[ CCPA / CPRA ]

    CCPA cookie consent and Do Not Sell or Share link

    Short answer: if your business sells or shares personal information of California residents, you must put a clear and conspicuous "Do Not Sell or Share My Personal Information" link on your website. You cannot require an account to opt out, you must treat the Global Privacy Control signal as a valid opt-out, and you must respect an opt-out for at least 12 months before asking the person to opt back in.

    • CCPA / CPRA
    • Cal. Civ. Code § 1798.135

    What California law requires

    These points come from the California Attorney General's CCPA page, which showed "last updated 28 August 2026" when reviewed. The statute section is California Civil Code section 1798.135.

    • California residents have five CCPA rights: to know, to delete, to opt out of the sale or sharing of their personal information, to correct, and to limit the use of sensitive personal information. CA Attorney General
    • "Sharing" means targeting advertising to a consumer based on personal information gathered from their activity across multiple websites. CA Attorney General
    • Businesses that sell or share personal information must provide a clear and conspicuous "Do Not Sell or Share My Personal Information" link on their website. CA Attorney General
    • Businesses cannot require consumers to create an account to submit an opt-out request. CA Attorney General
    • Businesses must respect an opt-out for at least 12 months before asking the consumer to opt back in. CA Attorney General
    • Businesses must treat the Global Privacy Control signal as a valid opt-out request; the Attorney General describes GPC as one easy way for consumers to opt out. CA Attorney General
    • Global Privacy Control describes itself as a browser or extension setting that signals a person's privacy preferences to the sites they visit.

    Questions to answer before you go live

    The Attorney General's guidance turns into a short checklist. Answer each question for your own business, ideally with your legal adviser, before you rely on your banner.

    • Do we sell personal information, or share it by targeting advertising based on activity across multiple websites? If so, we need the link.
    • Is our "Do Not Sell or Share My Personal Information" link clear and conspicuous on our website?
    • Can a visitor opt out without creating an account or logging in?
    • Do we treat a Global Privacy Control signal as a valid opt-out request?
    • Do we wait at least 12 months after an opt-out before asking the person to opt back in?
    • Do we have a way to handle the other rights — to know, to delete, to correct, and to limit the use of sensitive personal information? A cookie banner alone does not cover these.

    How CookieJar handles it

    CookieJar gives California visitors an opt-out path without extra work on your side. CookieJar is software, not legal advice.

    • Detects California visitors by location, so the California experience is shown to them.
    • Shows a "Do Not Sell or Share My Personal Information" link to those visitors in the banner.
    • Honors the Global Privacy Control signal automatically, with no click needed from the visitor.
    • Records each opt-out with a timestamp, so you have a record of when it happened.

    Step-by-step setup

    Use these steps to add an opt-out link for California visitors.

    1. Create a CookieJar account and add your domain.
    2. Run a scan to find the advertising and analytics scripts on your site.
    3. Decide, with your legal adviser, whether your business sells or shares personal information as the Attorney General defines it.
    4. Paste the CookieJar script tag into your site's <head> and publish.
    5. Test from California, or with a tool that simulates a California location, and confirm the "Do Not Sell or Share My Personal Information" link appears.
    6. Turn on Global Privacy Control in a supporting browser and confirm the visit is treated as an opt-out.
    7. Check your dashboard to confirm opt-outs are recorded with a timestamp.

    Common mistakes

    Each follows from the Attorney General's guidance above.

    • Hiding the opt-out link where visitors will not find it. The link must be clear and conspicuous.
    • Asking people to sign up or log in before they can opt out. You cannot require an account.
    • Ignoring the Global Privacy Control signal. It must be treated as a valid opt-out.
    • Asking people to opt back in soon after they opt out. You must wait at least 12 months.
    • Assuming ad targeting is not "sharing". Targeting ads based on activity across multiple websites is sharing.

    [ FAQ ]

    Common questions

    Last reviewed: 3 October 2026 by CookieJar team.

    Need our DPA or security details?

    One email and you'll have everything your security and legal teams need.

    View DPA