Skip to main content
Category: Tracking Technologies

Cross-Context Behavioural Advertising

Also known as: CCBA, Cross-Context Behavioral Advertising
Simply put

Cross-context behavioural advertising is the practice of targeting ads to a person based on their behaviour and activity gathered across multiple different websites, apps, or services, rather than within the single service they are currently using. In California, this kind of activity is central to how the state's privacy laws define 'sharing' of personal information, which gives consumers specific rights to opt out.

Formal definition

Cross-context behavioural advertising refers to ad targeting that draws on personal information collected about a consumer across businesses, distinctly branded websites, applications, or services, other than the one with which the consumer is intentionally interacting. Under the California Consumer Privacy Act as amended by the CPRA, the concept is tied closely to the defined term 'sharing,' and disclosing personal information for cross-context behavioural advertising can constitute a 'sharing' (and, in some analyses, a 'sale') that triggers opt-out rights for consumers. The scope, precise boundaries, and treatment of this concept are defined by California statute; obligations and terminology differ under other US state privacy laws and under EU/UK frameworks, which generally rely on prior opt-in consent for advertising cookies and similar tracking technologies rather than an opt-out model. This definition addresses the concept as framed in the cited California materials and does not resolve contested questions about when specific data flows qualify as 'sale' versus 'sharing.'

Why it matters

Cross-context behavioural advertising sits at the centre of how California's privacy framework defines the 'sharing' of personal information. Under the CCPA as amended by the CPRA, disclosing personal information for cross-context behavioural advertising can constitute 'sharing', a defined term distinct from, though sometimes overlapping with, 'sale.' This distinction matters because it triggers specific consumer rights, including the right to opt out. For businesses that rely on ad targeting drawing on data collected across multiple websites, apps, or services, correctly identifying when their data flows fall within this concept is a threshold compliance question rather than an academic one.

The treatment of cross-context behavioural advertising illustrates a broader divergence between US and EU/UK approaches. California's model generally relies on giving consumers the ability to opt out of sharing for this purpose, whereas EU and UK frameworks generally require prior opt-in consent before advertising cookies and similar tracking technologies are placed or accessed. Organisations operating across these jurisdictions cannot assume that a single mechanism satisfies all applicable regimes, and terminology such as 'sharing,' 'sale,' and 'targeted advertising' varies between individual US state laws as well.

A further practical complication is that the boundary between what qualifies as a 'sale' and what qualifies as 'sharing' remains contested. Commentary in the privacy field has argued that the label 'sale' is broad and, for practical purposes, encompasses much cross-context behavioural advertising activity. Because these characterisations affect which disclosures, opt-out links, and honouring of signals a business must implement, the classification carries direct operational consequences even where the underlying data flows are otherwise similar.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for compliance need to determine whether their organisation's ad-targeting activities constitute 'sharing' for cross-context behavioural advertising under California law, and to implement the corresponding opt-out rights. They should also be alert to how the analysis differs from the opt-in consent model that generally applies to advertising trackers under EU and UK frameworks.
Legal counsel
Counsel advising on US state privacy compliance must grapple with the unresolved boundary between 'sale' and 'sharing,' since the classification affects disclosure obligations and consumer rights. They should also account for differing terminology and requirements across individual US state laws and other regimes rather than treating California's approach as universal.
Marketing and advertising compliance teams
Teams running targeted advertising campaigns that rely on data collected across multiple sites, apps, or services need to understand when those activities fall within cross-context behavioural advertising and may trigger opt-out obligations. Compliance judgment, not tooling alone, should drive decisions about which data flows are permissible in each jurisdiction.
Web developers and engineers
Developers implement the technical mechanisms that support these rights, such as opt-out links and the honouring of opt-out preference signals, and configure tracking technologies including cookies, pixels, SDKs, and local storage. Their work supports compliance but does not by itself determine whether a given data flow qualifies as sharing under the law.

Inside CCBA

Cross-Context Behavioural Advertising (definition)
A term used primarily in US state privacy laws (such as the CPRA in California and comparable statutes in other states) to describe the targeting of advertising to a consumer based on personal data obtained from that consumer's activity across businesses, distinctly-branded websites, applications, or services, other than the business or service with which the consumer intentionally interacts. The precise statutory wording and scope vary by state.
Cross-context or cross-site element
The defining feature is that data is collected across different, unaffiliated contexts rather than within a single first-party relationship. Advertising based solely on a consumer's activity within one business's own service is generally treated differently and may fall outside this category.
Underlying tracking technologies
The behaviour that feeds this advertising is typically enabled by cookies, tracking pixels, SDKs, device or browser fingerprinting, and similar technologies. In the EU and UK, the placing of and access to such information on a user's device is governed by the ePrivacy Directive and its national implementations, while any resulting processing of personal data is governed by the GDPR (or UK GDPR).
Relationship to opt-out rights
Under several US state frameworks, consumers have a right to opt out of cross-context behavioural advertising, and businesses may be required to honour opt-out preference signals such as Global Privacy Control (GPC) where the applicable law recognises them. The exact obligations differ by state.
EU/UK counterpart concepts
There is no exact one-to-one equivalent term in EU or UK law. Comparable activity is addressed through consent requirements under the ePrivacy regime for the tracking technologies involved and through the GDPR for the associated personal data processing, which generally rely on prior opt-in consent rather than opt-out.

Common questions

Answers to the questions practitioners most commonly ask about CCBA.

