Opt out is the easy half of a sentence and the expensive half of a system. It means a person is included until they tell you otherwise, which sounds like a marketing preference and is in fact a promise about four separate pieces of plumbing. This page is what the word actually commits you to, and where the commitment usually breaks.
What the word means, precisely
Opt out is a default of INCLUDED. You may send, track or share until the person objects, and once they object you must stop. Opt in is the mirror: nothing happens until the person says yes. Almost every argument about consent is really an argument about which of the two applies to a given activity, and the answer differs by activity and by jurisdiction rather than by company policy.
The four places it has to work
An opt-out that only reaches your mailing tool is not an opt-out. It has to reach: the sending system, so no more messages go; the tracking on your own site, so the profile stops growing; the vendors you have already passed the person to, so their copies stop too; and the record, so you can show when it took effect. Most failures are the third one, because nobody keeps a list of who has a copy.
The clock, because there is one
Under CAN-SPAM the FTC's rule at 16 CFR Part 316 requires that a sender honour an opt-out request within 10 business days, and that no fee, no information beyond an email address and no step other than sending a reply or visiting a single page may be required to make it. That is a hard deadline on a system, not a courtesy, and it is why a manual suppression list eventually fails.
Why the record matters more than the button
When somebody complains that they opted out and still received mail, the question is not whether your link works today. It is what happened on the date they used it. A record that holds the request, the systems it was applied to and the date is the difference between a two-email conversation and an argument you cannot win.
Questions people ask about opt out meaning
Is opt out enough, or do I need opt in?
It depends on the activity and where the person is. Marketing email in the United States generally runs on opt-out under CAN-SPAM; setting non-essential cookies for a person in the EU generally does not. The safe engineering position is to build for opt-in and treat opt-out as the weaker case, because a system that can capture a yes can always record a no.
Does an unsubscribe link cover me?
For email, mostly, if it works within the ten business days and asks for nothing beyond an email address. It does nothing at all for the tracking on your site, the data you have already shared, or a request that arrives as a plain email rather than a click.
What about do not sell?
That is a specific California opt-out with its own published link and its own scope. It is not the same as an email unsubscribe and cannot be served by the same control.