Skip to content
Adrythm
Email, texting and privacy

Sale and sharing of personal information

cross-context behavioral advertising / Do Not Sell or Share My Personal Information / CCPA sale of personal information

In short

Under California's CCPA, a business sells personal information by passing it to a third party for money or other valuable consideration, and shares it by passing it on for cross-context behavioral advertising, paid or unpaid. Both trigger an opt-out right, so a pixel feeding ads on other sites can require a Do Not Sell or Share link.

California Civil Code section 1798.140 defines both words. Selling, in subdivision (ad), is making a consumer's personal information available to a third party for money or other valuable consideration. Sharing, in subdivision (ah), is the same kind of transfer made for cross-context behavioral advertising, even when no money is exchanged.

Subdivision (k) defines cross-context behavioral advertising as targeting ads at a consumer based on their activity across other businesses, websites, apps or services. The identifiers the law names include cookies, beacons and pixel tags.

Both definitions depend on the recipient being a third party. The law excludes service providers and contractors from that term. The exclusion needs a written contract. It must bar the vendor from selling or sharing the data, using it for other purposes, or combining it with data from elsewhere. Service providers may run ads, except cross-context behavioral ads.

In one Attorney General enforcement sweep, online retailers used tracking to give third parties personal information in exchange for advertising or analytics. They offered no opt-out and had not ensured the recipients were CCPA-compliant service providers.

A covered business that sells or shares must post a clear and conspicuous link titled Do Not Sell or Share My Personal Information. The home page needs it, and so does any page that collects personal information. One combined link that also covers limiting sensitive personal information is allowed. The California Privacy Protection Agency also accepts the labels Your Privacy Choices or Your California Privacy Choices, in the footer or header.

The privacy policy must describe the opt-out right, and opting out cannot require an account. The business must stop selling or sharing as soon as feasibly possible, within 15 business days at most. It must wait at least 12 months before asking again.

Covered businesses must also honor browser signals such as Global Privacy Control as valid opt-out requests. Under revised regulations in effect since January 1, 2026, a business must display on its website whether it has processed a visitor's signal.

Under section 1798.120, selling or sharing data about a consumer known to be under 16 needs an opt-in, from a parent or guardian if under 13.

In practice

A kitchen remodeler covered by the CCPA adds an ad platform's pixel to show ads to past visitors on other sites. The platform receives visitor data for cross-context behavioral advertising, which counts as sharing with no payment involved. The remodeler posts the opt-out link and stops the pixel for anyone who opts out there or arrives with Global Privacy Control on. A toggle on the site shows those visitors they have opted out.

Not the same as

Disclosure to a service provider
The CCPA excludes service providers and contractors from the definition of a third party. A vendor handling data for a business purpose under a written contract with the required limits receives it outside the sale and sharing rules, though cross-context behavioral advertising cannot be one of its services.
Limit the Use of My Sensitive Personal Information
That separate link lets a consumer limit how a business uses or discloses sensitive personal information. The Do Not Sell or Share link stops the sale or sharing itself, and the statute allows one combined link covering both.

Why it matters to you

Since January 1, 2023, the CCPA no longer requires notice of a violation or a chance to cure before an enforcement action is filed. Tags, the opt-out link, signal handling and vendor contracts need to line up before anyone complains.

What to ask or check

  1. 01Which tags on your website send visitor data to ad platforms or other third parties, and for what purpose?
  2. 02Does each vendor contract carry the CCPA service provider restrictions, including the bars on selling, sharing, and using or combining the data for other purposes?
  3. 03When someone opts out by link or browser signal, which tags stop firing, and has anyone tested it?
  4. 04When a visitor arrives with Global Privacy Control on, does your website display whether the opt-out was processed?

What people get wrong

That tracking tags fall outside the law when nobody pays for the data. The CCPA counts a transfer for cross-context behavioral advertising as sharing whether or not money or anything else of value is involved.

Red flags

  • Opt-out requests routed only to an advertising trade association's tool, with no way to opt out of the business's own sales.
  • An ad or analytics vendor receiving visitor data under its standard terms, with no contract carrying the CCPA service provider restrictions.

Global Privacy Control

Global Privacy Control is a signal a web browser sends to every site a person visits, saying they do not want their personal information sold or shared. California's CCPA counts it as a valid opt-out request, and Colorado recognizes it as a universal opt-out, so covered businesses must honor it automatically.

CCPA business thresholds

The CCPA business thresholds are the three tests that decide whether California's privacy law covers a for-profit company doing business in the state. Meeting any one is enough: revenue above $26,625,000 a year, buying, selling or sharing personal information of 100,000 or more consumers or households, or earning half its revenue from selling or sharing it.

Notice at collection

A notice at collection is the disclosure California's privacy law requires before or as a covered business collects personal information. It says what is collected and why, whether it is sold or shared, and how long it is kept. So it belongs wherever the information is gathered, such as a website form.

Right to delete

The CCPA right to delete lets a California consumer ask a covered business to erase personal information collected from them. Unless an exception applies, the business deletes it within 45 days, extendable once by 45 when reasonably necessary with notice. It also notifies service providers, contractors and, unless impossible or disproportionate, third parties it sold or shared data with.

Consent mode

Consent mode is how an advertising tag is told whether a visitor agreed to be tracked. Both major platforms now require a consent signal, and the penalties differ in kind: Google's policy allows it to suspend or terminate your account, while Microsoft simply stops recording your conversions.

DKIM

DKIM attaches a cryptographic signature to a message so a receiver can confirm the signed parts were not altered. The standard describes it as a domain claiming some responsibility for the message, and it separates the signer from the purported author. Modifying a message in transit breaks the signature.

Want this explained against your own numbers?

Twenty minutes, a straight answer, and no follow-up sequence if you decide not to work with us.