Under the CCPA, a sale involves disclosing personal information to a third party for money or other valuable consideration. Sharing involves disclosure to a third party for cross-context behavioural advertising, whether or not anything is paid. A transfer can meet both definitions.
The practical question is what happens to the information. Installing an analytics tool does not automatically settle its legal classification, and paying a vendor does not automatically make that vendor a service provider.
This guide provides a way to assess those transfers and record the resulting implementation decisions. It covers California’s CCPA as amended by the CPRA, using sources reviewed on 19 September 2026. The worked examples are illustrative scenarios, not findings about a particular customer or vendor configuration.
Sale and sharing: the key differences
| Question | Sale | Sharing |
|---|---|---|
| What triggers the definition? | A business discloses personal information to a third party for monetary or other valuable consideration | A business discloses personal information to a third party for cross-context behavioural advertising |
| Must money change hands? | No. Other valuable consideration can qualify | No. Consideration is not required |
| Is advertising required? | No | Cross-context behavioural advertising is the relevant purpose |
| Can the same transfer qualify? | Yes, if it meets both definitions | Yes, if it meets both definitions |
| What consumer choice applies? | The right to opt out of sale | The right to opt out of sharing |
Cross-context behavioural advertising means targeting advertising using personal information from activity across businesses, distinctly branded websites, apps or services other than the one the consumer is intentionally interacting with. This is different from using the subject of the current page to select an advertisement.
The definitions and their exceptions appear in Civil Code § 1798.140(k), (ad) and (ah). “Sharing” in everyday conversation is broader than the statutory advertising definition: sending information to someone else is not necessarily CCPA sharing, though other duties may still apply.
Assess the transfer in five steps
1. Identify the personal information
List the actual fields, identifiers and events transmitted. Include browser identifiers, IP addresses, account IDs, page URLs, purchases, audience membership and inferences where present.
Removing a name does not automatically remove personal information. A hashed email used to match a person to an advertising account should not be treated as anonymous merely because it is unreadable to a person. Check whether information can reasonably be linked to a consumer or household, and whether any claimed deidentification meets the statutory requirements.
2. Identify the recipient’s role for this activity
Is the recipient acting as a restricted service provider or contractor, or as a third party? Assess the particular service and transfer. The same supplier can have different roles for different activities.
Review the executed terms and actual use. A service-provider label requires the relevant restrictions and compliant conduct. Under regulation § 7050(b), a recipient providing cross-context behavioural advertising is a third party for those services; that activity cannot be converted into service-provider processing by a contract heading.
3. Test the advertising purpose
Does the recipient use the information to target advertising based on activity across businesses or services? Consider audience matching, retargeting and the way the recipient combines information.
A tool labelled “measurement” may also feed advertising audiences. Conversely, contextual advertising is not automatically cross-context behavioural advertising. Trace the enabled functions and downstream use.
4. Test consideration separately
If the transfer is not sharing, still ask whether it is a sale. What does the business receive in exchange for making information available? Consider the commercial arrangement, including non-cash benefits, rather than looking only for an invoice purchasing customer data.
The Attorney General’s Sephora settlement announcement describes a sale theory involving access to personal information in exchange for advertising and analytics benefits. It does not establish that every analytics installation has the same facts.
5. Check exceptions and document the conclusion
The statutory definitions contain exceptions, including qualifying consumer-directed disclosures, restricted use of opt-out identifiers and certain business transactions. Check each exception’s conditions. A privacy-policy disclosure or ordinary visit to a website is not, by itself, evidence that a consumer intentionally directed every embedded third-party transfer.
Record whether the activity is sale, sharing, both, neither, or unresolved. For an unresolved activity, identify the missing contractual or technical evidence and assign someone to resolve it before relying on an exemption.
Worked examples for common data flows
The conclusions below depend on the stated facts. Changing the recipient’s rights or actual use can change the result.
| Illustrative activity | Assessment | What to inspect |
|---|---|---|
| A retailer sells its identifiable customer list to a data broker for payment | Sale; assess sharing separately if the purpose includes cross-context advertising | Recipient, payment, permitted purposes and onward disclosures |
| A retailer sends browsing identifiers to an ad network to retarget visitors on unrelated websites | Sharing; assess whether the transfer also meets the sale definition | Audience creation, cross-site use, consideration and opt-out handling |
| A provider produces site-performance reports solely for the business under compliant service-provider restrictions | Can fall outside sale and sharing if the role and actual processing meet the requirements | Executed terms, permitted uses, combining restrictions and enabled integrations |
| An email service sends the business’s own newsletter under compliant restrictions and does not reuse the list for another business | Can be service-provider processing rather than sale or sharing | List reuse, subcontractors and contractual restrictions |
| A business sends customer email hashes to a social platform to identify those customers and target ads to them | The regulations identify this customer-list advertising use as outside the service-provider role; assess it as sharing on these facts | Matching purpose, recipient role, audience use and suppression |
| A conversion event travels through the business’s server before reaching an advertising recipient | The server route does not decide the classification | Fields forwarded, recipient use and the applicable sale and sharing tests |
The email-service and customer-list examples draw on the distinctions in regulation § 7050. They illustrate why the purpose and recipient’s role matter more than the transport method.
