
Do not sell or share: what the privacy policy says
At a glance
US-04HighCal. Civ. Code §§1798.115(c), 1798.130(a)(5)(C), 1798.120(b), 1798.140(ad), (ah); 11 CCR §7011(e)(1)(D)-(F)
Peeky compares the advertising tools a page loads with what the privacy policy says about selling and sharing personal information.
Last checked against the source:
The rule
The CCPA asks a business to be open about what it does with personal information, and the privacy policy is where the answer on selling and sharing has to be written down. Two definitions decide what counts.
“Sell” means “selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating” a consumer’s personal information to a third party “for monetary or other valuable consideration.” “Share” means doing the same thing “for cross-context behavioral advertising, whether or not for monetary or other valuable consideration, including transactions between a business and a third party for cross-context behavioral advertising for the benefit of a business in which no money is exchanged.”
Cross-context behavioral advertising (§1798.140(k)) is advertising targeted from a consumer’s activity “across businesses, distinctly branded internet websites, applications, or services.” A tag from an ad network that profiles visitors across sites is the usual example.
The disclosure itself is required by two provisions read together. Section 1798.115(c) obliges a business that sells or shares to disclose the categories of personal information “it has sold or shared,” and “if the business has not sold or shared consumers’ personal information, it shall disclose that fact.” Section 1798.130(a)(5)(C) puts this in the online privacy policy as two separate lists, one for personal information sold or shared and one for personal information disclosed for a business purpose, covering the preceding 12 months. If nothing was sold or shared, the business “shall prominently disclose that fact in its privacy policy.” The policy must be updated at least once every 12 months.
The regulations fill in the detail. Section 7011(e)(1)(D) to (G) of the CCPA Regulations asks the policy to name the categories sold or shared, the categories of third parties receiving each, the business or commercial purpose, and whether the business has actual knowledge that it sells or shares the information of consumers under 16.
The same facts trigger further duties. Under §1798.120(b) and §1798.135(a)(1), a business that sells or shares must tell consumers they have the “right to opt out” and give a clear link titled “Do Not Sell or Share My Personal Information” on its homepage. Whether that link works is the subject of US-02, and the browser signal that does the same job is covered in US-03.
A “business” under §1798.140(d) does business in California and meets one of three thresholds: annual gross revenue above $25 million (adjusted for inflation; $26,625,000 on the CPPA’s threshold page), buying, selling or sharing the personal information of 100,000 or more consumers or households, or earning 50 percent or more of revenue from selling or sharing it. The second counts sharing, so an ad-funded site with modest turnover can be inside it.
Penalties come in two forms. The California Privacy Protection Agency can impose administrative fines under §1798.155, and the Attorney General can recover civil penalties under §1798.199.90. Each statute caps the amount at “$2,500 for each violation”, or $7,500 for intentional ones and those involving minors, adjusted for inflation. The CPPA’s current figures are $2,663 and $7,988. The statute sets the amount “for each violation” and does not define the unit. This article does not estimate a total for any company.
What PeekWell checks and how
US-04 asks one question: given the advertising tools a page loads, does the privacy policy say anything about selling or sharing? The check applies when a site’s markets include California. Its detection is AI-assisted: the browser evidence is gathered and compared by code, and a language model helps read the policy.
The scan opens the public pages in a fresh browser and records the network requests the page makes. Request domains are matched to advertising and tracking trackers. In parallel it finds the privacy policy and reads it for the elements the rule asks for: whether it mentions selling or sharing, whether it lists categories and categories of third parties, and whether it says plainly that nothing is sold or shared. The comparison is set logic on those two results. Ad tools with no matching statement is a finding.
The language model reads the policy text. It never decides that a tracker was present or that a business sold anything.
The limits are those of a visit from outside. The scan sees public pages and nothing behind a sign-in, and it does not submit forms or open addresses nobody linked to. It cannot see data sent from your servers to a partner, so a page with no ad tags can still sell, and it cannot see the contracts that decide whether a vendor is a service provider. A Passed means the observed ad tools and the policy line up on the pages scanned. It does not say the business complies. The comparison works the way EU-04 does for processors: what was observed set against what the policy discloses.
Why it matters for a company
The enforcement record shows the Attorney General reading the sale definition widely and then checking the policy. In the Sephora settlement of 24 August 2022, the Attorney General said that allowing third-party analytics and advertising companies to monitor consumers was a sale, and that Sephora did not tell consumers about the sale or let them opt out. The settlement was $1.2 million with updated disclosures, support for the Global Privacy Control signal and reports to the Attorney General. The allegations were settled, not decided in court.
DoorDash, on 21 February 2024, settled for $375,000. The Attorney General alleged that DoorDash sold customer names, addresses and transaction histories by taking part in marketing cooperatives, which in the Attorney General’s words “enable businesses to trade personal information.” The complaint alleges the sale breached the CCPA, and separately alleges that DoorDash’s posted privacy policy did not state that it disclosed personal information to the cooperatives, under the California Online Privacy Protection Act. This one turned on a sale the policy did not mention, not on a tag.
Healthline Media settled for $1.55 million on 1 July 2025 over allegations that its trackers kept sharing data after consumers opted out and that it lacked the required contracts with advertising partners.
The facts are findable from outside, because a policy is public and so are the requests a page makes. A policy copied from a template may say “we do not sell” while a tag on the same page shares with an ad network, and the definition does not depend on what the policy calls it. These matters also rested on more than disclosure: opt-outs that did not work, or contracts that were missing.
Smaller companies and larger companies
The rule has a size test, but it is lower than many founders expect. A smaller company is inside it if it has an audience of 100,000 California consumers or households and shares their data with an ad network, whatever its revenue. Below that, and below the revenue line, the CCPA does not apply to it, though other states’ laws may (see US-11).
In a smaller company the policy usually comes from a generator and says “we do not sell your personal information”. Someone in marketing then adds a retargeting tag or an affiliate network, and the sentence no longer matches what the pages do. The California Attorney General’s own page lists anonymised examples, such as a telehealth portal and several online retailers, that changed their notices and tools after a notice of alleged noncompliance. The page does not say how large they are.
In a larger company the sale can sit outside the website. Customer lists go to marketing cooperatives, data partners or loyalty-programme vendors through back-office exports, as at DoorDash, and the policy is owned by a legal team that never sees them.
Enforcement cases
Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

Larger companies
Sephora
The California Attorney General alleged that Sephora did not tell consumers it was selling their personal information and did not honour opt-out requests sent through Global Privacy Control. The Attorney General's position was that letting third-party analytics and advertising companies track consumers in return for benefits was a sale under the CCPA.
Read the California Attorney General (United States) publication about SephoraDoorDash
The California Attorney General alleged that DoorDash sold customers' names, addresses and transaction histories by trading them to a marketing cooperative. The complaint alleges its privacy policy did not state that this information was disclosed.
Read the California Attorney General (United States) publication about DoorDash
Smaller companies
No enforcement decision on an undisclosed sale or sharing against a named smaller company could be confirmed at an authority's own page, so none is listed. The California Attorney General publishes only anonymised examples of businesses that fixed their notices after a warning, and does not state their size.
How to fix it
Start from what the site does, then change the policy to match. Changing only one side leaves the gap open.
- List every advertising and analytics tool. Open your site in a private window with the network tab open and write down each third-party request on the home page, a product page and a form page. Add the tools you know about that do not show up there, such as customer-list uploads to ad platforms and marketing cooperatives.
- Decide for each one whether it is a sale, sharing, or a service. A tool that sends visitor data to an ad network for targeting across other sites is sharing. A tool that only works for you under a contract that limits its use may be a service provider. Your legal adviser should confirm the classification. Peeky reports only what it observes.
- Write the two lists. In the privacy policy, list the categories of personal information sold or shared in the last 12 months and the categories of third parties that received them. List separately what you disclosed for business purposes. If you sold or shared nothing, say so in a sentence that stands out.
- Add the opt-out pieces. If anything is sold or shared, add the “Do Not Sell or Share My Personal Information” link to the homepage header or footer, and make sure it stops the tags it names. See US-02 and US-03.
- Put the contracts in place. Section 1798.100(d) requires an agreement with each third party that receives personal information, limiting the purposes and binding the third party to the same level of protection.
- Set a review date. The statute asks for a policy update at least every 12 months; add a check whenever a tag is added.
- Re-scan. Run a scan after the policy and tags are changed. The finding should clear once the policy discloses what the page does.
Questions
Does a privacy policy have to say whether a business sells or shares data?
Yes. A business covered by the CCPA must list the categories of personal information it sold or shared in the past 12 months, or say prominently that it has not. The list sits in the privacy policy and has to be refreshed at least once every 12 months. The rule has the wording.
Does sending data to an ad network count as selling it?
It can, even when no money changes hands. The CCPA defines selling as handing personal information to a third party for money or other valuable consideration, and sharing as handing it over for cross-context behavioral advertising whether or not anything is paid. The California Attorney General treated ad-tech tracking as a sale in the Sephora matter.
What is the difference between selling and sharing?
Selling needs payment or other valuable consideration, while sharing is defined by its purpose, targeted advertising across different sites and apps. The sharing definition exists so that ad-tech arrangements in which no money is exchanged are covered too. Both trigger the same notice and opt-out duties.
Do we need a Do Not Sell or Share link?
Only if the business sells or shares personal information. Then it needs a clear link on its homepage titled "Do Not Sell or Share My Personal Information", or a recognised opt-out signal handled instead. A business that does neither does not need the link but still has to say so in its policy.
How does Peeky check the selling and sharing disclosure?
Peeky records the advertising and tracking requests a public page makes, reads the privacy policy, and compares the two. A page with ad tools and a policy that never mentions selling or sharing becomes a finding with both pieces of evidence attached. It never signs in and never fills a form. How a scan works has the full path.
Filed with
The rule
California Consumer Privacy Act of 2018, Cal. Civ. Code §§1798.100, 1798.115, 1798.120, 1798.130(a)(5), 1798.135 and 1798.140(ad), (ah) (text effective 1 January 2026)
Read the rule (California Consumer Privacy Act of 2018, Cal. Civ. Code §§1798.100, 1798.115, 1798.120, 1798.130(a)(5), 1798.135 and 1798.140(ad), (ah) (text effective 1 January 2026))Sources
- California Consumer Privacy Act of 2018, as amended, text effective 1 January 2026 (CPPA copy, posted December 2025)
- CCPA Regulations, 11 CCR §§7000 and following, effective 1 January 2026 (CPPA copy)
- CPPA, Updated monetary thresholds in the CCPA (adjustment of 1 January 2025)
- California Attorney General, CCPA enforcement case examples (updated 24 August 2022)
- California Attorney General, Settlement with Sephora, 24 August 2022
- California Attorney General, Settlement with DoorDash, 21 February 2024
- California Attorney General, Healthline Media settlement, 1 July 2025
- CPPA, Tractor Supply Company decision announced 30 September 2025
Last checked against the source:
For information only. Not legal advice.


