Also known as: CCBA, Cross-Context Behavioral Advertising, Cross-Site Behavioral Advertising, Behavioral Advertising
Under the California Consumer Privacy Act (CCPA), cross-context behavioral advertising is specifically defined around advertising targeted using personal information obtained from a consumer's activity across businesses, distinctly branded websites, applications, or services other than the business or service with which the consumer intentionally interacts.
The concept is important because the CCPA gives consumers the right to opt out of the sharing of their personal information for cross-context behavioral advertising. Businesses subject to the CCPA must therefore ensure that applicable opt-out choices and signals are actually respected by their advertising and tracking technologies.
Cross-context behavioral advertising occurs when information about a consumer's activity in one context is used to target advertising to that consumer in another context.
For example:
A consumer visits Website A.
A tracking technology records information about the consumer's activity.
The information is made available to an advertising or technology company.
The consumer later visits Website B.
Advertising is targeted based on information associated with the consumer's activity across those different contexts.
The important element is the cross-context use of information for advertising targeting.
It is therefore broader than simply showing a personalised advertisement based on activity occurring entirely within one website.
Imagine a consumer visits an online furniture retailer and looks at several sofas.
A third-party advertising technology records information about that activity.
Later, the consumer visits a separate website and sees advertisements for the same furniture retailer or related products.
If the advertising is targeted using the consumer's personal information obtained from activity across different businesses, websites, applications or services, the activity may fall within the CCPA's definition of cross-context behavioral advertising.
The exact legal classification of a particular advertising practice depends on the facts and applicable law.
Cross-context behavioral advertising is particularly important under the CCPA because California consumers have the right to opt out of the sharing of their personal information for cross-context behavioral advertising.
For businesses, this means privacy compliance cannot stop at publishing a privacy policy.
If a consumer opts out, the organisation needs to ensure that the applicable preference is communicated to and respected by the technologies involved in advertising and data sharing.
These technologies can include:
Under the CCPA, sharing has a specific statutory meaning that is particularly relevant to cross-context behavioral advertising.
The concept covers the communication of a consumer's personal information to a third party for cross-context behavioral advertising.
This is why a business can have CCPA obligations even where it does not think of its advertising activity as a traditional "sale" of personal information.
The CCPA separately gives consumers a right to opt out of the sale of personal information and a right to opt out of sharing personal information for cross-context behavioral advertising.
No.
Selling and sharing are separate concepts under the CCPA.
A business may have an obligation to honour a consumer's opt-out even where the relevant activity is classified as sharing for cross-context behavioral advertising rather than a sale.
This distinction is especially important for digital advertising because personal information may be transferred or made available to advertising platforms without money changing hands directly between the parties.
Businesses should therefore evaluate both their sale and sharing activities when assessing CCPA compliance.
Cookies are one technology that can facilitate cross-context behavioral advertising, but CCBA is not limited to cookies.
Other technologies can include:
The legal question is not simply:
"Is this a cookie?"
The more useful question is:
"What personal information does this technology collect, where does it go, and how is it used for advertising?"
This is why websites should maintain visibility into the actual scripts and third-party technologies running on their properties.
Under the CCPA, the key consumer control is generally the right to opt out of sale or sharing, rather than a GDPR-style requirement to obtain prior consent for every instance of targeted advertising.
This distinction matters.
A CCPA implementation may therefore need to:
Other privacy laws may impose different requirements.
For example, a website serving EU users may have separate obligations under the GDPR and ePrivacy framework.
Global Privacy Control (GPC) is a browser or user-agent privacy signal that communicates a consumer's opt-out preference.
Under the CCPA, qualifying opt-out preference signals can allow consumers to exercise their right to opt out of the sale or sharing of their personal information.
The current CCPA regulations contain detailed examples concerning how businesses should handle opt-out preference signals, including situations involving browsers, accounts and different devices.
This makes GPC an important technical component of CCPA privacy compliance.
When a covered business receives a valid opt-out preference signal, it may need to stop applicable selling or sharing of personal information for cross-context behavioral advertising.
For example, the current CCPA regulations describe situations in which a business receiving an opt-out signal must stop selling or sharing information associated with the consumer's browser identifier for cross-context behavioral advertising.
The implementation can become more complex when the business also knows the consumer through an account or other identifier.
This is why GPC support should be implemented as a real privacy control rather than treated as a decorative browser feature.
Third parties play an important role in many advertising ecosystems.
A business may use third-party advertising platforms to:
Under the CCPA regulations, a service provider or contractor cannot contract with a business to provide cross-context behavioral advertising. A party providing such services is treated as a third party for that activity rather than as a service provider or contractor for the CCBA service.
This distinction matters when businesses assess their advertising vendors and data-sharing arrangements.
First-party advertising generally involves using information within the business's own relationship or context.
For example:
An online retailer recommends products based on products a customer previously viewed on that retailer's own website.
Cross-context behavioral advertising involves using personal information obtained from activity across different businesses, websites, applications or services to target advertising.
