The business must offer two or more easy methods to opt out, at least one matching its main channel; an online business must accept opt-out preference signals plus a form, link or policy route, and a cookie banner alone does not count. No verification or account may be required, and only suspected fraud documented in good faith justifies refusal. It must stop selling and sharing as soon as feasible and no later than 15 business days after receipt. It must notify every third party to which it sold or shared the consumer's data between receipt of the request and the moment the request took effect, telling them to honour it and to pass it to anyone they in turn made the data available to in that window. Consumers must be able to confirm the request was processed, agents with signed permission may act for them, and the business must wait 12 months before asking the consumer to opt back in.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
CCPA/CPRA CCR 7026 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CCPA/CPRA your existing evidence covers. Hold GDPR and 17 of 89 CCPA/CPRA controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the GDPR pair alone.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.