Introduction
If your website shares visitor data with ad platforms – and if you run the Meta Pixel or Google Ads remarketing, it does – US state privacy laws require you to give visitors a way out. The centerpiece is the “Do Not Sell or Share My Personal Information” link and the opt-out page behind it. Here’s how to build one that satisfies California’s CCPA/CPRA and the 19 other state laws now in force, including the parts most sites get wrong.
First: Do You Actually “Sell” Data? (Probably Yes)
Under the CCPA as amended by the CPRA, “selling” means transferring personal information for money or any other valuable consideration, and “sharing” covers disclosure for cross-context behavioral advertising even when no money changes hands. That definition captures:
- Ad and retargeting pixels (Meta, TikTok, LinkedIn, Google Ads remarketing tags)
- Programmatic advertising and ad networks
- Data passed to analytics or CDP vendors who use it for their own purposes
- Affiliate and data-broker relationships
If none of that applies to you – you truly don’t sell or share – you aren’t required to post the link (but your privacy policy must accurately say so). For everyone else, read on.
Who Must Comply in 2026
California’s CCPA covers for-profit businesses doing business in the state that meet any one of: gross revenue above $26,625,000 (the current inflation-adjusted threshold), 100,000+ California consumers or households, or 50%+ of revenue from selling/sharing personal data. Your headquarters location is irrelevant.
Nineteen other states run comparable opt-out rights – Virginia, Colorado, Connecticut, Texas, Oregon, and the January 2026 arrivals Indiana, Kentucky, and Rhode Island among them, with Arkansas effective July 2026. Because most copy the same template, one well-built opt-out page can serve residents of all of them.
The Link: Wording and Placement Rules
- Exact-style wording: “Do Not Sell or Share My Personal Information” – or the approved alternative “Your Privacy Choices” / “Your California Privacy Choices” accompanied by the standard opt-out icon.
- Placement: clear and conspicuous in the footer of every page, in your privacy policy, and on any page where personal information is collected. It must work on mobile and desktop.
- No login walls: you cannot require account creation to opt out, and you shouldn’t demand identity verification (basic questions to locate the right record are fine).
- If you collect sensitive personal information (precise geolocation, health data, etc.) for purposes beyond the permitted ones, you also need a “Limit the Use of My Sensitive Personal Information” link – combinable with the main opt-out page.
What the Opt-Out Page Itself Must Contain
- A plain-English explanation of the right – what “sell or share” means and what opting out changes.
- An interactive opt-out mechanism -a web form or, better, a one-click toggle that immediately suppresses ad-tech cookies and data sharing. California requires at least two submission methods; pair the form/toggle with a toll-free number or designated email.
- Immediate effect for cookie-based sharing. The cleanest pattern: the toggle flips your CMP’s state, which blocks advertising scripts and fires the opt-out signal to Google (Consent Mode), the IAB GPP string, and your tag manager-no 15-day wait for the browser-level part.
- Scope disclosures: whether the opt-out is cookie/device-based, account-based, or both, and what happens on other devices.
- No dark patterns: the opt-out path must be as easy as any opt-in. Regulators explicitly test for asymmetry.
- Respect the choice for 12 months before asking the consumer to opt back in.
New for 2026
Since 1 January 2026, California requires businesses to visibly confirm that an opt-out was processed -an “Opt-Out Request Honored” message, badge, or a toggle that reflects the honored state. This applies to GPC signals too: silent back-end processing no longer satisfies the regulation. Your page (and banner) should show the user their current status.
Global Privacy Control: The Opt-Out You Receive Without a Click
GPC is a browser-level signal (on by default in Firefox and Brave, available as extensions elsewhere) that transmits a legal opt-out request automatically on every page load. As of 2026, roughly a dozen states mandate honoring it – California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas- meaning:
- Detection is mandatory, not optional. You are already receiving GPC signals whether your site listens or not.
- The signal equals a link click. A valid GPC signal carries the same legal weight as a submitted opt-out form.
- It must propagate. Enforcement cases show the common failure: the CMP reads the signal, but the tag manager, server-side pipeline, and CDP keep firing. Disney’s $2.75M settlement turned partly on honoring GPC only per-device instead of across known, logged-in users. In late 2025, California, Colorado, and Connecticut ran a joint GPC enforcement sweep.
Reference Build: a Compliant Opt-Out Page in Five Blocks
- Heading: “Do Not Sell or Share My Personal Information”
- Explanation: your data practices + the rights, in plain English
- Toggle: [ Opt out of sale/sharing ] → flips CMP state instantly,suppresses ad pixels, updates GPP + Consent Mode signals,then shows “✓ Your opt-out request has been honored”
- GPC notice: “We automatically honor Global Privacy Control. Your browser is currently sending GPC: [Yes/No]”
- Alternate methods + scope: email/toll-free number, device vs account scope, link to full privacy policy
Well-known implementations to study: T-Mobile’s toggle-based preference page and the webform patterns used by Levi’s and McDonald’s- all footer – linked, form-light, and account-free.
Common Mistakes That Trigger Enforcement
- The link exists but the mechanism is broken. In the Todd Snyder case, a misconfigured consent banner silently blocked opt-outs for an extended period – the malfunction itself was the violation.
- Opt-out recorded, pixels keep firing. California’s enforcement wave (over $9M in fines since 2025, including Healthline and PlayOn Sports) focuses on network-level verification: regulators load your site post-opt-out and watch what still transmits – see the full list of compliance mistakes that cost companies money.
- Ignoring GPC or honoring it only at the CMP layer.
- Hiding the link on mobile, or burying it behind a login.
- Cookie banner ≠ opt-out compliance. An EU-style accept/reject banner does not by itself satisfy the link, two-methods, GPC, and confirmation requirements.
Frequently Asked Questions
No. One opt-out page serves all states because the underlying right stop selling/sharing my data, honor my universal opt-out signal is the common template. Just avoid California-only wording if you honor requests from all US visitors (recommended: honor everyone, verify no one).
You may geo-target it, but most businesses show it to all US visitors it’s simpler, safer as more states come online, and consumers increasingly expect it.
Cookie-based sharing should stop effectively immediately via your CMP. Back-end requests (e.g., stopping list sales) must be completed within 15 business days in California, and you must instruct downstream recipients accordingly.
No – they’ll see non-personalized ads. Opting out stops the sale/sharing of their data for cross-context behavioral advertising, not advertising itself. Say this on the page; it reduces support tickets.
Ship a compliant opt-out flow today
CookieLet’s opt-out banner handles the link, the preference page, instant script suppression, GPP signals, GPC recognition, and the 2026 confirmation requirement – across all 20 state laws.