Join our Newsletter — 33% off our NHI Course

How should organisations implement a clear Do Not Sell or Share option on their websites under CPRA?

Organisations should place a clear, conspicuous opt out link on their homepage and any page where personal information is collected, and make it easy to use without creating an account. The workflow should also support a global opt out preference signal, provide a privacy notice explaining the right, and keep the experience consistent across web and app channels.

What “Do Not Sell or Share” should look like on the page

A CPRA opt-out must be obvious, persistent, and easy to act on. The practical test is whether a visitor can find it quickly, understand what it does, and complete the request without friction. A good implementation uses plain language, places the link where users expect privacy choices, and avoids burying the option inside layered menus or dense legal text.

The experience should also work cleanly across device types and channels. If a website collects personal information in multiple places, the opt-out entry point should appear consistently where the data collection happens, not only in a single footer location. That reduces missed notices and helps the organisation treat the right as an operating requirement rather than a one-off page design task.

For practical reference, privacy notice structure and control design are often easier to align when teams treat the opt-out as part of a broader control set, not a standalone compliance artifact. Guidance such as ISO/IEC 27002:2022 Information Security Controls can help teams anchor the implementation in consistent governance and review discipline.

How the opt-out workflow should behave

The workflow should be simple enough that a consumer does not need to create an account, log in, or navigate a high-friction identity process just to exercise the choice. The best pattern is a direct request path, a clear confirmation state, and a backend process that can propagate the preference to the systems actually using or disclosing the data. If the control only changes one web form but not the downstream sharing logic, it is incomplete.

The “global opt out preference signal” matters because consumers increasingly expect one request to carry across pages, devices, and sessions. Organisations should design for preference persistence, not just form submission. That means the signal needs to be recognised, stored, and respected in the places where adtech, analytics, or other data-sharing decisions are made, rather than handled as a cosmetic banner dismissal.

Implementation guidance from OWASP Cheat Sheet Series is useful here because the control often fails at the handoff between user interface, request handling, and backend enforcement.

What good CPRA alignment requires behind the scenes

A compliant design is not just a link and a page. Teams need a durable notice, a consistent preference record, and a verified path for downstream systems to honour the request. That includes web forms, apps, tag managers, consent tooling, and any third party receiving data under a selling or sharing relationship. If one channel ignores the preference, the organisation has not really implemented the right, it has only displayed it.

Privacy governance also benefits from mapping the flow of the request against the actual data ecosystem. That is where privacy management, records of processing, and control testing become important. A privacy-oriented control framework such as NIST Privacy Framework can help teams connect the consumer-facing choice to internal handling, retention, and oversight responsibilities.

For teams that need to coordinate this across access, logging, and change control, NIST SP 800-53 Rev 5 Security and Privacy Controls provides a control vocabulary that supports consistent implementation and auditability.

Risk and Threat Considerations

CPRA opt-out failures are often not dramatic, but they are consequential: a buried link, a broken preference store, or a mismatch between the website and downstream sharing systems can result in continuing disclosures after a consumer has opted out. The risk increases when multiple vendors, scripts, or app channels participate in the data flow.

Failure mechanism: The visible opt-out works only at the page layer, while the actual sharing or sale continues because preference data is not propagated to the systems that make the disclosure decision, or because the preference is not consistently recognised across channels.

Impact: The organisation can create compliance exposure, consumer trust loss, and remediation overhead, especially if the failure is systemic rather than isolated to one page or one product team.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
ISO/IEC 27001:2022 A.5.34 — Privacy and protection of PII CPRA opt-out handling is a privacy control over personal information use and disclosure.
Recommendation — Align the opt-out workflow to privacy controls and verify downstream enforcement of the preference.
NIST SP 800-53 Rev 5 AP-1 — Authority to Process Personal Data The opt-out is a privacy requirement that should be governed as an authorised personal-data processing decision.
AU-2 — Event Logging Opt-out processing needs traceable evidence that requests were received and enforced.
IA-2 — Identification and Authentication (Organizational Users) The user-facing workflow should avoid unnecessary authentication friction for exercising the privacy right.
Recommendation — Define and review the authority for selling or sharing personal data under a documented privacy process. Log opt-out submissions and enforcement events so teams can verify end-to-end handling. Avoid forcing account creation or excess authentication for a consumer privacy opt-out.

Practitioner Guidance

What to verify: Test the full path from the homepage or collection page to the backend system that enforces the preference. The key question is not whether the link exists, but whether the opt-out survives page refreshes, device changes, and app-web transitions.

Decision rule: If the consumer can only exercise the right after account creation, or if the preference is not visibly persistent, treat the implementation as insufficient and redesign the workflow before relying on it operationally.

Practitioner takeaway: The right control is the one that changes downstream behaviour, not the one that merely tells the user they have a right.