{"id":1522,"date":"2026-08-28T11:42:15","date_gmt":"2026-08-28T06:12:15","guid":{"rendered":"https:\/\/www.cookielet.com\/blog\/?p=1522"},"modified":"2026-08-31T09:54:09","modified_gmt":"2026-08-31T04:24:09","slug":"do-not-sell-page-setup","status":"publish","type":"post","link":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup","title":{"rendered":"How to Set Up a &#8220;Do Not Sell&#8221; Page for US Visitors"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Introduction<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">If your website shares visitor data with ad platforms &#8211; and if you run the Meta Pixel or Google Ads remarketing, it does &#8211; US state privacy laws require you to give visitors a way out. The centerpiece is the &#8220;Do Not Sell or Share My Personal Information&#8221; link and the opt-out page behind it. Here&#8217;s how to build one that satisfies California&#8217;s CCPA\/CPRA and the 19 other state laws now in force, including the parts most sites get wrong.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">First: Do You Actually &#8220;Sell&#8221; Data? (Probably Yes)<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Under the CCPA as amended by the CPRA, &#8220;selling&#8221; means transferring personal information for money&nbsp;<em>or any other valuable consideration<\/em>, and &#8220;sharing&#8221; covers disclosure for&nbsp;<strong>cross-context behavioral advertising even when no money changes hands<\/strong>. That definition captures:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-medium-font-size\">Ad and retargeting pixels (Meta, TikTok, LinkedIn, Google Ads remarketing tags)<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Programmatic advertising and ad networks<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Data passed to analytics or CDP vendors who use it for their own purposes<\/li>\n\n\n\n<li class=\"has-medium-font-size\">Affiliate and data-broker relationships<\/li>\n<\/ul>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">If none of that applies to you &#8211; you truly don&#8217;t sell or share &#8211; you aren&#8217;t required to post the link (but your privacy policy must accurately say so). For everyone else, read on.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Who Must Comply in 2026<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">California&#8217;s CCPA covers for-profit businesses doing business in the state that meet any one of:&nbsp;<strong>gross revenue above $26,625,000<\/strong>&nbsp;(the current inflation-adjusted threshold),&nbsp;<strong>100,000+ California consumers or households<\/strong>, or&nbsp;<strong>50%+ of revenue from selling\/sharing personal data<\/strong>. Your headquarters location is irrelevant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nineteen other states run comparable opt-out rights &#8211; Virginia, Colorado, Connecticut, Texas, Oregon, and the January 2026 arrivals Indiana, Kentucky, and Rhode Island among them, with Arkansas effective July 2026. Because most copy the same template,&nbsp;<strong>one well-built opt-out page can serve residents of all of them<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Link: Wording and Placement Rules<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-medium-font-size\"><strong>Exact-style wording:<\/strong>&nbsp;&#8220;Do Not Sell or Share My Personal Information&#8221; &#8211; or the approved alternative &#8220;Your Privacy Choices&#8221; \/ &#8220;Your California Privacy Choices&#8221; accompanied by the standard opt-out icon.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>Placement:<\/strong>&nbsp;clear and conspicuous in the&nbsp;<strong>footer of every page<\/strong>, in your privacy policy, and on any page where personal information is collected. It must work on mobile and desktop.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>No login walls:<\/strong>&nbsp;you cannot require account creation to opt out, and you shouldn&#8217;t demand identity verification (basic questions to locate the right record are fine).<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>If you collect sensitive personal information<\/strong>&nbsp;(precise geolocation, health data, etc.) for purposes beyond the permitted ones, you also need a &#8220;Limit the Use of My Sensitive Personal Information&#8221; link &#8211; combinable with the main opt-out page.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">What the Opt-Out Page Itself Must Contain<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>A plain-English explanation of the right<\/strong> &#8211; what &#8220;sell or share&#8221; means and what opting out changes.<\/li>\n\n\n\n<li><strong>An interactive opt-out mechanism<\/strong>&nbsp;-a web form or, better, a one-click toggle that immediately suppresses ad-tech cookies and data sharing. California requires&nbsp;<strong>at least two submission methods<\/strong>; pair the form\/toggle with a toll-free number or designated email.