Do Not Sell or Share My Personal Information — the opt-out mechanism CCPA (and now CPRA) requires for sites doing business with California residents.
The "or Share" was added by CPRA in 2023 — "share" covers behavioural advertising, which most ecommerce stores do via Meta Pixel, Google Ads remarketing, TikTok Pixel.
Required:
- Visible on every page (typically a footer link).
- Takes the user to a page or modal where they can exercise the opt-out.
- Two-step rule: the opt-out flow can have at most two steps. No emails-then-verification-then-captcha.
- Applies immediately and persistently.
- Honoured automatically when the GPC browser signal is detected (CPRA explicitly requires this).
Sephora's $1.2M settlement in 2022 was for a missing/non-functional opt-out. Don't skip this if you do California business.