Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Consent Interfaces

Privacy Choices Link

Also known as: Your Privacy Choices link, Your California Privacy Choices link
Simply put

A Privacy Choices Link is a clearly labeled link, often titled "Your Privacy Choices" or "Your California Privacy Choices," that businesses place on their website to let visitors exercise privacy options such as opting out of certain data sharing or sales. It gives consumers a recognizable, direct way to manage how their personal information is used. The specific labeling and placement requirements come from certain US state privacy laws rather than from a single universal standard.

Formal definition

In the context of certain US state privacy frameworks (notably California's regime), a Privacy Choices Link is a mechanism businesses may use to enable consumers to exercise opt-out rights, such as opting out of the sale or sharing of personal information. Where an alternative single-link approach is used in California, guidance indicates the link should be titled "Your Privacy Choices" or "Your California Privacy Choices" and be presented in a conspicuous location. This mechanism operates under an opt-out model characteristic of US state privacy laws, which differs materially from the prior opt-in consent model generally applicable to non-essential cookies under EU and UK law; the evidence provided does not detail exact placement, formatting, or icon requirements, and specific obligations can vary by state and evolve with regulatory guidance.

Why it matters

For businesses subject to certain US state privacy laws, notably California's regime, the Privacy Choices Link is one of the practical ways consumers are given a recognizable route to exercise opt-out rights such as opting out of the sale or sharing of their personal information. Because these frameworks generally operate on an opt-out rather than an opt-in model, the visibility and accessibility of this mechanism matters: if consumers cannot easily find a way to exercise their rights, the underlying opt-out entitlement has little practical effect. A consistent, standardized label such as "Your Privacy Choices" or "Your California Privacy Choices" is intended to make that route recognizable across different websites.

The link also matters because it reflects a materially different compliance approach from the one that generally applies to non-essential cookies under EU and UK law, where a prior opt-in consent model typically governs. Teams that manage compliance across multiple jurisdictions cannot assume that a single mechanism satisfies every regime. A Privacy Choices Link addresses opt-out obligations under applicable US state laws but does not, on its own, satisfy the opt-in consent requirements that generally apply in the EU and UK, nor does it replace the broader privacy notice and record-keeping obligations a business may have.

Businesses should also treat labeling and placement as fact- and jurisdiction-specific rather than universal. Guidance associated with California's regime indicates that where an alternative single-link approach is used, the link should be titled "Your Privacy Choices" or "Your California Privacy Choices" and presented conspicuously. The evidence available here does not detail exact placement, formatting, or icon requirements, and specific obligations can vary by state and evolve with regulatory guidance, so legal review of current requirements in each relevant state remains necessary.

Who it's relevant to

Privacy and compliance officers
Those responsible for US state privacy compliance need to determine whether their organization is subject to laws such as California's regime and, if so, whether a Privacy Choices Link or an alternative approach is appropriate. They should confirm current labeling, placement, and destination requirements for each relevant state, since obligations can vary and evolve, and should not assume the link satisfies opt-in requirements applicable in the EU or UK.
Legal counsel
Counsel advising on multi-jurisdictional privacy programs should assess how the opt-out model behind a Privacy Choices Link differs from the opt-in consent model that generally governs non-essential cookies under EU and UK law. Because exact placement, formatting, and icon requirements are not settled by the evidence here and may change with regulatory guidance, counsel should verify current state-specific rules rather than relying on a single universal standard.
Web developers and marketing teams
Developers and marketing compliance staff implement the link's labeling, conspicuous placement, and the workflow that carries out a consumer's opt-out request. They should coordinate with legal and privacy teams on the correct title and location, and recognize that similar tracking technologies beyond literal cookies may be in scope for the underlying data practices consumers are opting out of.
Consumers exercising privacy rights
Individuals use the Privacy Choices Link as a recognizable, direct route to manage how their personal information is used, including opting out of certain sharing or sales. Resources from organizations such as the NAI can help consumers exercise these choices with participating companies, though the specific options available depend on the applicable state law and the business involved.

Inside Privacy Choices Link

Purpose of the link
A user-facing link, commonly labeled with wording such as 'Your Privacy Choices' or 'Do Not Sell or Share My Personal Information,' that provides a mechanism for individuals to exercise opt-out rights over certain uses of their personal information, including cookie-based tracking. This mechanism is primarily associated with US state privacy frameworks such as the CCPA/CPRA in California, rather than with EU or UK law.
Placement and accessibility
The link is typically expected to be clear, conspicuous, and readily available to users, often placed in the website footer or a persistent location. It is intended to be reachable without unnecessary friction so that users can locate and use it easily.
Opt-out functions it may support
Depending on the applicable US state law and the business's activities, the link may allow users to opt out of the sale or sharing of personal information and, under some frameworks, to limit the use of sensitive personal information. The precise scope of available choices depends on the specific state law and the facts of the business's processing.
Relationship to opt-out signals
In some US jurisdictions, businesses may be required to honor browser-based opt-out preference signals such as the Global Privacy Control (GPC). A privacy choices link often works alongside, rather than instead of, recognition of such signals.
Connection to cookies and tracking technologies
Because cookies, pixels, SDKs, and similar tracking technologies can be involved in the sale or sharing of personal information under US state law definitions, choices made through the link may need to translate into changes in how these technologies operate on the user's device.

