Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable for making CPRA Do Not…
Governance, Ownership & Risk

Who is accountable for making CPRA Do Not Sell or Share rights work across privacy, marketing, and vendor operations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 23, 2026 Domain: Governance, Ownership & Risk

Accountability should sit with the privacy or data governance function, but execution spans marketing, web operations, data engineering, and vendor management. The article makes clear that governance cannot be isolated in one team because consumer choices have to flow through notices, interfaces, systems, and third-party relationships. Effective ownership is cross-functional, with one team coordinating control design and evidence.

How CPRA Do Not Sell or Share Rights Become an Operating Control, Not Just a Privacy Notice

CPRA rights only work when the organisation turns a legal requirement into an operating workflow. That means the right is not fulfilled by a policy page alone, it has to be reflected in notice language, preference capture, suppression logic, audience and tag management, downstream data flows, and vendor instructions. The accountability question is therefore about who owns the control design and who can prove it works end to end.

In practice, the accountable function should coordinate the standard and own the evidence trail, while other teams execute the parts they control. Privacy or data governance usually defines the rule, but marketing, web operations, data engineering, and vendor management each influence whether a sale or sharing signal is actually honoured across channels and partners.

That cross-functional shape is why a “single team owns compliance” model often fails. If the business cannot connect the preference capture point to every system that consumes it, the consumer right exists on paper but not in production.

Where Accountability Breaks Down Across Privacy, Marketing, and Vendors

The failure mode is usually fragmentation. Privacy may own the policy, marketing may own audience tools, engineering may own pipelines, and vendors may process the data, but nobody owns the full control path. When those handoffs are unclear, rights requests are lost, suppression lists lag behind, and third-party disclosures continue after an opt-out.

A useful way to think about accountability is by control layer. The accountable owner should set the requirement, define the evidence standard, and resolve conflicts, while each operational team is responsible for implementation in its own systems. The privacy function is often best placed to arbitrate exceptions because it can judge legal interpretation without being trapped inside one channel or platform.

That same model also helps when the business uses multiple adtech, analytics, or data-sharing vendors. Vendor management cannot be an afterthought because CPRA rights depend on contract terms, data flow mapping, and confirmation that suppression instructions are actually enforced outside the organisation’s perimeter.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-02 — Mission, Stakeholders, and Legal RequirementsCPRA rights require cross-functional ownership and legal obligations to be translated into operations.
GV.RM-03 — Risk Management StrategyCross-team failure to propagate opt-out signals creates governance and compliance risk across the data lifecycle.
PR.DS-01 — Data-at-Rest and Data-in-Transit ProtectionDo Not Sell or Share rights depend on controlling how data moves between systems and third parties.
Recommendation — Assign a clear accountable owner for translating CPRA obligations into implemented controls and evidence. Set a risk strategy that covers notice, suppression, and vendor flow enforcement end to end. Control data sharing paths so opt-out state is enforced wherever data is transferred or processed.
CIS Controls v816.13 — Establish and Maintain Data Retention and Disposal ProcessesRights enforcement depends on limiting continued use and propagation of data after a consumer opts out.
6.3 — User Account Access Establishment and RemovalOperational rights handling needs timely removal or blocking of data-sharing pathways and access channels.
Recommendation — Define retention and disposal rules that support suppression and downstream sharing limits. Remove or block access paths that would continue selling or sharing opted-out data.
NIST SP 800-634.5 — Federation and Assertion ManagementPreference signals often move across systems and vendors as asserted state that must remain trustworthy.
6.1 — Digital Identity LifecycleThe right must persist across lifecycle changes in systems, tools, and outsourced processing relationships.
Recommendation — Preserve trustworthy assertion handling so opt-out state is carried consistently between systems. Maintain lifecycle controls so consumer preference state remains current across operational changes.

Practitioner Guidance

What to prioritise: Assign one accountable owner for the control, then document which teams implement notices, preference capture, suppression, data propagation, and vendor enforcement. If any one of those steps is missing, the right is not reliably operational.

What to verify: Test the full path from user request to downstream stop-sell or stop-share behaviour, including marketing tools and third-party recipients. Evidence should show when the signal was received, where it was propagated, and how exceptions were handled.

Common mistake: Treating vendor contracts or a privacy page as proof of compliance. The operational test is whether the opt-out survives real data movement, campaign execution, and partner processing.

Practitioner takeaway: Accountability should sit with the team that can coordinate and prove end-to-end control, because CPRA rights fail when ownership stops at policy and does not extend into the systems and vendors that actually use the data.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org