Privacy

A Practical Guide to CCPA and Data Protection

Taras Shynkarenko
Taras Shynkarenko
•Updated: •7 min read
A Practical Guide to CCPA and Data ProtectionA Practical Guide to CCPA and Data Protection

TL;DR, Quick Answer

7 min read

The CCPA's broad data-sharing rules directly impact web analytics and marketing. The Sephora case proved that routine analytics activities can trigger violations and million-dollar settlements.

California's law is not a cookie law in the European sense, and yet the CCPA impact cookies marketing analytics stacks feel is very real: opt-out rights and the sale-or-share rules reach every pixel on the page.

The California Consumer Privacy Act is not a "cookie law" in the European sense. It does not say every analytics cookie needs opt-in consent. But it absolutely affects cookies, pixels, advertising tags, and analytics vendors because it gives Californians rights over the sale and sharing of personal information.

For marketing teams, the practical question is not "do we use cookies?" It is "are we disclosing, selling, sharing, or enabling cross-context behavioral advertising with personal information?"

Why Analytics Data Can Be Personal Information

California defines personal information broadly. The law covers information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a consumer or household. The California Attorney General's CCPA materials include online identifiers and IP addresses within this broad framing.

This matters because many routine web tools collect identifiers even when the site owner never sees a name. A third-party analytics or ad platform may receive:

  • cookie IDs
  • IP-derived location
  • device and browser information
  • page URLs
  • referrer data
  • ad click identifiers
  • conversion events
  • hashed emails or customer IDs, in some setups

If that data is used for cross-context behavioral advertising, measurement across clients, audience building, or platform enrichment, CCPA obligations may apply.

How Ordinary Analytics Data Becomes a CCPA Question
1
Identifier collected. A tag picks up cookie IDs, IP-derived location, or device data.
2
Sent to a third party. An analytics or ad platform receives page URLs, referrer data, and conversion events.
3
Used beyond your site. The data feeds cross-context behavioral advertising, audience building, or platform enrichment.
4
CCPA obligations apply. Sale/share rules and opt-out rights attach to that data.
Once analytics data is used for cross-context advertising or audience building, CCPA obligations can follow.

Sale, Sharing, and the Sephora Lesson

The Sephora enforcement action is the case every marketing team should know. In 2022, the California Attorney General announced a USD 1.2 million settlement with Sephora alleging that Sephora failed to disclose that it was selling personal information, failed to process opt-out requests sent through Global Privacy Control, and failed to cure the alleged violations.

The important detail is that the case involved common online tracking practices. The California AG described third-party companies receiving information about consumers, including through analytics and advertising technologies. That means a company does not need to sell a spreadsheet to a data broker to create CCPA risk. Allowing third-party trackers to collect personal information on your site can be enough.

Since the CPRA amendments, "sharing" is especially important. It covers disclosures for cross-context behavioral advertising, even where money does not change hands.

What the Sephora Settlement Alleged
DisclosureFailed to disclose that personal information was being sold
Opt-outFailed to process opt-out requests sent through Global Privacy Control
CureFailed to cure the alleged violations
The California Attorney General reached a USD 1.2 million settlement with Sephora in 2022 over these three failures.

A person adjusts privacy settings in a browser on a laptop, reflecting how sites must detect and honor opt-out signals like Global Privacy Control.

Global Privacy Control Is Not Optional

California's Attorney General states that businesses covered by the CCPA must honor a user-enabled Global Privacy Control as a valid request to opt out of sale or sharing. The California Privacy Protection Agency also describes opt-out preference signals as browser or extension settings that automatically send a user's opt-out choice.

In practice, this means your site needs to detect and act on GPC where applicable. A privacy banner that ignores the browser signal is not enough. If a visitor has GPC enabled, do not load sale/share-related advertising pixels and do not send data to vendors for cross-context behavioral advertising unless you have a legally valid reason to do so.

What This Means for Cookies

Under CCPA, cookies fall into several buckets:

Cookie or tag typeTypical CCPA concern
Strictly necessary cookiesusually low, but disclose in privacy policy
First-party aggregate analyticslower risk if not shared or used for ads
Third-party analyticsreview vendor use, contracts, and disclosures
Retargeting pixelshigh risk for sale/share and opt-out
Ad conversion tagsdepends on data sent and vendor use
Data clean room or enhanced conversion tagshigh risk if customer data is uploaded

The safest analytics architecture is first-party, minimal, and purpose-limited. If your analytics provider does not use visitor data across customers, does not build ad profiles, does not set tracking cookies, and does not sell or share personal information, compliance becomes simpler.

A CCPA Checklist for Marketing Analytics

  1. Map every third-party tag. Include Google Analytics, Google Tag Manager, Meta Pixel, LinkedIn Insight Tag, TikTok Pixel, chat tools, heatmaps, affiliate scripts, and A/B testing tools.

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

  • Read vendor terms. Determine whether each vendor acts as a service provider/contractor or uses data for its own purposes. Contract labels matter less than actual data use.

  • Classify data flows. Note whether the tag receives identifiers, page URLs, event names, email hashes, IP addresses, or transaction details.

  • Update notices. Your privacy policy should explain categories of personal information collected, purposes, categories of recipients, retention, and opt-out rights.

  • Implement opt-out controls. Provide a "Do Not Sell or Share My Personal Information" mechanism where required and honor GPC.

  • Gate high-risk tags. Retargeting and cross-context advertising tags should not fire for users who opt out.

  • Minimize event payloads. Do not send names, emails, account IDs, health data, financial details, or free-form form fields to analytics.

