Artifact GuideCaliforniaSharing and Cross-Context Behavioral Advertising

California CPRA Sharing and Cross-Context Behavioral Advertising

A covered business shares personal information when it makes that information available to a third party for cross-context behavioral advertising, even if no money changes hands.

Classify each advertising data flow by purpose and recipient role, then apply the notice, opt-out, preference-signal, contract, and downstream controls that match the facts.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), is making a consumer's personal information available to a for , whether or not the parties exchange money or other value. Cross-context behavioral advertising targets advertising from personal information obtained through the consumer's activity across businesses, distinctly branded websites, apps, or services other than the one with which the consumer intentionally interacts. A covered business that shares must give notice, provide and honor opt-out methods, process qualifying opt-out preference signals, control recipients by contract, and keep evidence that the controls work.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

How do you decide whether an advertising data flow is sharing?

Trace the information from collection to the advertising recipient and ask four questions: Is it personal information? Does the business communicate or make it available to another person? Is that person a for this service? Will the recipient target advertising using information obtained from the consumer's activity across other businesses or distinctly branded sites, apps, or services? If all four answers are yes, the flow is even when the arrangement is unpaid.

The statute excludes three situations from : the consumer directs an intentional disclosure or intentionally interacts with a ; the business passes an opt-out or sensitive-information limitation identifier so others can honor the choice; or personal information transfers as an asset in a merger, acquisition, bankruptcy, or similar change-of-control transaction and remains subject to the statutory conditions. These are narrow exclusions. A consumer's ordinary use of a website is not enough by itself to show that the consumer directed an ad-tech disclosure.

Contextual or nonpersonalized advertising based only on the consumer's current interaction can fall outside . A may provide advertising or marketing services, but cannot contract to provide cross-context behavioral advertising in that role. A person providing cross-context behavioral advertising is a for that service. The label in the contract does not override the recipient's actual use of the data.

  • Inventory pixels, cookies, SDKs, server-side events, identity matching, audience uploads, and real-time bidding rather than reviewing browser tags alone.
  • Record the personal-information categories, recipient, advertising purpose, source contexts, contract role, and whether the recipient combines data across contexts.
  • Test separately. A flow may trigger the sale opt-out even when it is not for .
Citations
Question 2

What notice and opt-out controls must a sharing business provide?

A business that shares must tell consumers that their personal information may be sold or shared and that they have a right to opt out. Its privacy policy must describe the right and the available method. Unless the business qualifies for the frictionless preference-signal alternative in Civil Code section 1798.135(b) and section 7025 of the regulations, it must also provide the required "Do Not Sell or Share My Personal Information" link or compliant alternative link.

The business must offer at least two designated opt-out methods, chosen for how it interacts with consumers and collects the information. An online business must, at minimum, accept a qualifying opt-out preference signal and provide an interactive form through the required link, alternative link, or privacy policy when the frictionless alternative applies. It cannot require an account or identity verification and may request only information needed to carry out the opt-out.

A qualifying opt-out preference signal applies to the browser or device and associated consumer profiles, including pseudonymous profiles. If the business knows the consumer, it must also apply the signal to that consumer. An anonymous browser signal does not require the business to connect data it cannot reasonably associate with that browser. Posting an opt-out link does not excuse the business from processing qualifying signals.

Stop as soon as feasibly possible and no later than 15 business days after receiving the request. Notify third parties that received the consumer's information after the request but before compliance, direct them to honor the request, and require them to pass it to anyone to whom they made the information available during that period. The business must provide a way for the consumer to confirm that the opt-out was processed and generally must wait at least 12 months before asking the consumer to consent again.

  • Test the link or alternative choice, qualifying preference signals, account and pseudonymous-profile propagation, tag suppression, downstream notice, and confirmation state.
  • Do not treat the absence of a later preference signal as consent when a known consumer previously sent one.
  • For a consumer under 16 whom the business actually knows is under 16, obtain the age-appropriate affirmative authorization before selling or ; willfully disregarding age counts as actual knowledge.
Citations
CPPA approved regulations, sections 7025-7026

Binding operational requirements for qualifying opt-out preference signals, linked profiles, frictionless processing, designated methods, the 15-business-day outside limit, downstream notification, confirmation, and later consent requests.

Question 3

What contracts and evidence should the business maintain?

A business that shares with a must have an agreement identifying the limited and specified purposes, limiting the third party to those purposes, requiring the same level of CCPA protection for the information, and giving the business rights to check, stop, and remediate unauthorized use. The agreement must also require notice if the third party can no longer comply. A service-provider or contractor agreement needs the separate terms in section 7051; using that label without the required contract and restricted use may leave the recipient outside that role.

Keep a dated inventory of advertising technologies and server-side transfers; data-flow and recipient-role maps; the and analysis; contracts and due diligence; privacy-policy and choice-interface captures; preference-signal test results; consent and under-16 authorization records where applicable; suppression and downstream-notification logs; confirmation-state tests; and retests after material product, vendor, or purpose changes.

Test actual behavior before and after an opt-out. Common failures include sending identifiers before the choice takes effect, failing to cover server-side transfers or a known consumer's linked profile, treating an unpaid disclosure as outside , or relying on contract wording while the recipient combines data for cross-context advertising.

  • Assign an owner for each tag, SDK, audience list, bidding integration, and server-side advertising event.
  • Match the public notice, preference center, contracts, consent state, and runtime behavior to the same data-flow inventory.
  • Reclassify the recipient if its actual use no longer fits the contracted role, and stop the transfer until the required controls are in place.
Citations
CPPA approved regulations, sections 7050-7053

Binding recipient-role rules and contract terms for service providers, contractors, and third parties, including purpose limits, compliance duties, oversight, remediation, and downstream request handling.

Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Binding definitions of cross-context behavioral advertising, sharing, third party, service provider, contractor, and the statutory exclusions from sharing.
"whether or not for monetary or other valuable consideration"
leginfo.legislature.ca.gov
Referenced sections
  • Binding right to opt out, notice requirement, under-16 opt-in rule, homepage-link or preference-signal routes, privacy-policy disclosure, data-use restriction, and 12-month waiting period.
"A consumer shall have the right, at any time"
leginfo.legislature.ca.gov
Referenced sections
  • Current official statutory text for the sale and sharing opt-out right, notice, under-16 authorization, choice methods, privacy-policy disclosure, and later consent.
"right to opt out of sale or sharing"
cppa.ca.gov
Referenced sections
  • Current approved operational rules for opt-out preference signals, opt-out requests, recipient roles, and contracts.
"A business that sells or shares personal information shall process any opt-out preference signal"
cppa.ca.gov
Referenced sections
  • Binding rules and examples distinguishing third-party cross-context behavioral advertising from advertising services a service provider or contractor may perform.
"A person who contracts with a business to provide cross-context behavioral advertising is a third party"
cppa.ca.gov
Referenced sections
  • Binding operational requirements for qualifying opt-out preference signals, linked profiles, frictionless processing, designated methods, the 15-business-day outside limit, downstream notification, confirmation, and later consent requests.
"as soon as feasibly possible, but no later than 15 business days"
cppa.ca.gov
Referenced sections
  • Binding recipient-role rules and contract terms for service providers, contractors, and third parties, including purpose limits, compliance duties, oversight, remediation, and downstream request handling.
"Identifies the limited and specified purpose(s)"
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
US CPRA Sharing and Cross-Context Behavioral Advertising Guide
How to classify advertising data flows as sharing for cross-context behavioral advertising under the California CCPA and CPRA.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.