<\/li>\n\n\n\n<li><strong>Immediate effect for cookie-based sharing.<\/strong>&nbsp;The cleanest pattern: the toggle flips your CMP&#8217;s state, which blocks advertising scripts and fires the opt-out signal to Google (Consent Mode), the IAB GPP string, and your tag manager-no 15-day wait for the browser-level part.<\/li>\n\n\n\n<li><strong>Scope disclosures:<\/strong>&nbsp;whether the opt-out is cookie\/device-based, account-based, or both, and what happens on other devices.<\/li>\n\n\n\n<li><strong>No dark patterns:<\/strong>&nbsp;the opt-out path must be as easy as any opt-in. Regulators explicitly test for asymmetry.<\/li>\n\n\n\n<li><strong>Respect the choice for 12 months<\/strong>&nbsp;before asking the consumer to opt back in.<\/li>\n<\/ol>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>New for 2026<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since&nbsp;<strong>1 January 2026<\/strong>, California requires businesses to&nbsp;<strong>visibly confirm<\/strong>&nbsp;that an opt-out was processed -an &#8220;Opt-Out Request Honored&#8221; message, badge, or a toggle that reflects the honored state. This applies to GPC signals too: silent back-end processing no longer satisfies the regulation. Your page (and banner) should show the user their current status.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">Global Privacy Control: The Opt-Out You Receive Without a Click<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">GPC is a browser-level signal (on by default in Firefox and Brave, available as extensions elsewhere) that transmits a legal opt-out request automatically on every page load. As of 2026, roughly a dozen states mandate honoring it &#8211; California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas- meaning:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li class=\"has-medium-font-size\"><strong>Detection is mandatory, not optional.<\/strong>&nbsp;You are already receiving GPC signals whether your site listens or not.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>The signal equals a link click.<\/strong>&nbsp;A valid GPC signal carries the same legal weight as a submitted opt-out form.<\/li>\n\n\n\n<li class=\"has-medium-font-size\"><strong>It must propagate.<\/strong>&nbsp;Enforcement cases show the common failure: the CMP reads the signal, but the tag manager, server-side pipeline, and CDP keep firing. Disney&#8217;s $2.75M settlement turned partly on honoring GPC only per-device instead of across known, logged-in users. In late 2025, California, Colorado, and Connecticut ran a joint GPC enforcement sweep.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Reference Build: a Compliant Opt-Out Page in Five Blocks<\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Heading: &#8220;Do Not Sell or Share My Personal Information&#8221;<\/li>\n\n\n\n<li>Explanation: your data practices + the rights, in plain English<\/li>\n\n\n\n<li>Toggle: [ Opt out of sale\/sharing ] \u2192 flips CMP state instantly,suppresses ad pixels, updates GPP + Consent Mode signals,then shows &#8220;\u2713 Your opt-out request has been honored&#8221;<\/li>\n\n\n\n<li>GPC notice: &#8220;We automatically honor Global Privacy Control. Your browser is currently sending GPC: [Yes\/No]&#8221;<\/li>\n\n\n\n<li>Alternate methods + scope: email\/toll-free number, device vs  account scope, link to full privacy policy<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Well-known implementations to study: T-Mobile&#8217;s toggle-based preference page and the webform patterns used by Levi&#8217;s and McDonald&#8217;s- all footer &#8211; linked, form-light, and account-free.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Common Mistakes That Trigger Enforcement<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The link exists but the mechanism is broken.<\/strong>&nbsp;In the Todd Snyder case, a misconfigured consent banner silently blocked opt-outs for an extended period &#8211; the malfunction itself was the violation.<\/li>\n\n\n\n<li><strong>Opt-out recorded, pixels keep firing.<\/strong>&nbsp;California&#8217;s enforcement wave (over $9M in fines since 2025, including Healthline and PlayOn Sports) focuses on network-level verification: regulators load your site post-opt-out and watch what still transmits &#8211; see&nbsp;the full list of compliance mistakes that cost companies money.<\/li>\n\n\n\n<li><strong>Ignoring GPC<\/strong>&nbsp;or honoring it only at the CMP layer.<\/li>\n\n\n\n<li><strong>Hiding the link<\/strong>&nbsp;on mobile, or burying it behind a login.<\/li>\n\n\n\n<li><strong>Cookie banner \u2260 opt-out compliance.<\/strong>&nbsp;An&nbsp;EU-style accept\/reject banner&nbsp;does not by itself satisfy the link, two-methods, GPC, and confirmation requirements.