Do Not Sell or Share My Personal Information: State Rules (2026)
Termly can generate and maintain your privacy policy, consent banner, and data-request workflow as requirements change.
What Does "Do Not Sell My Personal Information" Mean?
If you've browsed a website recently, you've likely seen a link in the footer that reads "Do Not Sell My Personal Information" or "Do Not Sell or Share My Personal Information." This phrase comes directly from the California Consumer Privacy Act (CCPA), which requires businesses that sell personal information to provide consumers with a clear, conspicuous opt-out mechanism.
Since the CCPA was enacted in 2020, the concept has spread far beyond California. Over 20 US states now have comprehensive privacy laws, and most of them include some form of opt-out right covering the sale of personal data — and increasingly, targeted advertising and profiling as well.
Which States Require a "Do Not Sell" Opt-Out — and Which Dictate the Wording?
As of August 11, 2026, 20 in-force state privacy laws give consumers an opt-out right, but only 1 — California — dictates what the link must actually say. Cal. Civ. Code § 1798.135(a) prescribes two link titles verbatim: "Do Not Sell or Share My Personal Information" and "Limit the Use of My Sensitive Personal Information." Every other state requires a clear and conspicuous opt-out method and leaves the label to you. (Statute text retrieved August 11, 2026.)
That asymmetry is the part most compliance write-ups skip, and it cuts both ways: a business that puts California's exact phrase in its footer nationwide is over-labelling — telling Texas and Virginia visitors about a "sale" the business may not make — while a business that paraphrases it in California ("Manage My Data," "Privacy Options") is in breach of § 1798.135(a)(1) no matter how well its opt-out works.
This table is generated from the same dataset behind our state law pages, so it covers every in-force law rather than the handful most guides list:
| State (law) | Opt-out covers | Link wording prescribed by statute? | Must honor GPC / universal opt-out |
|---|---|---|---|
| California (CCPA/CPRA) | Sale, targeted advertising, and profiling | “Do Not Sell or Share My Personal Information” and “Limit the Use of My Sensitive Personal Information” | Yes — since March 29, 2024 |
| Colorado (CPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since July 1, 2024 |
| Connecticut (CTDPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since January 1, 2025 |
| Delaware (DPDPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since January 1, 2026 |
| Florida (FDBR) | Sale, targeted advertising, and profiling | No prescribed wording | Not required |
| Indiana (INCDPA) | Sale, targeted advertising, and profiling | No prescribed wording | Not required |
| Kentucky (KCDPA) | Sale, targeted advertising, and profiling | No prescribed wording | Not required |
| Maryland (MODPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since October 1, 2025 |
| Minnesota (MCDPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since July 31, 2025 |
| Montana (MCDPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since January 1, 2025 |
| Nebraska (NDPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since January 1, 2026 |
| New Hampshire (NHPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since January 1, 2025 |
| New Jersey (NJDPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since January 15, 2025 |
| Oregon (OCPA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since January 1, 2026 |
| Rhode Island (RIDTPPA) | Sale, targeted advertising, and profiling | No prescribed wording | Not required |
| Tennessee (TIPA) | Sale, targeted advertising, and profiling | No prescribed wording | Not required |
| Texas (TDPSA) | Sale, targeted advertising, and profiling | No prescribed wording | Yes — since January 1, 2025 |
| Virginia (VCDPA) | Sale, targeted advertising, and profiling | No prescribed wording | Not required |
| Iowa (ICDPA) | Sale, and targeted advertising | No prescribed wording | Not required |
| Utah (UCPA) | Sale, and targeted advertising | No prescribed wording | Not required |
Use our privacy law calculator to determine which of these laws apply to your business based on your revenue, consumer count, and data practices, or generate footer-ready markup with the Do Not Sell link generator.
Do you still need the link if you honor GPC?
In California, not necessarily. Section 1798.135(b) lets a business skip the homepage links entirely if it processes opt-out preference signals in a frictionless way, and § 1798.135(a)(3) lets a single clearly labeled link replace both mandated titles. The CCPA regulations cover that route at 11 CCR § 7013 (the Do Not Sell or Share link) and § 7015 (the alternative opt-out link). Most businesses post the link anyway, because it is the only version of compliance a regulator can confirm from outside the site — and because the 12 states that mandate universal opt-out signals are still a minority of the 20 with opt-out rights.
What Counts as a "Sale" of Personal Information?
The definition of "sale" under state privacy laws is broader than you might expect. It generally means making personal information available to a third party in exchange for monetary or other valuable consideration. This includes:
- Sharing data with ad networks — if you use third-party advertising cookies or pixels that transmit user data to ad platforms, that may qualify as a "sale"
- Data broker transfers — selling or licensing consumer data to data aggregators
- Analytics sharing — providing user-level data to analytics providers who use it for their own purposes
- Cross-context behavioral advertising — under California's CPRA, "sharing" personal data for targeted advertising is treated the same as "selling"
Common exemptions include sharing data with service providers who process it solely on your behalf (under a written contract), disclosures required by law, and transfers as part of a merger or acquisition.
