Navigating the CPRA’s “Do Not Sell or Share” requirement | Blog | OneTrust

Skip to main content

OneTrust Named a Visionary in the 2026 Gartner® Magic Quadrant™ for AI Governance Platforms

Download the report

On-demand webinar coming soon...


On-demand webinar coming soon...

Blog

Navigating the CCPA As Amended “Do Not Sell or Share” Requirement

Understand the expanded “Do Not Sell or Share” requirements under the CCPA as amended and how your business can stay ahead in managing consumer data opt-outs and sensitive information

Kadi Coult Wharton

Director, Content Marketing, CIPM, CIPP/E

October 28, 2022


Table of contents

The ultimate guide to CCPA compliance

Download the Ultimate Guide to CCPA Compliance eBook to discover the key compliance areas

[Download now](/content/resources/the-ultimate-guide-to-ccpa-compliance-ebook/ "Download now"/index.html)

Since January 1, 2023, California's "Do Not Sell" opt-out requirement now covers the sharing of personal information under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). Businesses must adapt to this expanded consumer right and ensure compliance with the latest regulations.

The CCPA has been shaping how businesses handle consumer personal information since 2020. However, the CCPA as amended expands consumer rights, particularly the “Do Not Sell or Share My Personal Information” requirement. This gives consumers more control over the sale and sharing of their personal data, introducing several key updates for businesses to adopt.

What Is the CCPA “do Not Sell or Share” Requirement?

The CCPA as amended expands the original CCPA’s mandate by including the sharing of personal information with third parties for cross-context behavioral advertising. It also introduces limitations on the use of sensitive personal information. Key requirements include:

  1. Notifying consumers of the sale and/or sharing of personal information and offering them the option to opt out.
  2. Displaying clear opt-out links such as “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information” on websites, especially on homepages and data collection pages.
  3. Providing accessible opt-out methods that do not require consumers to create an account.
  4. Maintaining opt-out requests for at least 12 months before seeking consumer consent again.
  5. Training personnel to handle privacy rights inquiries and process opt-out requests efficiently.

Sensitive Personal Information and the CCPA

The CCPA as amended enhances protection for sensitive personal information, covering:

Publicly available information, as defined by law, remains excluded from the category of sensitive personal information under the CCPA as amended.

Managing Opt-out Requests Effectively

Managing opt-out and consent requests under the CCPA as amended, can be complex for businesses that handle large volumes of personal data. It’s essential to automate intake and compliance processes to honor consumer choices. Detailed records of consent and opt-out requests are vital to ensure compliance across all data sharing activities.

Designing Opt-out Pages

To meet CCPA as amended compliance, businesses must design user-friendly opt-out pages. Consolidating these pages with a combined link like “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information” can streamline the process and improve user experience.

Ensuring Transparency in Data Sales

If your business sells personal information, it’s crucial to be transparent. Clearly communicate what personal information is being sold, to whom, and why. Providing transparency will allow consumers to make an informed decision regarding whether to opt out.

Simplify Your CCPA Compliance With OneTrust

The CCPA as amended has been in effect since 2023, and businesses need a robust compliance strategy. OneTrust offers comprehensive tools to streamline your compliance efforts. With our Consent & Preferences solution, you can easily create, manage, and automate opt-out pages across web, mobile, and CMP channels.

OneTrust Privacy Automation enables you to meet end-to-end compliance, extending beyond the sale of data to include the sharing of personal information and sensitive data usage. Our integrated data governance tools help you understand your data landscape, control third-party access, and maintain the detailed recordkeeping required by the CCPA as amended.

Ready to accelerate your CCPA as amended compliance efforts? Request a demo today to see how OneTrust can support your privacy program.

Key Questions About the CPRA “Do Not Sell or Share” Requirement

What additional obligations accompany the “Do Not Sell or Share” requirement?

In addition to providing the opt-out link, businesses must update privacy notices to describe how personal information is sold or shared, what categories are involved, and how consumers can exercise their right; they must establish mechanisms to honour opt-out signals (including browser-based signals like GPC), ensure downstream enforcement of consumer choices, and incorporate the requirement into their governance, data inventory and vendor-management processes.

What steps should organisations take to operationalise compliance with the “Do Not Sell or Share” requirement?

Organisations should map data flows to identify where personal information is sold or shared, integrate opt-out controls into consent/ preference management platforms, configure and monitor linked upstream and downstream systems to honour consumer choices, train teams responsible for marketing and data sharing, update public-facing links and notices, and conduct audits to ensure vendor and platform compliance. This lifecycle-based approach supports both operational effectiveness and regulatory defensibility.

What are the key design elements for a compliant opt-out mechanism under CPRA?

A compliant opt-out mechanism must be clear, conspicuous and easy to use — for example through a homepage footer link labelled “Do Not Sell or Share My Personal Information” that does not require the consumer to create an account. The opt-out choice must be honoured across relevant systems and the business must retain the consumer’s decision for at least twelve months before seeking reconfirmation. These features reduce friction, support transparency and help demonstrate accountability.