Blog

Do Not Sell or Share Link: Form Checklist

By
The Reform Team
Use AI to summarize text or ask questions

If you sell or share personal information, your opt-out link must be easy to find, easy to use, and processed within 15 business days.

Here’s the short version: I need to place the “Do Not Sell or Share My Personal Information” or “Your Privacy Choices” link on the homepage and on any page where personal information is collected. I also need to make sure it works on mobile, stays visible in multi-step forms, honors Global Privacy Control (GPC), and shows “Opt-Out Request Honored” when that signal is processed as of January 1, 2026.

At a glance, this checklist comes down to four things:

  • Place the link where people can see it
  • Keep the opt-out path short and clear
  • Route requests to the right team and suppress sharing
  • Log each request and review the setup on a schedule

A few rules matter most:

  • Exact link text matters
  • No account creation can be required
  • No extra identity checks can be required for the opt-out request
  • Processing deadline: 15 business days
  • No asking the person to opt back in for 12 months

If I use embedded forms, lead forms, ad pixels, or third-party trackers, this is not just a footer issue. The form flow itself can trigger the rule.

The rest of the article walks through placement, mobile checks, request handling, GPC response, suppression, and audit logs in a simple step-by-step way.

Do Not Sell or Share My Personal Information: Compliance Checklist

Do Not Sell or Share My Personal Information: Compliance Checklist

Start with placement, then check form visibility. Put the link in your sitewide footer and on every page that collects personal information.

Your sitewide footer is the starting point. It should include the opt-out link on homepages, landing page forms, and other pages that collect personal information. If a page has an embedded form, show the link near the form or inside the form’s privacy text so people can spot it right where data is being collected.

Use the required opt-out label, and if you use a shorter version, make sure it’s just as clear. Keep the wording simple. People should understand it at a glance without having to guess what it means.

Send the link straight to the opt-out form or the opt-out section, not to a general privacy page.

For high-conversion lead forms, add a second opt-out link near the submit button or in the form’s privacy text. The link should appear before submission and at the point of collection.

In Reform multi-step forms, keep the link visible on every step, not only on the last screen.

Once the link appears everywhere someone can submit data, test it on mobile and across multi-step flows.

Checklist 2: Make the opt-out path work on mobile and in form flows

Next, check that the opt-out path works on mobile and across every form path.

Mobile UI can hide the link fast. Keep it visible in the footer or in the form text. Don’t tuck it behind sticky bars, chat widgets, or collapsed menus.

A few things to check on mobile:

  • The footer link stays visible and easy to read on small screens

CCPA/CPRA rules require opt-out notices to appear in a readable format on smaller screens.

Mobile visibility is just one place where things can fail. You also need to check every step and every branch.

Maintain access through multi-step and conditional form flows

When a form loads one step at a time, privacy text from step one often doesn’t carry over. Conditional logic can drop that text too. If a branch sends someone down a different path, the link may never show up.

In Reform multi-step forms, audit each step and branch on its own. Each route needs the link before submission. Don’t assume one step covers the rest. Each route needs its own visible link.

Keep the opt-out path short, clear, and available on every step and branch. A persistent footer is a practical way to keep it accessible across the full flow.

Test how the site responds to browser-based privacy signals

Visible links cover manual opt-outs. GPC covers signal-based opt-outs. California treats GPC as a valid opt-out signal.

When GPC is on, block sale/share tracking on its own and confirm the opt-out on screen. If those scripts still fire, the site is not honoring GPC. A broken GPC response is a CCPA compliance issue.

Once the link and signal work, verify routing, suppression, and logging downstream.

Checklist 3: Route requests correctly and verify identity carefully

The next step is internal processing: each opt-out needs one clear owner and one suppression workflow.

Send requests to the right team and system

Every opt-out request needs a clear owner the moment it arrives. Route it at once to the right privacy or legal workflow based on the request type and the region it came from. If that handoff is messy, requests can sit in inboxes and miss deadlines.

