Home
California CCPA: Cookies Policy

California CCPA: Cookies Policy

4 months ago
João Bruno Soares
26 minutes

California has a requirement that no other US state privacy law has: the "Do Not Sell or Share My Personal Information" link visibly displayed on the homepage.

This page covers one piece of the picture. For the full scope of the CCPA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the CCPA and cookies.

That link exists because of cookies.

When a site installs an advertising pixel, that pixel collects data about user behavior and sends it to the advertising platform. This constitutes "sharing" of data for cross-context behavioral advertising under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA). And sharing requires an opt-out.

This article focuses exclusively on what the CCPA/CPRA requires from a Cookies Policy: what must be in the document, how consent and opt-out must work, and what the law's specific requirements mean for each tracker on your site.

Cookies Policy vs. cookie banner: the necessary distinction

The cookie banner is the visual interface. It is what the visitor sees when they access the site and where they make choices about what they accept.

The Cookies Policy is the detailed document. It is where the user finds complete information about every technology operating on the site: what it collects, what it is for, who receives the data, how long it is retained, and how to exercise rights.

Both need to exist. Both need to be aligned. And the Cookies Policy must be accessible from a link within the consent notice itself.

"Sale" and "sharing" of data via cookies

The distinction created by the CPRA is fundamental to understanding what the CCPA requires in the context of cookies.

Sale (§ 1798.140(ad)): transfer of data for monetary or other valuable consideration to third parties.

Sharing (§ 1798.140(ah)): transfer of data to third parties for cross-context behavioral advertising, with or without monetary consideration.

Cross-context behavioral advertising (§ 1798.140(k)): ads targeted based on personal information obtained from consumer activity across different businesses, distinctly branded websites, applications, or services.

In practice: if your site has a pixel that sends user behavior data to an advertising platform to display ads on other sites, that is "sharing" under the CCPA/CPRA, even if you receive no money directly. And sharing requires:

The "Do Not Sell or Share My Personal Information" link on the homepage.

Clear and conspicuous disclosure in the privacy notice.

Honoring the opt-out when exercised.

What the CCPA/CPRA specifically requires for cookies

Specific purpose for each category

§ 1798.100(a)(1) requires the business to inform consumers, at or before the point of collection, of the categories of personal information to be collected and the purposes for which they are collected or used, and whether that information is sold or shared.

For cookies, each tracker category needs a specific purpose description. "Cookies to improve your experience" is not a purpose.

What works:

"Analytics cookies: collect browsing behavior data including pages visited, traffic source, and session duration. Used to identify opportunities for content improvement. This data is not sold or shared with third parties for advertising."

"Advertising cookies: collect behavioral identifiers that are shared with advertising platforms for cross-context behavioral advertising. Data is shared with partners such as Meta Ads and Google Ads. Consumers can opt out via the 'Do Not Sell or Share My Personal Information' link."

Cookie categories present on the site

The Policy must list the tracker categories:

Necessary cookies: essential for basic functionality. Do not constitute sale or sharing and do not require the opt-out link. But must be documented.

Analytics cookies: depends on configuration. If data stays within company systems and is not sent to third parties for targeting, they generally do not constitute "sale" or "sharing." But most major analytics platform cookies send data to the provider, which may constitute a business purpose disclosure.

Advertising and retargeting cookies: almost always constitute "sharing" under the CCPA/CPRA. Meta Pixel, Google Ads, TikTok Pixel, programmatic DSP pixels: all send data to platforms that use that data to display behavioral ads to the user on other sites.

Functional cookies: remember user preferences. Generally do not constitute sale or sharing if the data stays internal.

Third-party cookies: fired by external services integrated into the site. Correct tag categorization is what makes it possible to document each one accurately.

Who receives data via cookies

The Policy must identify the categories of third parties receiving data via cookies.

§ 1798.115(a) requires the business to disclose, upon consumer request, the categories of third parties to whom it sold or shared data, by category of personal information.

For cookies, this means documenting that, for example: browsing behavior data was shared with digital advertising platforms; session data was disclosed to analytics service providers; user identifiers were shared with programmatic advertising networks.

Retention period for each category

§ 1798.100(a)(3) requires the business to disclose the length of time it intends to retain each category of data, or the criteria used to determine that period.

For cookies, the Policy must document:

How long each cookie category remains active on the user's device.

How long data collected via cookies is retained in company systems.

Whether and when data is deleted.

The Global Privacy Control (GPC): how to handle it in the context of cookies

§ 1798.135(b) allows the business to comply with opt-out requirements by honoring the opt-out preference signal sent by platforms, technologies, or mechanisms with the consumer's consent.

The Global Privacy Control (GPC) is the best-known mechanism implementing this functionality. When the user activates the GPC in their browser, the site must interpret this signal as an opt-out of sale and sharing.

The Cookies Policy must state whether the site respects the GPC and how this mechanism works.

