CCPA, CPRA and US state law

CCPA Sale vs. Sharing: Analytics and Advertising Explained

Learn the difference between sale and sharing under the CCPA, assess analytics and advertising data flows, and connect each decision to working opt-out controls.

Published
Reading time
8 min

Under the CCPA, a sale involves disclosing personal information to a third party for money or other valuable consideration. Sharing involves disclosure to a third party for cross-context behavioural advertising, whether or not anything is paid. A transfer can meet both definitions.

The practical question is what happens to the information. Installing an analytics tool does not automatically settle its legal classification, and paying a vendor does not automatically make that vendor a service provider.

This guide provides a way to assess those transfers and record the resulting implementation decisions. It covers California’s CCPA as amended by the CPRA, using sources reviewed on 19 September 2026. The worked examples are illustrative scenarios, not findings about a particular customer or vendor configuration.

Sale and sharing: the key differences

QuestionSaleSharing
What triggers the definition?A business discloses personal information to a third party for monetary or other valuable considerationA business discloses personal information to a third party for cross-context behavioural advertising
Must money change hands?No. Other valuable consideration can qualifyNo. Consideration is not required
Is advertising required?NoCross-context behavioural advertising is the relevant purpose
Can the same transfer qualify?Yes, if it meets both definitionsYes, if it meets both definitions
What consumer choice applies?The right to opt out of saleThe right to opt out of sharing

Cross-context behavioural advertising means targeting advertising using personal information from activity across businesses, distinctly branded websites, apps or services other than the one the consumer is intentionally interacting with. This is different from using the subject of the current page to select an advertisement.

The definitions and their exceptions appear in Civil Code § 1798.140(k), (ad) and (ah). “Sharing” in everyday conversation is broader than the statutory advertising definition: sending information to someone else is not necessarily CCPA sharing, though other duties may still apply.

Assess the transfer in five steps

1. Identify the personal information

List the actual fields, identifiers and events transmitted. Include browser identifiers, IP addresses, account IDs, page URLs, purchases, audience membership and inferences where present.

Removing a name does not automatically remove personal information. A hashed email used to match a person to an advertising account should not be treated as anonymous merely because it is unreadable to a person. Check whether information can reasonably be linked to a consumer or household, and whether any claimed deidentification meets the statutory requirements.

2. Identify the recipient’s role for this activity

Is the recipient acting as a restricted service provider or contractor, or as a third party? Assess the particular service and transfer. The same supplier can have different roles for different activities.

Review the executed terms and actual use. A service-provider label requires the relevant restrictions and compliant conduct. Under regulation § 7050(b), a recipient providing cross-context behavioural advertising is a third party for those services; that activity cannot be converted into service-provider processing by a contract heading.

3. Test the advertising purpose

Does the recipient use the information to target advertising based on activity across businesses or services? Consider audience matching, retargeting and the way the recipient combines information.

A tool labelled “measurement” may also feed advertising audiences. Conversely, contextual advertising is not automatically cross-context behavioural advertising. Trace the enabled functions and downstream use.

4. Test consideration separately

If the transfer is not sharing, still ask whether it is a sale. What does the business receive in exchange for making information available? Consider the commercial arrangement, including non-cash benefits, rather than looking only for an invoice purchasing customer data.

The Attorney General’s Sephora settlement announcement describes a sale theory involving access to personal information in exchange for advertising and analytics benefits. It does not establish that every analytics installation has the same facts.

5. Check exceptions and document the conclusion

The statutory definitions contain exceptions, including qualifying consumer-directed disclosures, restricted use of opt-out identifiers and certain business transactions. Check each exception’s conditions. A privacy-policy disclosure or ordinary visit to a website is not, by itself, evidence that a consumer intentionally directed every embedded third-party transfer.

Record whether the activity is sale, sharing, both, neither, or unresolved. For an unresolved activity, identify the missing contractual or technical evidence and assign someone to resolve it before relying on an exemption.

Worked examples for common data flows

The conclusions below depend on the stated facts. Changing the recipient’s rights or actual use can change the result.

Illustrative activityAssessmentWhat to inspect
A retailer sells its identifiable customer list to a data broker for paymentSale; assess sharing separately if the purpose includes cross-context advertisingRecipient, payment, permitted purposes and onward disclosures
A retailer sends browsing identifiers to an ad network to retarget visitors on unrelated websitesSharing; assess whether the transfer also meets the sale definitionAudience creation, cross-site use, consideration and opt-out handling
A provider produces site-performance reports solely for the business under compliant service-provider restrictionsCan fall outside sale and sharing if the role and actual processing meet the requirementsExecuted terms, permitted uses, combining restrictions and enabled integrations
An email service sends the business’s own newsletter under compliant restrictions and does not reuse the list for another businessCan be service-provider processing rather than sale or sharingList reuse, subcontractors and contractual restrictions
A business sends customer email hashes to a social platform to identify those customers and target ads to themThe regulations identify this customer-list advertising use as outside the service-provider role; assess it as sharing on these factsMatching purpose, recipient role, audience use and suppression
A conversion event travels through the business’s server before reaching an advertising recipientThe server route does not decide the classificationFields forwarded, recipient use and the applicable sale and sharing tests

The email-service and customer-list examples draw on the distinctions in regulation § 7050. They illustrate why the purpose and recipient’s role matter more than the transport method.