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Frequently Asked Questions<\/h2>\n\n\n\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-1787897312383\"><strong class=\"schema-faq-question\">1.Do I need a separate page per state?<\/strong> <p class=\"schema-faq-answer\">No. One opt-out page serves all states because the underlying right stop selling\/sharing my data, honor my universal opt-out signal is the common template. Just avoid California-only wording if you honor requests from all US visitors (recommended: honor everyone, verify no one).<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1787897328261\"><strong class=\"schema-faq-question\">2.Should I show the link only to Californians?<\/strong> <p class=\"schema-faq-answer\">You may geo-target it, but most businesses show it to all US visitors it&#8217;s simpler, safer as more states come online, and consumers increasingly expect it.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1787897344565\"><strong class=\"schema-faq-question\">3.What&#8217;s the deadline to process an opt-out?<\/strong> <p class=\"schema-faq-answer\">Cookie-based sharing should stop effectively immediately via your CMP. Back-end requests (e.g., stopping list sales) must be completed within 15 business days in California, and you must instruct downstream recipients accordingly.<\/p> <\/div> <div class=\"schema-faq-section\" id=\"faq-question-1787897373908\"><strong class=\"schema-faq-question\">4.Does opting out mean the visitor sees no ads?<\/strong> <p class=\"schema-faq-answer\">No &#8211; they&#8217;ll see non-personalized ads. Opting out stops the sale\/sharing of their data for cross-context behavioral advertising, not advertising itself. Say this on the page; it reduces support tickets.<\/p> <\/div> <\/div>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Ship a compliant opt-out flow today<\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">CookieLet&#8217;s opt-out banner handles the link, the preference page, instant script suppression, GPP signals, GPC recognition, and the 2026 confirmation requirement &#8211; across all 20 state laws.<\/p>\n\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"https:\/\/www.cookielet.com\/\">Get started free \u2192<\/a><\/div>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Introduction If your website shares visitor data with ad platforms &#8211; and if you run the Meta Pixel or Google Ads remarketing, it does &#8211; US state privacy&hellip;<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-1522","post","type-post","status-publish","format-standard","hentry","category-compliance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Do Not Sell Page Setup: A Step-by-Step CCPA Guide | CookieLet<\/title>\n<meta name=\"description\" content=\"Setting up a &quot;Do Not Sell&quot; page? This step-by-step guide covers CCPA link wording, opt-out toggles, GPC signals, and the 2026 confirmation rule.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Build a Compliant &quot;Do Not Sell&quot; Page - Step by Step | CookieLet\" \/>\n<meta property=\"og:description\" content=\"Exact link wording, a 5-block page structure, GPC signal handling, and the new 2026 confirmation rule - everything you need to get it right.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup\" \/>\n<meta property=\"og:site_name\" content=\"CookieLet\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-28T06:12:15+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-31T04:24:09+00:00\" \/>\n<meta name=\"author\" content=\"Sibin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sibin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup\"},\"author\":{\"name\":\"Sibin\",\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/#\\\/schema\\\/person\\\/547ab6e3c6f9c8890fe45c6e417bf796\"},\"headline\":\"How to Set Up a &#8220;Do Not Sell&#8221; Page for US Visitors\",\"datePublished\":\"2026-08-28T06:12:15+00:00\",\"dateModified\":\"2026-08-31T04:24:09+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup\"},\"wordCount\":1257,\"articleSection\":[\"Compliance\"],\"inLanguage\":\"en-US\"},{\"@type\":[\"WebPage\",\"FAQPage\"],\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup\",\"url\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup\",\"name\":\"Do Not Sell Page Setup: A Step-by-Step CCPA Guide | CookieLet\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/#website\"},\"datePublished\":\"2026-08-28T06:12:15+00:00\",\"dateModified\":\"2026-08-31T04:24:09+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/#\\\/schema\\\/person\\\/547ab6e3c6f9c8890fe45c6e417bf796\"},\"description\":\"Setting up a \\\"Do Not Sell\\\" page? This step-by-step guide covers CCPA link wording, opt-out toggles, GPC signals, and the 2026 confirmation rule.