Under the CCPA, identifiability shapes Do Not Sell or Share obligations, while California’s expanded deletion right raises the operational stakes and urgency for tracking personal information across first-party and third-party sources.
Harry Chambers
Regulatory Content Strategist
October 1, 2026
The CCPA’s Do Not Sell or Share right depends on a deceptively simple question: when does information relate to an identifiable consumer?
Under the CCPA, personal information includes information that identifies, relates to, describes, is reasonably capable of being associated with, or reasonably links, directly or indirectly, to a particular consumer or household. The “directly or indirectly” concept brings a wider set of data into the analysis when an organization or its partners have realistic ways to connect it back to a person or household.
IP addresses, device identifiers, cookies, tracking technologies, persistent identifiers, and similar signals deserve close scrutiny when they support recognition, linkage, or differentiated treatment.
That question now reaches a wider part of the CCPA rights workflow. On September 27, 2026, California’s Governor signed the Expanding Privacy Rights Act, SB 923, which expands the CCPA right to delete. Starting January 1, 2027, businesses must delete personal information upon request regardless of whether they collected it directly from the consumer or obtained it from another source, namely third parties.
Key Takeaways
A browser cookie might identify the same user across sessions without revealing a name. An advertising ID might let a business or partner recognize the same device repeatedly. An IP address or combination of attributes might connect activity across services.
The operational question is whether those signals reasonably link the information to a particular consumer or household. DNS/S assessments therefore need to examine how data functions in context.
The European Data Protection Board’s (EDPB) Guidelines 02/2026 on Anonymisation comes from a different legal regime, yet the criteria offer a useful analytical lens. The Guidelines whether a person is singled out, whether information links across datasets, and whether information supports inference about that person.
The CCPA’s definition of sale covers making personal information available to a third party for monetary or other valuable consideration. Sharing covers personal information used for cross-context behavioral advertising, regardless of monetary consideration.
Identifiability therefore influences opt-out scope. If an advertising identifier lets a business or its partners recognize the same browser or device across sessions, that identifier belongs in the DNS/S analysis.
Consider a consumer who opts out of sale or sharing on a mobile app. The business also recognizes that person on its website and connected device through identifiers associated with the same consumer. Recording the mobile-app election addresses only the source interaction. The current opt-out state also needs to affect the services and devices where the business reasonably identifies that consumer.
A DNS/S link or opt-out control presents the choice. The underlying consent and preference management layer carries that choice into the systems responsible for advertising, analytics, partner data flows, and other relevant downstream uses.
Opt-out preference signals such as Global Privacy Control add another layer. The CCPA and revised CCPA Regulations allow consumers to communicate an intent to opt out through a qualifying preference signal.
A GPC signal reaches one browser, so the business needs to determine which consumer, account, device, property, or service it reasonably associates with that interaction.
For example, a logged-in consumer sends a GPC signal from a laptop while the business also associates the same account with a mobile app and connected TV. A browser-only response leaves conflicting states across services tied to the same person. The compliance issue sits in the gap between recognizing the signal and enforcing the consumer’s choice across associated environments.
Businesses must notify third parties to whom they sold or shared the consumer’s personal information about the opt-out request. That already requires visibility into which identifiers leave the organization and where an updated opt-out state needs to travel.
California’s Expanding Privacy Rights Act, SB 923, raises the stakes for those third-party data flows. From January 1, 2027, businesses must delete personal information upon request regardless of whether they collected it directly from the consumer or received it from another source. The law also allows businesses to maintain suppression lists because businesses must now ensure that deleted information stays deleted when new third-party data arrives.
Consider a consumer whose records have been deleted, followed weeks later by a third-party dataset containing an identifier linked to that same person. The operational issue becomes whether the organization recognizes that returning data and applies the consumer’s existing deletion state.
The same scrutiny applies to information described as deidentified or anonymous. Removing names and email addresses deals with one route to identification, while persistent identifiers, dataset linkage, or inference might still support the recognition of the same consumer.
The common requirement across DNS/S and deletion is consistent identity handling. Organizations need to understand which information reasonably identifies a consumer, where that information flows, and which existing privacy choice or deletion state should follow it.
A practical model connects four stages: recognize the consumer choice, operationalize the required suppression, propagate the current state where the consumer is reasonably identified, and preserve evidence showing what happened.
OneTrust CMP Suite is positioned for focused DNS/S and Global Opt-Out use cases involving GPC handling, opt-out proof, coordinated privacy experiences, and downstream action.
Explore OneTrust Consent & Preferences to see how connected consent infrastructure supports consumer choice across digital experiences and the systems behind them.
Explore OneTrust Privacy Automation to see how privacy teams manage consumer rights requests from intake through data identification, deletion, and fulfillment.
It refers to information that reasonably links, directly or indirectly, to a particular consumer or household. The analysis reaches beyond obvious identifiers and considers whether available data and realistic means of linkage associate information with that consumer.
Removing a direct identifier addresses one path to identification. Linkage, persistent identifiers, dataset combinations, and inference still affect whether information remains reasonably identifiable. The assessment should focus on how the data functions across the organization’s systems and relevant third-party relationships.
Starting January 1, 2027, businesses must delete personal information upon request regardless of where that information came from. The law also allows suppression lists because businesses are must prevent deleted consumer information from returning when new third-party data is acquired. Online-only businesses must also provide an online method for submitting privacy requests.