Do Not Sell opt-out requests under the CCPA rose 37% in 2024 compared to 2023, according to DataGrail's 2025 Data Privacy Trends Report, which analyzed data subject requests processed for its customers between January and December 2024. No state agency publishes a single official count of opt-out requests filed each year, so this year-over-year growth rate from a major privacy-request processor is the closest thing to a national tracker currently available.

Do Not Sell opt-out requests rose 37 percent in 2024 37% more Do Not Sell opt-outrequests filed in 2024

How many CCPA opt-out requests are filed each year?

Nobody publishes a definitive annual total. The CCPA requires businesses to honor Do Not Sell and Do Not Share requests, but unlike GDPR fines or CCPA enforcement settlements, opt-out volume is never reported to a central state registry, so any answer to "how many" has to come from a privacy-technology vendor's own processing data rather than a government count.

The most current proxy is DataGrail's 2025 Data Privacy Trends Report, built from data subject requests the company processed on behalf of its customers throughout 2024. It found that Do Not Sell opt-out requests grew 37% year over year, a smaller increase than deletion requests but still a clear sign that more California consumers are actively exercising their opt-out rights rather than letting them sit unused.

CCPA/CPRA request growth by type, 2023 to 2024 Deletion82%Do Not Sell (Opt-Out)37%Access-45%bar = actual, tick = target

Figure 1: Year-over-year change in CCPA/CPRA data subject request volume by type, 2023 to 2024. Source: DataGrail, 2025 Data Privacy Trends Report.

Deletion requests grew fastest, at 82%, while access requests actually fell 45% over the same period. Read together, the trend suggests California consumers are shifting from wanting to see their data toward wanting it gone or excluded from sale entirely, and opt-out requests are rising alongside that shift even if they are not the single largest category.

What share of CCPA requests are opt-out versus deletion or access?

Deletion requests remain the largest category by volume, averaging more than 40% of all data subject requests across the businesses DataGrail tracked, a share it has held for four consecutive years. Opt-out and access requests split most of the remaining volume, though DataGrail does not publish an exact percentage for each of those two categories individually.

Request type2024 YoY changeShare of DSR volume
Deletion+82%Over 40% (largest single category)
Do Not Sell (Opt-Out)+37%Remainder, split with access and correction
Access-45%Remainder, split with opt-out and correction
Composition of CCPA/CPRA data subject requests 6040Access, opt-out, and correction combined60Deletion requests40

Figure 2: Deletion accounts for just over 40% of total request volume; the rest splits across access, opt-out, and correction requests. Source: DataGrail, 2024 Data Privacy Trends Report.

If you run a site that collects California resident data, this composition matters for staffing your privacy request process: deletion requests need the most operational capacity, but opt-out requests are the ones tied most directly to advertising and data-sale revenue, and they are the category growing second-fastest.

How much has total request volume grown since CCPA took effect?

Total data subject request volume across DataGrail's customer base rose 246% between 2021 and 2023, climbing from 248 to 859 requests per million identities, according to the company's 2024 Data Privacy Trends Report, published May 1, 2024 and based on an analysis of more than 700 million records. Within that period, 2022 to 2023 alone accounted for a 32% year-over-year increase.

Data subject request volume per million identities 02505007501,00020212023859

Figure 3: Total data subject request volume, including opt-out requests, per million identities tracked. Source: DataGrail, 2024 Data Privacy Trends Report.

Do businesses actually honor CCPA opt-out requests?

Not consistently. DataGrail's audit of more than 5,000 websites, run as part of its 2025 Data Privacy Trends Report, found that 69% of organizations still fire three or more cookie trackers even after a visitor has opted out, an implementation failure rather than a policy one, since the opt-out request was received but not carried through to the ad and analytics tags on the page.

Figure 4: Regulatory milestones shaping how CCPA opt-out rights are exercised and enforced. Source: California Privacy Protection Agency announcements, California Attorney General press releases.

Regulators are treating this gap as an enforcement priority rather than a technical footnote. On September 9, 2025, the California Privacy Protection Agency joined the Colorado and Connecticut Attorneys General to announce a joint investigative sweep targeting businesses that were not honoring Global Privacy Control signals, the browser-level opt-out mechanism the CCPA recognizes as a valid Do Not Sell request. The same announcement referenced past CCPA settlements including a $632,500 penalty against American Honda Motor Co. and a $345,178 penalty against retailer Todd Snyder, both tied to consumer-rights violations.

Businesses that operate in California and have not reviewed how their site actually processes an opt-out signal, as opposed to how their privacy policy says it does, can generate a CCPA-ready privacy policy that discloses Do Not Sell and Do Not Share rights, GPC recognition, and data broker obligations in the language regulators expect to see. Not every business is covered by the law in the first place; see how many businesses must comply with the CCPA and where the revenue and data-volume thresholds fall.

What is California's new Delete Request and Opt-out Platform (DROP)?

DROP is a free, centralized tool built by the California Privacy Protection Agency that lets a California resident submit one opt-out and deletion request that reaches every registered data broker simultaneously, instead of contacting each broker individually. It went live on January 1, 2026, and every registered data broker is required to begin processing requests submitted through DROP by August 1, 2026.

Figure 5: How a single DROP submission reaches every registered California data broker. Source: California Privacy Protection Agency, Data Broker Registry.

DROP does not replace the direct Do Not Sell requests a consumer sends to an individual business's own website. It specifically targets data brokers, companies whose primary business is buying and reselling personal information they did not collect directly from the consumer, which is a narrower category than the businesses covered by the general CCPA. California is one of a growing list of states layering these mechanisms on top of a comprehensive privacy law; see the full US state privacy laws tracker for how other states handle opt-out rights. Once DROP's first full year of processing data becomes available, it should give researchers a genuine, centralized opt-out request count for the data-broker segment of the market for the first time, something no source has provided before.

The Bottom Line

There is still no official, government-published count of how many CCPA opt-out requests are filed each year, and that gap is unlikely to close for ordinary businesses even after DROP starts generating data-broker-specific numbers in 2026. What the available evidence shows clearly is direction: Do Not Sell requests grew 37% in 2024, total request volume more than tripled between 2021 and 2023, and regulators are actively investigating whether businesses actually honor the requests they receive rather than assuming compliance stops at the privacy policy. For any site handling California resident data, the practical risk is not a slow-moving request queue, it is an opt-out signal that reaches the server but never reaches the ad tag, cookie script, or third-party pixel still firing after the fact.

Frequently Asked Questions

How many CCPA opt-out requests are filed each year? There is no single public count, since the CCPA does not require businesses to report opt-out volumes to a state registry. The best available proxy comes from DataGrail's 2025 Data Privacy Trends Report, which found Do Not Sell opt-out requests rose 37% in 2024 over 2023 across the data subject requests it processed for customers between January and December 2024.

What percentage of CCPA requests are opt-out requests versus deletion requests? Deletion is the largest single category, averaging more than 40% of all data subject requests and growing 82% in 2024, while Do Not Sell opt-out requests grew a smaller 37% over the same year and access requests fell 45%, according to DataGrail's 2025 report.

Do businesses actually honor CCPA opt-out requests? Not consistently. DataGrail's audit of more than 5,000 websites found 69% still fire three or more cookie trackers after a visitor opts out, and in September 2025 California, Colorado, and Connecticut announced a joint sweep against businesses ignoring Global Privacy Control signals.

What is California's new Delete Request and Opt-out Platform (DROP)? DROP is a centralized tool that lets California residents send one opt-out and deletion request to every registered data broker at once. It went live on January 1, 2026, and data brokers must begin processing requests submitted through it by August 1, 2026, according to the California Privacy Protection Agency.

Where the Numbers Come From

  1. DataGrail. (2025). "Data Privacy Trends Report 2025, Privacy Request Types." Do Not Sell requests up 37% over 2023; deletion requests up 82%; access requests down 45%, based on DSRs processed January through December 2024.
  2. DataGrail. (2025). "Data Privacy Trends Report 2025, Opt-Out Requests." 69% of organizations fire three or more cookie trackers after opt-out, from an audit of more than 5,000 websites.
  3. DataGrail via PR Newswire. (2024, May 1). "Brace for Pressure: DataGrail Reports Worldwide Surge in Data Privacy Requests." 246% increase in DSR volume from 2021 to 2023, from 248 to 859 requests per million identities, analysis of more than 700 million records.
  4. California Privacy Protection Agency. "Data Broker Registry." DROP live for consumer submissions since January 1, 2026; data brokers required to begin processing requests by August 1, 2026.
  5. California Privacy Protection Agency. (2025, September 9). "Joint Investigative Privacy Sweep: CA, CO, and CT Investigate Businesses Refusing to Honor Consumers' Right to Opt-Out." References prior settlements including $632,500 against American Honda Motor Co. and $345,178 against Todd Snyder.

Note: All figures verified as of August 2026. DROP request volumes were not yet published as of this post's initial publication and will be added once the California Privacy Protection Agency releases a first full-year figure. Opt-out and DSR growth figures are refreshed at least twice a year to track new DataGrail Data Privacy Trends Report editions.