SiteScanReport

Privacy

The CCPA "Do Not Sell or Share" link: who needs it, and how to check yours

By SiteScanReport August 16, 2026

That "Do Not Sell or Share My Personal Information" link you have seen in website footers is a specific California requirement, not decoration. Whether your site needs one is a narrower question than most owners assume, and the answer often hinges on something easy to miss: the ad-tracking pixels already running on your pages. Here is who is covered, when the link is required, and how to check your own site.

Who the CCPA actually covers

The California Consumer Privacy Act, as amended by the CPRA, applies to a for-profit business that does business in California and meets at least one of three thresholds:

  • Annual gross revenue above roughly $26.6 million (the figure is adjusted for inflation), or
  • Buys, sells, or shares the personal information of 100,000 or more California consumers or households in a year, or
  • Earns 50 percent or more of its annual revenue from selling or sharing personal information.

Meet any one and you are covered. Most small businesses fall below all three and are not directly covered, which is worth knowing before you assume you have a problem. But the second threshold is where ordinary sites get pulled in, and it is not about revenue at all.

The pixel trap

Under the CCPA, "sharing" includes disclosing personal information to advertising vendors for cross-context behavioral advertising, the ordinary retargeting that follows a visitor around the web. A common ad or analytics pixel that sends visitor data to an ad network can count as "sharing." A site with real traffic can reach the 100,000-consumer threshold on that basis without ever selling a thing in the everyday sense. If you run retargeting, this is the part to look at closely.

When the link is required

If you are covered by a threshold and you sell or share personal information, you must give visitors a way to opt out. In practice that means:

  • A clear and conspicuous link, titled "Do Not Sell or Share My Personal Information" or a "Your Privacy Choices" link with the opt-out icon, and
  • A working opt-out behind it, and
  • Honoring the Global Privacy Control, the browser signal that tells you a visitor has opted out, as a valid request.

If you are not covered, or you genuinely do not sell or share, you do not need the link. The trouble is that many owners do not actually know which pixels are on their site or what those pixels send.

How to check your own site

Three things to look at:

  • Is the link present and easy to find? It should be reachable from the homepage, clearly labeled, and lead to a real opt-out, not a dead anchor.
  • What is actually loading on your pages? This is the one owners rarely see. Every third-party script, pixel, and tracker your pages load is a candidate for "sharing." You cannot judge your obligation without knowing what is running.
  • Do you honor Global Privacy Control? If you are covered, an opt-out signal from the browser has to be respected.

A scan is the fast way to see the first two. Run a scan and the report shows whether a privacy policy and opt-out link are present and lists the third parties actually loading on your pages, read from real network traffic. That tells you what your site is doing, which is the input every one of these decisions depends on. What a scan does not do is judge whether your policy is legally sufficient; presence is a signal, not a legal verdict. Our methodology page explains exactly where that line is.

Where to start

Find out what is loading on your site before you assume you are in the clear or panic that you are not. Once you can see the trackers and whether the opt-out link is present and working, the legal question gets a lot more concrete, and it is the right moment to bring in counsel if you need one.

This article is information, not legal advice.

FAQ

Does my small business need a Do Not Sell link?

Only if you meet a CCPA threshold and you sell or share personal information. Many small sites do not, but retargeting pixels can pull a site over the 100,000-consumer "sharing" threshold, so it is worth checking what is actually loading rather than assuming.

What counts as "selling" or "sharing" data?

"Selling" is the exchange of personal information for value. "Sharing" is broader and includes disclosing data to ad vendors for cross-context behavioral advertising, which is what ordinary retargeting does.

Is "Your Privacy Choices" the same as "Do Not Sell or Share"?

Yes, it is the alternative label California allows, shown with the opt-out icon. Either satisfies the link requirement when it leads to a working opt-out.

Sources

  1. California Attorney General, California Consumer Privacy Act (CCPA)
  2. Get Up To Code, CCPA for small business: who is covered and what applies

See where your site stands.

Run the free scan for a plain read on your site's accessibility, privacy, and security, with the fixes that matter most.