Common questions

Answers to the questions practitioners most commonly ask about Privacy Choices Link.

Does adding a 'Your Privacy Choices' link mean my site is compliant with cookie consent rules everywhere?
No. A privacy choices link is one mechanism associated primarily with certain US state privacy frameworks, and its presence does not by itself establish compliance across jurisdictions. In most EU and UK contexts, cookie consent obligations generally require prior, affirmative opt-in consent for non-essential cookies under the ePrivacy rules and GDPR, which an opt-out style link does not satisfy on its own. The scope and legal effect of such a link vary by jurisdiction, and it supports compliance rather than guaranteeing it. Legal judgment remains necessary.
Is a 'Privacy Choices' link the same thing as an opt-out of cookies?
Not exactly. A privacy choices link is a labeled entry point that typically directs users to controls or requests, which may include opt-outs of certain data practices such as sale or sharing under some US state laws. Whether it functions as a cookie opt-out depends on how it is configured and which practices it is connected to. It is a navigational and disclosure element, not itself a consent or opt-out setting, and the underlying mechanisms it links to determine its actual effect. The relationship between such links and technical cookie controls should be verified against the applicable framework.
Where should a Privacy Choices link be placed on a website?
Placement practices commonly favor a clear and conspicuous location, such as the website footer, so the link is reachable from most pages. Some organizations also surface it within a preference center or privacy settings area. The specific placement expectations may differ by jurisdiction and by the framework a site is following, and this entry does not prescribe a single universally required location. Confirm placement requirements against the applicable law and any relevant regulatory guidance.
How does a Privacy Choices link relate to a consent management platform (CMP)?
A privacy choices link often serves as an access point that routes users to controls a CMP or preference center manages, such as toggles for cookie categories or requests to opt out of certain processing. The link is the labeled entry point, while the CMP typically handles the presentation of choices, application of preferences, and consent or opt-out logging. Relying on a CMP does not remove the need for legal review, since the tool supports but does not replace compliance judgment.
Should the Privacy Choices link connect to the same controls used for cookies, pixels, and other tracking technologies?
It may be appropriate to route the link to controls covering the relevant tracking technologies, since similar technologies such as pixels, local storage, SDKs, and fingerprinting can fall within the same rules as cookies even though they are not literally cookies. Whether a single link should encompass all of these depends on the practices involved and the applicable framework. Mapping which technologies each control governs is a fact-specific exercise that this definition does not resolve on its own.
Do we need to keep records of choices submitted through a Privacy Choices link?
Record-keeping of consent or opt-out choices is generally regarded as important for demonstrating that user preferences were captured and honored, and consent logging is a recognized organizational component of consent management. The specific record-keeping obligations tied to choices submitted through such a link depend on the governing framework and may differ between jurisdictions. This entry does not specify retention periods or particular documentation requirements, which should be determined by reference to the applicable law and any relevant regulatory guidance.

Common misconceptions

A privacy choices link satisfies EU and UK cookie consent requirements.
The link is generally an opt-out mechanism tied to US state privacy laws such as the CCPA/CPRA. In most EU and UK contexts, non-essential cookies typically require prior, freely given, specific, informed, and unambiguous consent through a clear affirmative action, which an opt-out link alone does not provide. The two approaches address different legal standards.
Displaying the link automatically makes a business compliant with applicable US state law.
The link is one component that supports compliance, not a guarantee of it. Compliance also depends on factors such as which state laws apply, whether the business actually sells or shares personal information, whether opt-out signals like GPC are honored, and whether the opt-out is effectively implemented. Legal judgment about the specific facts remains necessary.
Every website needs a privacy choices link.
Whether the link is required depends on the applicable jurisdiction and the nature of the business's data practices. Obligations vary across individual US states and differ from EU and UK regimes, so the requirement is not universal and should be assessed against the specific laws that apply to the business.

Best practices

Determine which jurisdictions and specific US state laws apply to your business and confirm whether a privacy choices link, and which opt-out functions, are required for your particular processing activities before implementing generic wording.
Place the link in a clear, conspicuous, and persistent location such as the footer, and use labeling consistent with the applicable law's expectations so users can readily find and use it.
Ensure that opt-out choices made through the link actually take effect for the relevant cookies, pixels, SDKs, and similar tracking technologies, rather than presenting a link that does not change underlying behavior.
Assess whether you are required to recognize browser-based opt-out preference signals such as Global Privacy Control in the applicable states, and coordinate signal handling with the link-based mechanism.
Keep the link distinct from EU/UK cookie consent mechanisms and do not treat an opt-out link as a substitute for prior opt-in consent where that standard applies, so that each legal regime is addressed on its own terms.
Document your analysis and configuration, and involve legal counsel to confirm that the implementation matches your data practices, recognizing that tools and links support compliance but do not replace legal judgment.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps