The CCPA “Do Not Sell My Personal Information” Guide
The California Consumer Privacy Act (CCPA) has transformed privacy rights in the US, providing individuals with greater control over their personal data. One of the most visible provisions of this regulation is the CCPA “do not sell my personal information” link that many businesses must display on their websites, forms, checkout pages, etc., before collecting a customer’s personal data.
Honoring users’ requests not to sell their personal data is a compliance obligation and a critical part of creating brand loyalty and consumer confidence, as legal protections are being put in place to protect these requests.
As Jeannine Crooks, an ex-Partner Acquisition & Development Manager of Awin and a founder of Sled Dog Consulting, wisely stated in Phonexa’s Amplify webinar series: “Put your audience first. Seriously. There are always those high-ticket items that can bring you a lot of money if you sell them, but is that really putting your audience first? If it’s not, don’t do it. You may have just spent years building the trust of that audience, and you could lose it all because it seems like you’re chasing their money rather than trying to help their audience”.
Sign up with ValidRecord to protect your business from fraud & screen leads in real-time.
What Does “Do Not Sell My Personal Information” Mean?
In addition to selling consumer data directly, the “Do Not Sell My Personal Information” term applies to renting, releasing, revealing, disseminating, making available, or transferring personal data to a third party in any other way in exchange for any other form of value.
So many companies that believe they do not sell information to third-party entities actually do sell it. If your website uses third-party cookies for behavioral advertising or cross-site tracking, you are likely engaging in the sale of personal information. In this case, you must provide a clear “do not sell my personal information” link to give users a choice regarding their data.
“Personal information” under the CCPA is information that identifies, relates to, characterizes, or is reasonably capable of being associated with you, including your real name, postal address, email address, IP address, purchase history, and browsing history. Every page you visit, every ad you click, your geolocation data, too. Your phone knows your location, and that is tracked.
Another personal information category includes inferred data profiles: inferences. Companies gather all of that data and draw judgments about who you are to build consumer profiles and make predictions.
CCPA vs. CPRA: What’s the Difference?
The original California Consumer Privacy Act (CCPA) gave consumers the basic right to opt out of the selling of their personal data. But all of that changed dramatically with the passage of the California Privacy Rights Act (CPRA) that went into effect on January 1, 2023. The CPRA expanded the framework to cover specifically the “sharing” of personal information for cross-context behavioral advertising, with or without compensation.
Businesses now have to include a “do not sell or share my personal information” link to cover both: selling and sharing. When the customer clicks on this link, they are exercising their CPRA opt-out rights, and the company is prohibited from sharing their data for targeted advertising purposes. The distinction matters because it stops businesses from evading the law by arguing they are merely “sharing” data, rather than “selling” it.
Who Needs to Comply with CCPA and CPRA?
Not every business is required to feature a “we will not sell your information” disclaimer, or a “do not sell” link. The CCPA and CPRA apply specifically to for-profit companies that do business in California and meet certain financial or data volume thresholds.
A business must comply if it meets any of the following criteria:
- Annual gross revenue of over $25 million
- Buys, receives, sells, or shares the personal information of 100,000 or more California residents, households, or devices annually
- Derives 50% or more of its annual revenue from selling or sharing personal information
If your business is located in another state or overseas, but you provide services to people in California and meet these requirements, the law still applies.
How to Handle the Do Not Sell My Personal Information Requests
You must have efficient systems in place when a user decides to exercise their privacy rights and presents a request to opt out of sharing personal information. You must respond to these requests as soon as reasonably practicable, and in any event within 15 business days. If a consumer has opted out, you cannot ask them for reauthorization of the sale or sharing of their data for at least 12 months.
The CCPA has different rules that apply to children. Users under 16 must affirmatively consent to the selling of their personal information, and users under 13 must have parental authority. Providing the link is only part of it – you need to make sure your internal data system complies with every valid request.
Implementing the Link & Notice on Your Website
Companies are required to publish the “do not sell my personal information” CCPA link on your homepage and on every online page where you gather personal information. This link should lead consumers to a page dedicated to personal information or to a list of “do not sell my personal information” choices, making it easy to submit their request.
Important: You cannot require a user to create an account in order to exercise the right to opt out.
The good news is that there are consent management platforms (CMPs) to help you manage CCPA compliance. If a user clicks “do not disclose my personal information”, the platform will automatically update their preferences and prevent non-essential cookies from following them.
It’s legally required to have a clear privacy policy that describes customers’ rights and the exact categories of data collected. Also, companies have to automatically honor a legitimate “do not sell my data” request when a user has enabled a Global Privacy Control (GPC) signal in their browser.
How Consumers Can Protect Their Data
From the consumer’s perspective, discovering that companies commercialize their personal information can be frustrating.
To better protect your personal information, proactively send opt-out requests, use privacy-focused browsers with Global Privacy Control enabled, and be mindful of the details you provide online. Likewise, check website footers for “do not sell my personal information” links and disable third-party tracking.
ValidRecord: Elevating Your Data Compliance & Quality
As data privacy rules get more complicated, ValidRecord can help you remain compliant and prevent marketing fraud:
- iClaim captures, stores, and transfers customer consent to buyers when the lead is sold, providing verifiable digital evidence that the lead is genuine and has given their consent for marketing communications.
- iClear screens leads in real time, allowing you to automatically accept, reject, or flag consumers based on predefined criteria.
Together, iClaim and iClear help create a risk-free environment for lead generation and distribution, so you can buy or sell leads while being confident you comply with CCPA and other pertinent regulations.
Sign up with ValidRecord to screen leads in real-time and prevent fraud.
Frequently Asked Questions
How do laws like CCPA protect my personal data from being sold?
The CCPA protects consumers by requiring companies to properly disclose to customers their personal data collection and intended usage. That offers consumers the obvious choice to opt out of having that data sold or shared with third parties, and it makes it a legal requirement for businesses to honor their privacy decisions.
Are there any legal regulations governing the sale of personal data?
Yes. A few jurisdictions have actually stepped up with extensive privacy laws. California has some of the most thorough privacy laws, the CCPA and CPRA. Within these laws, violations can trigger significant regulatory fines.
Is it legal to sell consumer data?
The short answer is yes, provided you comply with the privacy rules and offer an easy way to opt out. That said, there are still limits on the sale of personal data established by the CCPA, CPRA, VCDPA (Virginia), and CPA (Colorado).
Can I sue a company for selling my information?
The CCPA does not allow consumers to sue a company simply for selling the consumer’s information or for refusing an opt-out request. In general, private claims are limited to particular data breaches, including unencrypted personal information and a failure to use reasonable security measures.