Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Consent Interfaces

Your Privacy Choices

Also known as: Your California Privacy Choices
Simply put

"Your Privacy Choices" is the standardized wording used for a link that certain US businesses place on their websites to let people exercise privacy rights, such as opting out of the sale or sharing of their personal information. Clicking the link typically takes the user to a form or settings page where they can submit their requests. The term reflects US state privacy law practice, which generally relies on giving people the ability to opt out rather than asking them to opt in beforehand.

Formal definition

"Your Privacy Choices" is a prescribed link label used to provide a consumer-facing mechanism for exercising opt-out and related rights under certain US state privacy laws. According to the evidence, businesses may title this alternative link "Your Privacy Choices" or "Your California Privacy Choices," and it is intended to route residents of California and certain other states with comparable laws to a form or interface for exercising their statutory rights. This mechanism generally supports opt-out-based rights (for example, opting out of the sale or sharing of personal information), which is distinct from the opt-in consent model that typically applies to non-essential cookies and similar technologies under EU and UK law (the ePrivacy regime for device access and the GDPR for subsequent processing). The evidence does not specify the exact placement requirements, the full set of triggering states, or the precise rights covered, and these details vary by state law and evolving regulatory guidance; practitioners should confirm applicability against the specific statutes and any implementing regulations relevant to their operations.

Why it matters

The "Your Privacy Choices" link reflects a distinctly US approach to privacy rights, one built primarily around giving people the ability to opt out rather than requiring businesses to obtain opt-in consent beforehand. For compliance teams operating across jurisdictions, this distinction matters a great deal. The opt-out model that this link supports, for example, opting out of the sale or sharing of personal information, is fundamentally different from the opt-in consent model that generally applies to non-essential cookies and similar technologies under EU and UK law, where the ePrivacy regime governs access to information on a user's device and the GDPR governs any subsequent processing of personal data. Treating one framework's mechanism as satisfying the other's requirements is a common and consequential error.

Standardized wording also matters because it reduces ambiguity for consumers and helps businesses demonstrate that they have provided a recognizable, consistent route to exercising rights. According to the evidence, businesses may title this alternative link "Your Privacy Choices" or "Your California Privacy Choices," and it is intended to route residents of California and certain other states with comparable laws to a form or interface for exercising their statutory rights. Using the prescribed label helps signal to users where they can act, and it aligns the business with the practice contemplated by the relevant state framework.

Because the specifics vary, the practical significance of the link depends on the exact statutes that apply to a given business. The evidence does not specify the full set of triggering states, the precise placement requirements, or the complete set of rights covered, and these details differ by state law and evolving regulatory guidance. Organizations should therefore treat the link as one component of a broader compliance program and confirm applicability against the specific laws and any implementing regulations relevant to their operations, rather than assuming that adding the link alone establishes compliance.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for operationalizing US state privacy rights need to understand where and how the "Your Privacy Choices" link should be presented and where it routes users. Because placement requirements, triggering states, and covered rights vary by statute and are not fully specified in the available evidence, these professionals should confirm applicability against the specific laws and any implementing regulations relevant to their business.
Legal counsel
Counsel advising on multi-state and cross-border compliance should note that the link reflects the opt-out model of US state privacy law and is distinct from the opt-in consent requirements that generally apply under EU and UK law. They can help determine which state laws apply, whether the prescribed label is required, and what unresolved or state-specific interpretive questions remain.
Web developers
Developers implementing the link must ensure it uses the prescribed wording and connects users to a functional form or settings interface where opt-out and related requests can be submitted. They should coordinate with legal and privacy teams on placement, since the exact positioning requirements depend on the applicable state law rather than a single universal standard.
Marketing compliance teams
Teams managing advertising and data-sharing practices are directly affected, since the link commonly supports opting out of the sale or sharing of personal information. They should understand how a user's choices flow through to campaign and data-sharing operations, while recognizing that the link is one part of a broader compliance program and does not by itself guarantee compliance.

Inside Your Privacy Choices

Opt-out link or control
"Your Privacy Choices" is a standardized link or button used primarily under certain US state privacy laws (such as California's CPRA framework) to give consumers a mechanism to exercise opt-out rights, for example opting out of the sale or sharing of personal information or targeted advertising. Its precise required wording and placement depend on the applicable state law and implementing regulations.
Scope of the choices offered
The control typically routes users to options such as opting out of the sale/sharing of personal information and limiting the use of sensitive personal information. The exact rights covered vary by state, and not every US state that has enacted privacy legislation mandates this specific label or the same set of choices.
Relationship to opt-out signals
In several US states, businesses may also be required to honor browser-based opt-out signals such as Global Privacy Control. "Your Privacy Choices" is a user-facing control that can operate alongside, but does not necessarily replace, the obligation to recognize such signals where that obligation applies.
Jurisdictional basis
This mechanism reflects the opt-out model common to US state privacy laws rather than the opt-in consent model generally required in the EU and UK for non-essential cookies and similar technologies. It is not a recognized standard for satisfying EU ePrivacy or GDPR consent requirements.

