
Do Not Sell or Share link: missing or not working
At a glance
US-02CriticalCal. Civ. Code §§ 1798.135(a)(1), 1798.155(a) and 1798.199.90(a); Cal. Code Regs. tit. 11, §§ 7013, 7026
Peeky looks for the Do Not Sell or Share My Personal Information link when a page runs advertising trackers, and checks that the link leads somewhere that works.
Last checked against the source:
The rule
Section 1798.135(a) of the California Consumer Privacy Act applies to “a business that sells or shares consumers’ personal information.” It must, “in a form that is reasonably accessible to consumers,” provide “a clear and conspicuous link on the business’ internet homepages, titled ‘Do Not Sell or Share My Personal Information,’ to an internet web page that enables a consumer, or a person authorized by the consumer, to opt out of the sale or sharing of the consumer’s personal information.”
Under Section 1798.140(ad) and (ah), “sell” and “share” are not limited to payment, and the enforcement record treats advertising tags that send visitor data to third parties as sale or sharing. The statute applies to a “business” that does business in California and meets one of three thresholds: annual gross revenue above $25,000,000 as adjusted, buying, selling or sharing the data of 100,000 or more consumers or households, or earning 50 percent or more of revenue from selling or sharing. The CPPA’s inflation notice puts the revenue figure at $26,625,000 from 1 January 2025. The 100,000 threshold is the one a smaller site with a lot of traffic can cross.
The regulations fill in the link. Section 7013 asks for a conspicuous link in the header or footer of the homepage, and Section 7003(c) says a required website link “shall appear in a similar manner as other similarly-posted links used by the business on its homepage(s).”
The link is not the only route. Section 1798.135(b)(3) says a business “may elect whether to comply with subdivision (a) or subdivision (b)”, the second being opt-out through a preference signal. The regulations narrow that for the web: a business that collects personal information online “shall, at a minimum, allow consumers to submit requests to opt-out of sale/sharing through an opt-out preference signal and at least one of the following methods: an interactive form accessible via the ‘Do Not Sell or Share My Personal Information’ link, the Alternative Opt-out Link, or the business’s privacy policy if the business processes an opt-out preference signal in a frictionless manner.”
A link that exists is not enough. Section 7026(a)(4) addresses a common shortcut in direct terms.
“A notification or tool regarding cookies, such as a cookie banner or cookie controls, is not by itself an acceptable method for submitting requests to opt-out of sale/sharing because cookies concern the collection of personal information and not the sale or sharing of personal information. An acceptable method for submitting requests to opt-out of sale/sharing must address the sale and sharing of personal information.”
The statute states penalties in two places: administrative fines of up to $2,500 for each offence, or $7,500 for each intentional one and each one involving the data of consumers known to be under 16, in Section 1798.155(a), and civil penalties in the same amounts in Section 1798.199.90(a) for actions brought by the Attorney General. Both are inflation-adjusted. The CPPA’s notice puts them at $2,663 and $7,988 from 1 January 2025, and the next adjustment falls in January 2027. The Attorney General’s August 2022 Sephora announcement said the CCPA’s notice and cure provision would expire on 1 January 2023.
What PeekWell checks and how
US-02 is run where the site’s markets include California. It asks two questions: do trackers that point to sale or sharing appear on the page, and if so, is there a link that opens a working opt-out?
The scan loads a public page in a fresh browser with no saved choices and records the network requests and cookies. Request domains are matched against a maintained list of advertising and cross-site tracker signatures. If a match appears, the scan looks in the page for a link with the Do Not Sell or Share title and follows it to see that it resolves. It then looks at the page it reaches for a form set up to send the request. A tracker with no link, a link that does not resolve, or a page with no working form each become a finding, with the requests and the link target as evidence.
A person has to read the result with the alternatives in mind. The regulations allow a business to honour opt-out signals in a frictionless way instead of using the standard link, or to use the Alternative Opt-out Link, so a missing standard link is a prompt to check what the site does, not an answer on its own. US-03 covers the signal side.
Code makes the decision from what the browser saw. A language model never decides that a tracker ran or that a link is missing.
