Your Privacy Rights
What 'Do Not Sell My Personal Info' Actually Does
The short version
The link in the footer is a real legal request, not decoration. Clicking it orders that company to stop selling and sharing your data, and California gives it 15 business days to comply. But it is not a deletion request - the company keeps everything it already has. It also only covers that one company, in that one browser, and clearing your cookies can erase it. The fix almost nobody uses is Global Privacy Control: a browser setting that sends the same opt-out to every site automatically, and that businesses in California, Colorado, Connecticut and other states are legally required to honor.
What the link legally obligates a company to do
Clicking "Do Not Sell or Share My Personal Information" submits a formal request under the California Consumer Privacy Act. Once a covered business receives it, the California Attorney General says it must stop selling and sharing your personal information as soon as feasibly possible, and no later than 15 business days from the date it received the request.
Two other rules come with it. The business cannot make you create an account to submit the request, and after you opt out it must wait at least 12 months before asking you to opt back in. So the annoying "are you sure?" upsell cannot legally be an annual ritual.
You will see the same right behind several labels. Some sites use the full "Do Not Sell or Share My Personal Information" wording; others use an alternative link titled "Your Privacy Choices" or "Your California Privacy Choices" next to a small blue-and-white toggle icon. They lead to the same place.
What the link does not do: it is not a deletion request
This is the single biggest misunderstanding about the footer link. Opting out stops future sales and sharing. It does not delete anything. The company keeps every record it already collected, keeps collecting new data, and can keep using that data itself and with its own service providers.
The California Privacy Protection Agency treats these as two separate rights: you may request that a business stop selling or sharing your information, and you may separately request that it delete personal information it collected from you. Exercising one does not trigger the other.
| Do Not Sell link | GPC signal | Deletion request | |
|---|---|---|---|
| What it stops | Sale and sharing by one company | Sale and sharing by every site you visit | Nothing; it removes stored data |
| Data already held | Kept | Kept | Deleted, with exceptions |
| Scope | One company | One browser, all sites | One company |
| Effort | Once per company | Once per browser | Once per company |
Based on the California Attorney General's CCPA guidance and the California Privacy Protection Agency's description of the opt-out and deletion rights (2026).
If deletion is what you actually want, that is a different form and a different legal basis. We cover the deletion process separately, and California residents have a bulk shortcut through the state's DROP platform for registered data brokers.
Why "sale" covers far more than money changing hands
Most people skip the link because they assume no one literally sold their data. The legal definition is much wider. The California Attorney General defines a sale as disclosing personal information to a third party for monetary or other valuable consideration, and defines "sharing" separately as disclosure for cross-context behavioral advertising.
That second category is the one that matters. Cross-context behavioral advertising means targeting ads to you based on your activity across many different sites - in other words, ordinary ad tech. The trackers and pixels on a typical retail page fall inside the definition even when no invoice ever changes hands.
This is not a theoretical reading. In the Attorney General's first CCPA enforcement action, announced in August 2022, Sephora agreed to a $1.2 million penalty after the state concluded that letting third-party advertising and analytics companies install trackers on its site constituted a sale of consumer information.
Per company and per browser: the limits that trip people up
An opt-out submitted through a website link reaches exactly one company. There is no central registry and no universal off switch. Visit a hundred sites and you would need a hundred requests, which is why almost nobody keeps up.
The second limit is technical. If you are not signed in, the business has no way to tie the request to you as a person, so it ties it to your browser. Under California's opt-out regulations, a signal is treated as a valid request for that browser or device and any profile associated with it. Opt out on your laptop and your phone is still fair game.
That browser-level storage is usually a cookie or similar site data. Clear your cookies, switch to a private window, or reinstall the browser, and the record of your opt-out can disappear along with everything else. The site is not cheating - it simply has nothing left to recognize you by.
Global Privacy Control: the opt-out you only set once
Global Privacy Control, usually shortened to GPC, solves the per-company problem. It is a setting in your browser, or a browser extension, that attaches a small signal to every page request you make. The California Attorney General describes it plainly as a "stop selling or sharing my data switch" available in some browsers.
It is not a polite suggestion. The Attorney General's guidance states that under law GPC must be honored by covered businesses as a valid consumer request to stop the sale or sharing of personal information. It carries the same legal weight as clicking the footer link, on every site you visit, without you doing anything.
Because it is a browser setting rather than a cookie, it also survives a cookie clear. Wipe your site data and the signal is simply sent again on your next visit. That makes it the more durable of the two mechanisms, and the only one that scales.
How to turn on Global Privacy Control
Turning GPC on takes under a minute, but support varies sharply by browser. Three browsers ship it built in; the three most popular ones currently do not, and need an extension instead. Here is where things stand as of July 2026.
| Browser | Built-in GPC | What to do |
|---|---|---|
| Brave | Yes, on by default | Nothing - it is already sending the signal |
| DuckDuckGo browser and extensions | Yes, on by default | Nothing, though DuckDuckGo disables it on a short list of sites it would break |
| Firefox | Yes, off by default | Settings > Privacy & Security > Website Privacy Preferences > tick "Tell websites not to sell or share my data" |
| Chrome | Not in the stable release | Install a GPC extension; the California Attorney General points consumers to EFF's Privacy Badger |
| Safari | No | Install a GPC extension |
| Edge | No | Install a GPC extension |
Compiled July 2026 from globalprivacycontrol.org, the California Attorney General's GPC page, Mozilla Support, Brave, and DuckDuckGo's help pages.
