Right to Opt-out
The right to opt-out lets consumers tell a business to stop certain uses of their personal information, such as selling or sharing it. Under an opt-out approach, data may be used or shared by default, and the individual must take an affirmative step to prevent it. This differs from opt-in models, where no such use is permitted until the individual first agrees.
The right to opt-out is a consumer privacy right, prominent in US state privacy frameworks such as the California Consumer Privacy Act (CCPA), that allows a consumer to direct a business to cease specified processing activities, notably the sale or sharing of their personal information. It reflects an opt-out consent model in which processing is permissible by default until the consumer exercises the right, in contrast to the opt-in model generally required for non-essential cookies and similar technologies under EU and UK ePrivacy and GDPR rules. Applicable regulations typically require businesses to provide reasonable and simple methods for exercising the right; for example, regulatory provisions permit a business to require use of a specific opt-out means so long as that means is reasonable and simple for the consumer. The precise scope, covered processing activities, required mechanisms (which may include recognition of opt-out preference signals), and enforcement expectations vary by jurisdiction and by individual statute, and this definition does not resolve those jurisdiction-specific details.
Why it matters
The right to opt-out is central to how several US state privacy frameworks, most prominently the California Consumer Privacy Act (CCPA), allocate control over personal information. Because these frameworks generally operate on an opt-out model, personal information may be sold or shared by default until a consumer takes an affirmative step to stop it. This places the burden of action on the individual, which is a meaningful contrast to the opt-in model generally required for non-essential cookies and similar technologies under EU and UK ePrivacy and GDPR rules, where processing is not permitted until the individual first agrees.
For businesses operating across jurisdictions, this distinction has direct compliance consequences. A consent posture designed around US opt-out rights will not typically satisfy the prior, affirmative consent standard expected in most EU jurisdictions, and vice versa. Treating the two models as interchangeable is a common source of compliance risk. Organizations that serve users in multiple regions generally need to account for both approaches rather than assuming that meeting one standard is sufficient everywhere.
The practical scope of the right, including which processing activities it covers, what mechanisms must be offered, and whether opt-out preference signals must be recognized, varies by jurisdiction and by individual statute. Because these details differ and regulatory expectations continue to evolve, organizations should treat the right to opt-out as a jurisdiction-specific obligation and confirm the applicable requirements for each region in which they operate.
Who it's relevant to
Inside Right to Opt-out
Common questions
Answers to the questions practitioners most commonly ask about Right to Opt-out.

