Home
ClikBy
ClikBy Knowledge Base
CCPA

Do Not Sell or Share: the link, cookies, and opt-out

When you need an opt-out link, why ad cookies fall under sale/share, whether a banner is required under CPRA, and what notifications on smart links actually do.

14–18 min Updated: July 2026
DNSMPIссылка
sale/shareпиксели
GPCсигнал

Коротко

  • If you sell or share PI of California residents, you need a conspicuous Do Not Sell or Share link (or Your California Privacy Choices).
  • Sale is broader than a “cash sale”: valuable consideration + third-party cookies/ads often enter the discussion.
  • CCPA/CPRA ≠ GDPR opt-in: a banner is not always legally required, but notice + a working opt-out is, if there is sale/share.
  • On ClikBy smart links: Reject in pixel_notification stops pixels based on cookie consent{link_id}; the DNSMPI footer is your zone on the site.

Not legal advice

A guide for setting up notifications and funnels. Whether your pixel is sale/share is a legal assessment, not a product one.

A guide to structure and facts: www.cookieyes.com/… · www.cookieyes.com/…. Summary KB section: CookieYes → CCPA. This is not legal advice and not a verbatim translation of other articles.

What the Do Not Sell requirement is

CCPA gives the consumer the right to require a business to stop selling their personal information to third parties (with exceptions). CPRA expands the wording to Do Not Sell or Share — including share for cross-context behavioral advertising.

A business must:

  • Provide a clear and conspicuous opt-out mechanism;
  • Stop sale/share after the request (until the consumer expressly opt-in again);
  • Not ask again for permission to sale for at least 12 months after opt-out;
  • Provide ≥2 opt-out methods (link/form + email/toll-free, etc., per your model);
  • Describe the right and the process in the privacy notice.

Sale, share, and third party

Sale includes renting, disclosing, releasing, disseminating, transferring, or otherwise communicating PI to another business or third party for monetary or other valuable consideration.

Service provider under a written contract with limits on PI use is usually taken out of “sale.” A transfer in an M&A context is also often excluded from the sale definition.

Share (CPRA) — the focus is cross-context behavioral advertising: when PI leaves for targeting across different contexts/sites. Non-targeted ads without that sharing are a separate conversation.

If you “just connected a Meta pixel” without reviewing the contract and disclosures, that is not automatically “not a sale.”

Do cookies count as a sale of PI?

Regulations and CookieYes reviews treat unique personal identifiers (cookies, IP, mobile ad IDs) as PI if they can recognize a device linked to a consumer/family over time and across services.

A typical scenario: the site sets a tracking cookie that lets an advertising network build a profile and show targeting on other sites in the network. Letting a third party read/write such identifiers is often discussed as a sale or share of PI.

Implication for marketing: first-party analytics ≠ automatically safe; ad pixels and sync are a risk zone. Opt-out must actually turn off the relevant tracker categories, not just hide the banner.

ScenarioFrequent questionWhat to do
First-party analytics cookieSale?Assess with a lawyer; disclose in the policy; give control in settings
Third-party ad pixelSale / share?High share risk; DNSMPI + a block before/after opt-out
ClikBy as a click processorSale?Usually a service provider under contract; it does not remove responsibility for your pixels
Pixel on the link redirectShare?You initiate it; pixel_notification + disclosures

Ban on dark patterns

Amendments ban interfaces that substantially subvert or impair the opt-out choice. You must not:

  • Make opt-out longer/harder than a later opt-in;
  • Use confusing language (double negatives such as “Don't Not Sell…”);
  • Force people to click/listen to “why you should not opt-out”;
  • Hide the link so people have to hunt for it in the policy text.

Global Privacy Control (GPC)

GPC is a browser/extension signal to “opt out of sale/share.” In the CCPA/CPRA ecosystem and CMP reviews (including CookieYes) it is increasingly described as a signal a business must recognize and handle on par with a DNSMPI click — confirm the current duty with a lawyer and CPPA regulations.

In practice: if you claim GPC support in the policy, make sure your CMP/tag manager actually mutes sale/share tags on the signal, not merely logs the event.

Four steps on the site

1. Do Not Sell or Share link

In the footer and/or header → a page with collection purposes, the fact of sale/share, and an opt-out form.

2. Opt-out form / button

Minimal fields; confirmation; an email/phone alternative. Industry examples: a button, cookie settings, a combined CCPA+Nevada form — pick a clear UX without dark patterns.

3. Cookie / opt-out notice

If third parties collect activity via cookies, pixels, beacons, social plugins — show a notice and provide a way to opt out of the relevant categories.

4. Privacy policy

PI categories for the past 12 months, purposes, sources, sale/share/disclose, rights, authorized agent, contacts, process for minors, update date. A link to the policy from the homepage.

A detailed disclosures checklist is also in CCPA Requirements (CookieYes).

How this fits with ClikBy

  • Client site: DNSMPI / Your Privacy Choices + CMP (CookieYes or the ClikBy /cookies module) — your responsibility.
  • Smart link redirect: enable pixel_notification; Reject → consent{link_id}=0 → pixels do not fire when consent is checked.
  • Consistency: site copy saying «we do not sell data» while ad pixels are active on links — a disclosures conflict.
  • Data-subject requests: the clicker writes to you; you can escalate visit deletion to ClikBy under the DPA/support.

In ClikBy: roles Customer = controller / ClikBy = processor for clicks; the controls are Cookie Consent and pixel_notification on the redirect. A CCPA badge on the landing page does not replace your Do Not Sell or Share notice.

FAQ

Do we need a DNSMPI link if we «do not sell» data?

If you truly do not sell and do not share PI as the law defines it, the link may not be required — but «we do not sell» with active ad pixels is often contested. Lock the position with counsel.

Is Reject in the ClikBy banner enough?

It is a product control for cookie / pixel categories on the redirect or site. It does not replace a legal notice and the verifiable consumer requests process.

Where else to read in the KB?

Cards on the opt-out link, Do Not Sell or Share, cookie banner under CPRA, GPC — in CookieYes KB → CCPA.

What’s next?

Review pixels on links

Turn on the redirect notice and describe vendors in the policy.