If a Visitor Says "Don't Sell My Data," Can I Still Track Them?
US websites offer two privacy controls that look interchangeable: the cookie banner and the "Do Not Sell" link. Does using one force you to honor the other?
Jon Cairo US websites offer two privacy controls that look interchangeable: the cookie banner and the “Do Not Sell or Share My Personal Information” link. One controls tracking and cookies in the browser, the other controls where visitor data gets sent. Whether using one forces you to honor the other is the question this article attempts to answer. The answer requires building up a few premises, so let’s take them in order.
First, some plain-language definitions
Opt-out region: tracking is allowed by default, and it’s on the visitor to say “stop.” In these regions, you can begin tracking the moment someone lands on your site. All US state privacy laws work this way on the books — though California, as you’ll see, is the exception in practice.
Opt-in region: tracking is not allowed until the visitor says “yes.” In these regions, nothing can fire until permission is given. Europe (GDPR) works this way, which is why EU sites make you click a banner before anything loads.
Cookie: a small piece of data a website stores in your browser so it can recognize you later. Advertising and analytics tools use cookies to follow visitor behavior.
Cookie opt-out: the visitor uses your banner or settings to say “don’t put marketing or analytics cookies in my browser.”
Data sale: sending visitor information to another company for something of value. Courts have ruled this doesn’t require money changing hands; giving data to Meta, Google Ads, or TikTok in exchange for their advertising services counts as a sale.
Data sale opt-out (“Do Not Sell My Data”): a legal right in the 20 US states with comprehensive privacy laws (CA, VA, CO, CT, UT, TX, OR, MT, FL, DE, IA, NE, NH, NJ, TN, MN, MD, IN, KY, RI). The visitor tells you to stop giving their information to other companies, however you’re doing it.
So the question in plain terms: if a visitor uses one of these controls, must you assume that choice carries over to the other one?
Premise 1: No US law requires a cookie banner, but in practice California requires one (or something very much like it)
No US state statute requires a cookie banner or permission before setting cookies. Everything is opt-out. The cookie banner is a European invention, born from European law, and every one you see on a US site is either serving EU visitors or borrowed convention.
What changed the picture in California is litigation, not legislation. A 1967 wiretap law called CIPA has spawned thousands of lawsuits and demand letters claiming that everyday website tools, like ad pixels, session recording, and chat widgets, are illegal “wiretaps.” These demands typically settle for $10K-$25K each, courts disagree on whether the claims are valid, and the reform bill (SB 690) isn’t law yet.
Getting the visitor’s explicit permission before any tracking fires defeats every one of these claims. So the logical move in California is: ask first, track nothing until the visitor agrees. Yes, you’ll lose data on your California visitors — expect about half of them to opt in. But between the frequency of these lawsuits, their expense, and the distraction and stress they cause, California has effectively become an opt-in state through litigation rather than law.
Premise 2: The “cookie banner” California needs isn’t just about cookies
Notice what CIPA actually complains about: tracking. Wiretapping, recording, capturing what a visitor does. Not cookies specifically.
So the permission you need in California isn’t “may I store cookies in your browser?” It’s “may I track you and use your data to understand your behavior?” That covers everything: cookies, other browser storage, and the network requests that carry visitor information to advertising and analytics companies.
In practice, the banner this produces looks a lot like what’s required in Europe — similar enough that everyone calls it a cookie banner, borrows the terminology and the UI, and treats the two as the same thing. But that familiarity misleads. A GDPR-style banner is typically known for asking permission to store cookies in your browser, among other things. The American banner taking shape in California is something a little different: a data-sale approval banner. What it has to communicate isn’t just “this site uses cookies” — though that’s probably a good idea too — it’s also that information about the visitor (an IP address, stored cookies, sometimes outright personal information) is being transferred to third parties like Meta, Google, and analytics vendors, and that the visitor can refuse. The cookies are incidental; the sale is the point.
Keep that in mind, because it’s the key to everything that follows. If the banner is really about data changing hands, not cookies, then the wall between “cookie controls” and “data controls” is looking very thin.
Premise 3: If you’re transferring data to third parties, you’re selling data
All 20 state privacy laws grant a “Do Not Sell” right; only California requires the exact link text “Do Not Sell or Share My Personal Information” on your homepage. Elsewhere, a clear link in your footer is enough.
