Skip to main content
Category: Data Subject Rights

Do Not Sell or Share

Also known as: Do Not Sell or Share My Personal Information, Do Not Sell/Do Not Share, Do Not Sell My Personal Information
Simply put

"Do Not Sell or Share" is a consumer right under California's privacy law that lets people tell a business to stop selling or sharing their personal information. Once a business receives this opt-out request, it generally must stop those activities unless the consumer later authorizes them again. This is an opt-out right specific to California and is not automatically the same in other U.S. states or under other privacy regimes.

Formal definition

Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), "Do Not Sell or Share" is an opt-out right that allows a consumer to direct a business to cease the selling and sharing of their personal information. Following receipt of a valid opt-out request, a business generally may not resume selling or sharing that consumer's personal information unless the consumer subsequently authorizes it again. This entry addresses the existence and general nature of the opt-out right only; it does not cover the statutory definitions of "sell" and "share," the mechanics of honoring opt-out signals, exemptions, timing obligations, or enforcement. This right originates in California law; treatment of comparable opt-out rights differs across other jurisdictions and privacy frameworks, and should not be assumed to be equivalent.

Why it matters

The "Do Not Sell or Share" right is a cornerstone of California's consumer-facing privacy protections because it gives individuals direct control over two of the most commercially significant uses of their personal information: selling it and sharing it. For businesses subject to the CCPA as amended by the CPRA, honoring this opt-out is not optional once a valid request is received; a business generally may not resume selling or sharing a consumer's personal information unless that consumer later authorizes it again. This creates an ongoing operational obligation rather than a one-time task, and demonstrating that opt-outs are actually honored is a matter of accountability, not merely stated intent.

The practical stakes are heightened because this right is specific to California law. Organizations that operate nationally often mistakenly assume a single opt-out mechanism satisfies comparable rights across other U.S. states or other privacy regimes. Treatment of similar opt-out rights differs across jurisdictions and frameworks, so a California-compliant approach cannot be assumed to be portable. Compliance depends on context, jurisdiction, and implementation, and conflating California's opt-out with other regimes is a common source of gaps.

This entry addresses only the existence and general nature of the opt-out right. It does not cover the statutory definitions of "sell" and "share," the mechanics of honoring opt-out signals, applicable exemptions, timing obligations, or enforcement consequences. Readers evaluating their obligations should treat those as separate questions requiring their own analysis.

Who it's relevant to

Privacy and compliance officers at businesses subject to the CCPA/CPRA
Those responsible for California privacy compliance must ensure the organization can receive opt-out requests and can demonstrably stop selling and sharing a consumer's personal information once a valid request is received. Because accountability requires evidence rather than stated intent, they should be able to show that opt-outs are honored on an ongoing basis, not just acknowledged.
Legal and regulatory teams advising on multi-state operations
Counsel and advisors should note that this right originates in California law and that comparable opt-out rights in other U.S. states or other privacy regimes should not be assumed equivalent. A single opt-out approach may not satisfy differing requirements across jurisdictions, and each regime warrants its own analysis.
Privacy engineers and product teams implementing opt-out functionality
Teams building consumer-facing controls need to translate the opt-out right into working mechanisms that stop the selling and sharing of personal information and prevent resumption absent later authorization. The detailed mechanics of honoring opt-out signals fall outside this entry and require reference to the applicable California requirements.
Data governance and stewardship leads
Governance functions responsible for data ownership, lineage, and policy should ensure that opt-out status is tracked so that downstream selling or sharing activities can be halted for consumers who have exercised the right. This intersects with, but is distinct from, the security controls protecting the underlying data.

Inside Do Not Sell or Share

Consumer Opt-Out Right
A right, established under California law (the CCPA as amended by the CPRA), allowing consumers to direct a business not to sell or share their personal information. The 'sale' concept covers disclosures for monetary or other valuable consideration, while 'share' was added by the CPRA to address disclosures for cross-context behavioral advertising. This right is a creature of California statute and does not automatically apply under other regimes such as the EU GDPR or UK GDPR, which structure comparable objections differently.
'Sell' Versus 'Share' Distinction
Under the California framework, 'sell' generally refers to disclosing personal information to a third party for monetary or other valuable consideration, whereas 'share' generally refers to disclosing personal information for cross-context behavioral advertising, whether or not for consideration. The two terms overlap but are not identical, and a business may trigger one without the other depending on the nature of the disclosure.
Opt-Out Mechanism
A method by which a business enables consumers to exercise the opt-out, typically including a clearly labeled link or equivalent facility. This is an opt-out model rather than an opt-in model, meaning processing may generally proceed until the consumer objects, which differs from consent-based frameworks in other jurisdictions.
Opt-Out Preference Signals
Browser- or platform-level signals that communicate a consumer's opt-out choice automatically, which businesses subject to the California framework are generally expected to recognize and honor. The specifics of which signals must be honored and how depend on regulatory guidance and implementation context.
Scope of 'Personal Information'
The right attaches to personal information as defined under the applicable California statute. Note that measures such as encryption or tokenization do not, by themselves, remove data from the scope of personal information; data may remain personal information even after such controls are applied.

