Only 31% of websites actually stop tracking a visitor after they click Do Not Sell, meaning 69% keep firing three or more ad, analytics, or fingerprinting trackers regardless, according to DataGrail's 2025 Data Privacy Trends Report, an audit of more than 5,000 websites and the most current large-scale figure available as of August 2026. The link exists on paper far more often than it works in practice, and the gap between clicking it and actually being left alone is the real story behind Do Not Sell link usage heading into 2026.

Sites that stop tracking after a Do Not Sell click, versus sites that do not 31% 69% share of sites that stoppedtrackers after a Do Not Sellclick, versus sites still firing

Does clicking Do Not Sell actually stop tracking?

Clicking a "Do Not Sell My Personal Information" link does not guarantee an end to tracking. DataGrail's 2025 Data Privacy Trends Report audited more than 5,000 websites and found that 69% still fired three or more cookie, analytics, or fingerprinting trackers after a visitor submitted an opt-out request, meaning only 31% of sites actually stopped.

The gap is not always intentional. A privacy team can update a legal disclosure and a Do Not Sell form without ever reconfiguring the ad tags, tag manager rules, and third-party pixels that keep firing regardless of what a visitor clicked. The request reaches a database; it does not automatically reach the script tag that would need to react to it.

Figure 1: A click does not automatically reach every tracking script on a page. Source: DataGrail, 2025 Data Privacy Trends Report.

This is the practical difference between a legally correct disclosure and a legally correct outcome, and it is where most Do Not Sell complaints and enforcement actions originate.

Not many. Most businesses report Do Not Sell or general opt-out click-through rates of only 1 to 5%, whether the link sits on a website, inside a mobile app, or in an OTT/CTV interface, according to the Interactive Advertising Bureau's CCPA Benchmark Survey, which polled roughly 80 senior privacy lawyers in spring 2020 and published its findings that November.

That low click rate cuts both ways. A business with a narrow opt-out click rate has less operational load to process, but it also means the businesses that do get flagged for a broken link are the ones a small, motivated minority of privacy-conscious visitors actually tested, not a broad random sample. Regulators and researchers who audit Do Not Sell handling directly, rather than waiting for visitor complaints, are the reason gaps like DataGrail's 69% figure surface at all.

Requests are still growing year over year even at a low click rate. Do Not Sell opt-out requests rose 37% in 2024 over 2023 across the businesses DataGrail tracks for its customers, part of a broader climb in CCPA opt-out request volume that has continued since the law took effect in 2020.

Not every business is legally required to post a Do Not Sell link in the first place. Only businesses that meet the CCPA's revenue or data-volume thresholds and that actually sell or share personal information owe visitors the link at all, and some post it anyway even when they do not have to. Only 8% of companies that publicly state they do not sell personal information add a Do Not Sell link regardless, according to a Greenberg Traurig LLP review of 555 companies conducted in September and October 2022, drawn from recent Fortune 500 membership plus additional companies added from underrepresented industries.

Among businesses that do process Do Not Sell requests, denials are uncommon but not zero. Fortune 500 retailers denied an average of 1.7% of the Do Not Sell requests they received, per a separate Greenberg Traurig review of retailers' own published CCPA request metrics from August 2021, the kind of annual disclosure California Code of Regulations Title 11, Section 999.317(g) requires from businesses handling a high volume of consumer requests.

MeasureRateSourceYear
Sites still tracking after a Do Not Sell click69%DataGrail, 2025 Data Privacy Trends Report2025
Site visitors who click the Do Not Sell or opt-out link1 to 5%IAB CCPA Benchmark Survey2020
Businesses voluntarily posting the link when not required8%Greenberg Traurig LLP, 555-company review2022
Do Not Sell requests denied by Fortune 500 retailers1.7%Greenberg Traurig LLP, retailer metrics review2021
Covered websites honoring the automated GPC alternative45%Hausladen et al., USENIX Security 20252024

Table 1: Five independent measures of how the Do Not Sell mechanism actually performs, from posting the link to honoring what it promises.

Businesses that have never checked whether their own Do Not Sell form actually stops the tags it is supposed to stop can generate a CCPA-ready privacy policy that documents the mechanism correctly as a first step, though the disclosure alone does not fix a tag manager that ignores it.

