Target · Target Terms and Conditions · View original document ↗

CCPA Privacy Controls and Data Opt-Out

Medium severity Medium confidence Inferredfromcontext Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Target recorded 7 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Target Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

If you are a California resident, you have the right to request that Target not sell your personal information to third parties, and Target provides an opt-out mechanism for this purpose.

This analysis describes what Target's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

California's CCPA gives residents legally enforceable rights to access, delete, and opt out of the sale of their personal data; Target's platform infrastructure includes CCPA-specific API endpoints suggesting these rights are operationally implemented, but consumers must actively exercise them.

Interpretive note: The exact CCPA disclosure language was not fully visible in the truncated document; the existence of CCPA-specific API endpoints in the site infrastructure strongly implies operational implementation, but the precise disclosure text and opt-out scope require confirmation against the full privacy policy.

Recent Activity

This document changed recently

Medium Apr 30, 2026

California customers using Target's same-day delivery service will now pay a CA Shipt Shopper Benefit Fee in addition to standard delivery costs, according to the updated terms. The terms do not spec…

Medium Apr 16, 2026

Target removed specific language that explained how Target Circle Bonus rewards are earned, calculated, and reflected in customer accounts across different purchase methods (online, in-store, Same Da…

Consumer impact (what this means for users)

California residents can request access to, deletion of, or opt out of the sale of their personal information held by Target, but these rights require proactive exercise through Target's privacy controls and do not apply automatically.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Navigate to Target's privacy page at target.com/privacy, locate the privacy controls or Do Not Sell My Personal Information link, and follow the prompts to submit a data access, deletion, or opt-out request.

How other platforms handle this

Verizon Medium

California law gives residents the right to know what personal information we collect, use, share or sell; to delete personal information under certain circumstances; to opt-out of the sale or sharing of their personal information; to correct inaccurate personal information; to limit the use and dis...

FanDuel Medium

If you would like to opt out of the disclosure of your personal information for purposes that could be considered "sales" for those third parties' own commercial purposes, or "sharing" or processing for purposes of targeted advertising, please visit the following link, which is also available in the...

Zendesk Medium

Zendesk complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. When Zendesk transfers personal data from the EU, UK, or Switzerland to the United ...

See all platforms with this clause type →

Monitoring

Target has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
California residents may have the right to opt out of the sale of their personal information. Target provides a 'Do Not Sell My Personal Information' link and privacy controls through which California residents can exercise their rights under applicable California law.

— Excerpt from Target's Target Terms and Conditions

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: This provision directly engages the California Consumer Privacy Act and its amendment, the California Privacy Rights Act, enforced by the California Privacy Protection Agency and the California Attorney General. CCPA requires businesses meeting applicable thresholds to provide consumers with rights to know, delete, correct, and opt out of sale or sharing of personal information. The CCPA-specific API endpoints visible in Target's site infrastructure (including do_not_sell_requests and privacy_controls endpoints) indicate operational implementation of these rights, which must align with CCPA's substantive and procedural requirements. GOVERNANCE EXPOSURE: High for California-specific compliance. Target's scale and data collection practices across loyalty, payment, advertising, and registry systems create a broad personal information footprint. Failure to honor opt-out requests within the CCPA-required 15-business-day window, or inadequate disclosure of data sharing practices that constitute a sale or sharing under CPRA, creates enforcement exposure. JURISDICTION FLAGS: California is the primary jurisdiction. Other states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Texas, Montana) have enacted similar but non-identical frameworks; Target's compliance infrastructure should be mapped against each applicable state law. Illinois BIPA may apply if Target collects biometric identifiers through any feature of its platform. CONTRACT AND VENDOR IMPLICATIONS: Third-party advertising and data partners integrated into Target's ecosystem (visible through the advertising API infrastructure in the document) must be assessed as to whether data flows to them constitute a sale or sharing under CCPA, triggering opt-out obligations. Service provider agreements with these partners should include CCPA-compliant data processing terms. COMPLIANCE CONSIDERATIONS: Compliance teams should audit whether the Do Not Sell and Do Not Share opt-out mechanisms meet CPRA requirements, including Global Privacy Control signal recognition. Data mapping should confirm that all personal information categories collected across the Target digital ecosystem (loyalty, payment, advertising, registry) are accurately disclosed in the CCPA privacy notice. Response time and verification procedures for consumer rights requests should be tested against statutory requirements.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • State AG
    The California Attorney General and California Privacy Protection Agency have enforcement authority over CCPA and CPRA compliance, including Target's data sale opt-out and consumer rights processes
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
TCPA
United States Federal
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Target Terms and Conditions
Entity
Target
Document last updated
May 5, 2026
Tracking information
First tracked
May 11, 2026
Last verified
May 11, 2026
Record ID
CA-P-010279
Document ID
CA-D-00259
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
8084aaa6d924bb58f3064cfc42f494ac29023c9f847f99cbea548a30c20ac686
Analysis generated
May 11, 2026 04:12 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Target
Document: Target Terms and Conditions
Record ID: CA-P-010279
Captured: 2026-05-11 04:12:11 UTC
SHA-256: 8084aaa6d924bb58…
URL: https://conductatlas.com/platform/target/target-terms-and-conditions/ccpa-privacy-controls-and-data-opt-out/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Target's CCPA Privacy Controls and Data Opt-Out clause do?

California's CCPA gives residents legally enforceable rights to access, delete, and opt out of the sale of their personal data; Target's platform infrastructure includes CCPA-specific API endpoints suggesting these rights are operationally implemented, but consumers must actively exercise them.

How does this clause affect you?

California residents can request access to, deletion of, or opt out of the sale of their personal information held by Target, but these rights require proactive exercise through Target's privacy controls and do not apply automatically.

Is ConductAtlas affiliated with Target?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Target.