One-Line Definition
"Do Not Sell My Personal Information" is a mandatory opt-out link that websites must display to California consumers under the CCPA, allowing them to instruct a business to stop selling their personal information to third parties.
Real-Life Analogy
Think of your personal data like a trading card. You hand your card to a shop owner to get a service (say, a free app or a discount). What you may not realize is that the shop owner is also photocopying your card and selling those copies to other businesses — advertisers, data brokers, lead generators — without asking you. The "Do Not Sell My Personal Information" link is essentially a "stop photocopying my card" button. Once you click it, the shop owner is legally required to stop selling copies of your card, though they can still use the original to provide you the service you asked for.
The analogy holds up well because, like a trading card, your personal information has value. Data brokers pay real money for it. And like a shop that quietly photocopies cards, many websites were monetizing user data long before anyone thought to ask permission.
Core Formula
The CCPA's opt-out mechanism can be simplified into this formula:
Business collects PI → Sells PI to third party → Consumer clicks "Do Not Sell My Personal Information" → Business must stop selling PI → Business must honor request within 15 business days → Business cannot retaliate
Breaking it down:
- Trigger: A "sale" occurs when a business discloses personal information to a third party for monetary or other valuable consideration. Under the CPRA amendment, "valuable consideration" is interpreted broadly — even sharing data for cross-context behavioral advertising can count.
- Notice: The business must post a clear and conspicuous link titled exactly "Do Not Sell My Personal Information" (or "Do Not Sell or Share My Personal Information" under CPRA).
- Response: The business must comply within 15 business days of receiving a verifiable request.
- No retaliation: The business cannot deny goods or services, charge different prices, or provide a lower quality of service because you opted out.
Comparison with Related Terms
| Term | What It Means | Who It Applies To | Key Difference |
|---|---|---|---|
| **Do Not Sell My Personal Information** | Opt-out of the sale of personal data to third parties | California consumers (CCPA/CPRA) | Specific to "sales" — not deletion or correction |
| **Do Not Track (DNT)** | Browser signal requesting sites not to track browsing | Anyone with a DNT-enabled browser | Voluntary; no legal enforcement in most jurisdictions |
| **Right to Opt Out of Sharing** | Opt-out of cross-context behavioral advertising | California consumers (CPRA) | Broader than "sale" — covers ad tech sharing |
| **Right to Delete** | Request deletion of personal information | California consumers (CCPA) | Different right; deletion vs. stopping sale |
| **GDPR Right to Object** | Object to processing based on legitimate interests | EU/EEA data subjects | Broader scope; not limited to "sales" |
| **Global Privacy Control (GPC)** | Browser-level signal automatically opting out | California consumers (recognized under CPRA) | Automated version of the manual opt-out link |
The critical distinction: "Do Not Sell" is not the same as "Do Not Track" or "Delete My Data." It specifically targets the commercial transfer of personal information, not its collection, use, or retention.
Use Cases
1. E-commerce stores with third-party ad pixels
A Shopify store installs Facebook Pixel and Google Ads tags. When a California visitor clicks "Do Not Sell My Personal Information," the store must stop passing that visitor's data to Meta and Google for ad targeting. This often requires a consent management platform (CMP) that can fire or suppress tags based on the user's choice.
2. Lead-generation websites
A mortgage quote site sells leads to lenders. Under CCPA, a California consumer can click the opt-out link and the site must stop selling their contact information. The site must also pass the opt-out downstream to the lenders who already received the data.
3. Data brokers and people-search sites
Sites like Whitepages or Spokeo must provide the link and honor opt-outs. Many have built dedicated suppression lists and API endpoints to handle the volume — some process thousands of opt-out requests per day.
4. SaaS platforms with embedded analytics
A B2B SaaS tool that shares user behavior data with a marketing analytics vendor may trigger the "sale" definition if the vendor uses it for its own purposes. The SaaS company must offer the link to California users.
5. Mobile apps
Apps that share device identifiers with ad networks must provide the opt-out mechanism, often via an in-app settings toggle or a link in the privacy policy.
Misconceptions
Misconception 1: "Do Not Sell" means the business stops using my data entirely.
False. The business can still use your data to provide the service you requested, for internal analytics, for security, and for other purposes permitted under CCPA. It only stops *selling* it.
Misconception 2: The link only applies to California residents.
Technically true under CCPA, but many businesses extend the right to all U.S. users to simplify compliance and avoid geolocation complexity. Some states (Virginia, Colorado, Connecticut) have similar but not identical opt-out rights.
Misconception 3: Clicking the link deletes my data.
No. Deletion is a separate right. Opting out of sale stops future sales but does not erase data already collected.
Misconception 4: The business can ignore the request if it doesn't respond.
Wrong. Under CCPA, businesses must respond within 15 business days and are subject to enforcement by the California Privacy Protection Agency (CPPA). Fines can reach $2,500 per violation and $7,500 per intentional violation.
Misconception 5: A "Do Not Sell" link is enough for full compliance.
Not quite. Businesses must also honor opt-out preference signals like the Global Privacy Control, provide a notice at collection, and ensure service providers contractually limit their use of the data.
Related Terms
- CCPA (California Consumer Privacy Act): The law that created the "Do Not Sell" requirement.
- CPRA (California Privacy Rights Act): 2020 amendment that expanded CCPA, added "sharing" opt-out, and created the CPPA.
- Global Privacy Control (GPC): A browser signal that automatically sends opt-out requests; businesses must honor it under CPRA.
- Notice at Collection: The disclosure you must give consumers before or at the point of collecting their data.
- Service Provider: A vendor that processes data on your behalf under contract; not considered a "sale" if properly contracted.
- Third Party: Any entity that is not the business or a service provider; sales to third parties trigger the opt-out right.
- Verifiable Consumer Request: A request that the business can reasonably verify as coming from the actual consumer.
- Opt-Out Preference Signal: A technical signal (like GPC) that communicates the consumer's opt-out choice automatically.
- Data Broker: A business that buys and sells personal information, often subject to the opt-out requirement.
- CPPA (California Privacy Protection Agency): The enforcement body for CCPA/CPRA.
Bottom line: The "Do Not Sell My Personal Information" link is not a courtesy — it's a legal requirement for any business that sells California consumers' data. For DTC and cross-border e-commerce operators, it means auditing your ad tech stack, mapping data flows to third parties, and implementing a compliant opt-out mechanism that actually works. Ignoring it invites fines starting at $2,500 per violation, and in a state with 39+ million consumers, the math gets ugly fast.