For example:
An advertising platform uses information about a consumer's activity on one website to target that consumer with advertising on another website.
The distinction is important because the CCPA's statutory definition specifically focuses on activity across different contexts.
| Cross-context behavioral advertising | Contextual advertising |
|---|---|
| Uses information about activity across different contexts | Uses the context of the current page or environment |
| Can involve third-party advertising technology | Can operate without cross-site behavioural profiles |
| Can involve personal information obtained from other businesses or services | Can target based on page content |
| Relevant to CCPA sale/sharing opt-out rights | Not automatically CCBA |
| Often associated with retargeting and audience targeting | Commonly associated with content-based advertising |
The same advertising campaign can involve multiple technologies, so businesses should evaluate the underlying data flows rather than classifying an entire advertising strategy with a single label.
When a consumer opts out of applicable sale or sharing, businesses should ensure that the privacy preference is technically enforced.
A practical workflow is:
Receive the opt-out request.
Detect applicable GPC or other opt-out preference signals.
Record the privacy preference.
Update the consumer's applicable privacy state.
Prevent relevant data sharing.
Restrict advertising technologies affected by the opt-out.
Propagate the preference to relevant systems and vendors.
Maintain evidence of the preference and its enforcement.
Test the implementation regularly.
The important point is that an opt-out should affect the underlying data flow, not merely change the appearance of a privacy settings page.
If a website continues sending applicable personal information to advertising technologies after a consumer has exercised an opt-out, there can be a disconnect between the consumer's stated privacy preference and the website's technical behaviour.
For example, a website might:
That implementation may fail to meaningfully enforce the consumer's choice.
The CCPA framework places importance on businesses honouring applicable consumer privacy rights, making technical enforcement a critical part of a privacy programme.
Businesses can begin by identifying the technologies running on their websites and applications.
A privacy technology inventory should examine:
The next step is to determine:
Automated website scanning can help identify unexpected advertising technologies and changes to the site's tracking environment.
ConsentX helps organisations identify and control tracking technologies that may participate in advertising and data-sharing workflows.
Relevant capabilities include:
The current ConsentX glossary page specifically positions the platform around detecting trackers associated with cross-context advertising, honouring GPC and maintaining tamper-evident opt-out records.
The goal is to connect the consumer's privacy choice with the actual technical behaviour of the website.
A privacy preference is only useful if the underlying technologies respect it.
ConsentX can help create a workflow in which:
This provides a stronger implementation than simply placing a privacy link on a website.
For CCPA use cases, the relevant objective is to ensure that applicable sale/sharing opt-outs are reflected in the technologies and third parties involved in cross-context behavioral advertising.
No.
Cross-context behavioral advertising is not automatically illegal.
The CCPA establishes specific consumer rights and obligations concerning the collection, sale and sharing of personal information, including the right to opt out of sharing for cross-context behavioral advertising.
The compliance question is whether the business's practices satisfy the applicable legal requirements and whether consumer privacy choices are properly honoured.
A business should therefore avoid treating CCBA as something that is inherently prohibited.
Instead, it should understand:
The term is most strongly associated with the California CCPA/CPRA framework, where it has a specific statutory definition.
Other US state privacy laws use related concepts such as targeted advertising and may provide consumers with similar opt-out rights.
However, the definitions and requirements are not necessarily identical.
Businesses operating across multiple US states should therefore avoid assuming that a CCPA CCBA implementation automatically satisfies every other state privacy law.
Several US state privacy frameworks address targeted or behavioural advertising.
The terminology can differ:
The legal definitions and implementation requirements can vary by jurisdiction.
A multi-state privacy platform should therefore use jurisdiction-aware rules rather than applying one universal privacy preference to every visitor.
A practical compliance review should include:
Cross-context behavioral advertising (CCBA) is advertising targeted using personal information obtained from a consumer's activity across different businesses, websites, applications or services.
The most important points are:
Cross-context behavioral advertising compliance is not simply about adding a "Do Not Sell or Share" link. Businesses need to understand which technologies collect personal information, which third parties receive it, and what happens after a consumer opts out. ConsentX helps organisations detect tracking technologies, honour applicable privacy signals and turn consumer privacy choices into enforceable, auditable controls. Make your website's privacy preferences technically enforceable with ConsentX.
California's comprehensive consumer privacy law, as amended by the CPRA.
A browser or user-agent signal that communicates a consumer's privacy preference.
A CCPA privacy choice allowing consumers to opt out of applicable sale or sharing of personal information.
A broader term used by several US state privacy laws for advertising based on information about a consumer's activities or interests.
A mechanism for obtaining and managing permission for cookies and trackers where consent is required.
Technology used to manage consent and privacy preferences across websites.
The practice of preventing relevant non-essential processing until the required consent has been obtained.
Advertising that targets users based on previous interactions, which can in some circumstances involve cross-context behavioral advertising.
An interface where users can review and modify privacy choices.