Does Google Analytics count as a sale or sharing?

There is no reliable answer based only on the name “Google Analytics”. Review the property’s configuration, applicable terms, data-sharing choices, linked products and exports. Separate reporting from any activity that makes information available for advertising.

Google’s Analytics data-safeguarding documentation describes its data-protection terms and controls. Use those materials as evidence about the service, then compare your actual setup with the CCPA requirements. Do not infer a legal conclusion from a consent-platform category called “Analytics”.

For example, a review limited to reporting may reach a different conclusion from one involving audience exports to an advertising service. Document each path separately rather than recording “GA4 compliant” as a single finding.

What about Meta Pixel and Google Ads?

For Meta Pixel or another advertising integration, ask whether the implementation sends personal information for retargeting or other cross-context behavioural advertising. Where those facts meet the sharing definition, the choice must reach that disclosure. Do not treat every possible function of a named product as legally identical.

Google documents restricted data processing for certain advertising services. The scope is product- and feature-dependent, and linked services may need their own configuration. A restricted-processing setting is relevant evidence, not a substitute for reviewing the applicable terms and actual data flows.

For any vendor control, record which service it covers, which uses it restricts and how it is activated. Test the browser and server paths. Do not assume a flag on one request changes every account export or offline upload.

Connect the classification to privacy controls

Once a covered activity is classified as sale or sharing, connect that decision to the relevant notices, opt-out route and GPC processing. Applicable obligations also include contracts and risk assessments; classifying a transfer is the beginning of implementation work.

A useful review record can use the following fields. This is a suggested working format, not a prescribed statutory form.

FieldWhat to record
Activity and ownerThe specific transfer and the team responsible
Data and destinationFields, identifiers, endpoints and recipients
Purpose and roleActual use, recipient role and applicable contract version
ClassificationSale, sharing, both, neither or unresolved, with reasons
Choice handlingThe control that stops or appropriately restricts the affected disclosure
Test resultWhat happened before and after a manual opt-out and GPC
Review triggerChanges to purposes, contracts, settings, recipients or integrations

Test signed-out browsing, known accounts and later visits where relevant. A browser cookie setting may change while a server event, customer-list upload or account-linked disclosure continues. Equally, a network request remaining visible does not alone prove a prohibited sale or sharing: examine its contents and permitted processing.

Our CCPA cookie banner guide covers notice, links and signals. The opt-out form guide explains request handling without identity verification, and the audit guide covers wider governance and assessment requirements.

Frequently asked questions

Can the same disclosure be both a sale and sharing?

Yes. A disclosure for cross-context behavioural advertising may also involve monetary or other valuable consideration. Assess both definitions and any applicable exceptions.

Is it still a sale if we pay the vendor?

Paying for a service does not decide the recipient’s role or the nature of the exchange. Review the contract, actual processing and any consideration associated with making information available.

Does server-side tracking avoid CCPA sharing?

No. Moving a transfer from the browser to a server does not remove its advertising purpose or change the recipient’s use. The same classification questions apply.

Is a hashed email anonymous under the CCPA?

Not automatically. When it can be matched or reasonably linked to a consumer or household, it can remain personal information. Hashing alone does not establish statutory deidentification.

If we do not sell information, can we omit a sharing opt-out?

Not if the business shares personal information within the statutory definition. Assess sharing separately and then determine the required opt-out mechanisms and any applicable exception.

Does a sale/sharing opt-out require stopping every analytics request?

Not necessarily. The choice applies to sale and sharing, not every possible processing activity. Determine the recipient’s role, the data disclosed and its use, and test whether the remaining processing is permitted.

For help checking the implementation behind your classification decisions, discuss your CCPA and GPC setup or request a free consent audit.

Portrait of Doğancan Doğan
Written bySolution Engineer, Privacy Engineering

Solution engineer who has implemented consent management on 200+ corporate websites globally. Specialises in CCPA and GDPR operational compliance.

Keep reading

Related guides.

All of CCPA, CPRA and US state law →
  1. 01CCPA opt-out forms: collect only what you need, without identity verificationCCPA, CPRA and US state law · May 2026
  2. 02CCPA audit essentials: a practical compliance review for 2026CCPA, CPRA and US state law · Apr 2025
  3. 03CCPA vs. CPRA: what changed and what businesses need to reviewCCPA, CPRA and US state law · May 2025

See what fires before consent on your own site.

A free audit of your current banner and tags across regions, with the findings in writing and a 30-minute call to go through them.