Chrome is moving. A Chromium "Intent to Prototype" for Global Privacy Control was filed in January 2026, and the signal has since appeared in Chrome Canary, Google's early test channel. It is not in the version most people use yet, so an extension is still the answer today.
That gap has a deadline. California's Opt Me Out Act, AB 566, was signed on October 8, 2025 and takes effect on January 1, 2027. From that date, browser developers must include a built-in, easy-to-find setting that sends an opt-out preference signal - which in practice means Chrome, Safari, and Edge all get one.
Where the signal is legally binding
GPC is enforceable law in a growing number of states, not a courtesy. California requires businesses that take online requests to offer an opt-out preference signal as one of their methods. Colorado has required controllers to honor GPC since July 1, 2024, and Connecticut since January 1, 2025.
Colorado's approach is the clearest to point at: the state Attorney General maintains an official public list of recognized universal opt-out mechanisms, and GPC is on it. Colorado consumers can use it to opt out of both the sale of their personal data and its use for targeted advertising.
Several other states with comprehensive privacy laws have adopted similar universal opt-out requirements on their own timetables. If you live somewhere without one, GPC still works wherever a company chooses to honor it nationwide - which many do, because running two versions of a website is expensive. Our guide for people outside California covers what else is available to you.
What to do when a business ignores it
Non-compliance is common enough that regulators went hunting for it. In September 2025 the California Privacy Protection Agency, together with the Attorneys General of California, Colorado, and Connecticut, announced a joint investigative sweep into businesses that were not processing opt-out requests sent through GPC.
The penalties are real. On September 30, 2025 the CPPA issued a $1.35 million order against Tractor Supply Company, its largest to date, in a case that included the company's failure to provide an effective opt-out mechanism. Under California's updated rules, businesses now also have to show on the page that a signal was honored, rather than processing it invisibly.
If a site clearly ignores your signal, take a dated screenshot and file a complaint with your state regulator - our companion post on where to file a privacy complaint walks through which agency to use. And remember that opting out of sales does nothing about data already sitting on people-search sites, which is a separate broker removal job, or about the location data your phone shares through apps.
Find out what is already out there
Turning on GPC stops new sales. Run a free exposure scan to see what has already been published about you - breaches tied to your email, public profiles, and the brokers likely listing you. No account, nothing stored.
Frequently asked questions
Does clicking 'Do Not Sell My Personal Info' delete my data?
No. It is an opt-out of sale and sharing, not a deletion request. The company keeps everything it has already collected, keeps collecting more, and can keep using it internally. Deletion is a separate right you have to exercise separately.
How long does a business have to honor my opt-out request?
Under the California Consumer Privacy Act, a business must act as soon as feasibly possible and no later than 15 business days from the date it received your request, according to the California Attorney General. It must also wait at least 12 months before asking you to opt back in.
Do I have to submit a Do Not Sell request on every website separately?
If you use the footer link, yes - each request reaches only that one company. A browser-level opt-out preference signal like Global Privacy Control is the exception: you turn it on once and it is sent automatically to every site you visit.
What is Global Privacy Control?
Global Privacy Control, or GPC, is a browser setting or extension that automatically tells every site you visit not to sell or share your personal information. The California Attorney General states that under law it must be honored by covered businesses as a valid consumer request.
Which browsers have Global Privacy Control built in?
As of July 2026, the Global Privacy Control project and the California Attorney General list Firefox, Brave, and DuckDuckGo as browsers with built-in support. Brave and DuckDuckGo enable it by default; Firefox has a checkbox you switch on. Chrome, Safari, and Edge need an extension.
Does clearing my cookies cancel my opt-out?
It can. When you are not signed in, a site-level opt-out is usually stored in your browser, so clearing cookies or site data can wipe it. A GPC signal is a browser setting rather than a cookie, so it survives a cookie clear and is re-sent on every visit.
Does 'sale' mean the company literally sold my data for cash?
Not necessarily. The California Attorney General defines sale as disclosing personal information for monetary or other valuable consideration, and separately covers sharing for cross-context behavioral advertising. In the Sephora settlement the Attorney General treated ordinary third-party advertising trackers as a sale.
What can I do if a business ignores my opt-out request?
Document it with a screenshot and the date, then file a complaint with your state regulator. California consumers can report to the California Attorney General or the California Privacy Protection Agency, both of which have brought enforcement actions specifically over ignored opt-out signals.
Sources: California Attorney General (CCPA consumer guidance, the Global Privacy Control page, and the August 2022 Sephora settlement); California Privacy Protection Agency (consumer FAQ, the September 2025 joint GPC investigative sweep, and the September 30, 2025 Tractor Supply order); California Code of Regulations title 11 section 7025 on opt-out preference signals; Colorado Attorney General (universal opt-out mechanism list); Connecticut Attorney General (December 2024 opt-out advisory); IAPP reporting on AB 566; globalprivacycontrol.org; Mozilla Support, Brave, and DuckDuckGo help pages; the Chromium blink-dev Intent to Prototype for Global Privacy Control. See also our opt-out guide library.