Process each request within 15 business days of receipt. Track status so every request has a timestamp, an assignee, and a completion record. Pass request metadata into your CRM or ticketing system.

Once routed, process the request using only the data already tied to the consumer record.

Verify identity without collecting extra data

Do not require identity verification. Match the request to records already on file, such as an email address, and collect no extra data. Use only the identifiers you already have on file to match the person to your suppression list, and use it only to match and suppress the record.

That means no extra forms, no extra ID checks, and no digging for more personal details. Keep it tight: match the request, suppress the record, and move on.

Then push the opt-out status into all systems that share or use the data.

Set up form routing and suppression rules

Processing the request is only half the job. The other half is making sure downstream systems stop sharing data.

Once an opt-out is confirmed:

  • Ad-related sharing must be suppressed
  • CRM and marketing platforms must be updated
  • The business cannot ask the consumer to opt back in for at least 12 months

If personal information is sold or shared after the request is received but before it is fully processed, the business must notify those third-party recipients that the consumer has opted out and that further sale or sharing is prohibited.

Use routing and integrations to pass opt-out status into CRM and marketing tools so suppression happens automatically.

Checklist 4: Keep audit logs and review the setup on a schedule

After routing and suppression, the next step is simple: write down what happened and check the setup on a set schedule.

Log each request, response, and downstream update

Suppression only holds up if you can show that it ran. For each opt-out request, record the receipt date, the request source, and the outcome. Note whether suppression was applied and, if personal information was sold or shared before the request was processed, whether third parties were told to stop further sale or sharing.

Your logs should also show that no extra data was collected during matching. And if automated signals were processed, the record needs to reflect the required visual confirmation shown to the user, including the phrase "Opt-Out Request Honored" starting January 1, 2026. Track the 12-month re-solicitation lockout too.

In plain English, the log should be complete enough to show:

  • when the request came in
  • what action was taken
  • what changed downstream

Once the log format is locked in, move from recordkeeping to routine checks on the live site.

Run reviews on a recurring schedule. Check that the Do Not Sell or Share link still appears in the footer across all site pages, landing pages, and embedded forms - the same placements covered in Checklist 1. Test California display logic and GPC handling from a California IP and a GPC-enabled browser.

Then confirm that sale/share tracking is suppressed when GPC is active. Also look for scripts or pixels sitting outside your tag manager. Those can slip past suppression rules and keep firing anyway.

Use the record to make sure the full flow still works over time.

Conclusion: The Do Not Sell or Share form checklist at a glance

The link starts the process. Logs and audits show that the process kept working.

FAQs

You need a Do Not Sell or Share My Personal Information link if your business collects personal information and uses it in ways the law treats as selling or sharing. That includes cross-context behavioral advertising, retargeting, and lookalike modeling.

Under state privacy laws like the CCPA, this applies when you share personal data with third parties for targeted advertising. And yes, that can include identifiers such as cookies.

No. Global Privacy Control (GPC) does not replace the Do Not Sell or Share My Personal Information link.

A business still has to do both:

  • Provide the Do Not Sell or Share My Personal Information link
  • Honor GPC signals as a valid opt-out request

GPC is an automated, user-enabled way for people to opt out. But the link still needs to be there as a separate path for consumers to use their rights.

What should I log for each request?

For every Do Not Sell or Share request, keep a precise, tamper-evident audit log. Include the Request ID, intake source, verification method, date received, systems updated, opt-out timestamp, and confirmation that the user was removed from the relevant ad audiences.

If you notify enrichment providers or other vendors, log their acknowledgment as well. Encrypt the logs and store them securely in case a regulator asks to review them.

Related Blog Posts

Use AI to summarize text or ask questions

Discover proven form optimizations that drive real results for B2B, Lead/Demand Generation, and SaaS companies.

Lead Conversion Playbook

Get new content delivered straight to your inbox

By clicking Sign Up you're confirming that you agree with our Terms and Conditions.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
The Playbook

Drive real results with form optimizations

Tested across hundreds of experiments, our strategies deliver a 215% lift in qualified leads for B2B and SaaS companies.