Skip to main content
Category: Tracking Technologies

Cross-Context Behavioral Advertising

Also known as: CCBA, Cross-Contextual Behavioral Advertising, Cross-Context Behavioral Tracking
Simply put

Cross-context behavioral advertising is the practice of showing people targeted ads based on their behavior and activities as they move across different websites, apps, or platforms, rather than just within a single service. Under California privacy law, this practice is a defined term with specific rules attached to it. It typically relies on trackers such as cookies to build profiles of users across multiple sites.

Formal definition

Cross-context behavioral advertising (CCBA) is a term defined under the California Consumer Privacy Act as amended by the CPRA, referring to the targeting of advertising to a consumer based on personal information obtained from the consumer's activity across businesses, distinctly-branded websites, applications, or services, other than the one with which the consumer is intentionally interacting. Trackers such as cookies, and functionally similar technologies, are commonly used to build the cross-site user profiles that enable this form of advertising. Under the CCPA/CPRA framework, disclosing personal information for CCBA falls within the statutory concept of 'sharing,' triggering consumer opt-out rights; the scope, exact statutory language, and enforcement interpretation are set by California law and applicable regulations, and this definition addresses the US California context rather than EU or other regimes, which use different terminology and consent standards.

Why it matters

Cross-context behavioral advertising sits at the center of how California's privacy regime treats targeted advertising. Under the CCPA as amended by the CPRA, disclosing personal information for CCBA generally falls within the statutory concept of 'sharing,' which triggers consumer opt-out rights. This means that even where no money changes hands, a business that discloses personal information to enable cross-site ad targeting may be engaging in an activity that consumers can opt out of. As commentators have noted, this effectively brings much of the behavioral advertising ecosystem within the same regulatory reach as a 'sale,' which is why the two concepts are often discussed together.

For businesses operating in California, correctly identifying whether their advertising practices constitute CCBA is a practical compliance question with direct operational consequences. If a business relies on cookies or similar trackers to build profiles across distinctly-branded sites and apps, it typically must provide mechanisms for consumers to exercise opt-out rights, such as a 'Do Not Sell or Share My Personal Information' link and support for opt-out preference signals. Misclassifying these activities can leave gaps in a company's opt-out infrastructure.

It is important to note that CCBA is a defined term specific to California law, and its exact scope and enforcement interpretation are set by California statute and applicable regulations. Other US states use their own terminology (for example, 'targeted advertising'), and the EU and UK operate under different frameworks that rely on prior consent rather than opt-out. This entry addresses the California context, and readers should not assume that satisfying California's CCBA obligations meets requirements under other regimes.

Who it's relevant to

Privacy officers and compliance teams
Those responsible for California compliance need to assess whether their organization's advertising activities constitute CCBA, because doing so generally brings those activities within the CPRA's 'sharing' concept and its associated opt-out obligations. This assessment shapes what opt-out mechanisms and disclosures a business must implement.
Legal counsel
Attorneys advising on CCPA/CPRA compliance must interpret the statutory definition of CCBA and how it interacts with 'sharing' and opt-out rights. Because the exact scope and enforcement interpretation are set by California law and evolving regulation, counsel should treat classification as a fact-dependent question rather than a settled one.
Marketing and advertising teams
Teams that run cross-site or cross-app targeted advertising campaigns are directly affected, since the trackers and profiles used to target ads across distinctly-branded services are what bring an activity within CCBA. They need to coordinate with compliance to ensure opt-out signals are respected in their ad targeting workflows.
Web developers and engineers
Developers implementing cookies, tags, and similar tracking technologies play a central role in enabling, or suppressing, CCBA. They are typically responsible for wiring up opt-out preference signal handling and ensuring that a consumer's opt-out is technically enforced across the relevant advertising integrations.

Inside CCBA

Definition and scope
Cross-context behavioral advertising generally refers to targeting advertisements to a consumer based on personal information collected from that consumer's activity across distinctly branded websites, applications, or services that are not owned by the business with which the consumer intentionally interacts. The term originates primarily in US state privacy law, notably the California Consumer Privacy Act as amended by the CPRA, and is distinct from advertising based solely on a consumer's activity within a single first-party context.
Cross-context data collection
The practice relies on tracking technologies that follow users across multiple, separately operated properties. These technologies commonly include cookies, but also pixels, SDKs embedded in mobile applications, local storage, and device or browser fingerprinting. Under EU law, the placing of or access to such identifiers on a user's device is governed by the ePrivacy Directive and its national implementations, while any subsequent processing of personal data is governed by the GDPR.
Relationship to first-party advertising
The concept is defined by contrast with first-party advertising, which is based on a consumer's interaction within a single business's own context. Advertising informed by activity across unrelated, separately branded services falls within cross-context behavioral advertising, whereas advertising limited to a business's own property typically does not.
Opt-out rights under US state law
Under the CCPA/CPRA in California and comparable statutes in other US states, consumers generally have a right to opt out of cross-context behavioral advertising. Many of these frameworks require businesses to honor opt-out preference signals such as the Global Privacy Control. The precise obligations, terminology, and covered entities vary between individual states, so scope should be checked against each applicable law.
Consent posture under EU and UK law
EU and UK frameworks do not typically use the phrase cross-context behavioral advertising, but the underlying activity, often described as online behavioral or targeted advertising, generally requires prior, freely given, specific, informed, and unambiguous consent obtained through a clear affirmative action before non-essential trackers are set. This differs from the opt-out model common in US state laws.
Consent and preference infrastructure
Managing this activity typically involves consent management platforms (CMPs), industry frameworks such as the IAB Transparency and Consent Framework (TCF), and mechanisms for receiving and honoring opt-out signals like the Global Privacy Control. Record-keeping and consent or opt-out logging support demonstrating accountability, though these tools support compliance rather than guarantee it.