The scan has limits, and the report says so. It sees public pages and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. The decision on whether an opt-out actually stops selling and sharing needs deeper or authorised testing, which a passive scan cannot do, so the scan checks the link, where it leads and that the form is set up to send. It does not read your contracts or know what a tag does beyond the category on its list, and a list only knows the trackers on it. Sharing that happens on a server is outside what a browser visit can see. A Passed means the expected behaviour was observed on the pages scanned. It does not say the site complies.
Why it matters for a company
In February 2026 the Attorney General announced a $2.75 million settlement with Disney. The allegation was that a visitor could use a toggle, a webform or a browser signal and the selling and sharing continued from other devices, services, or through third-party ad-tech code. Healthline’s settlement in July 2025 for $1.55 million turned on data that, the Attorney General said, kept going to advertising third parties after a consumer opted out. The CPPA’s Tractor Supply decision, announced on 30 September 2025, listed the lack of an effective opt-out mechanism among the allegations the company agreed to resolve by paying a $1,350,000 fine, alongside privacy notice failures.
The CPPA made the same point in its May 2025 Todd Snyder decision. The Enforcement Division alleged the company’s privacy portal was not configured so as to process opt-out requests for 40 days, and its head said that “using a consent management platform doesn’t get you off the hook for compliance.” The Stipulated Final Order the CPPA Board adopted on 27 February 2026 alleged that PlayOn’s phone and email opt-out methods did not reach the tracking technologies on its sites. PlayOn did not admit liability.
The link, the form behind it and the suppression that follows are three separate things, and the record shows gaps in each.
Smaller companies and larger companies
The rule is the same for every business that meets the thresholds. What changes is how the gap appears.
In a small business the site is often a template or hosted builder. Someone adds an advertising pixel for a campaign and a banner plugin goes on. No one adds the link, or it points to an email address, or it opens an empty page. The 100,000 consumers-or-households threshold depends on traffic, not revenue, so a small site can be in scope. We could not confirm a decision against a clearly small business, and the note under the cases says so.
In a larger business the difficulty is coverage. A tag manager holds dozens of tags owned by different teams, the company has several brands, apps and connected TV products, and the opt-out has to reach all of it. Disney is the example on the record. Each opt-out method worked in part, and none stopped everything.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
The Walt Disney Company
The Attorney General said that when a user opted out with a toggle, Disney applied the request only to the streaming service being watched, and often only to the specific device. It also said that its webform stopped sharing through Disney's own advertising platform but not with third-party ad-tech companies whose code ran in its sites and apps. Many connected TV apps had no in-app opt-out at all and sent people to the webform. Disney settled and agreed to opt-out methods that fully stop the selling and sharing.
Read the California Attorney General (United States) publication about The Walt Disney CompanyHealthline Media LLC
The Attorney General alleged that Healthline continued to share data with some advertising third parties even for consumers who exercised their right to opt out. The settlement requires Healthline to make sure its opt-out mechanisms function properly and to keep its online privacy disclosures accurate.
Read the California Attorney General (United States) publication about Healthline Media LLCTractor Supply Company
The CPPA's Board decision alleged that Tractor Supply failed to give consumers an effective mechanism to opt out of the selling and sharing of their personal information, including through opt-out preference signals such as Global Privacy Control. It also named a privacy policy that did not tell consumers their rights. The decision resolved the allegations; the company agreed to pay $1,350,000, to scan its digital properties for tracking technologies and to have an officer or director sign off on compliance each year for four years.
Read the CPPA (California, United States) publication about Tractor Supply Company
Smaller companies
No decision against a clearly small business could be confirmed at a regulator's own page. The decisions we could confirm involve companies large enough to clear the CCPA's thresholds, and the regulators' pages do not describe company size.
How to fix it
The steps below follow what the statute and regulations name: the title, the homepage placement, the method that has to address sale and sharing, and suppression after the request.
- List what shares data. In a private window with the network tab open, load the homepage and a few key pages. Write down every third-party advertising, retargeting and cross-site analytics request. Those are the tools the opt-out has to control.
- Add the link with the exact title. Put “Do Not Sell or Share My Personal Information” in the footer of the homepage, styled like the other footer links. If you offer a combined choice with the sensitive-data link, label it so it is clear what it does.