A well-configured consent management platform detects and honors the GPC automatically.

The "Limit the Use of My Sensitive Personal Information" link and cookies

Precise geolocation data (radius of 1,850 feet or less) is sensitive personal information under the CCPA/CPRA (§ 1798.140(ae)(1)(C)).

If the site collects precise geolocation data via cookies or location scripts for purposes beyond what is necessary to provide the requested product or service, the consumer has the right to limit this use via the "Limit the Use of My Sensitive Personal Information" link (§ 1798.121).

The Cookies Policy must identify whether precise geolocation data is collected, what it is used for, and how the consumer can limit its use.

Special protection for consumers under 16 years of age

§ 1798.120(c) prohibits the sale or sharing of data of consumers under 16 without affirmative authorization.

For consumers between 13 and 15: the consumer's own authorization.

For consumers under 13: parental or legal guardian authorization.

If the site may have users under 16, the Cookies Policy must describe how data from those users is treated differently, including how advertising cookies are blocked without adequate authorization.

When to update the Cookies Policy

§ 1798.130(a)(5) requires updating the privacy notice at least once every 12 months. For the Cookies Policy, this means a mandatory annual review.

Situations requiring immediate update:

Adding a new advertising pixel.

A new analytics tool that sends data to third parties.

A new chat or support plugin.

A new CRM or email marketing platform integration.

Any new partner receiving behavioral data.

Continuous data mapping is what keeps the cookie inventory synchronized with the document.

The CCPA/CPRA anti-avoidance provision

§ 1798.190 provides that transactions or series of steps intentionally created to avoid the definition of "sale" or "sharing," including eliminating monetary consideration to circumvent the law, will be disregarded.

This means that structuring data exchange agreements without monetary consideration to avoid the opt-out is not a valid strategy. The CCPA/CPRA looks at the substance of the transaction, not just its form.

Enforcement and penalties

The California Privacy Protection Agency (CPPA) can impose administrative fines of up to US$ 2,500 per violation and up to US$ 7,500 for intentional violations or violations involving minors. The Attorney General can seek civil penalties in the same amounts.

There is no guaranteed cure period before CPPA actions. The agency has discretion to investigate and act.

Additionally, § 1798.150 grants consumers the private right of action for security breaches: US$ 100 to US$ 750 per consumer per incident.

How AdOpt helps with the Cookies Policy under the CCPA/CPRA

AdOpt's automatic scan identifies all technologies active on the site, feeding the list of categories that must appear in the Cookies Policy.

The cookie notice configured through AdOpt blocks non-essential trackers before acceptance, presents categories with clear descriptions, offers real opt-out options, honors the GPC automatically, and logs every interaction for audit purposes.

Over 60,000 websites already run with AdOpt.

Privacy is not a banner. It is a position.

Want to build a Cookies Policy for your site that complies with the CCPA/CPRA? Talk to our team.

Checklist: what your Cookies Policy needs for the CCPA/CPRA

Visible link in the site footer and within the cookie banner.

Listing of cookie categories with a description of what each one does.

Specific purpose for each category, including a statement of whether data is sold or shared.

Identification of cookies that constitute "sale" or "sharing" under the CCPA/CPRA definition.

Categories of third parties that receive data via cookies.

"Do Not Sell or Share My Personal Information" link on the homepage when there is sale or sharing.

"Limit the Use of My Sensitive Personal Information" link when precise geolocation data is collected for purposes beyond the necessary.

Global Privacy Control (GPC): statement that the site honors the signal when sent by the user.

Retention period for each cookie category.

Protection for minors aged 13 to 15 and under 13.

Annual update of the document.

Accessible language, without legal jargon.

No dark patterns in opt-out mechanisms.

FAQ: CCPA/CPRA and Cookies Policy

1. Does an advertising pixel always constitute "sharing" under the CCPA/CPRA?
Almost always, yes. The CCPA/CPRA defines "sharing" as the transfer of data for cross-context behavioral advertising, with or without monetary consideration. A pixel that sends user behavior data from your site to a platform that uses that data to display ads to the same user on other sites constitutes sharing. The site needs the "Do Not Sell or Share My Personal Information" link and must honor the opt-out.

2. Does Google Analytics constitute "sharing" under the CCPA/CPRA?
It depends on the configuration. Google Analytics in its default configuration sends data to Google, which has its own data use policies. If that data is used by Google for ad targeting on other sites (which may occur depending on settings), there is a risk of constituting sharing. The safest approach is to use GA with enhanced privacy settings and review the data processing terms with Google.

3. What is the Global Privacy Control (GPC) and must the site respect it?
The GPC is a browser signal that the user can activate to indicate their opt-out preference for sale and sharing of data. § 1798.135(b) allows the business to comply with opt-out requirements by honoring the GPC, instead of maintaining the "Do Not Sell or Share" and "Limit Sensitive PI" links on the site. Both approaches are valid: visible links on the site, or honoring the GPC. The business may choose one of the two strategies.

