The California Consumer Privacy Act (CCPA), enhanced by the California Privacy Rights Act (CPRA), is a comprehensive state-level privacy law granting California residents control over their personal data. It requires businesses to disclose data collection practices, allow consumers to opt out of data sales and sharing, and delete personal data upon request. Often described as the U.S. equivalent of GDPR, CCPA/CPRA has become the de facto privacy standard shaping data strategy across the digital advertising industry.
How It Works in Practice
CCPA/CPRA applies to for-profit businesses that collect personal information and meet certain thresholds—such as annual gross revenue exceeding $25 million, processing data of 100,000 or more consumers, or deriving at least 50% of revenue from selling or sharing personal data. For adtech companies, this captures most demand-side platforms (DSPs), supply-side platforms (SSPs), data management platforms (DMPs), and major publishers.
When a California resident interacts with a website or app covered by the law, the business must provide a visible "Do Not Sell or Share My Personal Information" link. Clicking this link triggers an opt-out request that the business must honor and propagate to all downstream partners. Businesses are also required to recognize Global Privacy Control (GPC) signals transmitted via browser settings or device configurations.
Consumers may exercise several core rights under the law:
- Right to Know: Request disclosure of categories and specific pieces of personal information collected, sold, or shared.
- Right to Delete: Request deletion of personal information held by the business and its service providers.
- Right to Correct: Request correction of inaccurate personal information, added under CPRA.
- Right to Opt-Out: Stop the sale or sharing of personal information, including use in cross-context behavioral advertising.
- Right to Limit: Restrict the use of sensitive personal information to purposes disclosed at collection.
CPRA introduced additional obligations around sensitive personal information (SPI), which includes precise geolocation, health data, racial or ethnic origin, and biometric data. Businesses must limit SPI use to specified purposes and provide a separate opt-out mechanism.
Why It Matters in the Adtech Ecosystem
For digital advertising professionals, CCPA/CPRA fundamentally reshapes how data flows through the supply chain. The law defines "sale" broadly to include any exchange of personal information for monetary or other valuable consideration. "Sharing" specifically covers cross-context behavioral advertising, meaning most third-party cookie-based audience targeting falls under opt-out requirements.
This creates operational ripple effects across the ecosystem. Advertisers must ensure audience segments built from California users comply with opt-out propagation rules. Publishers must implement consent management platforms (CMPs) capable of capturing and signaling opt-outs across the programmatic supply chain, typically using the IAB Tech Lab's CCPA string (us_privacy). Data partners and service providers must honor deletion requests within 45 days and maintain documentation of compliance.
Key Benefits and Challenges
CCPA/CPRA offers several benefits for the industry. It establishes a clear framework for consumer trust, standardizing privacy expectations and giving brands a concrete compliance roadmap. The law has also accelerated innovation in cookieless advertising, contextual targeting, and first-party data strategies, pushing the industry toward more sustainable data practices.
However, compliance remains operationally complex. Data flows through numerous intermediaries in a typical adtech transaction, and opt-outs must be honored end-to-end—a significant technical challenge. Determining whether a given data exchange constitutes a sale or share often requires legal interpretation. The California Privacy Protection Agency (CPPA), established by CPRA as the first U.S. dedicated privacy regulator, continues to issue regulations and enforcement guidance, meaning the compliance landscape remains dynamic.
Real-World Examples
Consider a retail advertiser running display campaigns through a DSP. If California users opt out via the advertiser's website, those users must be excluded from audience activation. The DSP must also suppress bidding on those users when receiving bid requests containing the us_privacy string. Failure to propagate opt-outs properly can result in enforcement actions by the California Attorney General or the CPPA, with civil penalties up to $7,500 per intentional violation.
Similarly, a publisher monetizing inventory through header bidding must pass the privacy string in every bid request so buyers can suppress personalized bidding for opted-out users. Publishers that fail to pass valid signals risk non-compliance and potential liability for both themselves and their demand partners.
Relationship to Related Concepts
CCPA/CPRA is frequently compared to GDPR, though it differs in key respects. GDPR operates on an opt-in consent model, while CCPA uses an opt-out framework. Both laws, however, significantly impact how advertisers approach cookieless advertising and first-party data collection. As other states enact similar legislation—Virginia, Colorado, Connecticut, and Utah among them—CCPA/CPRA serves as the template for an emerging patchwork of U.S. privacy regulation that adtech vendors and advertisers must navigate collectively.