Yes, on paper. The CCPA lets a covered business forgo the manual "Do Not Sell My Personal Information" link if it instead processes an approved automated opt-out preference signal, chiefly Global Privacy Control (GPC), for every visitor who sends one. In practice, that substitute is honored about as inconsistently as the manual link itself.

Websites honoring Global Privacy Control, April 2024 45%55%Honored the signal45%Did not honor it55%45%honored GPC

Figure 2: Fewer than half of covered sites actually flip to opted-out status after receiving a GPC signal. Source: Hausladen et al., "Websites' Global Privacy Control Compliance at Scale and over Time," USENIX Security 2025, longitudinal crawl of 11,708 US websites.

Wesleyan University and Princeton University researchers tested 11,708 US websites across three separate crawls between December 2023 and April 2024 and found GPC compliance stuck in the mid-40s the entire time, rising only from 44% to 45% over five months. Twelve states now require honoring a signal like GPC by statute as of August 2026; see our full state-by-state universal opt-out tracker and our deeper breakdown of the GPC compliance study for the year-by-year trend behind this figure.

Every mechanism a consumer can use to exercise a Do Not Sell right trades consumer effort for reliability differently. Clicking a link on the page and turning on a browser-level GPC signal both ask almost nothing of the visitor, and both fall short of the halfway point on measured compliance. Sending a request through a state-registered authorized agent asks the most of a consumer but comes closest to a guaranteed outcome, reflected here in the low 1.7% Fortune 500 retailer denial rate for properly submitted requests.

Figure 3: Approximate positioning combining the closest available measure for each channel; the three studies behind these points use different methodologies and are not a single unified survey. Sources: Hausladen et al., USENIX Security 2025 (GPC); DataGrail, 2025 Data Privacy Trends Report (link click); Greenberg Traurig LLP, August 2021 (authorized agent, via denial-rate proxy).

Neither of the two zero-effort channels clears 50% compliance on its own, which is why relying on just one, and never verifying it, leaves a real gap between what a privacy policy promises and what a visitor actually gets.

What happens when regulators find a broken Do Not Sell mechanism?

It gets expensive. California's first CCPA settlement, announced by Attorney General Rob Bonta on August 24, 2022, fined Sephora $1.2 million specifically for failing to disclose that it sold personal information, failing to process opt-out requests including Global Privacy Control signals, and failing to cure the violations inside the CCPA's 30-day window.

CCPA fines for broken Do Not Sell or GPC handling Sephora (2022)1,200KAmerican Honda (2025)633KTodd Snyder (2025)345K

Figure 4: Three of the largest publicly confirmed CCPA fines tied directly to a broken Do Not Sell or GPC mechanism, sorted by amount. Source: California Attorney General (Sephora); California Privacy Protection Agency joint sweep announcement, September 9, 2025 (Honda, Todd Snyder).

CompanyFineViolationAnnounced
Sephora$1.2 millionFailed to disclose data sale and process GPC opt-outsAugust 2022
American Honda Motor Co.$632,500Failed to honor GPC opt-out signalSeptember 2025
Todd Snyder$345,178Failed to honor GPC opt-out signalSeptember 2025

Table 2: California's largest confirmed CCPA settlements tied specifically to Do Not Sell or GPC handling. Source: California Attorney General; California Privacy Protection Agency.

All three cases share the same underlying pattern this post has traced from the click-through data: a business had a Do Not Sell mechanism that looked correct in its privacy policy but did not actually change what happened to a visitor's data once the request came in.

How has Do Not Sell enforcement evolved since 2018?

The requirement to offer a Do Not Sell mechanism is older than most businesses' current implementation of it. California voters approved the CCPA in 2018, and enforcement of its Do Not Sell provisions has moved through several distinct phases since.

Figure 5: Eight years separate the Do Not Sell right's creation from a 12-state automated-signal mandate. Source: California Attorney General, California Privacy Protection Agency, Hausladen et al. (USENIX Security 2025).

Enforcement has moved from disclosure checks toward outcome checks. Early CCPA enforcement, including the 2021 review cycle that produced 27 published case examples, focused heavily on whether a Do Not Sell link existed on a homepage at all. The Sephora and later Honda and Todd Snyder settlements show regulators now testing whether the mechanism behind the link, or the GPC signal replacing it, actually works.