An opt-out stops future sale or sharing; it does not erase data the business already holds. Our US right to be forgotten and data deletion rights guide explains the separate deletion request and its state-by-state exceptions.
How to Implement "Do Not Sell" Compliance
Step 1: Add a Clear Opt-Out Link
California law specifically requires a "Do Not Sell or Share My Personal Information" link on your website homepage. Best practices include placing the link in your website footer where it is easily visible, using the exact or substantially similar language from the applicable state law, making the link functional (not just decorative), and ensuring it is available without requiring the user to create an account or log in.
Step 2: Honor Global Privacy Control (GPC) Signals
At least 12 states now require businesses to recognize universal opt-out mechanisms like Global Privacy Control (GPC). When a user's browser sends a GPC signal (the Sec-GPC: 1 HTTP header), your website must treat it as a valid opt-out request. This means suppressing third-party tracking cookies and pixels, stopping the transmission of user data to advertising partners, and recording the opt-out preference for that user.
Check your GPC obligations with our GPC Compliance Checker.
Step 3: Build an Opt-Out Mechanism That Works
When a consumer submits an opt-out request — whether via your link or through GPC — you must process the request within 15 business days (California standard), stop selling or sharing their personal information going forward, notify any third parties you've sold their data to in the prior 90 days, and not ask the consumer to re-submit or verify their identity (opt-out requests should not require ID verification under most state laws).
Step 4: Update Your Privacy Policy
Your privacy policy must disclose whether you sell personal information, the categories of personal information sold, the categories of third parties to whom you sell, and how consumers can exercise their opt-out rights (including mention of GPC). California requires that you list these disclosures in a specific format and update them at least annually.
Step 5: Avoid Dark Patterns
Regulators have made dark patterns a top enforcement priority. Practices that violate opt-out requirements include requiring multiple clicks or confirmation steps to opt out when opting in takes a single click, using confusing toggle labels (like "Do Not Do Not Sell" double negatives), requiring consumers to provide email verification before processing opt-out requests (Ford was fined $375K for this exact practice), and using manipulative language that discourages opt-outs.
Common Compliance Mistakes
- Missing the link entirely — some businesses simply don't include the required "Do Not Sell" link on their homepage. This is the most basic violation and the easiest to detect.
- Ignoring GPC signals — the multi-state GPC enforcement sweep specifically targeted businesses that failed to honor GPC. If your website doesn't detect and respond to the
Sec-GPCheader, you are at risk. - Treating it as California-only — with 20+ states now having opt-out rights, a California-only approach leaves you exposed in other jurisdictions. The safest strategy is to offer opt-out rights to all US consumers.
- Not stopping data flows downstream — opting out means nothing if you continue transmitting data to third-party ad partners. You must actually suppress the data sharing, not just record the preference.
- Resetting preferences after cookie deletion — if a consumer opts out and then clears their cookies, you cannot treat them as a new consumer who hasn't opted out. Server-side opt-out records help solve this problem.
Enforcement Is Real — and Growing
Opt-out compliance is one of the most actively enforced areas of state privacy law. In 2026 alone, California's CPPA has issued over $4 million in fines in three enforcement actions, with opt-out violations featured in every case. Notable penalties include Disney ($2.75M), Ford ($375K), and PlayOn Sports ($1.1M) — all stemming from failures to properly implement "Do Not Sell" mechanisms.
See the full list of enforcement actions on our penalties tracker.
Multi-State Compliance Checklist
- Add a "Do Not Sell or Share My Personal Information" link to your website footer
- Implement GPC signal detection and honor it as a valid opt-out
- Audit all third-party data sharing and categorize what constitutes a "sale"
- Process opt-out requests within 15 business days
- Notify downstream data recipients of consumer opt-outs
- Update your privacy policy with required disclosures
- Test your opt-out mechanism quarterly to ensure it still works after site updates
- Maintain server-side opt-out records (don't rely solely on cookies)
- Train customer service staff on how to handle verbal or email opt-out requests
Use our state law comparison tool to see exactly which opt-out requirements apply in each state, and our California compliance checklist for a step-by-step guide to CCPA compliance.
This article provides general educational information and is not legal advice. Consult qualified legal counsel for guidance specific to your organization. Published: March 28, 2026. Last verified: August 11, 2026 against Cal. Civ. Code § 1798.135 and the per-state opt-out and universal-opt-out records tracked on this site (date_retrieved: 2026-08-11).
Termly can turn the requirements above into a maintained privacy policy, consent banner, and data-request workflow.