- Point it at a page that works. The page needs a form or control a visitor can use without an account or extra personal details. A cookie banner or an email address on its own does not address the selling and sharing.
- Wire the request to the tags. When a visitor opts out, the advertising and cross-site tags have to stop for that browser, and the request has to reach your ad vendors and your tag manager rules. Test with a fresh browser after you submit it.
- Cover every product. Apps, connected TV, other brands and logged-in accounts need the same result.
- Honour the signal too. Websites are expected to accept a browser opt-out signal as well as offering a form. US-03 walks through that step.
- Re-scan. Run a scan again once the link and suppression are live. The finding should clear when the link opens and the page behind it works.
Whether this meets the law for your business is a question for your legal adviser. Peeky reports only what it sees.
Questions
What does the Do Not Sell or Share My Personal Information link do?
It takes a visitor to a page where they can tell the business to stop selling or sharing their personal information. The link has to sit on the homepage, be easy to see, and carry that title. If the page behind it does nothing, the link is just a label.
Does my website need a Do Not Sell link?
If the business sells or shares personal information and falls under the CCPA, yes, unless it honours opt-out signals instead. Running third-party advertising or cross-site tracking tags on your pages usually counts as sharing. The CCPA covers a business over $26,625,000 in revenue, one that buys, sells or shares data on 100,000 or more consumers or households, or one that earns half its revenue from selling or sharing data.
Is a cookie banner enough as a CCPA opt-out?
No. The regulations say a cookie banner or cookie controls are not by themselves an acceptable opt-out method, because cookies concern collection and not sale or sharing. The opt-out has to address the selling and sharing itself. Regulators have looked at this directly: the CPPA's February 2026 stipulated order with PlayOn Sports alleged that its phone and email opt-out did not reach its tracking technologies; PlayOn did not admit liability.
What should the link say and where does it go?
The statute names the title: Do Not Sell or Share My Personal Information. The regulations also require the link to look like the other links on the page and to sit in the header or footer of the homepage. It should lead to a page where the visitor can opt out without making an account.
How does Peeky check the Do Not Sell or Share link?
Peeky loads your public page in a clean browser, notes which advertising and cross-site trackers run, and looks for the link. It checks that the link opens and that the page behind it has a form set up to send the request. It never submits the form. How a scan works has the full path.
Filed with
The rule
California Consumer Privacy Act, Cal. Civ. Code §§ 1798.120, 1798.135, 1798.140 and 1798.155 (as posted by the CPPA, effective 1 January 2025)
Read the rule (California Consumer Privacy Act, Cal. Civ. Code §§ 1798.120, 1798.135, 1798.140 and 1798.155 (as posted by the CPPA, effective 1 January 2025))Sources
- California Consumer Privacy Act of 2018, statute text posted by the CPPA (effective 1 January 2025)
- Cal. Code Regs. tit. 11, § 7013, Notice of Right to Opt-out of Sale/Sharing and the Do Not Sell or Share link
- Cal. Code Regs. tit. 11, § 7026, Requests to Opt-Out of Sale/Sharing
- Cal. Code Regs. tit. 11, § 7003, Requirements for disclosures and communications to consumers
- CPPA, Updated monetary thresholds in the CCPA (effective 1 January 2025, posted 17 December 2024)
- California Attorney General, California Consumer Privacy Act (CCPA) page
- California Attorney General, CCPA enforcement case examples (updated 24 August 2022)
- California Attorney General, Attorney General Bonta announces settlement with Sephora (24 August 2022)
- CPPA, Nation's Largest Rural Lifestyle Retailer to Pay $1.35M Over CCPA Violations (30 September 2025)
- California Attorney General, Attorney General Bonta announces $2.75 million settlement with Disney (11 February 2026)
- California Attorney General, Attorney General Bonta announces largest CCPA settlement to date, $1.55 million from Healthline.com (1 July 2025)
- CPPA, CPPA Orders Clothing Retailer Todd Snyder to Pay Six-Figure Fine (6 May 2025)
- CPPA, Stipulated Final Order, 2080 Media, Inc. d/b/a PlayOn Sports, Case No. ENF24-S-PL-24 (adopted 27 February 2026)
Last checked against the source:
For information only. Not legal advice.


