Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Consumer Privacy Rights

Do Not Sell My Personal Information

Also known as: Do Not Sell or Share My Personal Information, Do Not Sell My Info, Do not sell or share rule
Simply put

"Do Not Sell My Personal Information" is a phrase, commonly appearing as a link on websites, that lets people tell a business to stop selling their personal information. It reflects an opt-out right created under California's privacy law, so it generally applies to consumers in that jurisdiction rather than universally. In some versions the link also covers the "sharing" of personal information.

Formal definition

"Do Not Sell My Personal Information" refers to a consumer opt-out right established under the California Consumer Privacy Act (CCPA), which generally requires covered businesses to enable consumers to direct that their personal information not be sold. Following subsequent amendments reflected in the frequently used phrasing "Do Not Sell or Share My Personal Information," the right is often presented as covering both the "sale" and the "sharing" of personal information, each as defined under the applicable California statutory framework. Operationally, businesses subject to this obligation typically provide a clearly labeled link (commonly in the website footer or app menu) through which consumers can exercise the opt-out. This is an opt-out mechanism rather than the prior opt-in consent model that generally applies to non-essential cookies in most EU jurisdictions under the ePrivacy Directive and the GDPR; the definitions of "sale," "share," and covered business, as well as the precise scope of the right, depend on the California statutory text and implementing regulations and are not addressed in detail here. The evidence provided does not describe the full eligibility criteria, exemptions, or how this right interacts with other US state privacy laws or with signals such as Global Privacy Control.

Why it matters

The "Do Not Sell My Personal Information" link is one of the most visible consumer-facing privacy controls in the United States, and its presence signals whether a business has operationalized the opt-out rights created under the California Consumer Privacy Act (CCPA). For consumers in California, this link is the primary way to direct that a business stop selling their personal information, and following amendments reflected in the phrasing "Do Not Sell or Share My Personal Information," it commonly extends to the "sharing" of that information as well. Because covered businesses are generally required to provide a clearly labeled link through which consumers can exercise this right, its absence or improper implementation can indicate a compliance gap.

For privacy officers and legal counsel, the distinction between this opt-out model and the opt-in consent model that generally applies to non-essential cookies in most EU jurisdictions is critical. Under the ePrivacy Directive and the GDPR, businesses typically must obtain prior consent before placing non-essential cookies, whereas the California framework generally allows the relevant processing to occur until a consumer opts out. Treating a single mechanism as satisfying both regimes is a common and consequential error; a compliant "Do Not Sell or Share" link does not by itself address EU consent obligations, and vice versa.

The scope of the right depends heavily on the statutory definitions of "sale," "share," and "covered business" under California law and its implementing regulations. Because these definitions, along with exemptions and interactions with other US state privacy laws, are not addressed in the underlying definition here, organizations should not assume that implementing the link resolves all related obligations. The mechanism is a required consumer touchpoint, but its correct configuration and the underlying data flows require case-specific legal analysis.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for privacy programs need to determine whether their organization is a covered business under the CCPA and, if so, ensure that a properly labeled opt-out link is presented and honored. They should also map how this opt-out right relates to, but does not replace, obligations under other regimes such as EU cookie consent requirements.
Legal counsel and compliance teams
Counsel must interpret the California statutory definitions of "sale," "share," and covered business, assess applicable exemptions, and advise on how the opt-out interacts with other US state privacy laws. Because these questions turn on the current statutory text and implementing regulations not detailed here, they generally require case-specific legal judgment rather than reliance on a tool alone.
Web developers and app teams
Developers typically implement the "Do Not Sell or Share My Personal Information" link in the website footer or app menu and build the back-end processes that give effect to a consumer's opt-out request. Correct placement, labeling, and functional handling of requests are part of operationalizing the right.
Marketing and advertising compliance teams
Because the right can affect activities that may constitute a "sale" or "sharing" of personal information under California law, marketing teams should understand which data flows and advertising practices may be implicated and how honoring an opt-out affects them. The specific classification of any given practice depends on the applicable statutory definitions.

Inside Do Not Sell My Personal Information

Opt-out mechanism
A required means for consumers to direct a business not to sell (and, under some laws, share) their personal information. Under California law this is typically presented through a clearly labeled link or an equivalent method, reflecting the opt-out model common to US state privacy laws rather than the opt-in consent model prevalent in the EU.
Statutory definition of 'sale'
The scope of the obligation depends on how the applicable statute defines 'sale.' Under the CCPA as amended by the CPRA, 'sale' can extend beyond monetary exchange to certain disclosures for other valuable consideration, which may capture some advertising and data-sharing arrangements. The precise reach is fact-specific and has been subject to interpretive debate.
'Sharing' for cross-context behavioral advertising
The CPRA added the concept of 'sharing' for cross-context behavioral advertising, which is why the required disclosure is often expressed as 'Do Not Sell or Share My Personal Information.' This addresses certain advertising activities that might not meet the definition of a 'sale.'
Global Privacy Control (GPC) and opt-out preference signals
Some US state frameworks, including California, treat browser-based opt-out preference signals such as GPC as a valid way for consumers to exercise opt-out rights. Businesses within scope may be required to recognize and honor such signals, though technical implementation and the precise obligations continue to evolve.
Consent management and disclosure tooling
Consent management platforms (CMPs) and related tools can help present opt-out links, capture opt-out requests, and honor preference signals. These tools support compliance efforts but do not by themselves guarantee compliance, which also depends on legal judgment and accurate configuration.
Record-keeping
Handling opt-out requests generally involves logging and honoring consumer choices so that a business can demonstrate it has processed requests. The specific retention and documentation expectations depend on the applicable statute and regulatory guidance.