Is cross-context behavioural advertising the same thing as targeted advertising based on data from a single website?
No. Cross-context behavioural advertising, as defined under certain US state privacy laws such as the CPRA in California, specifically concerns targeting a consumer with ads based on personal information obtained from their activity across businesses, distinctly-branded websites, applications, or services other than the one with which the consumer is currently interacting. Advertising based solely on a consumer's activity within a single first-party context generally falls outside this definition. The distinction matters because the cross-context element is what typically triggers specific opt-out rights and disclosure obligations under those state frameworks. Note that terminology and scope differ between jurisdictions, so the precise boundaries depend on the applicable law.
If we obtain consent for cookies under EU rules, does that automatically cover our cross-context behavioural advertising obligations?
Not necessarily. Cross-context behavioural advertising is a concept primarily associated with US state privacy laws, which generally rely on an opt-out model rather than the prior opt-in consent standard used in most EU jurisdictions. Consent collected to satisfy the ePrivacy Directive's rules on placing or accessing information on a device, and the GDPR's rules on subsequent processing, does not automatically discharge separate obligations under a framework like the CPRA, and vice versa. The applicable requirements depend on where your users are located and which laws apply. Organisations operating across regions typically need to map each regime's requirements separately rather than assuming one mechanism satisfies all of them, and this is an area where legal advice specific to the facts is often warranted.
How do we identify which of our advertising activities count as cross-context behavioural advertising?
A practical starting point is to inventory the tracking technologies and data flows on your properties, including cookies, pixels, SDKs, and similar tools, and to determine whether personal information collected in one context is used to target advertising in a different context or across distinctly-branded services. Where such cross-context use occurs, the activity may fall within the definitions used by applicable US state laws. Because the classification turns on facts such as who controls the data, how it is shared, and where users are located, this assessment generally benefits from input from legal, privacy, and technical teams. This entry does not resolve edge cases, and specific determinations depend on the applicable law and guidance.
What opt-out mechanisms should we consider providing for cross-context behavioural advertising?
Under several US state privacy laws, businesses engaged in cross-context behavioural advertising are typically expected to offer consumers a way to opt out. In practice this may include a clearly labelled opt-out link, preference controls within a consent management platform, and support for recognised opt-out preference signals such as Global Privacy Control where required. The exact requirements, including how such signals must be honoured, vary by jurisdiction and evolve as regulatory guidance develops. Implementing these mechanisms supports compliance but does not by itself guarantee it, and the specific configuration should be validated against the requirements of each applicable law.
How should Global Privacy Control signals be handled in relation to cross-context behavioural advertising?
Global Privacy Control is a browser-level signal that some US state privacy frameworks may treat as a valid opt-out of certain activities, which can include cross-context behavioural advertising depending on the jurisdiction. Where recognition of such signals is required, businesses generally need to detect the signal and apply the corresponding opt-out to the relevant data uses. Because the technical detection, the scope of what the signal covers, and the enforceability differ between jurisdictions and continue to develop, organisations should confirm current obligations for each applicable law rather than assuming uniform treatment. Honouring the signal is a supporting measure and does not on its own establish overall compliance.
What records should we keep to demonstrate how we handle cross-context behavioural advertising opt-outs?
Maintaining records that show opt-out requests and opt-out preference signals were received and acted upon can help demonstrate that applicable obligations are being met. This may include logs of consent or opt-out states, the technologies and vendors involved, and the data flows classified as cross-context behavioural advertising. Consent management platforms and related tooling can assist with this record-keeping, but they support rather than replace the underlying legal and organisational judgment. The specific record-keeping expectations depend on the applicable jurisdiction, and this entry does not set out mandatory retention periods or formats, which should be confirmed against the relevant law and guidance.

Common misconceptions

Cross-context behavioural advertising is a GDPR concept.
The term originates in US state privacy laws such as the CPRA. It is not a defined term in the GDPR or the ePrivacy Directive. In the EU and UK, similar advertising practices are addressed through separate consent and processing rules rather than under this specific label.
Providing an opt-out satisfies obligations everywhere.
Several US state laws generally rely on an opt-out model for this type of advertising. In most EU jurisdictions and the UK, by contrast, the underlying tracking technologies typically require prior consent that is freely given, specific, informed, and unambiguous, so an opt-out mechanism alone would generally not be sufficient.
It only involves cookies.
Although cookies are commonly involved, the same practices can rely on pixels, SDKs, local storage, and fingerprinting. In the EU and UK these non-cookie technologies fall within the same ePrivacy rules on accessing information on a device, and any personal data processing is subject to the GDPR.

Best practices

Identify the applicable legal regime for each audience: apply opt-in consent under the ePrivacy Directive and GDPR (or UK GDPR) for EU and UK users, and the relevant opt-out obligations under the specific US state law for consumers in those states.
Map all tracking technologies used for cross-context advertising, including cookies, pixels, SDKs, local storage, and fingerprinting, since they are governed by the same rules even though they are not literally cookies.
Where applicable US state law recognises opt-out preference signals such as Global Privacy Control, configure your systems to detect and honour them, and confirm the requirement against each relevant state's law.
Use a consent management platform to obtain, manage, and record consent or opt-out choices, while recognising that a CMP supports compliance but does not replace legal judgment.
Maintain records of consent and opt-out decisions to support accountability and record-keeping obligations, tailoring retention to the applicable framework.
Seek qualified legal advice for each jurisdiction, because statutory definitions, enforcement positions, and regulatory guidance for cross-context behavioural advertising vary and continue to evolve.