August 9, 2025
3 min read
The California Privacy Rights Act (CPRA) expands consumer rights beyond the California Consumer Privacy Act (CCPA) by mandating businesses to provide explicit opt-out options for both the sale and sharing of personal information. The CPRA articulates that:
“A consumer shall have the right, at any time, to direct a business that sells or shares personal information about the consumer to third parties not to sell or share the consumer’s personal information. This right may be referred to as the right to opt-out of sale or sharing.” (CPRA §1798.120)
This amendment introduces a dual opt-out mechanism, extending previous obligations that focused solely on sales of personal data. The requirement to address sharing reflects the evolving data ecosystem where personal information is often disseminated beyond transactional sales, such as data sharing for cross-context behavioral advertising.
Key mandates under CPRA include:
Clear and Conspicuous Link: Businesses must display a “Do Not Sell or Share My Personal Information” link prominently on their websites, ensuring easy consumer access. This link must be visible without requiring scrolling or navigating through multiple pages.
Respect for Global Opt-Out Signals: CPRA requires businesses to honor global privacy control signals like the Global Privacy Control (GPC). Such signals serve as a standardized mechanism for users to indicate their preference to opt out of sale or sharing across multiple websites.
The practical effect is a broader scope of consumer control:
This dual opt-out requirement aligns with findings in privacy research emphasizing that consumer awareness and control over data flows are critical for privacy preservation (Acquisti, Brandimarte, & Loewenstein, 2015). The CPRA’s explicit inclusion of sharing addresses gaps identified in prior laws where data exchanges that did not constitute sales were outside consumer control (Englehardt & Narayanan, 2016).
Summary of CPRA ‘Do Not Sell or Share’ Requirements:
This expanded framework reflects a significant regulatory shift aiming to enhance transparency and empower consumer privacy rights in digital environments.