4. Do analytics cookies need the "Do Not Sell or Share" link under the CCPA/CPRA?
It depends on how the data is used. If analytics data stays only within company systems and is not sent to third parties for targeting purposes, it generally does not constitute "sale" or "sharing." But if the analytics tool is from a major provider that may use the data for other purposes including targeting, there is risk. Reviewing the tool's data processing terms is essential.

5. What happens if the consumer opts out and the site continues sharing data?
Continued sale or sharing after opt-out is a direct violation of § 1798.120(d). The CPPA may investigate and impose fines of up to US$ 2,500 per violation or US$ 7,500 for intentional violations. Additionally, the affected consumer may have grounds for a civil lawsuit. The business must wait at least 12 months before requesting the consumer's consent to sale or sharing again.

Ready to build a Cookies Policy for your site that complies with the CCPA/CPRA? Talk to our team.

Tags

CCPA
Cookie Banner
Controller and Operator
Data Mapping
Cookies
Data Protection Officer - DPO

Related posts

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

Connecticut CTDPA: Cookies Policy

What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.

AdOpt post

The Differences Between Data Controller and Data Processor - LGPD

Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.

AdOpt post

7 Steps to GDPR-Compliant Cookie Banners in 2025

Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

California CCPA: DSAR Privacy Portal

How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.

AdOpt post

LGPD: An Opportunity for Digital Marketing Agencies!

Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.

AdOpt post

Why Give Consent on Every Website I Visit?

Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.

AdOpt post

New Hampshire NHDPA: Privacy Policy

Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.

AdOpt post

The Impact of Cookie Banners on Your E-commerce - LGPD

Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.

AdOpt post

California CPRA and Cookies: All you need to know

California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.

AdOpt post

MTCDPA Montana and Cookies: All you need to know

Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana

AdOpt post

IOWA ICDPA: DSAR and Privacy Portal

Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.

AdOpt post

Utah UCPA: DSAR and Privacy Portal

Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.

AdOpt post

Montana MTCDPA: Privacy Policy

Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.

AdOpt post

What is a privacy policy?

A privacy policy is a document that outlines how an organization collects, uses, discloses, and manages a customer's data. It's essential for building trust with users and complying with legal requirements. However, if you're not familiar with it, don't worry as we're here to help you.

AdOpt post

How does a cookie banner operate?

Here is a step-by-step explanation of how consent registration works in AdOpt.

AdOpt post

10 Marketing Processes You Should Rethink under the LGPD!

In the end, our goal has never been to predict doom for companies or to be part of the LGPD's Apocalypse Cavalry. But, since we've been in the market for some time, these kinds of issues always catch our attention when we start data mapping and having conversations with colleagues.

AdOpt post

New Hampshire NHDPA: DSAR Privacy Portal

What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.

AdOpt post

Tenesse TIPA: Cookies Policy

Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.

AdOpt post

Connecticut CTDPA and Cookies: All You Need to Know

The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.

AdOpt post

Florida FDBR and Cookies: All You Need to Know

Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.

AdOpt post

Colorado CPA: Cookies Policy

What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.

AdOpt post

Oregon OCPA and Cookies: All You Need to Know

Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.

AdOpt post

LGPD and Cookies all do you need to know?

In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.

AdOpt post

California CPRA: Privacy Policy

What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.

AdOpt post

Florida FDBR: Cookies Policy

What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

AdOpt post

Data Mapping or Data Inventory - a life jacket for the DPO!

With the data mapping we have a clear understanding of the 5 stages that every data goes through in a company.

AdOpt post

Tenesse TIPA: DSAR Privacy Portal

Learn how to build a TIPA-compliant Privacy Portal for Tennessee. Understand DSAR deadlines, consumer rights, opt-out mechanisms, and the affirmative defense that sets TIPA apart from every other US state privacy law.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt post

California CCPA: Privacy Policy

What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.

AdOpt post

Connecticut CTDPA: Privacy Policy

What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.

AdOpt post

Colorado CPA: Privacy Policy

What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.

AdOpt post

Utah UCPA and Cookies: All you need to know

Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.

AdOpt post

Oregon OCPA: Cookies Policy

What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.

AdOpt post

California CPRA: DSAR and Privacy Portal

California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.

AdOpt post

Texas TDPSA and Cookies: All You Need to Know

Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

Outsourcing the DPO (DPOaaS), Is It a Good Idea?

The Data Protection Officer, or DPO, is a new position that emerged all over the globe with the new privacy regulations, and more recently at the LGPD. Although it already existed in other international legislations, such as the EU's GDPR, it is still a novelty here since 2020. Along with it comes the possibility of outsourcing, known as DPO as a Service (DPOaaS).

AdOpt post

GDPR Legal Basis: An Introduction

In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.

AdOpt post

Florida FDBR: DSAR Privacy Portal

How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.

AdOpt post

IOWA ICDPA: Cookies Policy

What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