US State Law California, USA

CCPA and AdTech: Pixels, Sharing, and Opt-Out Mechanics

How the CCPA treats the advertising stack: why pixels are sales, cross-context behavioral advertising, GPC, and the enforcement actions built on ad-tech flows.

Regulation

CCPA/CPRA sale and sharing provisions (Civ. Code 1798.120, 1798.140(ad), (ah))

Max Penalty

$2,500 per violation; $7,500 per intentional violation or violation involving minors

Enforcing Authority

California Privacy Protection Agency (CPPA) and California Attorney General

Official Source

cppa.ca.gov

Executive Summary

  • Every California ad-tech enforcement action rests on the same theory: sending identifiers to third-party advertising platforms via pixels, tags, and SDKs is a 'sale' or 'share' requiring opt-out rights.
  • 'Sharing' was added by the CPRA specifically for cross-context behavioral advertising, closing the argument that no money changes hands with an ad platform.
  • Compliance requires a working opt-out surface: the Do Not Sell or Share link, GPC signal processing, downstream propagation within 15 business days, and tag suppression that actually stops the network calls.
  • Sephora ($1.2M), DoorDash ($375K), Honda ($632,500), Todd Snyder ($345,495), and Healthline ($1.55M) all turned on ad-stack behavior observable from a browser.
  • Health-adjacent and minors' ad flows carry multiplied risk: Healthline established that URLs implying medical conditions flowing to ad networks violate purpose-limitation expectations.

California privacy enforcement is, in practice, ad-tech enforcement. Five public actions, one theory: the browser tells the truth. Regulators load a site with GPC enabled, watch which network calls still carry identifiers to ad platforms, and compare the traffic against the privacy policy and the opt-out promises. Compliance is winning that experiment every time, on every page, including after your next marketing-tag deploy.

ProvisionsCiv. Code 1798.120, 1798.140(ad) “sale”, (ah) “sharing”
DutiesOpt-out link + GPC + suppression + downstream propagation
Enforcement recordSephora, DoorDash, Honda, Todd Snyder, Healthline
RegulatorCPPA + AG

Engineering the compliant ad stack

Inventory the real flows. Crawl your properties with a clean profile: every request to ad and analytics domains, the identifiers carried (cookies, hashed emails, device IDs, IPs plus fingerprint-adjacent parameters), and the pages that fire them. Include mobile SDKs and server-side containers, the CPPA reads network traffic, not tag-manager configs.

Classify each recipient. Service provider with a qualifying contract and configuration, or third party whose flow is a sale/share wired to the opt-out. Matched-audience uploads, conversions APIs, and data-co-op contributions are sales/shares no matter how the vendor brands them.

Make opt-out signal handling native. GPC intake at the edge, a consent state that tag managers and server-side pipelines both respect, per-platform restricted-processing flags for opted-out users, and 15-business-day propagation to third parties. Then test quarterly from a consumer’s seat; the CCPA checklist sequences the verification.

Treat sensitive contexts separately. Health-implying URLs, SPI categories, and minors’ sections need suppression regardless of opt-out state, or at minimum a documented risk assessment concluding the flow is defensible, most cannot reach that conclusion for condition-level health signals.

Watch the drift. Every campaign launch adds tags. Continuous scanning against an approved-endpoint baseline catches the new pixel before the regulator’s browser does. Start with a free scan to see your current tracker inventory and which calls survive a GPC signal.

Frequently Asked Questions

Why is a Meta pixel a 'sale' when Meta doesn't pay us?

Two independent reasons. 'Sale' includes disclosure for 'other valuable consideration,' and regulators treat free analytics, matched audiences, and measurement services as consideration (Sephora). And even absent consideration, disclosure for cross-context behavioral advertising is 'sharing' (1798.140(ah)), which carries identical opt-out duties. The only escape is a service-provider relationship, which major ad platforms accept only for limited, non-targeting configurations.

What does a compliant opt-out actually have to do?

Four things, verified end-to-end: (1) accept the click on your Do Not Sell or Share link and any GPC header/JS signal automatically; (2) suppress the tags for that browser/consumer so identifier-bearing calls stop; (3) forward the opt-out to third parties who already received data; (4) do all of it without login walls, fees, or dark-pattern friction. Todd Snyder shows the failure mode: a CMP that displayed choices but never propagated them cost $345,495.

Do restricted-data-processing modes fix this?

Partially. Google's RDP, Meta's Limited Data Use, and similar flags can convert some flows into service-provider processing for opted-out users, but they must be triggered per-user in response to opt-outs, configured per-platform, and validated, defaults do not enable them. They are the mechanism for honoring opt-outs while keeping measurement, not a substitute for the opt-out surface itself.

How do the other states change the ad-tech analysis?

Every Virginia-lineage state grants an opt-out of 'targeted advertising' (defined similarly to California's cross-context concept), and Colorado, Texas, Connecticut, and others mandate honoring universal opt-out signals like GPC on their own schedules. The practical convergence: treat GPC as a national opt-out of ad-targeting flows. Our universal opt-out guide covers the per-state mechanics.

What are the highest-risk ad-tech patterns right now?

Health-condition-adjacent content with ad pixels (Healthline theory); minors' data in ad flows (under-16 requires opt-in in California, and children's ad-targeting is banned in several states); precise-location-based ad segments (SPI, plus FTC location-broker actions); and server-side tagging that quietly rebuilds the flows your consent tool suppressed client-side. Audit server-side containers with the same rigor as browser tags.

Regulatory Crosswalk

CCPAState targeted-advertising opt-outsGPC

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.