Skip to content

Compliance

Do I need a Do Not Sell My Personal Information link

Under the CPRA, passing identifiers to an advertising network counts as sharing, and a conspicuous opt-out link on the homepage is required once you cross the applicability thresholds. The link and a working opt-out are what enforcement asks for first.

What 13x checks

This is rule compliance.ccpa-do-not-sell in the public registry: California opt-out link present. It runs on every audit, against the pages we actually fetched, and its result is derived from the response rather than estimated.

Surface
Compliance
Score weight
8 of the readiness score
Scope
Runs on every audited page
Applies
Only where the market or the page shape makes it relevant

Registry version 2026-07-30. Every rule is published, and the audit is deterministic — the same page produces the same finding every time.

The fix

The same text the audit hands you when this check fails on your own site.

You run advertising or tracking scripts () with no opt-out link. Under the CPRA, passing identifiers to an ad network counts as sharing personal information.

Add a conspicuous link in the footer of every page:

html code
<a href="/do-not-sell">Do Not Sell or Share My Personal Information</a>

"Your Privacy Choices" is also an accepted label, and may be paired with the official opt-out icon. The link has to lead to something that actually works — a form or a preference toggle that stops the sharing, not a restatement of the policy. Honouring the Global Privacy Control signal is the low-effort way to cover the automated case.

Does your site have this problem?

13x checks this and 112 others against your live URL in about 30 seconds. No account, and every finding comes with the fix for your framework.

No signup. Results in 30 seconds.

More compliance checks