TL;DR, Quick Answer
7 min readCalifornia Civil Code section 1798.135 requires a business that sells or shares personal information to post a link titled "Do Not Sell or Share My Personal Information" on its internet homepages, and the California Privacy Protection Agency's regulations place that link in the header or footer. The word "share" was added by the CPRA and covers passing personal information to a third party for cross-context behavioral advertising, with no money changing hands. A business that sells or shares must also process opt-out preference signals such as the Global Privacy Control, whether or not it posts the link.
What is the Do Not Sell or Share My Personal Information link?
California Civil Code section 1798.135 requires a business that sells or shares personal information to post a link titled "Do Not Sell or Share My Personal Information" on its internet homepages, and that link is how a California consumer submits an opt-out request. The right behind it sits in section 1798.120, which lets a consumer "at any time" direct a business not to sell or share their personal information. Copy the title character for character; the statute writes the words out instead of describing them.
What exactly must the link text say?
The wording is set by statute, and section 1798.135, subdivision (a)(1), names the link "Do Not Sell or Share My Personal Information." Subdivision (a)(2) adds a second link, "Limit the Use of My Sensitive Personal Information." Subdivision (a)(3) lets a business replace both with one combined link, and section 7015(b) of the California Privacy Protection Agency's regulations states that a business choosing that route "shall title the link, 'Your Privacy Choices,' or, 'Your California Privacy Choices,'" with the CPPA's opt-out icon beside it.
The older phrasing, "Do Not Sell My Personal Information," predates the CPRA amendments and quotes a version of section 1798.135 that no longer stands.
Where on a site does the link have to sit?
Section 7013(c) of the CPPA regulations places the link precisely: it "shall be a conspicuous link" that is "located at either the header or footer of the business's internet homepage(s)." Section 7003(c) defines conspicuous as appearing "in a similar manner as other similarly-posted links," at a font size and color at least approximately matching the links next to it. For mobile applications, section 7003(d) moves the link into the privacy policy, reachable from the app's platform or download page.
Section 7013(a)(1) sets what happens on click: the link either opts the consumer out, or leads to a webpage where the consumer "can learn about and make that choice." A privacy policy with no opt-out mechanism does neither.
| Option | Required link title | Where it goes | Source |
|---|---|---|---|
| Two separate links | "Do Not Sell or Share My Personal Information" plus "Limit the Use of My Sensitive Personal Information" | Header or footer of every homepage | Civil Code 1798.135(a)(1), (a)(2) |
| One combined link | "Your Privacy Choices" or "Your California Privacy Choices", with the opt-out icon adjacent | Header or footer of every homepage | CPPA regs 7015(b) |
| No link, signals honored frictionlessly | None | Privacy policy carries the notice of right to opt out plus four required statements | Civil Code 1798.135(b)(1), CPPA regs 7025(f), (g) |
| No link, no sale or sharing | None | Privacy policy states that the business does not sell or share | CPPA regs 7013(g) |
What does "share" mean in this link?
Sharing is defined in Civil Code section 1798.140 as transferring "a consumer's personal information by the business to a third party for cross-context behavioral advertising," and the same section defines cross-context behavioral advertising as "the targeting of advertising to a consumer based on the consumer's personal information obtained from the consumer's activity across businesses, distinctly branded internet websites, applications, or services, other than" the one the consumer intentionally interacts with. No money appears anywhere in that definition. Selling, defined in the same section, is the one that turns on "monetary or other valuable consideration."
This split is where most explainers of the link go wrong. A site that drops an advertising pixel and receives nothing in return is not selling, and it is still sharing, which triggers the link on its own. The CPRA added "share" and rewrote the link title around it, a change traced in the evolution from CCPA to CPRA. Audit every tag against the definition of cross-site tracking.

Who has to display the link?
A business that sells or shares personal information has to display it, and section 7013(g) of the CPPA regulations excuses a business only when it "does not sell or share personal information" and "states in its privacy policy" that it does not. Both conditions must hold. Section 7013(h) then bars a business from selling or sharing personal information it collected while the notice of right to opt out was missing, unless the consumer affirmatively consents.
Whether an entity counts as a business is set by section 1798.140(d)(1), which lists three qualifying conditions: annual gross revenues in excess of twenty-five million dollars, a figure the statute states is adjusted under section 1798.185(a)(5); buying, selling or sharing the personal information of 100,000 or more consumers or households annually; or deriving 50 percent or more of annual revenues from selling or sharing personal information. Check the current statutory text before relying on the first figure, since the adjustment mechanism moves it. The scope and thresholds breakdown covers how those conditions interact, and the consumer rights explainer covers what a qualifying business owes beyond this link.
How does the link relate to the Global Privacy Control?
Section 7025(b) of the CPPA regulations states that "a business that sells or shares personal information shall process any opt-out preference signal" meeting its requirements "as a valid request to opt-out of sale/sharing," and the Global Privacy Control is the browser signal built to meet them. The California Attorney General's office states that the GPC "must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information."
Section 7025(e) closes the loophole people reach for: "Even if the business posts the above-referenced links, the business must still process opt-out preference signals." Posting the link buys no exemption from the signal.
Section 7026(f)(1) then sets the clock: stop selling and sharing "as soon as feasibly possible, but no later than 15 business days from the date the business receives the request."