And don’t assume you’re exempt because you “don’t sell data.” In California’s first enforcement action, Sephora paid $1.2M partly for making that assumption. Transferring visitor data to third parties in exchange for their services is a sale, and that includes advertising platforms, analytics tools, and similar vendors. If data flows from your site to Meta, Google Ads, TikTok, an analytics provider, or any other partner, you’re selling.
Premise 4: Cookies and data-sending can’t be separated
A cookie is just stored data. What advertisers actually run on is your website sending visitor information to them, with or without a cookie involved.
That creates a tempting loophole: “the visitor blocked cookies, so I won’t store anything, but I can still send their information to my ad partners.”
Put the premises together and the two controls collapse into each other. The cookie banner is really asking permission to track. Tracking works by sending data to advertisers. Sending data to advertisers is legally a sale. So a cookie opt-out and a data sale opt-out are, at heart, trying to prevent the same thing. Now the two directions of our question almost answer themselves.
If a visitor opts out of data sale, do you have to stop tracking them and saving cookies?
Yes — and not because it’s the cautious play. It follows directly from the premises. Ad pixels and tracking requests transfer visitor data to third parties, and that transfer is the sale. So when a visitor opts out of the sale, they have opted out of the tracking, whether or not they ever mention cookies. These aren’t two separate requests; they’re one and the same.
Cookies your own site needs, like login and shopping cart, can stay — nothing about them sells data. And yes, options like Meta’s “Limited Data Use” mode or Google’s cookieless pings may follow the rules — though even that is up for debate — but they look very similar to breaking them: data still flowing to an advertiser after the visitor said stop. A lawyer inspecting your site can see the difference, but only by looking extremely closely; without detailed knowledge of how these systems work, the requests look almost identical. The extra data you gain from these workarounds is modest, and defending a technically-legal-but-suspicious-looking setup costs far more than it’s worth.
If a visitor rejects cookies, do you have to stop selling their data?
No law says so explicitly, but regulators act as if it does, so treat it as yes. A visitor who rejects marketing cookies has said “don’t use my data for advertising.” That’s the tracking permission from Premise 2, denied. If cookies stop but their information keeps flowing to Meta, Google Ads, or TikTok another way, that’s exactly the gap regulators fine.
Healthline paid $1.55M when its opt-out didn’t actually stop advertising data flows, and Todd Snyder paid $345K when a misconfigured consent tool silently ignored opt-outs for 40 days. The visitor opted out of the use of their data, not one particular mechanism.
FAQ
Is a cookie banner legally required in the United States?
No state law requires one. But California lawsuit risk (CIPA) makes asking permission before tracking the safest practice there, and that permission request ends up looking like a cookie banner.
If a visitor rejects marketing cookies, can I still send their data to Meta, Google, or TikTok another way?
Not for advertising purposes. Regulators treat a cookie rejection as covering all advertising data, not just cookies.
If a visitor clicks “Do Not Sell,” do all cookies have to stop?
Cookies your site needs to function (login, cart) can stay. Everything ad-related should stop, even flows that might technically be allowed, because outside observers can’t tell the difference.
Which states require a “Do Not Sell” option?
All 20 states with privacy laws grant the right; only California mandates the exact link text on your homepage.
Does “we don't sell data” exempt me?
Almost never. Giving data to ad and analytics platforms in exchange for their services counts as a sale, per the Sephora case.
Are the California (CIPA) tracking lawsuits legitimate?
Unsettled. Courts disagree, there’s no definitive ruling, and reform legislation is pending. Most businesses settle rather than fight.
What about Global Privacy Control (GPC) signals?
California requires honoring the GPC browser signal as a valid opt-out of sale — treat it exactly like a click on your “Do Not Sell” link. Other states’ universal opt-out rules point the same direction. We covered how the signal works, and what the law says about it, in What Is Global Privacy Control?.
Do these laws apply to small businesses?
Most state privacy laws only apply past thresholds — California’s kick in around $25M in annual revenue, or data on 100k+ consumers, or half your revenue coming from selling data. CIPA wiretap suits have no such threshold, though; small sites get demand letters too.
Do login and shopping-cart cookies count?
No. Strictly functional cookies don’t sell anyone’s data. Both opt-outs are aimed at advertising and analytics flows, not the cookies that keep your site working.