The Do Not Sell My Personal Information link is the web disclosure businesses must provide when they sell personal information. It gives consumers a visible path to opt out of that sale. The control is both a notice mechanism and an operational intake point for downstream preference handling.
Expanded Definition
The Do Not Sell My personal information link is a consumer-facing disclosure that signals a business may be selling personal information and provides a direct path to opt out. In practice, it is part legal notice, part workflow entry point, because the click must trigger downstream preference handling, not just satisfy page-copy requirements. In privacy operations, the link is closely related to consent management, request intake, and suppression logic, but it is not the same thing as a generic privacy policy link. Definitions vary across vendors and jurisdictions, yet the operational expectation is consistent: the disclosure must be visible, accurate, and connected to the systems that actually enforce the opt-out. That makes it a governance control as much as a website component, especially when personal data flows into analytics, adtech, and identity-linked automation. For broader control mapping, organisations often align this function with NIST Cybersecurity Framework 2.0 around governance and data protection obligations. The most common misapplication is placing the link on a page that does not route into real suppression workflows, which occurs when marketing and privacy teams update web copy without integrating the underlying preference systems.
Examples and Use Cases
Implementing this disclosure rigorously often introduces friction between user experience and compliance handling, requiring organisations to weigh simpler site navigation against the cost of maintaining accurate preference propagation.
- A retail site places the link in the footer and routes clicks into a verified opt-out form that updates adtech, CRM, and data broker sharing controls.
- An e-commerce brand uses the link to separate sale opt-outs from general unsubscribe requests, avoiding confusion between marketing email preferences and data sale restrictions.
- A multi-brand enterprise centralises the intake path so one disclosure feeds several business units, with consistent logging and response tracking.
- A privacy team reviews the link flow after incidents like the Schneider Electric credentials breach to confirm that consumer-facing notices still reflect actual data handling and access pathways.
- A security architect checks whether the same data path that handles opt-outs also respects identity and session controls described in the Ultimate Guide to NHIs, especially where automation touches personal data.
Because the link is an operational intake point, teams often validate it alongside the request lifecycle documented in the NIST Cybersecurity Framework 2.0, especially where data handling and response tracking need evidence.
Why It Matters in NHI Security
Although the term sounds like a privacy UI element, it matters in NHI security because NHI-driven systems frequently move personal data across automation, analytics, and third-party integrations. If the disclosure does not map to actual control enforcement, personal information can continue to be shared by service accounts, APIs, or agentic workflows after a consumer has opted out. NHIMG research shows that 97% of NHIs carry excessive privileges, which increases the likelihood that downstream systems can bypass intended data-sharing boundaries if governance is weak. That risk is amplified when secrets and service accounts are not tied to auditable preference logic, especially in environments with third-party data exchange. The control therefore supports both privacy compliance and access discipline, particularly where consumer data passes through machine identities that are harder to monitor than human users. The most important operational lesson is that the disclosure is only as effective as the systems behind it, including the identity paths that enforce suppression. Organisations typically encounter the real impact only after a complaint, audit finding, or breach reveals that the opt-out link existed while the data sale pipeline kept running.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207), NIST AI RMF and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV-01 | Governance and oversight depend on visible, enforceable privacy controls. |
| OWASP Non-Human Identity Top 10 | NHI-04 | Downstream handling often relies on service accounts and automation with excessive access. |
| NIST Zero Trust (SP 800-207) | JP-1 | Zero trust requires explicit policy enforcement across data-moving components. |
| NIST AI RMF | AI governance must account for data handling and consumer preference enforcement. | |
| NIST SP 800-63 | Identity assurance matters where requests change privacy state and access rules. |
Validate every data-sharing path against policy so suppression survives internal and third-party hops.
Related resources from NHI Mgmt Group
- Who is accountable when unauthorized use of personal information occurs?
- What breaks when sensitive personal information is shared too broadly with processors?
- Who is accountable when breach scoping misses affected personal information?
- What breaks when a firm cannot locate customer nonpublic personal information before an incident?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org