Requests to Opt-out of Sale/Sharing
Audited by Privisy: The Privisy scanner actively tests for compliance with this requirement.
What it requires
A business that sells or shares personal information must offer two or more designated methods for submitting a request to opt out of sale/sharing, and must honor the requests it receives. A cookie banner or cookie controls are not by themselves an acceptable method, because cookies concern collection rather than sale or sharing; a method only qualifies if it addresses the sale and sharing of personal information. Once a request arrives, the business must stop selling and sharing the consumer's personal information as soon as feasibly possible and no later than 15 business days after receipt, and must notify the third parties it sold or shared that information to, directing them to comply and pass the request on. Unlike § 7025, which governs opt-out preference signals such as Global Privacy Control, this section covers requests the consumer submits through a method the business provides.
Legal text (excerpt)
A business that sells or shares personal information shall provide two or more designated methods for submitting requests to opt-out of sale/sharing. [...] A notification or tool regarding cookies, such as a cookie banner or cookie controls, is not by itself an acceptable method for submitting requests to opt-out of sale/sharing because cookies concern the collection of personal information and not the sale or sharing of personal information. An acceptable method for submitting requests to opt-out of sale/sharing must address the sale and sharing of personal information. [...] A business shall comply with a request to opt-out of sale/sharing by: (1) Ceasing to sell to and/or share with third parties the consumer's personal information as soon as feasibly possible, but no later than 15 business days from the date the business receives the request. [...] (2) Notifying all third parties to whom the business has sold or shared the consumer's personal information, after the consumer submits the request to opt-out of sale/sharing and before the business complies with that request, that the consumer has made a request to opt-out of sale/sharing and directing them to comply with the consumer's request [...]
Primary source
California Privacy Protection Agency (CalPrivacy): § 7026: Requests to Opt-out of Sale/Sharing ↗Privisy checks
The following Privisy scanner checks are grounded in this citation:
- Consent Mechanism Effectiveness
A cookie banner alone is not an acceptable sale/share opt-out method (§ 7026(a)(4)); an opt-out must stop the selling and sharing (§ 7026(f)(1))
- USP API Consent String
Third parties must be notified of the opt-out (§ 7026(f)(2)); the US Privacy string is how CMPs tell them
- Google Consent Mode State
An opt-out must stop the sharing (§ 7026(f)(1)); Consent Mode must deny the ad signals (ad_storage, ad_user_data, ad_personalization)
- Marketing Cookies After Opt-Out
Marketing cookies persisting after opt-out keep the browser addressable, so the sharing need not stop (§ 7026(f)(1))
Not sure whether § 7026 applies to your site? Run an independent compliance audit to check your links, policies, and tracking scripts.
Audit Your Site →Legal notice: This page is for informational purposes only and does not constitute legal advice. The legal text excerpt is reproduced from official public sources and is current as of the stated effective date. Laws change: verify against the authoritative source and consult a licensed attorney for compliance guidance.