Коротко
- If you sell or share PI of California residents, you need a conspicuous Do Not Sell or Share link (or Your California Privacy Choices).
- Sale is broader than a “cash sale”: valuable consideration + third-party cookies/ads often enter the discussion.
- CCPA/CPRA ≠ GDPR opt-in: a banner is not always legally required, but notice + a working opt-out is, if there is sale/share.
- On ClikBy smart links: Reject in pixel_notification stops pixels based on cookie consent{link_id}; the DNSMPI footer is your zone on the site.
Not legal advice
A guide for setting up notifications and funnels. Whether your pixel is sale/share is a legal assessment, not a product one.
A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → CCPA. This is not legal advice and not a verbatim translation of other articles.
What the Do Not Sell requirement is
CCPA gives the consumer the right to require a business to stop selling their personal information to third parties (with exceptions). CPRA expands the wording to Do Not Sell or Share — including share for cross-context behavioral advertising.
A business must:
- Provide a clear and conspicuous opt-out mechanism;
- Stop sale/share after the request (until the consumer expressly opt-in again);
- Not ask again for permission to sale for at least 12 months after opt-out;
- Provide ≥2 opt-out methods (link/form + email/toll-free, etc., per your model);
- Describe the right and the process in the privacy notice.
Sale, share, and third party
Sale includes renting, disclosing, releasing, disseminating, transferring, or otherwise communicating PI to another business or third party for monetary or other valuable consideration.
Service provider under a written contract with limits on PI use is usually taken out of “sale.” A transfer in an M&A context is also often excluded from the sale definition.
Share (CPRA) — the focus is cross-context behavioral advertising: when PI leaves for targeting across different contexts/sites. Non-targeted ads without that sharing are a separate conversation.
If you “just connected a Meta pixel” without reviewing the contract and disclosures, that is not automatically “not a sale.”
Do Not Sell or Share link
- Place it on the homepage and pages where you collect PI; in apps — reachable from the UI;
- Copy: “Do Not Sell My Personal Information” / “Do Not Sell or Share My Personal Information” or the combined “Your Privacy Choices” / “Your California Privacy Choices”;
- The link goes to a page with an explanation and an opt-out form/button;
- You can add the official opt-out icon next to the link (optional under the amendments);
- For SPI — a separate or combined Limit the Use of My Sensitive Personal Information.
Enforcement reports from the first years of CCPA show a meaningful share of notices were about a missing DNSMPI link and incomplete privacy policies — this is not “cosmetics.”
The link should be as noticeable as other important links; hiding it at the end of a 40-page policy is an anti-pattern.
Ban on dark patterns
Amendments ban interfaces that substantially subvert or impair the opt-out choice. You must not:
- Make opt-out longer/harder than a later opt-in;
- Use confusing language (double negatives such as “Don't Not Sell…”);
- Force people to click/listen to “why you should not opt-out”;
- Hide the link so people have to hunt for it in the policy text.
Global Privacy Control (GPC)
GPC is a browser/extension signal to “opt out of sale/share.” In the CCPA/CPRA ecosystem and CMP reviews (including CookieYes) it is increasingly described as a signal a business must recognize and handle on par with a DNSMPI click — confirm the current duty with a lawyer and CPPA regulations.
In practice: if you claim GPC support in the policy, make sure your CMP/tag manager actually mutes sale/share tags on the signal, not merely logs the event.
Four steps on the site
1. Do Not Sell or Share link
In the footer and/or header → a page with collection purposes, the fact of sale/share, and an opt-out form.
2. Opt-out form / button
Minimal fields; confirmation; an email/phone alternative. Industry examples: a button, cookie settings, a combined CCPA+Nevada form — pick a clear UX without dark patterns.
3. Cookie / opt-out notice
If third parties collect activity via cookies, pixels, beacons, social plugins — show a notice and provide a way to opt out of the relevant categories.
4. Privacy policy
PI categories for the past 12 months, purposes, sources, sale/share/disclose, rights, authorized agent, contacts, process for minors, update date. A link to the policy from the homepage.
A detailed disclosures checklist is also in CCPA Requirements (CookieYes).
How this fits with ClikBy
- Client site: DNSMPI / Your Privacy Choices + CMP (CookieYes or the ClikBy /cookies module) — your responsibility.
- Smart link redirect: enable pixel_notification; Reject → consent{link_id}=0 → pixels do not fire when consent is checked.
- Consistency: site copy saying «we do not sell data» while ad pixels are active on links — a disclosures conflict.
- Data-subject requests: the clicker writes to you; you can escalate visit deletion to ClikBy under the DPA/support.
In ClikBy: roles Customer = controller / ClikBy = processor for clicks; the controls are Cookie Consent and pixel_notification on the redirect. A CCPA badge on the landing page does not replace your Do Not Sell or Share notice.
FAQ
Do we need a DNSMPI link if we «do not sell» data?
If you truly do not sell and do not share PI as the law defines it, the link may not be required — but «we do not sell» with active ad pixels is often contested. Lock the position with counsel.
Is Reject in the ClikBy banner enough?
It is a product control for cookie / pixel categories on the redirect or site. It does not replace a legal notice and the verifiable consumer requests process.
Where else to read in the KB?
Cards on the opt-out link, Do Not Sell or Share, cookie banner under CPRA, GPC — in CookieYes KB → CCPA.