Can a business drop the link entirely?
Section 1798.135(b)(1) lets a business skip the link when it honors opt-out preference signals in a frictionless manner, and section 7025(f) of the CPPA regulations defines frictionless. The business charges no fee for using the signal, does not change the consumer's experience of the product, and does not display "a notification, pop-up, text, graphic, animation, sound, video, or any interstitial content in response to the opt-out preference signal."
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
Section 7025(g) adds that the signal has to fully effectuate the request. A business that shares online and also sells personal information offline cannot use the exception, because a browser signal reaches only the browser. The privacy policy still has to describe the opt-out right, state that the business processes signals frictionlessly, explain how to enable one, and list any other request method.
What does this mean for an analytics setup?
An analytics setup triggers the link when it passes visitor data to a third party for ad targeting, and leaves it untriggered when the data stays first-party. Flowsery's privacy-first analytics is cookie-free, EU-hosted and GDPR by design. Map every tag against the section 1798.140 definition, using the CCPA analytics compliance guide as the checklist, then decide whether the link belongs in the footer.
Frequently Asked Questions
Is "Do Not Sell My Personal Information" still an acceptable link title?
Civil Code section 1798.135(a)(1) names the link "Do Not Sell or Share My Personal Information," so the shorter title reflects pre-CPRA text. A site running the old wording tells California visitors it opts them out of sales while staying silent on sharing. Match the statute.
Does the link have to be on every page of a site?
Section 7013(c) of the CPPA regulations places the link "at either the header or footer of the business's internet homepage(s)," plural because a business can run more than one homepage. A global footer satisfies it and puts the link on every page as a side effect.
Can a business hide the link behind a cookie banner?
Section 7003(c) requires the link to appear "in a similar manner as other similarly-posted links," at comparable font size and color. A link that exists only inside a dismissible banner is not in the header or footer where section 7013(c) puts it.
Does honoring the Global Privacy Control remove the need for the link?
A business drops the link only under the frictionless conditions in sections 7025(f) and 7025(g) of the CPPA regulations: no fee, no changed product experience, no interstitial response to the signal, four statements in the privacy policy, and a signal that fully effectuates the request. Short of that, section 7025(e) requires both the link and signal processing.
What is the difference between the opt-out link and the sensitive information link?
Civil Code section 1798.135(a)(1) covers sale and sharing of personal information, while subdivision (a)(2) covers a separate right to limit the use of sensitive personal information. The two rights come from different statutory sections and apply independently. Subdivision (a)(3) allows one combined link titled "Your Privacy Choices" or "Your California Privacy Choices."
How fast does a business have to act on a request from the link?
Section 7026(f)(1) of the CPPA regulations requires the business to stop selling and sharing "as soon as feasibly possible, but no later than 15 business days from the date the business receives the request." It also has to notify any third party that received the data in that gap and direct them to honor the opt-out. Section 7026(k) bars asking the consumer to opt back in for 12 months.
Where does the opt-out link appear on a mobile app instead of a homepage?
Section 7003(d) of the CPPA regulations moves the link off the app screen and into the privacy policy instead. The app's platform page or download page has to link to that privacy policy, so a consumer can reach the opt-out disclosure before installing anything.
What size does a business have to be before this link requirement applies?
Section 1798.140(d)(1) sets three thresholds, and meeting any one qualifies a company as a business under the statute: annual gross revenue over twenty-five million dollars, buying, selling or sharing the personal information of 100,000 or more consumers or households a year, or deriving 50 percent or more of annual revenue from selling or sharing personal information. The revenue figure adjusts under section 1798.185(a)(5), so check the current text before relying on it.
Does an ad pixel that pays a site nothing still count as sharing personal information?
It does, because section 1798.140 defines sharing as transferring personal information for cross-context behavioral advertising, with no mention of payment anywhere in that definition. Selling is the definition that requires monetary or other valuable consideration, and sharing sits apart from it. A pixel that hands data to an ad partner for free still triggers the link.
What does a business owe third parties after it processes an opt-out request from the link?
Section 7026(f)(1) requires the business to notify any third party that received the consumer's data during the window before the opt-out took effect and direct that party to honor the request too. The business itself has to stop selling and sharing within 15 business days. Section 7026(k) then bars asking that consumer to opt back in for 12 months.
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Glossary Terms


Understanding CPRA, California's privacy rights act
The CPRA amended the CCPA in 2023, adding sensitive personal information rules, a right to correct data, and a dedicated enforcement agency, the CPPA.


Under the GDPR and the CCPA, is an IP address personal data?
Under the GDPR, is an IP address personal data whenever the site operator has legal means to identify the visitor, the CJEU held in Breyer. US law is split.


Google Lists Seven Separate Causes of not set in GA4
Google's docs give not set in GA4 a different cause per dimension, from a missing session_start to an empty content_group. Here is each cause and its fix.


Reversibility decides pseudonymisation vs anonymisation under the GDPR
Reversibility decides pseudonymisation vs anonymisation. Article 4(5) data stays personal data. Recital 26 anonymous data leaves the GDPR for good.
What Server Side Tracking Fixes, and What It Leaves Untouched
Learn what server side tracking moves to your own server, which Safari cookie caps it escapes, how to deduplicate events, and why consent obligations stay.


What the Numbers Say About Average Bounce Rate by Industry
Nine tracked industries return a documented average bounce rate by industry ranging from 35.76% to 48.38%, sourced from Databox data dated September 2024.
Related Articles


Working Through the Average Order Value Formula Step by Step
The average order value formula divides revenue by orders, and a single discount code or return policy can quietly distort every number a team reports.


How B2B and B2C Sites Compare on Average Session Duration Benchmarks
Databox's own data puts average session duration benchmarks at 77.61 seconds for B2B sites and 92.33 seconds for B2C sites, split by industry and device too.


What Average Session Duration Actually Measures
In classic analytics, average session duration gives zero recorded time to the very last pageview of every session, which quietly drags the average down.