Common questions

Answers to the questions practitioners most commonly ask about Your Privacy Choices.

Does displaying a "Your Privacy Choices" link mean my site is compliant with EU cookie consent rules?
No. "Your Privacy Choices" is a control associated primarily with certain US state privacy frameworks, which generally rely on an opt-out model. EU rules under the ePrivacy Directive and GDPR typically require prior, affirmative opt-in consent before non-essential cookies are placed or accessed. An opt-out link alone does not satisfy the EU standard of consent that is freely given, specific, informed, and unambiguous. Sites operating across jurisdictions generally need to assess each applicable regime separately rather than assuming one mechanism covers all.
Is "Your Privacy Choices" just a rebranded name for a general cookie consent banner?
Not exactly. Although both relate to how users exercise choices over tracking, they typically serve different purposes. A cookie consent banner in the EU context is generally oriented toward obtaining opt-in consent before non-essential cookies are set. "Your Privacy Choices" is more commonly used as an opt-out control linked to concepts such as the sale or sharing of personal information and targeted advertising under some US state laws. The exact scope depends on the applicable framework, and the two mechanisms should not be treated as interchangeable.
Where should the "Your Privacy Choices" link be placed on a website?
In practice, such opt-out controls are often placed where users can readily find them, such as in the website footer, a privacy menu, or within the privacy policy. The goal is generally to make the choice reasonably accessible. Because specific placement and prominence expectations can vary by jurisdiction and evolving regulatory guidance, you should confirm the requirements applicable to the state laws or frameworks that govern your site rather than relying on a single fixed placement.
How does "Your Privacy Choices" interact with a Global Privacy Control (GPC) signal?
A "Your Privacy Choices" link typically offers a manual, user-facing way to exercise choices, while a signal such as GPC is a browser- or device-level mechanism that can communicate an opt-out preference automatically. Under some US state frameworks, honoring recognized opt-out preference signals may be expected in addition to providing a manual control. Whether and how you must recognize such signals depends on the specific law that applies, so both the manual link and any required signal handling should be evaluated together.
Should choices made through "Your Privacy Choices" be logged or recorded?
Maintaining records of user choices is generally advisable to support accountability and to demonstrate that opt-out requests were received and acted upon. Consent management platforms and similar tools can help capture and store these choices, but such tools support compliance rather than guarantee it. The extent and format of record-keeping that may be required depends on the applicable framework, and organizations should align their logging practices with the specific obligations that govern them.
Do we need to apply opt-out choices across all our systems and vendors, or only on the website where the link appears?
An opt-out expressed through "Your Privacy Choices" is generally intended to take effect for the relevant processing, which can extend beyond a single page to related systems, tags, and third-party recipients involved in the activities being opted out of. Coordinating this often requires mapping which vendors, pixels, SDKs, and data flows are affected and ensuring the choice propagates to them. The precise reach depends on the applicable law and your data practices, so a technical and organizational review is typically needed to implement the opt-out effectively.

Common misconceptions

Displaying a "Your Privacy Choices" link makes a website compliant everywhere.
This control is designed around the opt-out approach found in certain US state privacy laws. It does not, on its own, satisfy the prior opt-in consent generally required in most EU jurisdictions and the UK for analytics, advertising, and other non-essential cookies and technologies. Obligations vary by jurisdiction, and the presence of this link should not be treated as universal compliance.
"Your Privacy Choices" and a cookie consent banner are the same thing.
They generally serve different legal purposes. A consent banner in the EU/UK context typically seeks affirmative opt-in before non-essential cookies are set, whereas "Your Privacy Choices" typically provides an opt-out mechanism for rights recognized under some US state laws. A business operating across regions may need both, configured to reflect each applicable regime.
Adding the link means a business no longer needs to honor browser opt-out signals.
In states where honoring signals such as Global Privacy Control is required, that obligation is generally separate from providing a user-facing opt-out link. The specifics depend on the applicable state law, so both may be required rather than one substituting for the other.

Best practices

Confirm which US state laws apply to your users and whether the specific "Your Privacy Choices" label, wording, and placement are mandated in those states, since requirements are not uniform across states.
Do not rely on this opt-out control to meet EU or UK requirements; implement separate opt-in consent mechanisms for non-essential cookies and similar technologies where the ePrivacy rules and GDPR apply.
Where applicable state law requires it, ensure your systems can recognize and honor browser-based opt-out signals such as Global Privacy Control in addition to the user-facing link.
Map the specific rights the control must cover in each relevant jurisdiction (for example opt-out of sale/sharing and limits on sensitive personal information) and reflect any differences in the choices you present.
Maintain records of opt-out requests and how they are processed, and periodically review the control against evolving state regulations and enforcement guidance.
Treat consent management platforms and pre-built "Your Privacy Choices" templates as tools that support compliance, and validate their configuration against the specific laws applicable to your operations rather than assuming they guarantee compliance.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide