CCPA / CPRA Guide

Configure opt-out, Do Not Sell, and US state privacy patterns in CookieShift.

Consent Setup — CCPA / CPRA banner with Accept, Reject, and Customize
Consent Setup — CCPA / CPRA banner with Accept, Reject, and Customize

Use this guide for California (CCPA/CPRA) and similar US opt-out frameworks. CookieShift supports CCPA-style engines with Do Not Sell and reject flows—not legal advice.

US vs EU model (quick comparison)

TopicGDPR-style (EU)CCPA-style (US)
Default for non-essentialBlock until opt-inMay load until opt-out (configuration-dependent)
Primary actionAccept / CustomizeOften includes Do Not Sell
Sensitive sale/shareLess common labelDo Not Sell or Share link
Proof focusPrior consent logsOpt-out requests + disclosures
  1. Open Consent SetupCompliance.
  2. Select CCPA or apply a US state law from the law registry (many US states map to CCPA-style behavior in CookieShift).
  3. Enable Do Not Sell when selling/sharing personal information as defined by your counsel.
  4. Set Do Not Sell placement (inline, below banner, or preferences-only).
  5. Use button layout Accept + Reject or include Customize for granular control.
  6. Save and verify on a US IP or geo rule.

Do Not Sell control

SettingEffect
Do Not Sell enabledShows required link/label for CCPA-style regimes
Placement: InlineVisible on main banner
Placement: BelowSecondary line under primary buttons
Placement: Preferences onlyInside preference center

Match placement to your counsel’s UX requirements—some brands need persistent footer links beyond the banner.

Do Not Track (DNT)

Compliance tab includes Do Not Track handling:

ModeBehavior (high level)
OffIgnore DNT header
Telemetry onlyLog signal without auto-changing consent
Auto reject when unsetStronger default when DNT is set

DNT is not the same as Global Privacy Control (GPC). Confirm with legal how your program treats GPC signals.

Geo targeting for US visitors

Add a Geo → law rule: United States → CCPA (or specific state law). Keep EU visitors on GDPR via separate rules.

Test:

  • US VPN → CCPA banner variant
  • EU VPN → GDPR opt-in variant

Scanner and disclosures

CCPA requires accurate Notice at Collection and opt-out paths. Use Scanner to list trackers, then ensure Content tab descriptions mention analytics/marketing vendors you actually use.

Records for compliance

RecordSource
Opt-out / reject eventsConsent logs filtered by outcome
Inventory at point in timeCompliance PDF export
Policy versionYour published privacy policy + config save date

Common mistakes

MistakeFix
GDPR copy shown to California usersAdd US geo rule
No Reject buttonEnable Accept + Reject layout
Marketing tags in NecessaryReclassify in Scanner
Do Not Sell hidden in preferences only when law requires prominenceChange placement