The California Privacy Rights Act (CPRA) brought a change that directly affects any site with advertising pixels installed.
This page covers one piece of the picture. For the full scope of the CPRA — who must comply, the thresholds, the consumer rights and the penalties — start with our complete guide to the CPRA and cookies.
The CCPA talked about "selling" data. The CPRA added "sharing": the disclosure of personal information for cross-context behavioral advertising across different sites, even if no money changes hands directly.
This means the Meta Pixel on your site may constitute "sharing" of personal information under the CPRA, even if you receive no money for that specific sharing.
This article focuses exclusively on what the CPRA requires from a Cookies Policy: what the document must contain, how opt-out must work, and what changes for each tracker on your site.
The cookie banner is the consent interface. It is what the visitor sees when they first access the site.
The Cookies Policy is the detailed document. It is where the user finds complete information about each technology: what it collects, what it is for, who receives the data, and how to exercise rights over it.
Both need to exist. Both need to be aligned. And the Cookies Policy must be accessible from a clear link within the consent notice itself.
The CPRA requires businesses to collect personal information only for specific, explicit, and legitimate purposes and not to process data in ways incompatible with those purposes (Civil Code § 1798.100(a)(2)).
For cookies, each category needs a concrete purpose description.
What does not work: "cookies to improve your experience."
What works: "Analytics cookies: collect browsing behavior data including pages visited, traffic source, and session duration, to identify content and experience improvement opportunities. Data is sent to Google Analytics and retained for 14 months."
"Advertising cookies: collect behavioral identifiers sent to Meta and Google for creating advertising audiences and displaying personalized ads on other platforms. This constitutes sharing of personal information under the CPRA. Consumers may refuse this sharing via the 'Do Not Sell or Share My Personal Information' link or by activating the Global Privacy Control."
The Policy must list the tracker categories operating on the site:
Strictly necessary cookies: essential for basic functionality. Do not constitute selling or sharing. Must be documented.
Analytics cookies: measure browsing behavior. Depending on the tool, may constitute sharing of personal information if data is sent to third parties who use it for advertising on other sites.
Advertising and sharing cookies: feed ad pixels, build behavioral profiles for cross-site behavioral advertising. Almost always constitute "sharing" under the CPRA. Require an opt-out link.
Functional cookies: remember user preferences. Generally do not constitute selling or sharing.
Third-party cookies: fired by external services. Correct tag categorization is what makes accurate documentation possible.
This is the most important concept differentiating the CPRA from other laws for cookie purposes.
Selling is the exchange of personal information for monetary or other valuable consideration.
Sharing is the disclosure of personal information to a third party for cross-context behavioral advertising purposes, regardless of whether there is direct payment (Civil Code § 1798.140(ah)).
In practice, this means that when the Meta Pixel sends visitor behavior data from your site to Meta, that transmission may constitute "sharing" under the CPRA even if the business receives no money specifically for that data. What Meta does with that data to display ads on other platforms is the criterion.
Not a sale or sharing: disclosure to service providers processing data exclusively on behalf of the business, disclosure to provide the product or service requested by the consumer, and M&A transfers.
The Policy must identify the categories of third parties to which data is sold or shared via cookies (Civil Code § 1798.130).
This includes digital advertising platforms (Meta, Google, TikTok, Pinterest), programmatic advertising networks, analytics platforms that use data for other purposes, and any other partner receiving behavioral data from site users.
The CPRA introduced the requirement to disclose data retention periods, which the original CCPA did not have (Civil Code § 1798.130 a(5)(A)).
For the Cookies Policy, this means documenting:
How long each cookie remains active on the user's device.
How long data collected via cookies is retained in the business's servers and/or by involved third parties.
When and how data is deleted after the retention period.
The CPRA requires this link to be visible on the homepage and on any page where personal information is collected (Civil Code § 1798.120(a)).
This link must:
Be clear and conspicuous, not buried in menus.
Lead to a page where the consumer can opt out of selling and sharing.
Not require the consumer to create an account or go through multiple steps to opt out.
The Cookies Policy must identify this link and describe how the opt-out works in practice: which technologies are deactivated when the consumer clicks the link.
