The California Consumer Privacy Act (CCPA) outlines specific rules and requirements around targeted advertising that websites must follow, which is referred to as cross-context behavioral advertising in the text of the law.
Specifically, data privacy law gives California users the right to opt out of targeted advertising and any data processing used for those purposes.
Your website must abide by these requests and not discriminate against consumers who follow through on this right.
This is part of Termly’s ‘Ask the Privacy Experts’ series, where a member of our team briefly answers one of the top questions we hear from businesses about how data privacy and consent management impacts them.
What counts as targeted advertising under the CCPA?
The CCPA considers targeted advertising to occur when an entity tracks a user’s online behaviors and activities and uses that data to serve them with a personalized product or service recommendation.
Referred to as ‘cross context behavioral advertising’ by the law, this tracking must be obtained from activity that takes place outside of the business’s own branded websites.
Here’s how the text of the CCPA defines ‘cross context behavioral advertising’:
“… the targeting of advertising to a consumer based on the consumer’s personal information obtained from the consumer’s activity across businesses, distinctly branded internet websites, applications, or services, other than the business, distinctly branded internet website, application, or service with which the consumer intentionally interacts.”
This means using third party services like Google Analytics or Google Ads can qualify a form of targeted advertising in the following ways:
- The user’s data on your website is being shared with a third party (i.e., Google)
- Your website is tracking user online behavior when they’re not on your website.
What Are the CCPA Requirements Around Consent?
The CCPA explicitly defines consent as:
“… any freely given, specific, informed, and unambiguous indication of the consumer’s wishes by which the consumer, or the consumer’s legal guardian, a person who has power of attorney, or a person acting as a conservator for the consumer, including by a statement or by a clear affirmative action, signifies agreement to the processing of personal information relating to the consumer for a narrowly defined particular purpose.”
It goes on to clarify that certain activities do not count as consent under this law, including:
- Acceptance of a general or broad terms of use or other type of document containing descriptions of personal data along with other unrelated details,
- Hovering over something,
- Muting something,
- Pausing something.
- Closing a piece of content,
- Obtaining agreement by using dark patterns.
What Are the CCPA Requirements Around Targeted Advertising?
Under the CCPA, your website must allow California visitors to:
- Opt out of targeted advertising,
- Opt out of having their data shared or sold to a third party.
You must honor this request, even if it’s submitted through a browser-level preference technology like Global Privacy Control (GPC).
If your site uses Google Analytics or Ads, you must inform your California users as soon as they land on your page and provide them with a way to easily opt out of having these cookies placed on their browsers.
You must have the technology in place to adequately remove the cookies and honor these requests in a timely, legally compliant manner.
How To Manage Use Consent for Targeted Advertising In-Line With the CCPA
To align with the CCPA targeted advertising requirements, you must enable consumers to opt out of targeted advertising on your website, and ensure this request encompasses any data that might be shared with third-party advertisers.
Consider implementing the following consent management solutions on your website:
- Present users with an adequately configured cookie consent banner with access to a preference center.
- Provide consumers with a link to a cookie policy explaining what targeted advertising cookies are used and why.
- Provide consumers with an updated privacy policy informing them when and how you collect their data for targeted ads and how they can opt out.
- Include a ‘Do Not Sell or Share My Personal Information’ link in the footer of your website.
- Alternatively, include a ‘Do Not Sell/Do Not Share My Personal Information for Cross-Context Behavioral Advertising’ link in the footer of your website.
How Termly Makes CCPA Consent Management Easy
Termly makes it easy to comply with all the CCPA consent requirements with our Consent Management Platform.
Our Pro+ Users can configure their cookie consent banner to meet California opt out requirements, and our policy generators include provisions around targeted advertising.
Our solution has additional features that set it apart from other options, including script-auto blocking, multi-language supports, cross-regional consent settings, scheduled website scans, and additional automatic policy generators.
Sign up for Termly today and see just how easy it is to be CCPA-compliant.