Common questions

Answers to the questions practitioners most commonly ask about Do Not Sell or Share.

Does turning off the sale of my data mean my personal information is no longer processed at all?
No. The Do Not Sell or Share right, which originates in the California regime (the CCPA as amended by the CPRA), addresses specific processing activities defined as a sale or a share, not all processing. A consumer who exercises this right can still have their personal information processed for many other purposes, such as fulfilling a transaction or meeting a legal obligation, depending on the applicable exemptions. This entry does not cover the full scope of other consumer rights or the lawful bases and exemptions in detail.
Is Do Not Sell or Share the same as consent, so that offering it satisfies my broader privacy obligations?
No. Do Not Sell or Share is an opt-out mechanism specific to the California framework, not a consent mechanism, and it should not be conflated with consent as a lawful basis under regimes such as the EU or UK GDPR. Providing this opt-out addresses one defined set of activities under California law and does not by itself establish compliance with other frameworks or with other obligations. Compliance generally depends on jurisdiction, context, and implementation, and this entry does not address obligations outside the California regime.
How should a business surface the Do Not Sell or Share option to consumers?
Under the California regime, businesses that engage in activities meeting the definition of a sale or a share are typically expected to provide a clear and conspicuous method for consumers to exercise this right, which in practice often includes a designated link and honoring recognized opt-out preference signals. The specific presentation and technical requirements are governed by the applicable statute and its implementing regulations, which this entry does not reproduce in full; consult the current regulatory text for exact obligations.
What internal capabilities are generally needed to honor a Do Not Sell or Share request?
Honoring such requests typically requires the ability to identify where the relevant personal information flows to third parties, to distinguish activities that meet the sale or share definition from those that do not, and to propagate the opt-out to downstream recipients where applicable. This intersects with data governance capabilities such as data lineage and mapping, though those governance functions are distinct from the security controls that protect the data. This entry does not prescribe specific tooling.
How can a business demonstrate that it is actually honoring these requests rather than merely stating an intent to?
Accountability under governance and privacy frameworks generally requires demonstrable evidence, not merely stated intent. In practice this typically means maintaining records of requests received and actions taken, documenting how opt-out signals are recognized and applied, and being able to show that downstream recipients were instructed accordingly. The precise evidentiary expectations depend on the applicable regulatory text and enforcement context, which this entry does not detail.
Does honoring Do Not Sell or Share affect what data can be retained or transferred internationally?
Not directly. This right governs whether specific sale or share activities may occur; it is a separate matter from data retention rules and from cross-border transfer mechanisms, which are governed by other provisions and, in the case of international transfers, often by other regimes entirely. Those topics are out of scope for this entry, and businesses should address retention and transfer obligations under their applicable frameworks separately.

Common misconceptions

'Do Not Sell or Share' is a universal privacy right that applies wherever a consumer is located.
This right originates in California law (the CCPA as amended by the CPRA) and is scoped to that regime. Other jurisdictions address objection and behavioral advertising differently; the EU GDPR and UK GDPR, for example, do not use this framing. Applicability generally depends on the business meeting statutory thresholds and on the consumer's connection to California, and treatment elsewhere varies.
'Sell' and 'share' mean the same thing, so honoring one satisfies the other.
The two terms are distinct under the California framework. 'Sell' generally involves disclosure for monetary or other valuable consideration, while 'share' generally involves disclosure for cross-context behavioral advertising regardless of consideration. A disclosure may trigger one but not the other, and businesses should assess each independently rather than assuming equivalence.
This is a consent (opt-in) requirement like those found in some other privacy regimes.
It is generally structured as an opt-out mechanism, meaning the relevant processing may proceed until a consumer objects, rather than requiring affirmative consent beforehand. This differs from consent-based lawful bases used in other frameworks, and consent should not be conflated with the opt-out model.

Best practices

Map where personal information is disclosed and determine, for each flow, whether it constitutes a 'sale', a 'share', both, or neither under the California framework, documenting the analysis as demonstrable evidence rather than relying on stated intent.
Provide a clearly labeled and accessible opt-out mechanism, and ensure the pathway actually stops the qualifying disclosures rather than only recording a preference.
Configure systems to detect and honor opt-out preference signals in line with current regulatory guidance, and test that they propagate to downstream recipients.
Do not treat encryption or tokenization as taking data out of scope; assess whether the underlying data remains personal information subject to the right.
Assess this obligation as jurisdiction-specific and do not assume that honoring the California opt-out satisfies objection or advertising requirements under other regimes such as the EU GDPR or UK GDPR.
Maintain auditable records showing how opt-out requests and signals are received, actioned, and enforced across third parties, since accountability generally requires demonstrable evidence.