The Global Privacy Control (GPC) is a technical signal that consumers activate in their browser to automatically request opt-out of selling and sharing across all sites visited.
The CPPA (California Privacy Protection Agency) confirmed that the GPC constitutes a valid form of opt-out from selling and sharing under the CPRA. When a visitor accesses the site with the GPC enabled, the site must treat that as if the consumer had clicked "Do Not Sell or Share My Personal Information."
The Cookies Policy must state that the business recognizes and honors the GPC.
If the site collects sensitive personal information via cookies (such as precise geolocation data), the business must provide the "Limit the Use of My Sensitive Personal Information" link (Civil Code § 1798.121(a)).
Precise geolocation is one of the most relevant SPI categories for cookies: any cookie or technology that captures device location with enough precision to identify the user's position within a city block may constitute SPI collection.
If the site collects precise geolocation, the Cookies Policy must:
Identify this collection as SPI.
Describe the purpose of the use.
Explain how the consumer can limit that use via the specific link.
The CPRA uses an opt-out model for most personal information: processing is permitted by default for most purposes, and the consumer has the right to refuse selling and sharing.
But for sensitive personal information, the standard is different: use of SPI beyond essential purposes must be disclosed to the consumer, who has the right to limit that use.
And for consumers under 16, the standard is opt-in: the business cannot sell or share data of minors without active opt-in.
What is not valid as opt-out: processes requiring unnecessary multiple steps, account creation requirements to exercise opt-out, and any design that deliberately makes exercising the right more difficult.
The CPRA has strict rules for minors that must be described in the Cookies Policy.
For consumers under 16: the business cannot sell or share personal information (including via advertising cookies) without active opt-in.
For consumers under 13: opt-in must be given by parents or legal guardians.
If a consumer under 16 declines consent, the business must wait 12 months before requesting consent again.
Penalties for violations involving data of consumers under 16 are tripled and automatic.
If the site may have users in these age ranges, the Cookies Policy must describe how advertising cookies are deactivated for this audience and how opt-in is obtained.
Google Analytics, for example, collects browsing behavior data and sends it to Google's servers. Depending on how Google uses that data for its own advertising purposes or to provide advertising services to other advertisers, sending that data may constitute "sharing" under the CPRA.
The ANPD Cookie Guidance has documented how major analytics providers can cross-reference apparently anonymous data with other data they hold.
The safest approach: include Google Analytics in the category of cookies that may constitute sharing, offer opt-out, and document this categorization in the Cookies Policy.
Situations requiring an update:
Adding a new advertising pixel or tracker.
A new analytics tool sending data to third parties.
A new partner receiving behavioral data from site users.
Changes to retention periods for any category.
Change in the use of cookie data for new purposes.
Any modification to opt-out mechanisms or mandatory links.
Continuous data mapping is what keeps the cookie inventory synchronized with the document.
AdOpt's automatic scan identifies all active technologies on the site, feeding the list of categories that must appear in the Cookies Policy.
The cookie notice configured through AdOpt blocks non-necessary trackers before acceptance, presents categories with clear descriptions, honors the GPC automatically, and logs every interaction for audit purposes.
The integration with the "Do Not Sell or Share My Personal Information" link ensures that opt-outs are processed automatically and the corresponding trackers are deactivated.
Over 60,000 websites already run with AdOpt.
Privacy is not a banner. It is a position.
Want to build a Cookies Policy for your site that complies with the CPRA? Talk to our team.
Visible link in the footer and within the cookie notice.
Listing of cookie categories with a description of what each does on the site.
Specific purpose for each category, including whether it constitutes selling or sharing (Civil Code § 1798.100).
Identification of cookies constituting "sharing" for cross-context behavioral advertising (Civil Code § 1798.140(ah)).
Categories of third parties receiving data via cookies, including advertising platforms (Civil Code § 1798.130).
Retention period for each cookie category (Civil Code § 1798.130 a(5)(A)).
"Do Not Sell or Share My Personal Information" link visible on homepage and data collection pages (Civil Code § 1798.120).
"Limit the Use of My Sensitive Personal Information" link if SPI is collected via cookies (Civil Code § 1798.121).
GPC recognized and honored as a valid opt-out.
Protection for consumers under 16: mandatory opt-in for selling and sharing via advertising cookies.