The Bottom Line

The Do Not Sell link is used far less, and honored far less consistently, than most privacy policies imply. Only 1 to 5% of visitors click it, only 31% of audited sites actually stop tracking once someone does, and the automated GPC alternative fares only marginally better at 45%. None of that is a reason to treat the mechanism as low-stakes: California has now fined three separate companies over broken Do Not Sell or GPC handling, and the pattern in every case was the same disclosure-versus-outcome gap this data shows across the wider web. A business that has updated its privacy policy language but never confirmed its tag manager actually suppresses tracking after an opt-out click is closer to the 69% majority than it might assume.

Frequently Asked Questions

What percentage of websites actually stop tracking after a Do Not Sell click? Only 31% of audited sites stopped firing ad, analytics, or fingerprinting trackers after a visitor submitted a Do Not Sell request, meaning 69% still fired three or more trackers afterward, according to DataGrail's 2025 Data Privacy Trends Report, based on an audit of more than 5,000 websites.

How many site visitors actually click the Do Not Sell link? Most businesses see opt-out click-through rates of only 1 to 5%, consistent across website, mobile app, and OTT/CTV channels, according to the Interactive Advertising Bureau's CCPA Benchmark Survey of roughly 80 senior privacy lawyers, published in November 2020.

Do businesses have to display a Do Not Sell link if they already support Global Privacy Control? A covered business can skip the manual Do Not Sell link only if it honors an approved automated signal like Global Privacy Control for every visitor instead, but only 45% of covered sites actually did so when tested in April 2024, per Hausladen et al.'s USENIX Security 2025 study, so assuming GPC works without checking it is a common gap.

What happens if a business's Do Not Sell link does not actually work? It can trigger a state fine. California fined Sephora 1.2 million dollars in August 2022, its first CCPA settlement, specifically for failing to process opt-out requests including Global Privacy Control signals, then fined American Honda 632,500 dollars and retailer Todd Snyder 345,178 dollars in a September 2025 sweep for the same type of violation.

Where the Numbers Come From

  1. DataGrail. (2025). "Data Privacy Trends Report 2025, Opt-Out Requests." 69% of organizations fire three or more cookie trackers after opt-out, from an audit of more than 5,000 websites; Do Not Sell requests up 37% in 2024 over 2023.
  2. Interactive Advertising Bureau. (2020, November 12). "IAB CCPA Benchmark Survey." Roughly 80 senior privacy lawyers surveyed in spring 2020; most respondents reported Do Not Sell/opt-out click-through rates of 1 to 5% across website, mobile, and OTT/CTV channels.
  3. Greenberg Traurig LLP, via National Law Review. (2022, December 6). "How Many Businesses Put Up a Do Not Sell My Personal Information Link Even When They Don't Have To?" Review of 555 companies, September to October 2022; 8% of non-selling companies post the link voluntarily.
  4. Greenberg Traurig LLP, via National Law Review. (2021, September 27). "What Percentage of Do Not Sell Requests Do Retailers Deny Each Year?" Review of Fortune 500 retailers' published CCPA request metrics, August 2021; average 1.7% denial rate.
  5. Hausladen, Wang, Eng, Wang, Wijaya, May, and Zimmeck: Websites' Global Privacy Control Compliance at Scale and over Time (USENIX Security 2025). Wesleyan University and Princeton University. Longitudinal crawl of 11,708 US websites; 45% GPC compliance among covered sites in April 2024.
  6. California Attorney General. (2022, August 24). "Attorney General Bonta Announces Settlement with Sephora." $1.2 million settlement, California's first CCPA enforcement action.
  7. California Privacy Protection Agency. (2025, September 9). "Joint Investigative Privacy Sweep." American Honda fined $632,500 and Todd Snyder fined $345,178 for failing to honor Global Privacy Control opt-out requests.

Note: All figures verified as of August 2026. The 1.7% denial rate and 8% voluntary-adoption figures come from Greenberg Traurig LLP's own website reviews rather than a government-published dataset; the underlying company sample size for the denial-rate review was not stated in the source article. The IAB Benchmark Survey's 1 to 5% click-through range dates to 2020 and is the most recent large-scale survey of its kind currently available. This post is refreshed at least twice a year to track new DataGrail, USENIX, and CPPA enforcement updates.