Common questions

Answers to the questions practitioners most commonly ask about CCBA.

Is cross-context behavioral advertising the same as any online advertising that uses cookies?
No. Cross-context behavioral advertising refers specifically to targeting a consumer with ads based on personal information obtained from their activity across businesses, distinctly-branded websites, applications, or services other than the one they are currently interacting with. Advertising that relies only on a consumer's activity within a single business's own site or app (often called first-party or contextual advertising in this context) generally falls outside this specific term, even if it uses cookies. The distinguishing feature is the combination of data across different contexts, not the mere use of cookies or the fact that advertising occurs.
Does opting out of cross-context behavioral advertising stop all advertising or all cookies?
No. An opt-out of cross-context behavioral advertising is generally directed at the specific practice of cross-context targeting, not at advertising in general. A consumer who opts out may still see ads, including contextual ads that are not based on cross-context profiling. The opt-out also does not necessarily disable all cookies; strictly necessary or essential cookies and technologies used for purposes unrelated to cross-context targeting may continue to operate. The scope of what an opt-out covers depends on the applicable law and how the term is defined in that regime.
How should a business let consumers exercise the right to opt out of cross-context behavioral advertising?
Under several US state privacy frameworks, such as those in California, businesses are typically expected to provide a clear method for consumers to opt out, which may include a designated link and recognition of an opt-out preference signal such as Global Privacy Control. The specific mechanisms, required link wording, and whether preference signals must be honored vary by state and evolve with regulatory guidance. Because implementation details differ across jurisdictions and are subject to change, confirm the current requirements applicable to your operations rather than assuming a single method suffices everywhere.
How does this concept relate to consent obtained under EU cookie rules?
The term cross-context behavioral advertising is primarily associated with certain US state privacy laws, which generally operate on an opt-out model. This differs from the EU approach, where the ePrivacy Directive governs the placing of and access to information on a user's device and typically requires prior consent for advertising cookies and similar technologies, while the GDPR governs any resulting processing of personal data. Consent or opt-out status obtained under one regime does not automatically satisfy the other. Businesses operating across regions generally need to address each framework separately.
What technologies beyond cookies should be considered when addressing cross-context behavioral advertising?
Cross-context targeting can rely on technologies other than cookies, including tracking pixels, local storage, mobile advertising identifiers, SDKs embedded in apps, and fingerprinting techniques. Where these technologies are used to build or apply profiles across different businesses or contexts, they generally fall within the same considerations as cookie-based methods. An opt-out or control mechanism that addresses only cookies may leave other tracking technologies operating, so scoping should account for the full range of methods in use.
Can a consent management platform ensure compliance with cross-context behavioral advertising obligations?
A consent management platform or preference management tool can support compliance by presenting choices, capturing and logging consumer decisions, recognizing opt-out preference signals, and helping propagate those signals to relevant vendors. However, such tools support compliance rather than guarantee it. Correct configuration, accurate mapping of which data flows constitute cross-context behavioral advertising, vendor contract arrangements, and legal judgment about applicable requirements remain necessary. Whether a given configuration meets obligations in a particular jurisdiction is a fact-specific determination that a tool alone does not resolve.

Common misconceptions

Cross-context behavioral advertising is just a new name for all online advertising, so any consent or opt-out mechanism covers it automatically.
The term is specific to advertising based on data collected across distinctly branded, separately operated services, and is generally distinguished from first-party advertising within a single business's own context. Whether a particular arrangement qualifies depends on the facts, and the applicable obligations differ by jurisdiction.
Because US state laws use an opt-out model, an opt-out approach is sufficient for cross-context behavioral advertising everywhere.
Opt-out is the model common to US state privacy laws such as the CCPA/CPRA, but EU and UK frameworks generally require prior opt-in consent meeting the GDPR standard before non-essential trackers are set. A single opt-out mechanism does not satisfy both regimes, and geographic scope must be assessed.
Only literal cookies are relevant, so avoiding cookies avoids these obligations.
The same rules generally apply to pixels, SDKs, local storage, and fingerprinting used to build cross-context profiles. Under EU law the ePrivacy rules on device access and the GDPR rules on personal data processing can apply regardless of the specific technology used.

Best practices

Map the tracking technologies used across your properties, including cookies, pixels, SDKs, local storage, and any fingerprinting, and identify which flows involve data collected across distinctly branded services.
Distinguish first-party advertising within your own context from cross-context activity, and document that analysis, since the classification drives which obligations apply.
Apply jurisdiction-specific consent postures: seek prior opt-in consent meeting the GDPR standard for EU and UK users, and provide compliant opt-out mechanisms for US state laws such as the CCPA/CPRA, checking each applicable statute.
Configure your CMP and, where used, the IAB TCF to reflect the correct legal basis per region, and ensure opt-out preference signals such as Global Privacy Control are received and honored where required.
Maintain records of consent and opt-out choices to support accountability, while recognizing that tooling supports but does not substitute for legal judgment.
Obtain legal review for edge cases and contested interpretations, since terminology, covered entities, and enforcement positions vary between the EU, UK, and individual US states and continue to evolve.