Artifact GuideUSSharing and Cross-Context Behavioral Advertising

US CPRA Sharing and Cross-Context Behavioral Advertising

A business shares personal information when it makes that information available to a third party for cross-context behavioral advertising, even if no money changes hands.

Use this guide to classify recipients and advertising contexts, identify exceptions, apply opt-outs, and document how covered transfers stop.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
5

Structured answer sets in this page tree.

Primary sources
11

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), means communicating a consumer's personal information to a third party for , whether or not the business receives money or other value. Other disclosures require a separate classification. The decision depends on the information, recipient, contract and actual use, advertising context, and any statutory exception.

Section 1

When is an advertising data flow sharing?

targets advertising to a consumer using personal information from that consumer's activity across other businesses or distinctly branded websites, applications, or services. A common example is sending a browser, device, or audience identifier to an advertising platform that combines it with activity from multiple businesses to select targeted ads.

Advertising based solely on personal information from the consumer's current interaction with the business is not under this definition. The statute separately defines nonpersonalized advertising as advertising based solely on that current interaction, except for precise geolocation. Measurement data is only when the business makes it available for cross-context behavioral advertising; labels such as analytics, measurement, first party, or advertising partner do not decide the classification.

  • Identify the personal information sent or made available, including cookies, IP addresses, mobile advertising IDs, hashed contact details, event data, and audience membership.
  • Identify the recipient and whether it combines the information with activity from other businesses or distinctly branded services.
  • Document the advertising purpose, data sources, matching logic, permitted uses, and actual configuration.
  • Classify the flow as , , both, or neither; value exchanged can make a flow a sale, while cross-context advertising can make it sharing without payment.
Section 2

Which recipients and disclosures fall outside sharing?

A recipient that meets the statutory service-provider or contractor role is outside the definition of third party. The recipient must meet the role and contract requirements, and its processing must stay within permitted purposes. A contract label does not protect a flow if the recipient sells or shares the information, uses it outside the direct business relationship, or impermissibly combines it with information from other customers or its own consumer interactions.

The definition also excludes a disclosure when the consumer uses or directs the business to intentionally disclose personal information or intentionally interact with one or more third parties. It also excludes use of an opt-out identifier solely to communicate the consumer's choice and a qualifying transfer in a merger, acquisition, bankruptcy, or similar transaction. Each is fact-specific. Hovering over, muting, pausing, or closing content does not count as an intentional interaction.

  • Service provider or contractor: verify the written contract, limited business purpose, use restrictions, no prohibited combination, and actual processing.
  • Consumer-directed disclosure: preserve evidence of the deliberate interaction and the specific third party the consumer chose.
  • Corporate transaction: confirm the transfer is part of the transaction and that later use remains consistent with the statutory conditions.
  • Same-context advertising: verify that targeting does not use activity from another business or distinctly branded service.
Section 3

What must a business do when it shares personal information?

A business that shares personal information must disclose the practice and the consumer's right to opt out. It must provide the required notice and request method, honor qualifying opt-out preference signals such as Global Privacy Control (GPC), and stop the covered and as soon as feasibly possible and no later than 15 business days after receiving the request.

If the business shares information after receiving the request but before it implements the opt-out, it must notify those third parties, direct them to comply with the request, and direct them to forward the request to any person to whom they made the information available during that interval. Except where the regulations allow otherwise, the business must wait at least 12 months before asking the consumer to consent to or again.

Section 7150 also requires a risk assessment before a business begins selling or personal information. A covered flow already underway before January 1, 2026, must be assessed by December 31, 2027. Review each assessment at least every three years and update it within 45 calendar days after a material change. The assessment is separate from the consumer opt-out and should cover the actual recipients, data, purpose, safeguards, benefits, and negative impacts of the processing.

  • Provide a conspicuous "Do Not Sell or Share My Personal Information" link, an allowed alternative link, or meet every condition for the frictionless-signal exception.
  • Do not treat a privacy link as a substitute for GPC; a business that sells or shares must process a qualifying signal.
  • Apply the opt-out to and , not only to a subset labeled targeted advertising.
  • Use the regulations' two-step process if the consumer later chooses to opt in, and retain the pre-processing risk assessment with the flow record.
Section 4

Which edge cases need a separate decision?

A business with actual knowledge that a consumer is under 16 may not sell or share that consumer's personal information unless the required affirmative authorization is obtained: from the consumer when the consumer is at least 13 but under 16, or from the parent or guardian when the consumer is under 13. Willful disregard of age is treated as actual knowledge.

