CCPA/CPRA § 7025
Opt-out Preference Signals
The Privisy audit tests this section. See the checks
- Source
- Regulation
- In force from
- January 1, 2026
- Last reviewed
- September 2026
- Framework
- CCPA/CPRA
What it requires
Businesses that sell or share personal information must treat any qualifying opt-out preference signal as a valid request to opt out of sale/sharing for the consumer's browser, device, and associated profiles. The Register 2025, No. 39 amendments (operative January 1, 2026) substantively changed three subsections, all to the same end: a business that lawfully declines to act on a signal must still show the consumer where they stand. Subsections (c)(3) and (c)(4) each gained a closing sentence requiring the business to display the status of the consumer's choice in accordance with § 7025(c)(6) and § 7026(g); the conflict-resolution rules those subsections state are otherwise unchanged from the March 29, 2023 text. Subsection (c)(6) turned the status display from something a business "may" do into something it must do. Subsection (f)(3) was also amended, but only typographically ("(f)(1) through (3)" became "(f)(1)-(3)"): its exception for a link to a privacy settings page has been in force since the 2023 text, not added in 2026.
Regulation text
The business shall treat the opt-out preference signal as a valid request to opt-out of sale/sharing submitted pursuant to Civil Code section 1798.120 for that browser or device and any consumer profile associated with that browser or device, including pseudonymous profiles.
California Consumer Privacy Act / California Privacy Rights Act, § 7025Read the full section from California Privacy Protection Agency (CalPrivacy)
How Privisy tests it
- Consent Mechanism Presence
A business that sells or shares must process opt-out preference signals even if it posts the opt-out link (§ 7025(b), (e)); signal processing replaces the link only when frictionless under § 7025(f)-(g), and the Notice of Right to Opt-out must still be posted (§ 7013(d))
- Third-Party Marketing Trackers
- Third-Party Request Inventory
Basis for GPC blocking obligation
- Global Privacy Control (GPC) Signal
GPC must be treated as a valid opt-out request
- .well-known GPC Declaration
Machine-readable ecosystem signal supporting § 7025 signal processing
- USP API GPC Translation
GPC session should map to an opt-out-aware US Privacy API response
- GPP API Signal Change
GPC session should update the GPP API state passed to vendors
- Policy: Opt-Out Preference Signal Disclosure
Frictionless-processing policy disclosures (§ 7025(g)(2))
The audit runs these checks against your live site and shows the evidence behind every result.
Get Your AuditThis page is for information only and is not legal advice. The excerpt is reproduced from official public sources and was checked against them on the last-reviewed date above. Laws change: check the authoritative source and consult a licensed attorney for compliance guidance.