Cross-Context Behavioral Advertising
Cross-context behavioral advertising is the practice of showing people targeted ads based on their behavior and activities as they move across different websites, apps, or platforms, rather than just within a single service. Under California privacy law, this practice is a defined term with specific rules attached to it. It typically relies on trackers such as cookies to build profiles of users across multiple sites.
Cross-context behavioral advertising (CCBA) is a term defined under the California Consumer Privacy Act as amended by the CPRA, referring to the targeting of advertising to a consumer based on personal information obtained from the consumer's activity across businesses, distinctly-branded websites, applications, or services, other than the one with which the consumer is intentionally interacting. Trackers such as cookies, and functionally similar technologies, are commonly used to build the cross-site user profiles that enable this form of advertising. Under the CCPA/CPRA framework, disclosing personal information for CCBA falls within the statutory concept of 'sharing,' triggering consumer opt-out rights; the scope, exact statutory language, and enforcement interpretation are set by California law and applicable regulations, and this definition addresses the US California context rather than EU or other regimes, which use different terminology and consent standards.
Why it matters
Cross-context behavioral advertising sits at the center of how California's privacy regime treats targeted advertising. Under the CCPA as amended by the CPRA, disclosing personal information for CCBA generally falls within the statutory concept of 'sharing,' which triggers consumer opt-out rights. This means that even where no money changes hands, a business that discloses personal information to enable cross-site ad targeting may be engaging in an activity that consumers can opt out of. As commentators have noted, this effectively brings much of the behavioral advertising ecosystem within the same regulatory reach as a 'sale,' which is why the two concepts are often discussed together.
For businesses operating in California, correctly identifying whether their advertising practices constitute CCBA is a practical compliance question with direct operational consequences. If a business relies on cookies or similar trackers to build profiles across distinctly-branded sites and apps, it typically must provide mechanisms for consumers to exercise opt-out rights, such as a 'Do Not Sell or Share My Personal Information' link and support for opt-out preference signals. Misclassifying these activities can leave gaps in a company's opt-out infrastructure.
It is important to note that CCBA is a defined term specific to California law, and its exact scope and enforcement interpretation are set by California statute and applicable regulations. Other US states use their own terminology (for example, 'targeted advertising'), and the EU and UK operate under different frameworks that rely on prior consent rather than opt-out. This entry addresses the California context, and readers should not assume that satisfying California's CCBA obligations meets requirements under other regimes.
Who it's relevant to
Inside CCBA
Common questions
Answers to the questions practitioners most commonly ask about CCBA.