Does Google Analytics count as a sale or sharing?
There is no reliable answer based only on the name “Google Analytics”. Review the property’s configuration, applicable terms, data-sharing choices, linked products and exports. Separate reporting from any activity that makes information available for advertising.
Google’s Analytics data-safeguarding documentation describes its data-protection terms and controls. Use those materials as evidence about the service, then compare your actual setup with the CCPA requirements. Do not infer a legal conclusion from a consent-platform category called “Analytics”.
For example, a review limited to reporting may reach a different conclusion from one involving audience exports to an advertising service. Document each path separately rather than recording “GA4 compliant” as a single finding.
What about Meta Pixel and Google Ads?
For Meta Pixel or another advertising integration, ask whether the implementation sends personal information for retargeting or other cross-context behavioural advertising. Where those facts meet the sharing definition, the choice must reach that disclosure. Do not treat every possible function of a named product as legally identical.
Google documents restricted data processing for certain advertising services. The scope is product- and feature-dependent, and linked services may need their own configuration. A restricted-processing setting is relevant evidence, not a substitute for reviewing the applicable terms and actual data flows.
For any vendor control, record which service it covers, which uses it restricts and how it is activated. Test the browser and server paths. Do not assume a flag on one request changes every account export or offline upload.
Connect the classification to privacy controls
Once a covered activity is classified as sale or sharing, connect that decision to the relevant notices, opt-out route and GPC processing. Applicable obligations also include contracts and risk assessments; classifying a transfer is the beginning of implementation work.
A useful review record can use the following fields. This is a suggested working format, not a prescribed statutory form.
| Field | What to record |
|---|---|
| Activity and owner | The specific transfer and the team responsible |
| Data and destination | Fields, identifiers, endpoints and recipients |
| Purpose and role | Actual use, recipient role and applicable contract version |
| Classification | Sale, sharing, both, neither or unresolved, with reasons |
| Choice handling | The control that stops or appropriately restricts the affected disclosure |
| Test result | What happened before and after a manual opt-out and GPC |
| Review trigger | Changes to purposes, contracts, settings, recipients or integrations |
Test signed-out browsing, known accounts and later visits where relevant. A browser cookie setting may change while a server event, customer-list upload or account-linked disclosure continues. Equally, a network request remaining visible does not alone prove a prohibited sale or sharing: examine its contents and permitted processing.
Our CCPA cookie banner guide covers notice, links and signals. The opt-out form guide explains request handling without identity verification, and the audit guide covers wider governance and assessment requirements.
Frequently asked questions
Can the same disclosure be both a sale and sharing?
Yes. A disclosure for cross-context behavioural advertising may also involve monetary or other valuable consideration. Assess both definitions and any applicable exceptions.
Is it still a sale if we pay the vendor?
Paying for a service does not decide the recipient’s role or the nature of the exchange. Review the contract, actual processing and any consideration associated with making information available.
Does server-side tracking avoid CCPA sharing?
No. Moving a transfer from the browser to a server does not remove its advertising purpose or change the recipient’s use. The same classification questions apply.
Is a hashed email anonymous under the CCPA?
Not automatically. When it can be matched or reasonably linked to a consumer or household, it can remain personal information. Hashing alone does not establish statutory deidentification.
If we do not sell information, can we omit a sharing opt-out?
Not if the business shares personal information within the statutory definition. Assess sharing separately and then determine the required opt-out mechanisms and any applicable exception.
Does a sale/sharing opt-out require stopping every analytics request?
Not necessarily. The choice applies to sale and sharing, not every possible processing activity. Determine the recipient’s role, the data disclosed and its use, and test whether the remaining processing is permitted.
Related reading
- CCPA vs. CPRA: what changed
- Does the CCPA apply outside California?
- Honda, Ford and Disney: enforcement lessons
For help checking the implementation behind your classification decisions, discuss your CCPA and GPC setup or request a free consent audit.