  • Keep evidence. Document configuration, vendor decisions, consent/opt-out behavior, and test results.

  • CCPA vs GDPR: Do Not Mix the Rules

    GDPR and the ePrivacy Directive require prior consent for non-essential cookies and similar technologies in Europe. CCPA focuses on notice, access, deletion, correction, and opt-out rights, especially around sale/share. A setup can be acceptable under one regime and not the other.

    For a US-focused website, the biggest CCPA risk is uncontrolled third-party marketing tags. For an EU-facing website, the same tags may also require opt-in consent before they load.

    The Privacy-First Path

    A practical privacy-first analytics stack for CCPA compliance should:

    • avoid third-party advertising identifiers by default
    • avoid using analytics data for cross-context behavioral advertising
    • collect only aggregate metrics needed for site improvement
    • honor GPC where required
    • keep campaign attribution in UTM parameters, not user profiles
    • separate analytics from ad platform enrichment

    CCPA compliance is easier when analytics is not part of an advertising surveillance pipeline. Measure what helps you improve the site. Do not collect data simply because a tag manager makes it easy.

    An analyst reviews a spreadsheet at a desk, similar to the work of keeping a tag register with vendor roles and firing rules up to date.

    Marketing Tag Controls

    Separate collection from sale and sharing. A cookie banner can manage some collection choices, but a CCPA opt-out must also address whether personal information is sold or shared for cross-context behavioral advertising. Do not let retargeting tags, server-side conversion APIs, or audience syncs fire after an applicable opt-out or valid GPC signal.

    Keep a tag register with owner, purpose, data fields, vendor role, consent category, GPC behavior, firing rule, and deletion path. Review it whenever marketing adds a platform or changes campaign measurement.

    Frequently Asked Questions

    CCPA is not a cookie law in the European sense, so it does not say every analytics cookie needs opt-in consent. It instead gives Californians rights over the sale and sharing of personal information, so the practical question is whether a tag discloses, sells, shares, or enables cross-context behavioral advertising with that data.

    Flowsery
    Flowsery

    Start Your 14-Day Free Trial

    Real-time dashboard

    Goal tracking

    Cookie-free tracking

    What counts as personal information under CCPA for analytics?

    California defines personal information broadly, covering anything that identifies, relates to, describes, or could reasonably be linked to a consumer or household. The state Attorney General's CCPA materials list online identifiers and IP addresses within that framing, which is why cookie IDs, device data, and IP-derived location collected by analytics tools can qualify.

    What happened in the Sephora CCPA settlement?

    In 2022 the California Attorney General announced a USD 1.2 million settlement with Sephora. The state alleged that the company failed to disclose it was selling personal information, failed to process opt-out requests sent through Global Privacy Control, and failed to cure the violations. The case involved ordinary online tracking tools, not a data sale to a broker, which is why marketing teams treat it as the reference case.

    Do we have to honor Global Privacy Control (GPC) signals?

    The California Attorney General states that businesses covered by CCPA must honor a user-enabled Global Privacy Control as a valid request to opt out of sale or sharing. A privacy banner that ignores the browser signal is not enough. If a visitor has GPC enabled, sale and share-related advertising pixels should not load unless a legally valid exception applies.

    What is the difference between "sale" and "sharing" under CCPA?

    Since the CPRA amendments, "sharing" specifically covers disclosures made for cross-context behavioral advertising, even when no money changes hands. That means a company does not have to sell a spreadsheet to a data broker to trigger CCPA obligations, letting third-party trackers collect personal information on a site can be enough.

    Which cookies carry the highest CCPA risk?

    Retargeting pixels carry high risk for sale and share obligations along with opt-out handling. Data clean room or enhanced conversion tags carry high risk when customer data is uploaded to them. First-party aggregate analytics that is not shared or used for ads carries lower risk, while strictly necessary cookies are usually low risk but still need to be disclosed in the privacy policy.

    Do we need to sell data to a broker to trigger CCPA obligations?

    No. The Sephora case shows that allowing third-party trackers, including ordinary analytics and advertising technologies, to collect personal information on a site can itself create CCPA risk. The California Attorney General described third-party companies receiving consumer information through those tools as part of the alleged violation.

    What should a CCPA-compliant tag register include?

    A tag register should list the owner, purpose, data fields collected, vendor role, consent category, GPC behavior, firing rule, and deletion path for each tag. It should be reviewed whenever marketing adds a platform or changes campaign measurement, since retargeting tags, server-side conversion APIs, and audience syncs all need to stop firing after an applicable opt-out or valid GPC signal.

    Yes. GDPR and the ePrivacy Directive require prior consent for non-essential cookies in Europe, while CCPA focuses on notice, access, deletion, correction, and opt-out rights, especially around sale and sharing. A setup can be acceptable under one regime and not the other, so a US-focused site's biggest CCPA risk, uncontrolled third-party marketing tags, also needs opt-in consent on an EU-facing site.

    What makes an analytics setup "privacy-first" under CCPA?

    A privacy-first stack avoids third-party advertising identifiers by default, avoids using analytics data for cross-context behavioral advertising, and collects only aggregate metrics needed for site improvement. It also honors GPC where required, keeps campaign attribution in UTM parameters instead of user profiles, and separates analytics from ad platform enrichment.

    Was This Article Helpful?

    Let us know what you think!

    See us more often in Google

    One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

    Before you go...

    Flowsery

    Flowsery

    Revenue-first analytics for your website

    Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.

    Real-time dashboard

    Goal tracking

    Cookie-free tracking

    Related Articles