skip to content

Under the CCPA regulations, a logged-out visitor's browser sends an opt-out preference signal to a news site — what must the site do, and to what does it apply?

level: seniorimportance: should knowfreq 40%

answer

  1. a valid request, not a hint
  2. browser or device scope
  3. pseudonymous profiles too
  4. absence is not consent
  5. frictionless or not

basics

~20 s

Under 11 CCR 7025, a site that sells or shares must treat a valid signal as an opt-out for that browser or device and any profile tied to it, pseudonymous ones included, and for the person once known.

solid answer

~50 s

Under the CCPA regulations (11 CCR 7025), a business that sells or shares must process a signal as a valid opt-out if it is in a commonly used format, such as an HTTP header field or JavaScript object, and the sending mechanism makes clear that it opts the consumer out of sale and sharing. The site applies it to **that browser or device and any consumer profile associated with it, including pseudonymous profiles**; if it knows who the visitor is, to the consumer as well. It may not demand more information. For a logged-out visitor it cannot link to an account, the opt-out covers the browser identifier only. A later visit without the signal is not consent. Posting the links does not excuse ignoring signals (7025(e)); only frictionless processing, with no fee, changed experience or pop-up, lets a business drop the links (7025(f)-(g)).

go deeper

for a junior

Recall that a browser opt-out preference signal is a valid request to opt out of sale and sharing for businesses that sell or share.

for a middle

Explain the validity test in 11 CCR 7025(b), the browser-or-device scope, and why a missing signal on a later visit is not consent.

for a senior

Walk the logged-out case end to end: browser-level opt-out, pseudonymous profiles, account linkage on login, conflict handling and the frictionless rules.

for a principal

Decide whether to adopt frictionless processing and drop the links, weighing offline sales, incentive programmes and the cost of fully effectuating signals.

## What the signal is Under the CCPA as amended by the CPRA, an **opt-out preference signal** lets a consumer opt out of sale and sharing with every business they interact with online, without individual requests (11 CCR 7025(a)). Civil Code `1798.135(b)` refers to a signal sent with the consumer's consent by a platform, technology or mechanism, and `1798.135(e)` treats it as a way of authorising another person to opt out on the consumer's behalf. Under 7025(b), a business that sells or shares must process a signal as a **valid request to opt out** if: 1. it is in a **format commonly used and recognised** by businesses, such as an **HTTP header field** or a **JavaScript object**; and 2. the platform or mechanism sending it makes clear, in its configuration or public disclosures, that it is meant to opt the consumer out of sale and sharing. That disclosure need not mention California. A business that neither sells nor shares need not act on it. ## What the site must do for the logged-out visitor 7025(c) sets the scope: - Treat the signal as a valid `1798.120` opt-out **for that browser or device** and **any consumer profile associated with it, including pseudonymous profiles**. - If the consumer is **known**, apply it to the consumer too, including offline sale or sharing. - **Not require** more information than is needed to send the signal. It may offer an optional field, such as an email address, to extend the opt-out offline; if the visitor ignores it, the browser-level opt-out still applies. - Use any information collected with the request only to process it (7025(d)). The regulation's own example is exactly this visitor: a business that cannot associate the browser with an account must stop selling and sharing data tied to the **browser identifier**, but cannot apply the opt-out to the account because it does not know the connection. | Situation | What the opt-out covers | |---|---| | Logged-out visitor, no link to an account | That browser or device and its pseudonymous profile | | Logged-in or otherwise known visitor | Browser, device and the consumer's account, including offline sale or sharing | | Known visitor later arrives on a device without the signal | Opt-out stays; absence of the signal is not consent (7025(c)(5)) | | Visitor clears cookies and returns with the signal | Treated again at browser or device level | ## Conflicts - **Business-specific setting that allows sale.** The signal wins; the business may notify the consumer of the conflict and offer a way to consent, following 11 CCR 7004 (7025(c)(3)). - **Financial incentive that requires sale or sharing.** The business may ask the consumer to affirm that they intend to withdraw from the programme; if they do not affirm, it may ignore the signal for that programme while the consumer is known (7025(c)(4)). ## Frictionless or not `1798.135(b)(3)` lets a business elect between complying with subdivision (a), the links, and subdivision (b), the signal route. The regulations read that choice narrowly (7025(e)): it is a choice between **processing signals and posting the links**, or **processing signals frictionlessly and not posting the links**. It is never a choice between the links and the signals. **Frictionless** processing (7025(f)) means the business does not: - charge a fee or require valuable consideration for using the signal; - change the consumer's experience of the product or service; - show a notification, pop-up, interstitial or similar content in response to the signal (displaying that the opt-out was honoured is allowed). To drop the links, a business must also describe the signal route in its privacy policy and let the signal **fully effectuate** the opt-out (7025(g)). A business that also sells offline and would need extra information from the consumer to apply the opt-out there cannot use that route. ## Engineering consequences - Read the signal on every request at the edge, before any third-party tag fires. - Key the opt-out to the browser identifier and to every pseudonymous profile linked to it. - Persist the opt-out against the account once the visitor logs in, and do not clear it when a later session lacks the signal.

  • The site shows a pop-up asking signal users to reconsider. What does that cost it?
    Frictionless status. 11 CCR 7025(f)(3) says frictionless processing means no notification, pop-up or interstitial content in response to the signal. The site must still honour the signal, but it can no longer rely on the signal route to avoid posting the 'Do Not Sell or Share' or Alternative Opt-out Link.
  • Does a signal sent by a browser count as a request from an authorised agent needing signed permission?
    No. Civil Code 1798.135(e) lets a consumer authorise another person to opt out for them, including through an opt-out preference signal, and 11 CCR 7026(j) states that the signed-permission requirement for authorised agents does not apply to requests made by an opt-out preference signal.

saying these in an interview costs you the question

  • Ignores the signal because the visitor is not logged in
  • Demands an email address before honouring the signal
  • Believes posting a 'Do Not Sell or Share' link lets the site ignore signals
  • Treats a later visit without the signal as consent to resume sharing
  • Shows an interstitial on every signal yet claims frictionless processing