Sale and sharing of personal information
cross-context behavioral advertising / Do Not Sell or Share My Personal Information / CCPA sale of personal information
Under California's CCPA, a business sells personal information by passing it to a third party for money or other valuable consideration, and shares it by passing it on for cross-context behavioral advertising, paid or unpaid. Both trigger an opt-out right, so a pixel feeding ads on other sites can require a Do Not Sell or Share link.
California Civil Code section 1798.140 defines both words. Selling, in subdivision (ad), is making a consumer's personal information available to a third party for money or other valuable consideration. Sharing, in subdivision (ah), is the same kind of transfer made for cross-context behavioral advertising, even when no money is exchanged.
Subdivision (k) defines cross-context behavioral advertising as targeting ads at a consumer based on their activity across other businesses, websites, apps or services. The identifiers the law names include cookies, beacons and pixel tags.
Both definitions depend on the recipient being a third party. The law excludes service providers and contractors from that term. The exclusion needs a written contract. It must bar the vendor from selling or sharing the data, using it for other purposes, or combining it with data from elsewhere. Service providers may run ads, except cross-context behavioral ads.
In one Attorney General enforcement sweep, online retailers used tracking to give third parties personal information in exchange for advertising or analytics. They offered no opt-out and had not ensured the recipients were CCPA-compliant service providers.
A covered business that sells or shares must post a clear and conspicuous link titled Do Not Sell or Share My Personal Information. The home page needs it, and so does any page that collects personal information. One combined link that also covers limiting sensitive personal information is allowed. The California Privacy Protection Agency also accepts the labels Your Privacy Choices or Your California Privacy Choices, in the footer or header.
The privacy policy must describe the opt-out right, and opting out cannot require an account. The business must stop selling or sharing as soon as feasibly possible, within 15 business days at most. It must wait at least 12 months before asking again.
Covered businesses must also honor browser signals such as Global Privacy Control as valid opt-out requests. Under revised regulations in effect since January 1, 2026, a business must display on its website whether it has processed a visitor's signal.
Under section 1798.120, selling or sharing data about a consumer known to be under 16 needs an opt-in, from a parent or guardian if under 13.
In practice
A kitchen remodeler covered by the CCPA adds an ad platform's pixel to show ads to past visitors on other sites. The platform receives visitor data for cross-context behavioral advertising, which counts as sharing with no payment involved. The remodeler posts the opt-out link and stops the pixel for anyone who opts out there or arrives with Global Privacy Control on. A toggle on the site shows those visitors they have opted out.
Not the same as
- Disclosure to a service provider
- The CCPA excludes service providers and contractors from the definition of a third party. A vendor handling data for a business purpose under a written contract with the required limits receives it outside the sale and sharing rules, though cross-context behavioral advertising cannot be one of its services.
- Limit the Use of My Sensitive Personal Information
- That separate link lets a consumer limit how a business uses or discloses sensitive personal information. The Do Not Sell or Share link stops the sale or sharing itself, and the statute allows one combined link covering both.
Why it matters to you
Since January 1, 2023, the CCPA no longer requires notice of a violation or a chance to cure before an enforcement action is filed. Tags, the opt-out link, signal handling and vendor contracts need to line up before anyone complains.
What to ask or check
- 01Which tags on your website send visitor data to ad platforms or other third parties, and for what purpose?
- 02Does each vendor contract carry the CCPA service provider restrictions, including the bars on selling, sharing, and using or combining the data for other purposes?
- 03When someone opts out by link or browser signal, which tags stop firing, and has anyone tested it?
- 04When a visitor arrives with Global Privacy Control on, does your website display whether the opt-out was processed?
What people get wrong
That tracking tags fall outside the law when nobody pays for the data. The CCPA counts a transfer for cross-context behavioral advertising as sharing whether or not money or anything else of value is involved.
Red flags
- Opt-out requests routed only to an advertising trade association's tool, with no way to opt out of the business's own sales.
- An ad or analytics vendor receiving visitor data under its standard terms, with no contract carrying the CCPA service provider restrictions.