Do Not Sell My Personal Information
"Do Not Sell My Personal Information" is a phrase, commonly appearing as a link on websites, that lets people tell a business to stop selling their personal information. It reflects an opt-out right created under California's privacy law, so it generally applies to consumers in that jurisdiction rather than universally. In some versions the link also covers the "sharing" of personal information.
"Do Not Sell My Personal Information" refers to a consumer opt-out right established under the California Consumer Privacy Act (CCPA), which generally requires covered businesses to enable consumers to direct that their personal information not be sold. Following subsequent amendments reflected in the frequently used phrasing "Do Not Sell or Share My Personal Information," the right is often presented as covering both the "sale" and the "sharing" of personal information, each as defined under the applicable California statutory framework. Operationally, businesses subject to this obligation typically provide a clearly labeled link (commonly in the website footer or app menu) through which consumers can exercise the opt-out. This is an opt-out mechanism rather than the prior opt-in consent model that generally applies to non-essential cookies in most EU jurisdictions under the ePrivacy Directive and the GDPR; the definitions of "sale," "share," and covered business, as well as the precise scope of the right, depend on the California statutory text and implementing regulations and are not addressed in detail here. The evidence provided does not describe the full eligibility criteria, exemptions, or how this right interacts with other US state privacy laws or with signals such as Global Privacy Control.
Why it matters
The "Do Not Sell My Personal Information" link is one of the most visible consumer-facing privacy controls in the United States, and its presence signals whether a business has operationalized the opt-out rights created under the California Consumer Privacy Act (CCPA). For consumers in California, this link is the primary way to direct that a business stop selling their personal information, and following amendments reflected in the phrasing "Do Not Sell or Share My Personal Information," it commonly extends to the "sharing" of that information as well. Because covered businesses are generally required to provide a clearly labeled link through which consumers can exercise this right, its absence or improper implementation can indicate a compliance gap.
For privacy officers and legal counsel, the distinction between this opt-out model and the opt-in consent model that generally applies to non-essential cookies in most EU jurisdictions is critical. Under the ePrivacy Directive and the GDPR, businesses typically must obtain prior consent before placing non-essential cookies, whereas the California framework generally allows the relevant processing to occur until a consumer opts out. Treating a single mechanism as satisfying both regimes is a common and consequential error; a compliant "Do Not Sell or Share" link does not by itself address EU consent obligations, and vice versa.
The scope of the right depends heavily on the statutory definitions of "sale," "share," and "covered business" under California law and its implementing regulations. Because these definitions, along with exemptions and interactions with other US state privacy laws, are not addressed in the underlying definition here, organizations should not assume that implementing the link resolves all related obligations. The mechanism is a required consumer touchpoint, but its correct configuration and the underlying data flows require case-specific legal analysis.
Who it's relevant to
Inside Do Not Sell My Personal Information
Common questions
Answers to the questions practitioners most commonly ask about Do Not Sell My Personal Information.

