"Do Not Sell or Share My Personal Information" is one of the most copied lines on the internet, sitting in the footer of sites that legally need it right next to sites that copied it from a template without checking whether they do. Adding a link you don't need isn't a violation, but it does create a promise you now have to honor, an actual working opt-out mechanism behind a link that says it exists. Skipping a link you do need is the real problem, and it's a specific, checkable question, not a guess.

What actually triggers the requirement

The CCPA, and the CPRA that amended it starting in 2023, applies to a "business" as the statute defines the term, not to every website. A for-profit entity that does business in California and collects California consumers' personal information falls under the law if it meets at least one of three thresholds:

  • Annual gross revenue over $25 million.
  • Buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year.
  • Derives 50% or more of its annual revenue from selling or sharing consumers' personal information.
25 million dollars in annual revenue is one of three thresholds that can trigger CCPA coverage $25M annual revenue, one of threeCCPA/CPRA coverage thresholds

A small site with modest traffic and no ad-network revenue share can sit entirely outside these thresholds, in which case the opt-out link isn't a legal requirement at all, no matter how much visitor data it collects. A business that meets even one threshold is covered, and the size of the site or the industry it's in doesn't change that.

Meeting the revenue or data threshold isn't the whole test

Being a covered business is the first gate. The second, narrower gate is whether the business actually "sells" or "shares" personal information as the statute defines those words, because the opt-out link is specifically about the right to opt out of sale or sharing, not a general right to opt out of all data collection.

"Sale" under the CCPA is defined broadly: exchanging personal information for money or other valuable consideration. "Sharing," added by the CPRA, covers disclosing personal information to a third party for cross-context behavioral advertising, even when no money changes hands. This is the part that catches businesses off guard: running standard third-party advertising or analytics tags that pass visitor identifiers to an ad network or attribution vendor can qualify as "sharing" under this definition, even though nobody at the business would describe what they're doing as "selling data."

Do Not Sell (2020 CCPA) vs. Do Not Sell or Share (CPRA)

CCPA (2020)CPRA amendment
CoversSale of personal informationSale, plus cross-context sharing
Triggered by ad/analytics tags with no payment
Must honor Global Privacy Control
Link wordingDo Not Sell My InfoDo Not Sell or Share My Info
Sensitive-data limit right

A business that runs no third-party ad tags, doesn't share data with attribution or ad-tech vendors, and doesn't otherwise sell information for value, may meet the revenue threshold and still have nothing to opt out of, because it isn't selling or sharing in the statute's sense. In practice this is rare for any site running standard analytics or advertising, which is why most covered businesses end up needing the link even when nobody involved thinks of what they're doing as "selling data."

If you're genuinely unsure whether your ad or analytics setup counts as "sharing," the safer assumption for most sites running Google Analytics, Meta Pixel, or a similar tool alongside real California traffic is to treat it as sharing and add the link, since the cost of an unnecessary opt-out mechanism is far lower than the cost of an enforcement action for skipping a required one.

Placement and mechanics the law is specific about

Once the link is required, the CPRA and its implementing regulations are specific about where it goes and how it has to work, not just that it exists somewhere on the site.

Homepage visibility. The link (or a clear equivalent, some businesses use a single combined "Your Privacy Choices" link that covers this along with other rights) needs to be reachable from the homepage, and from any other page where personal information is collected, not buried three clicks deep in a settings page nobody finds.

It has to actually work. A link that leads to a broken form, an email address that goes unanswered, or a page that just restates the privacy policy without an actual mechanism to opt out isn't compliant. The opt-out has to be a real, functioning process a consumer can complete without creating an account or jumping through unnecessary verification steps.

Global Privacy Control counts as an opt-out. Since the CPRA's regulations took effect, businesses covered by the requirement have to treat the GPC browser signal, a setting a visitor can turn on once and carry across every site they visit, as equivalent to clicking the link manually. A visitor browsing with GPC enabled should have their opt-out honored automatically, without being shown a banner asking them to also click the link.

No dark patterns. The opt-out flow can't be designed to be harder to complete than the flow for opting back in, and can't use confusing language, pre-selected choices, or extra friction intended to discourage the request. Regulators have specifically called out opt-out flows that ask unnecessary confirmation questions or require an account login as compliance risks.

What this means for your privacy policy

The link itself is a UI requirement, but it doesn't stand alone. Your privacy policy needs to describe the categories of personal information sold or shared, the categories of third parties that receive it, and the consumer rights the CCPA and CPRA grant, know, delete, correct, opt out of sale and sharing, and limit use of sensitive personal information, in language that matches what the link on your site actually does. A policy that doesn't mention selling or sharing at all, sitting next to a footer link that says "Do Not Sell or Share My Personal Information," is an inconsistency that's easy for a regulator or a plaintiff's attorney to point at.

Our Privacy Policy Generator builds CCPA and CPRA-specific disclosures, including the opt-out right and sensitive-data limitations, based on the jurisdictions and data practices you tell it about, so the policy and the link on your site tell the same story. If GDPR also applies to your business, GDPR vs CCPA Cookie Consent Requirements Explained covers how the two laws' opt-in and opt-out models sit side by side on one site.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.