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#breadcrumb\"},\"mainEntity\":[{\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897312383\"},{\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897328261\"},{\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897344565\"},{\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897373908\"}],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Set Up a &#8220;Do Not Sell&#8221; Page for US Visitors\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/\",\"name\":\"CookieLet\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/#\\\/schema\\\/person\\\/547ab6e3c6f9c8890fe45c6e417bf796\",\"name\":\"Sibin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a38eb912dbb9e1abe1560de7fa83dae86fea24663267504c0f64b26949a98d83?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a38eb912dbb9e1abe1560de7fa83dae86fea24663267504c0f64b26949a98d83?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a38eb912dbb9e1abe1560de7fa83dae86fea24663267504c0f64b26949a98d83?s=96&d=mm&r=g\",\"caption\":\"Sibin\"},\"description\":\"Privacy Compliance Specialist &amp; Content Writer at CookieLet specializing in cookie compliance, consent management, and global data protection regulations including GDPR, CCPA, and ePrivacy Directive.\",\"url\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/author\\\/sibin\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897312383\",\"position\":1,\"url\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897312383\",\"name\":\"1.Do I need a separate page per state?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. One opt-out page serves all states because the underlying right stop selling\\\/sharing my data, honor my universal opt-out signal is the common template. Just avoid California-only wording if you honor requests from all US visitors (recommended: honor everyone, verify no one).\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897328261\",\"position\":2,\"url\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897328261\",\"name\":\"2.Should I show the link only to Californians?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"You may geo-target it, but most businesses show it to all US visitors it's simpler, safer as more states come online, and consumers increasingly expect it.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897344565\",\"position\":3,\"url\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897344565\",\"name\":\"3.What's the deadline to process an opt-out?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Cookie-based sharing should stop effectively immediately via your CMP. Back-end requests (e.g., stopping list sales) must be completed within 15 business days in California, and you must instruct downstream recipients accordingly.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"},{\"@type\":\"Question\",\"@id\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897373908\",\"position\":4,\"url\":\"https:\\\/\\\/www.cookielet.com\\\/blog\\\/do-not-sell-page-setup#faq-question-1787897373908\",\"name\":\"4.Does opting out mean the visitor sees no ads?\",\"answerCount\":1,\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No - they'll see non-personalized ads. Opting out stops the sale\\\/sharing of their data for cross-context behavioral advertising, not advertising itself. Say this on the page; it reduces support tickets.\",\"inLanguage\":\"en-US\"},\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Do Not Sell Page Setup: A Step-by-Step CCPA Guide | CookieLet","description":"Setting up a \"Do Not Sell\" page? This step-by-step guide covers CCPA link wording, opt-out toggles, GPC signals, and the 2026 confirmation rule.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup","og_locale":"en_US","og_type":"article","og_title":"Build a Compliant \"Do Not Sell\" Page - Step by Step | CookieLet","og_description":"Exact link wording, a 5-block page structure, GPC signal handling, and the new 2026 confirmation rule - everything you need to get it right.","og_url":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup","og_site_name":"CookieLet","article_published_time":"2026-08-28T06:12:15+00:00","article_modified_time":"2026-08-31T04:24:09+00:00","author":"Sibin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sibin","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#article","isPartOf":{"@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup"},"author":{"name":"Sibin","@id":"https:\/\/www.cookielet.com\/blog\/#\/schema\/person\/547ab6e3c6f9c8890fe45c6e417bf796"},"headline":"How to Set Up a &#8220;Do Not Sell&#8221; Page for US Visitors","datePublished":"2026-08-28T06:12:15+00:00","dateModified":"2026-08-31T04:24:09+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup"},"wordCount":1257,"articleSection":["Compliance"],"inLanguage":"en-US"},{"@type":["WebPage","FAQPage"],"@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup","url":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup","name":"Do