The challenge
Your legal team developed a single opt-out mechanism for targeted advertising across U.S. state privacy laws. It worked for Virginia, Colorado, Utah, Connecticut, Montana, Iowa, Tennessee, and Indiana. But California's CPRA exposed a compliance gap.
The problem is clear. While eight state privacy statutes define "targeted advertising" consistently, California uses "cross-context Behavioural Advertising" (CCBA) instead. The CPRA's definition at Cal. Civ. Code 1798.140(k) omits two requirements found in other states: observing consumer activities "over time" and predicting consumer preferences or interests.
This isn't just a drafting issue. It's a compliance challenge that forces you to either build California-specific controls or hope the California Privacy Protection Agency (CPPA) will align the definition through rulemaking.
The environment and constraints
The eight-state consensus provides a clear standard. Virginia (Va. Code 59.1-571), Colorado (C.R.S. 6-1-1303(24)(a)), Utah (Utah Code Ann. 13-61-101(34)(a)), Connecticut (Substitute Bill No. 6, § 1(28)), Montana (S.B. 384 at § 2(25)(a)), Iowa (S.F. 262 at Section 1(28)), Tennessee (Amd. No. 1 to H.B. 1181 at § 47-18-3201(28)), and Indiana (Senate Enrolled Act No. 5, at IC 24-15 Chp. 2 § 1(30)(a)) all require:
- Display of ads to a consumer
- Based on personal information from the consumer's activity across non-affiliated businesses
- Involving observation over time or prediction of preferences/interests
California's definition requires only the first two. The CPRA defines CCBA as "the targeting of advertising to a consumer based on the consumer's [personal information] obtained from the consumer's activity across businesses, distinctly-branded websites, applications, or services, other than the business, distinctly-branded website, application, or service with which the consumer intentionally interacts."
Your constraints:
- California accounts for about 12% of the U.S. population and a significant share of digital advertising revenue
- Building parallel opt-out systems increases engineering costs and audit complexity
- The CPPA hasn't clarified if "over time" and "prediction" are implied
- California courts haven't decided if the narrower definition was intentional or an oversight
The approach taken
Organizations facing this gap typically choose one of three paths, each with different risks.
Path one: Build to the narrowest definition. Configure your Consent Management Platform (CMP) and opt-out controls to treat any cross-context data sharing for ad targeting as CCBA, regardless of temporal observation or predictive modeling. This covers activities that might not qualify as "targeted advertising" under the eight-state consensus but could fall under California's broader scope.
The advantage: No need for parallel systems. Your single opt-out covers California's potentially wider definition and the narrower eight-state standard.
The cost: You're offering opt-outs for advertising practices that may not legally require them in non-California states. Some advertising partners may push back because you're restricting data flows they consider compliant elsewhere.
Path two: Build California-specific controls. Maintain separate logic in your CMP that applies California's definition only to California residents. This requires geolocation, state-specific consent strings, and parallel documentation of opt-out-eligible practices in California versus other states.
The advantage: You don't over-restrict advertising in states with narrower laws.
The cost: You're maintaining two frameworks, two sets of vendor instructions, and two audit trails. When the CPPA issues guidance, you'll need to update California-specific logic separately.
Path three: Wait for CPPA alignment. Assume the CPPA or California courts will eventually interpret CCBA to include "over time" and "prediction" elements, aligning California with the consensus definition. Operate under the eight-state standard and document your interpretation.
The advantage: You avoid premature engineering work that may become obsolete if California aligns its definition through regulation or case law.
The cost: You're accepting enforcement risk during the gap period. If the CPPA decides California's definition was intentionally broader, you've been under-complying.
Results and metrics
Organizations that chose path one report simpler vendor management but more friction with advertising partners questioning why California-resident data is restricted more than the statute appears to require.
Organizations that chose path two have functional compliance but higher operational overhead. Every new ad vendor requires California-specific onboarding, and consent renewal cycles must account for state-specific definitions.
Organizations that chose path three are closely monitoring CPPA rulemaking. The agency hasn't yet issued regulations clarifying whether the missing elements are implied, leaving the risk unquantified.
What they would do differently
The clearest lesson: Don't assume statutory silence means alignment. California's choice of different terminology ("cross-context Behavioural Advertising" instead of "targeted advertising") and omission of specific elements present in eight other states was a signal to build flexibility into your compliance architecture from the start.
Teams that hard-coded a single definition into their CMP configuration faced expensive re-engineering when they realized California's scope might be broader. Teams that built state-specific logic from the beginning absorbed the California difference without disruption.
The second lesson: Document your interpretation contemporaneously. If you're choosing path three and operating under the assumption that California's definition will converge with the consensus, write down why you believe "over time" and "prediction" are implied. If the CPPA disagrees, you'll need to demonstrate that your interpretation was reasonable at the time, not opportunistic.
Takeaways for your team
Don't wait for perfect clarity. The CPPA may align California's definition with the eight-state consensus, or it may decide the narrower language was intentional. You can't build a compliance program around what the law might say. Choose a defensible interpretation now.
Audit your CMP's state-awareness. If your platform can't apply different opt-out logic based on consumer location, you're forced into path one by default. Confirm whether your system can maintain separate consent strings for California residents before committing to a compliance strategy.
Map your actual advertising practices to both definitions. Don't rely on abstract legal analysis. List the specific data flows, vendor integrations, and targeting methods you use. Then check each one against both California's definition and the eight-state standard. The gap may be smaller than you think, or it may be larger.
Prepare for CPPA rulemaking. The agency's interpretation will settle this question, but you don't know when that guidance will arrive. Your compliance posture should work under either outcome: California's definition stays broader, or it converges with the consensus. That means building state-specific capability even if you're not using it yet.
The definitional split won't disappear until California acts. Your job is to choose the compliance path that matches your risk tolerance and engineering capacity, then document why that choice was reasonable given the statutory ambiguity. That documentation matters if the CPPA's eventual guidance goes the other way.





