when it accurately reflects your data practices. Customize it honestly, test it thoroughly, and update it when your practices change.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like