Also assess sensitive-personal-information limits separately. One processing activity can trigger more than one CCPA rule, but a -and- opt-out does not automatically exercise every other right. Sector, data, entity, and activity exemptions in Civil Code section 1798.145 can change the analysis and should be applied to the specific information and conduct, not to an organization by label alone.

  • Minors: document the age-knowledge basis, authorization path, identity linkage, and suppression behavior.
  • Sensitive information: determine whether the right to limit applies in addition to the -and- opt-out.
  • Overlapping rights: record which , , sensitive-information, deletion, and correction controls apply to the same data.
  • Exemptions: record the exact statutory provision, information, purpose, and boundary rather than marking an entire vendor or dataset exempt.
Section 5

What evidence should the business keep?

Privacy should approve the classification method and notices; marketing and advertising operations should inventory campaigns and recipients; engineering should control tags, SDKs, APIs, audience exports, and preference propagation; procurement should maintain contract restrictions; and a named owner should test the complete opt-out path.

For each flow, keep the data categories and identifiers, source and destination, recipient role, contract, advertising purpose, cross-context data sources, -and- classification, exception analysis, consumer-facing notice, GPC and link behavior, downstream instructions, and dated test result. Reassess after changes to vendors, campaign features, identity matching, data clean rooms, conversion APIs, or recipient terms.

  • Test signed-in and signed-out users, GPC on and off, browser and device changes, and a manual opt-out.
  • Verify that blocked browser collection is not replaced by server-side events, audience uploads, or offline matching.
  • Confirm the opt-out reaches every covered recipient within the regulatory deadline.
  • Review actual configurations and logs; a contract or consent-platform label alone does not prove how the data is used.
Primary sources

References and citations

leginfo.legislature.ca.gov
Referenced sections
  • Requires limited-purpose recipient contracts, CCPA-level protection, business oversight rights, notice of inability to comply, and remediation rights.
leginfo.legislature.ca.gov
Referenced sections
  • Defines personal information, cross-context behavioral advertising, nonpersonalized advertising, sale, sharing, service provider, contractor, third party, and intentionally interacts.
cppa.ca.gov
Referenced sections
  • Official CPPA explanatory material on sale-and-sharing opt-outs, GPC, privacy-choice links, and the distinction among CCPA rights; the FAQ states that it is not legal advice or regulatory guidance.
Related guides

