CCPA/CPRA
Opt-out of sale or sharing, limiting sensitive data and preference signals – CCPA/CPRA

CCPA/CPRA CCR 7026: Handle requests to opt out of sale or sharing

The business must offer two or more easy methods to opt out, at least one matching its main channel; an online business must accept opt-out preference signals plus a form, link or policy route, and a cookie banner alone does not count. No verification or account may be required, and only suspected fraud documented in good faith justifies refusal. It must stop selling and sharing as soon as feasible and no later than 15 business days after receipt. It must notify every third party to which it sold or shared the consumer's data between receipt of the request and the moment the request took effect, telling them to honour it and to pass it to anyone they in turn made the data available to in that window. Consumers must be able to confirm the request was processed, agents with signed permission may act for them, and the business must wait 12 months before asking the consumer to opt back in.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27701:2025 · 2 controls

  • A.1.3.6 Providing mechanism to object to PII processing
  • A.1.3.8 PII controllers' obligations to inform third parties

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Opt-out of sale or sharing, limiting sensitive data and preference signals – CCPA/CPRA

You are reading one control. How much of CCPA/CPRA have you already done?

CCPA/CPRA CCR 7026 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CCPA/CPRA your existing evidence covers. Hold GDPR and 17 of 89 CCPA/CPRA controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the GDPR pair alone.

Query this from an agent

The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.