12-month waiting rule after consumers under 16 decline consent.
Accessible language, without legal jargon.
No unnecessary multiple steps to exercise opt-out.
1. What is "sharing" of data under the CPRA and why is it different from "selling"?
The CCPA used only the concept of "selling" data (exchange for monetary consideration). The CPRA added "sharing," defined in Civil Code § 1798.140(ah) as disclosing personal information to third parties for cross-context behavioral advertising purposes, regardless of whether there is direct payment. This means that when the Meta Pixel sends visitor behavior data from your site to Meta, this may constitute "sharing" under the CPRA even if the business receives no money specifically for that data. The CPRA requires opt-out from both selling and sharing.
2. Is the GPC mandatory for sites serving California consumers?
Yes, in practice. The CPPA confirmed that the GPC constitutes a valid form of opt-out from selling and sharing personal information under the CPRA. This means that if a visitor arrives at your site with the GPC enabled in their browser, the site is required to treat that signal as an opt-out from selling and sharing. Ignoring the GPC may constitute a CPRA violation. A properly configured CMP detects and honors the GPC automatically.
3. Do analytics cookies like Google Analytics constitute "sharing" under the CPRA?
It depends on how the provider uses the data. If Google Analytics only generates usage reports for the business that installed the tool, it may be configured as a service provider without constituting "sharing." If data is used by Google for its own advertising purposes or to provide advertising services to other advertisers, it may constitute sharing. Google offers privacy-safe configurations in GA4 that can reduce this risk. The safest approach is to offer opt-out and consult a specialist to evaluate the specific configuration.
4. What must change in the Cookies Policy to update from CCPA to CPRA?
The main changes are: replace references to "selling" data to include "selling and sharing"; add description of what constitutes sharing for cross-context behavioral advertising; update the opt-out link from "Do Not Sell My Personal Information" to "Do Not Sell or Share My Personal Information"; add the "Limit the Use of My Sensitive Personal Information" link if SPI is collected via cookies; include retention periods for each cookie category; and add mention of the GPC as a valid form of opt-out.
5. If a consumer under 16 declines consent for advertising cookies, what can the business do?
It may keep strictly necessary cookies active, as those do not require consent. It must deactivate all advertising and sharing cookies. And it must wait 12 months before requesting consent for advertising cookies again. This 12-month rule is one of the most specific elements of the CPRA compared to other US state laws, and it reflects the legislature's intent to protect minor consumers from repeated consent requests.
Ready to build a Cookies Policy for your site that complies with the CPRA? Talk to our team.
Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.
What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.
Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.
How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.
LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?
How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.
Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.
Have you ever noticed that every time you sign up for a service to access information or register on a website for purchases, you need to give consent? If you're wondering why you have to give consent on every website you visit, you'll find the answer here.
Learn what your Privacy Policy must contain under the NHDPA. We break down the 8 mandatory elements and how to comply with New Hampshire's data privacy law.
Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.
California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.
Find out if the MTCDPA applies to your site, key compliance deadlines, and new rules for cookies and consent in Montana
Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.
Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.
Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.
Here is a step-by-step explanation of how consent registration works in AdOpt.
What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.
Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.
The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.
Everything you need to know about the Florida Digital Bill of Rights (FDBR): who must comply, the $1 billion threshold, 7 consumer rights, FIPA vs FDBR explained, penalties, and cookies.
What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.
Everything about the Oregon OCPA: who must comply, the payment transaction exclusion, 25% revenue threshold, derived data in scope, GPC requirement from January 2026, and elimination of the cure period.
In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.
What the California CPRA requires from your Privacy Policy: SPI category, two mandatory links, data retention periods, sharing disclosure, right to correct, GPC, and minor protections.
What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.
Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.
The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?
What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.
What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.
What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.
What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.
Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.
What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.
California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.
Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.
How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.
In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.
How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.
What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.
It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.
Rights, Policy and how to understand about the DSAR Montana MTCDPA
Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!
What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!
Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.
Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.
14 May 2025
Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819
15 Rue du Général Campredon, 34000 Montpellier, France
207 Rue de Bercy, 75012 Paris, France
EIN: 86-3965064
Phone: +1 (407) 768-3792
AdOpt
Resources
Product
Certifications