Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
U.S. State Targeted Advertising ExemptionsLaws and Regulations
5 min readFor Privacy Officers

U.S. State Targeted Advertising Exemptions

Scope

This guide explains how nine U.S. state privacy laws define targeted advertising and what activities they exempt. You'll find statutory citations, a comparative reference table, and guidance for multi-state compliance programs.

If your team operates advertising technology, manages consumer opt-out requests, or configures consent mechanisms across state lines, you need to know where California's approach differs from the Virginia-derived model most other states follow.

Key Concepts and Definitions

Targeted Advertising (Virginia model): Displaying ads to a consumer based on personal data from their activities across non-affiliated websites, apps, or online services to predict preferences or interests.

Cross-Context Behavioural Advertising (California): The California Privacy Rights Act (CPRA) uses this term and omits two elements present in other state definitions:

  • No reference to "tracking a person over time"
  • No reference to "making predictions about a person's interests"

This narrower definition doesn't necessarily broaden what counts as regulated advertising. The practical consequence lies in the exemptions.

Exemptions: Activities that resemble targeted advertising but are excluded from the statutory definition. Most states carve out four categories. California carves out none.

Requirements Breakdown

States Following the Virginia Model

Eight states provide identical or near-identical exemptions:

Virginia (Va. Code § 59.1-571)
Colorado (C.R.S. § 6-1-1303(24)(b))
Utah (Utah Code Ann. § 13-61-101(34)(b))
Connecticut (Conn. Substitute Bill No. 6, § 1(28))
Montana (S.B. 384, § 2(25)(b))
Iowa (S.F. 262, § 1(28))
Tennessee (H.B. 1181, § 47-18-3201(28)(B))
Indiana (Senate Enrolled Act No. 5, IC 24-15 Ch. 2 § 1(30)(b))

These states exempt four types of activities from their targeted advertising definitions:

  1. Contextual advertising: Ads based on the consumer's current visit to a website or app, without tracking across contexts.
  2. First-party advertising: Ads based on predicted preferences derived from the consumer's activities with the same business (not across non-affiliated properties).
  3. Search query advertising: Ads displayed in response to a consumer's search request.
  4. Performance measurement: Processing personal data solely to measure or report ad performance, reach, or frequency.

California's Approach

California Privacy Rights Act (Cal. Civ. Code § 1798.140(k), § 1798.140(ah)(1))

California provides zero express exemptions for cross-context Behavioural Advertising. The statute does not exclude contextual ads, search-based ads, first-party predictions, or performance measurement from its definition of "sharing" for cross-context Behavioural Advertising purposes.

This doesn't automatically mean those activities trigger opt-out obligations. If an activity doesn't satisfy the definition of cross-context Behavioural Advertising, it doesn't need an exemption. But you can't rely on statutory safe harbor language as in Virginia or Colorado.

Implementation Guidance

Build to California's Standard

If you operate in multiple states, configure your systems to meet California's requirements. You'll satisfy every other state by default.

For contextual advertising: Document that your ad selection uses only the current page context, URL, content category, search query on that page, without cross-referencing browsing history or identifiers tied to other sites. California doesn't exempt this, but it shouldn't meet the cross-context definition if implemented correctly.

For first-party ads: Limit predictions to data collected directly from the consumer's interactions with your properties. Don't enrich with third-party segments or data from partners. Again, no California exemption exists, but proper first-party use shouldn't constitute "sharing" with third parties under Cal. Civ. Code § 1798.140(ai).

For search ads: If you display ads based on a user's search query, ensure you're not layering behavioral profiles from other contexts onto that query. The query itself is contextual. Adding cross-site tracking data moves you into regulated territory in California.

For measurement: California doesn't exempt sharing data for ad performance reporting. If you send hashed email identifiers or device IDs to a measurement vendor, that's "sharing" under the CPRA unless the vendor qualifies as a service provider or contractor under Cal. Civ. Code § 1798.140(ai). Review your vendor agreements.

Audit Your Exemption Assumptions

Many teams assume that because an activity is exempt in Virginia, it's safe everywhere. That's not true.

Run this test: For each advertising workflow, ask whether it would survive California's definition without relying on an exemption. If the answer is no, you need either a service provider agreement or an opt-out mechanism that works in California.

Vendor Contract Language

Your data processing agreements should specify:

  • Whether the vendor acts as a service provider/contractor (California) or processor (other states)
  • What data is shared and for what purpose
  • Whether the vendor may use data for its own commercial purposes (which would disqualify service provider status in California)

Don't assume a vendor that qualifies as a processor under Virginia law automatically qualifies as a service provider under the CPRA. The definitions differ.

Common Pitfalls

Pitfall 1: Treating "contextual" as a universal safe harbor
You configure your ad server to show contextual ads and assume you're exempt everywhere. In California, you're not exempt, you're simply arguing the activity doesn't meet the definition. That's a harder position to defend if your implementation is sloppy.

Pitfall 2: Relying on search query exemptions for retargeting
A consumer searches for "hiking boots" on your site. You show them hiking boot ads on partner sites for the next 30 days. That's not a search query exemption, that's cross-context tracking. No state exempts it.

Pitfall 3: Misclassifying measurement vendors
You send user-level data to an analytics platform that aggregates it with data from other clients to build industry benchmarks. That vendor isn't a service provider. You're sharing data for a commercial purpose. California requires an opt-out.

Pitfall 4: Assuming California will follow other states
California's legislature deliberately omitted the Virginia exemptions. Don't expect regulatory guidance or enforcement to create them through interpretation. The statute says what it says.

Quick Reference Table

Exemption Type VA, CO, UT, CT, MT, IA, TN, IN California (CPRA)
Contextual ads (current visit only) Exempt No exemption
First-party predictions Exempt No exemption
Search query-based ads Exempt No exemption
Ad performance measurement Exempt No exemption
Service provider/contractor processing Not "targeted advertising" Not "sharing" if contract qualifies

Statutory References:

  • Virginia: Va. Code § 59.1-571
  • Colorado: C.R.S. § 6-1-1303(24)(b)
  • Utah: Utah Code Ann. § 13-61-101(34)(b)
  • Connecticut: Conn. Sub. Bill No. 6, § 1(28)
  • Montana: S.B. 384, § 2(25)(b)
  • Iowa: S.F. 262, § 1(28)
  • Tennessee: H.B. 1181, § 47-18-3201(28)(B)
  • Indiana: SEA No. 5, IC 24-15 Ch. 2 § 1(30)(b)
  • California: Cal. Civ. Code § 1798.140(k), (ah)(1), (ai)

Key Takeaway: California's absence of exemptions doesn't necessarily expand what counts as regulated advertising, but it removes the statutory clarity other states provide. Your compliance strategy should assume California's stricter framework and work backward to confirm you're also meeting the exemption criteria in other states, not the reverse.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like