Common questions

Answers to the questions practitioners most commonly ask about Do Not Sell My Personal Information.

Does the "Do Not Sell My Personal Information" link mean the business is selling my data in the way I'd normally understand that word?
Not necessarily. Under the California Consumer Privacy Act (CCPA) as amended by the CPRA, "sale" is defined broadly to include disclosing or making personal information available to a third party for monetary or other valuable consideration. This can capture arrangements that many people would not intuitively call a "sale," such as sharing identifiers with advertising or analytics partners. The presence of the link reflects this broad statutory definition rather than a narrow commercial transaction, and whether a given data flow qualifies as a "sale" or "share" depends on the specific facts and remains an area of interpretation.
Is offering a "Do Not Sell My Personal Information" link enough to make a business compliant everywhere?
No. This mechanism is primarily associated with certain US state privacy laws, notably the CCPA/CPRA in California, and several other US states have adopted comparable opt-out approaches with their own terminology and requirements. It does not reflect the EU or UK model, which generally relies on prior opt-in consent for non-essential cookies and similar technologies under the ePrivacy rules and the GDPR rather than an opt-out of "sale." A single opt-out link should not be treated as a universal compliance solution, and businesses typically need to assess obligations jurisdiction by jurisdiction with legal input.
Where should the "Do Not Sell My Personal Information" link be placed on a website?
Under the CCPA/CPRA, the opt-out mechanism is generally expected to be clear and conspicuous, and it has commonly been placed in the website footer or a privacy-related menu so it is reasonably accessible on relevant pages. Some businesses use combined phrasing such as "Do Not Sell or Share My Personal Information" to reflect the CPRA's addition of a right to opt out of "sharing" for cross-context behavioral advertising. Exact placement and wording expectations may evolve with regulatory guidance, so current requirements for each applicable state should be confirmed.
How does an opt-out link relate to Global Privacy Control (GPC) signals?
The opt-out link is a user-initiated request made through the interface, while GPC is a browser or device signal that communicates an opt-out preference automatically. In California, regulators have indicated that businesses subject to the CCPA/CPRA are generally expected to treat a recognized opt-out preference signal such as GPC as a valid opt-out request. In practice this means a compliance approach may need to handle both the manual link and automated signals. How signals must be honored can vary by state and continues to develop, so specifics should be verified against current guidance.
What records should a business keep when a consumer uses the opt-out mechanism?
Businesses handling opt-out requests generally need to be able to demonstrate that requests were received and acted upon, which typically involves logging when a request was made and how it was applied to relevant data flows. This supports accountability and responses to any regulatory inquiry. A consent management platform (CMP) or preference-management tool can help capture and store this information, but such tools support recordkeeping rather than guarantee compliance, and the appropriate retention and detail of records should be assessed with legal advice for each applicable regime.
How quickly and how completely does an opt-out request need to take effect across advertising and analytics partners?
Opt-out requests generally need to be actioned within the timeframes set by the applicable law and applied not only to the business's own processing but also propagated to third parties that received the personal information for "sale" or "sharing," so that downstream partners honor the opt-out. This often requires coordination with vendors, tags, and SDKs, since these technologies fall within the same rules even when they are not literally cookies. Exact deadlines, the scope of downstream obligations, and how they apply to each partner depend on the specific state law and current regulatory interpretation, which should be confirmed for each jurisdiction.

Common misconceptions

A 'Do Not Sell My Personal Information' link is required everywhere, including the EU and UK.
This mechanism arises from US state privacy laws such as the CCPA/CPRA in California and reflects an opt-out model. It is not the governing standard in the EU or UK, where cookies and tracking are generally addressed through the ePrivacy rules on placing information on a device and, for personal data, the GDPR's opt-in consent model. Obligations vary by jurisdiction, and the geographic scope should always be considered.
If a business does not exchange data for money, the opt-out requirement does not apply.
Under the CCPA as amended by the CPRA, 'sale' can extend beyond monetary exchange to certain disclosures for other valuable consideration, and 'sharing' separately covers cross-context behavioral advertising. Whether a particular activity falls within these definitions is fact-specific and has been subject to interpretive debate, so a no-money arrangement does not automatically remove the obligation.
Presenting an opt-out link is enough to comply, and the tool handles the rest.
The link is one component. Businesses within scope may also need to honor opt-out preference signals such as GPC, actually process and log requests, and apply the choice across relevant systems. CMPs and similar tools support these tasks but do not replace legal judgment, and their presence does not guarantee compliance.

Best practices

Determine whether your organization falls within the scope of the applicable US state privacy law before implementing an opt-out mechanism, and document the geographic and legal basis for your approach.
Analyze whether your data flows constitute a 'sale' or 'sharing' under the relevant statutory definitions, recognizing that these can extend beyond monetary exchange and cover cross-context behavioral advertising; involve legal counsel where the analysis is fact-specific.
Present a clearly labeled opt-out mechanism (for example, 'Do Not Sell or Share My Personal Information') consistent with the requirements of the applicable law, and make it straightforward for consumers to use.
Configure systems to recognize and honor opt-out preference signals such as Global Privacy Control where the applicable framework requires it, and monitor evolving guidance on implementation.
Maintain records of opt-out requests and preference signals so you can demonstrate that consumer choices were received and applied across relevant systems.
Treat CMPs and related tooling as support for compliance rather than a guarantee of it, and pair technical configuration with periodic legal review as enforcement positions and guidance evolve.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.