Accountability should sit with the privacy or data governance function, but execution spans marketing, web operations, data engineering, and vendor management. The article makes clear that governance cannot be isolated in one team because consumer choices have to flow through notices, interfaces, systems, and third-party relationships. Effective ownership is cross-functional, with one team coordinating control design and evidence.
How CPRA Do Not Sell or Share Rights Become an Operating Control, Not Just a Privacy Notice
CPRA rights only work when the organisation turns a legal requirement into an operating workflow. That means the right is not fulfilled by a policy page alone, it has to be reflected in notice language, preference capture, suppression logic, audience and tag management, downstream data flows, and vendor instructions. The accountability question is therefore about who owns the control design and who can prove it works end to end.
In practice, the accountable function should coordinate the standard and own the evidence trail, while other teams execute the parts they control. Privacy or data governance usually defines the rule, but marketing, web operations, data engineering, and vendor management each influence whether a sale or sharing signal is actually honoured across channels and partners.
That cross-functional shape is why a “single team owns compliance” model often fails. If the business cannot connect the preference capture point to every system that consumes it, the consumer right exists on paper but not in production.
Where Accountability Breaks Down Across Privacy, Marketing, and Vendors
The failure mode is usually fragmentation. Privacy may own the policy, marketing may own audience tools, engineering may own pipelines, and vendors may process the data, but nobody owns the full control path. When those handoffs are unclear, rights requests are lost, suppression lists lag behind, and third-party disclosures continue after an opt-out.
A useful way to think about accountability is by control layer. The accountable owner should set the requirement, define the evidence standard, and resolve conflicts, while each operational team is responsible for implementation in its own systems. The privacy function is often best placed to arbitrate exceptions because it can judge legal interpretation without being trapped inside one channel or platform.
That same model also helps when the business uses multiple adtech, analytics, or data-sharing vendors. Vendor management cannot be an afterthought because CPRA rights depend on contract terms, data flow mapping, and confirmation that suppression instructions are actually enforced outside the organisation’s perimeter.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-02 — Mission, Stakeholders, and Legal Requirements | CPRA rights require cross-functional ownership and legal obligations to be translated into operations. |
| GV.RM-03 — Risk Management Strategy | Cross-team failure to propagate opt-out signals creates governance and compliance risk across the data lifecycle. | |
| PR.DS-01 — Data-at-Rest and Data-in-Transit Protection | Do Not Sell or Share rights depend on controlling how data moves between systems and third parties. | |
| Recommendation — Assign a clear accountable owner for translating CPRA obligations into implemented controls and evidence. Set a risk strategy that covers notice, suppression, and vendor flow enforcement end to end. Control data sharing paths so opt-out state is enforced wherever data is transferred or processed. | ||
| CIS Controls v8 | 16.13 — Establish and Maintain Data Retention and Disposal Processes | Rights enforcement depends on limiting continued use and propagation of data after a consumer opts out. |
| 6.3 — User Account Access Establishment and Removal | Operational rights handling needs timely removal or blocking of data-sharing pathways and access channels. | |
| Recommendation — Define retention and disposal rules that support suppression and downstream sharing limits. Remove or block access paths that would continue selling or sharing opted-out data. | ||
| NIST SP 800-63 | 4.5 — Federation and Assertion Management | Preference signals often move across systems and vendors as asserted state that must remain trustworthy. |
| 6.1 — Digital Identity Lifecycle | The right must persist across lifecycle changes in systems, tools, and outsourced processing relationships. | |
| Recommendation — Preserve trustworthy assertion handling so opt-out state is carried consistently between systems. Maintain lifecycle controls so consumer preference state remains current across operational changes. | ||
Practitioner Guidance
What to prioritise: Assign one accountable owner for the control, then document which teams implement notices, preference capture, suppression, data propagation, and vendor enforcement. If any one of those steps is missing, the right is not reliably operational.
What to verify: Test the full path from user request to downstream stop-sell or stop-share behaviour, including marketing tools and third-party recipients. Evidence should show when the signal was received, where it was propagated, and how exceptions were handled.
Common mistake: Treating vendor contracts or a privacy page as proof of compliance. The operational test is whether the opt-out survives real data movement, campaign execution, and partner processing.
Practitioner takeaway: Accountability should sit with the team that can coordinate and prove end-to-end control, because CPRA rights fail when ownership stops at policy and does not extend into the systems and vendors that actually use the data.
Related resources from NHI Mgmt Group
- Who is accountable for making security and privacy collaboration work across the organisation?
- Who is accountable for making PAM work across the lifecycle?
- Who should be accountable when privacy controls slow down marketing operations?
- Who is accountable when a vendor supports automated decision-making or privacy workflows?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org