CCPA Compliance

CCPA opt-out and Do Not Sell, built in

Consentify includes a configurable 'Do Not Sell My Personal Information' link and automatic Global Privacy Control (GPC) detection, both required for CCPA and CPRA compliance.

What is CCPA?

The California Consumer Privacy Act (CCPA), updated by CPRA in 2023, gives California residents the right to know what personal data is collected, the right to delete it, and the right to opt out of the sale or sharing of their data. Businesses covered by CCPA must honour opt-out requests (including browser-level GPC signals) within 15 business days.

How Consentify covers CCPA

Do Not Sell button

Enable the 'Do Not Sell My Personal Information' link directly from the banner editor. When clicked, analytics and marketing scripts are blocked and the decision is stored with a doNotSell flag in the consent record.

Global Privacy Control (GPC)

When a visitor's browser sends the GPC signal (Firefox, Brave, or a GPC-enabled extension), Consentify automatically applies an opt-out: no banner shown, analytics and marketing denied, and the consent record flagged with gpc: true. This meets the CPRA requirement to honor GPC as a valid opt-out.

Opt-out audit trail

Every Do Not Sell click and GPC opt-out is stored in the consent log with a timestamp and distinguishing flags, ready for regulatory requests.

Right to delete

Each consent record has a unique delete token. You can expose this to users to satisfy CCPA deletion requests.

Frequently asked questions

Does my site need a CCPA banner?

CCPA does not require a cookie banner the way GDPR does. What it requires is a visible 'Do Not Sell or Share My Personal Information' link. Consentify shows that link in the banner, and every click is recorded as an opt-out. A permanent link in your site footer is not something Consentify places for you today, so if your setup needs one there, you add it yourself.

What is Global Privacy Control (GPC)?

GPC is a browser-level signal (navigator.globalPrivacyControl) that tells websites the user does not want their data sold or shared. Under CPRA, California businesses must treat GPC as a valid opt-out request. Consentify detects GPC automatically and applies an opt-out without showing the banner.

Does Consentify support CPRA (the 2023 update to CCPA)?

Yes. The key CPRA additions relevant to Consentify are: honoring GPC signals (implemented), a 'Do Not Share' right alongside 'Do Not Sell' (both covered by blocking analytics and marketing), and opt-out audit logs (stored with distinguishing flags).

Can I use Consentify for both GDPR and CCPA on the same site?

Partly, and it is worth knowing where the line goes. GPC is handled everywhere: any visitor whose browser sends the signal is opted out automatically, wherever they are. What Consentify does not do is change behaviour based on where the visitor is, so everyone sees the same banner. For a site serving both Europe and the US, the safe setup is the standard consent banner for everyone. It meets GDPR, and it goes further than CCPA asks for.

Free scan, no account

Check your own site against this

The scan lists the scripts that run before consent, so you know what you actually need to block.

  • Results in about 10 seconds
  • No account needed
  • Shareable report link
Free forever, no credit card

Add CCPA opt-out to your site today

Free forever for one domain. Setup takes 5 minutes.

  • 1 domain
  • 5,000 pageviews/mo
  • All integrations
  • GDPR, CCPA and ePrivacy
Start for free

No credit card. Free forever.

Compare plans