Explore more topics

California CCPA and CPRA Applicability Test
Decide whether the CCPA as amended by the CPRA applies, using California nexus, current business thresholds, related-entity rules, and data-specific exemptions.
California CCPA and CPRA Compliance Checklist
A California CCPA/CPRA implementation checklist covering scope, notices, rights, opt-outs, vendor contracts, retention, security, and 2026 regulations.
California CCPA/CPRA Deadlines and Compliance Calendar
Track California CCPA and CPRA request clocks, phased 2026 regulation deadlines, recurring metrics, and separate Delete Act dates.
California CCPA/CPRA Penalties, Fines, and Private Damages
Understand current California CCPA and CPRA fine caps, who enforces them, the limited private action for security breaches, and the evidence to preserve.
California CPRA FAQ
Practical California CPRA FAQ guidance with implementation decisions, evidence, edge cases, and official California source citations.
California CPRA Requirements Guide
California CCPA/CPRA requirements for covered businesses: notices, rights, opt-outs, data-use limits, contracts, security, and phased 2026 rules.
California CPRA Risk Assessments, Cybersecurity Audits, and ADMT Guide
Apply the separate California trigger tests, duties, phase-in dates, evidence, and consumer rights for risk assessments, cybersecurity audits, and ADMT.
California Data Broker Deletion Workflow Guide
California Delete Act and CPRA-adjacent guidance for data broker deletion workflows, with practical decisions, evidence, edge cases, and official citations.
California Data Broker Registry and DROP Guide
California Delete Act guide to data-broker scope, annual registration, DROP processing from August 1, 2026, deletion, opt-out fallback, metrics, and audits.
California Delete Act data broker registry and DROP guide
California Delete Act guidance for the data broker registry and Delete Request and Opt-Out Platform (DROP), with owners, evidence, and official sources.
CCPA vs CPRA: What Changed in California Privacy Law
Compare the original CCPA with the CPRA amendments, including scope thresholds, new rights, contracts, retention, enforcement, and implementation steps.
CPPA Regulations Tracker | CCPA and CPRA
Track the in-force 2023 and 2026 CCPA regulations, their legal status, affected processing, and phased risk, audit, and ADMT deadlines.
CPRA enforcement advisories: CPPA investigations, fines, and risk mitigation
US CPRA guidance for Enforcement Advisories, with practical decisions, evidence, edge cases, and external source citations.
CPRA Global Privacy Control (GPC): opt-out requirements and enforcement FAQ
US CPRA guidance for GPC, with practical decisions, evidence, edge cases, and external source citations.
CPRA vs Colorado Privacy Act: Practical Comparison
Compare California and Colorado privacy law on scope, consumer rights, opt-outs, sensitive data, contracts, assessments, and enforcement.
CPRA vs Virginia VCDPA: Practical Comparison
Compare California and Virginia privacy law on scope, rights, sale, advertising, sensitive data, contracts, assessments, and enforcement.
US CPRA Compliance Guide
Build a CCPA/CPRA compliance program for scope, notices, consumer rights, opt-outs, vendor contracts, retention, security, and phased 2026 duties.
US CPRA Consumer Rights Workflow Guide
Run California CCPA and CPRA requests to know, delete, correct, opt out, limit, and access or opt out of covered ADMT, with deadlines, verification, exceptions, and evidence.
US CPRA Contract Terms Guide
Required CCPA/CPRA contract terms for service providers, contractors, and third parties, with role tests, clause checks, and evidence.
US CPRA Contracts Contractors and Service Providers Guide
Classify CCPA recipients as service providers, contractors, or third parties and apply the correct purpose limits, contracts, and consumer instructions.
US CPRA Correction Rights Guide
Handle CCPA correction requests: verification, accuracy review, documentation, system and vendor updates, response timing, denials, and records.
US CPRA Cyber Audit Readiness Workflow Guide
US CPRA guidance for Cyber Audit Readiness Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA DSAR and Correction Workflow Guide
US CPRA guidance for DSAR and Correction Workflow, with practical decisions, evidence, edge cases, and external source citations.
US CPRA GPC Handling Guide
How businesses subject to the CCPA must detect, apply, test, and document Global Privacy Control opt-out signals.
US CPRA GPC Handling Workflow Guide
A California GPC workflow for signal detection, browser and profile scope, conflicts, downstream suppression, 15-business-day completion, and test evidence.
US CPRA Retention Guide
How to set, disclose, implement, and review personal-information retention periods under the California CCPA and CPRA.
US CPRA Risk Assessment Intake Workflow Guide
Screen the six CPPA risk-assessment triggers, record exceptions and evidence, hold covered launches for approval, and track review and submission dates.
US CPRA Risk Assessment Template Guide
US CPRA guidance for CPRA Risk Assessment Template, with practical decisions, evidence, edge cases, and external source citations.
US CPRA Risk Assessments and Cybersecurity Audits Guide
Apply the separate CPPA trigger tests for processing-level risk assessments and entity-level annual cybersecurity audits, with phase-in dates and evidence.
US CPRA Sensitive Personal Information Guide
Classify California sensitive personal information, distinguish category status from the right to limit, and apply notices, assessments, controls, and deadlines.
US CPRA Sensitive Personal Information Limits Guide
Decide when California's right to limit applies, map uses to section 7027(m), implement the 15-business-day restriction, and preserve evidence.
What counts as sharing under the California CPRA?
How to identify sharing for cross-context behavioral advertising and implement California notice, opt-out, preference-signal, contract, and recordkeeping duties.
What should teams do about ADMT under the US CPRA?
Decide whether California's ADMT rules cover an automated decision, then apply the 2027 notice, access, opt-out, appeal, and evidence requirements.
What should teams do about Contract Terms under the US CPRA?
Classify California data recipients and check the required service-provider, contractor, third-party, subcontractor, monitoring, and remediation terms.
What should teams do about Correction Rights under the US CPRA?
Handle a California request to correct with the right verification, 10-day confirmation, 45-day response, accuracy test, denial rules, and downstream evidence.
What should teams do about Cybersecurity Audits under the US CPRA?
US CPRA guidance for Cybersecurity Audits, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about retention under the California CPRA?
California CPRA guidance for retention, including data minimization, privacy policy disclosures, evidence records, and official source citations.
What should teams do about Sensitive Personal Information Limits under the US CPRA?
US CPRA guidance for Sensitive Personal Information Limits, with practical decisions, evidence, edge cases, and external source citations.
When is a CPRA risk assessment required?
When California businesses must conduct CPRA risk assessments, what each report must contain, and the review, retention, and filing deadlines.