Not Sell Page Setup: A Step-by-Step CCPA Guide | CookieLet","isPartOf":{"@id":"https:\/\/www.cookielet.com\/blog\/#website"},"datePublished":"2026-08-28T06:12:15+00:00","dateModified":"2026-08-31T04:24:09+00:00","author":{"@id":"https:\/\/www.cookielet.com\/blog\/#\/schema\/person\/547ab6e3c6f9c8890fe45c6e417bf796"},"description":"Setting up a \"Do Not Sell\" page? This step-by-step guide covers CCPA link wording, opt-out toggles, GPC signals, and the 2026 confirmation rule.","breadcrumb":{"@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#breadcrumb"},"mainEntity":[{"@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897312383"},{"@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897328261"},{"@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897344565"},{"@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897373908"}],"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cookielet.com\/blog\/"},{"@type":"ListItem","position":2,"name":"How to Set Up a &#8220;Do Not Sell&#8221; Page for US Visitors"}]},{"@type":"WebSite","@id":"https:\/\/www.cookielet.com\/blog\/#website","url":"https:\/\/www.cookielet.com\/blog\/","name":"CookieLet","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cookielet.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.cookielet.com\/blog\/#\/schema\/person\/547ab6e3c6f9c8890fe45c6e417bf796","name":"Sibin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a38eb912dbb9e1abe1560de7fa83dae86fea24663267504c0f64b26949a98d83?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a38eb912dbb9e1abe1560de7fa83dae86fea24663267504c0f64b26949a98d83?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a38eb912dbb9e1abe1560de7fa83dae86fea24663267504c0f64b26949a98d83?s=96&d=mm&r=g","caption":"Sibin"},"description":"Privacy Compliance Specialist &amp; Content Writer at CookieLet specializing in cookie compliance, consent management, and global data protection regulations including GDPR, CCPA, and ePrivacy Directive.","url":"https:\/\/www.cookielet.com\/blog\/author\/sibin"},{"@type":"Question","@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897312383","position":1,"url":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897312383","name":"1.Do I need a separate page per state?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"No. One opt-out page serves all states because the underlying right stop selling\/sharing my data, honor my universal opt-out signal is the common template. Just avoid California-only wording if you honor requests from all US visitors (recommended: honor everyone, verify no one).","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897328261","position":2,"url":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897328261","name":"2.Should I show the link only to Californians?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"You may geo-target it, but most businesses show it to all US visitors it's simpler, safer as more states come online, and consumers increasingly expect it.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897344565","position":3,"url":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897344565","name":"3.What's the deadline to process an opt-out?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"Cookie-based sharing should stop effectively immediately via your CMP. Back-end requests (e.g., stopping list sales) must be completed within 15 business days in California, and you must instruct downstream recipients accordingly.","inLanguage":"en-US"},"inLanguage":"en-US"},{"@type":"Question","@id":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897373908","position":4,"url":"https:\/\/www.cookielet.com\/blog\/do-not-sell-page-setup#faq-question-1787897373908","name":"4.Does opting out mean the visitor sees no ads?","answerCount":1,"acceptedAnswer":{"@type":"Answer","text":"No - they'll see non-personalized ads. Opting out stops the sale\/sharing of their data for cross-context behavioral advertising, not advertising itself. Say this on the page; it reduces support tickets.","inLanguage":"en-US"},"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/posts\/1522","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/comments?post=1522"}],"version-history":[{"count":4,"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/posts\/1522\/revisions"}],"predecessor-version":[{"id":1546,"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/posts\/1522\/revisions\/1546"}],"wp:attachment":[{"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/media?parent=1522"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/categories?post=1522"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cookielet.com\/blog\/wp-json\/wp\/v2\/tags?post=1522"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}