CCPA (California Consumer Privacy Act) is a consumer privacy law in effect in California. It was expanded in 2023 by CPRA (California Privacy Rights Act), which also created a dedicated agency (CPPA) to oversee the law.
The law regulates personal data processing in a manner similar to GDPR, but uses a different framework: instead of consent, the “opt-out” right sits at its center. From an ad measurement standpoint, the most critical concept is the definition of “selling” or “sharing” data; third-party data sharing for advertising purposes often falls within the scope of this definition.
The official page of the California Privacy Protection Agency (CPPA) states that the agency is tasked with protecting consumer privacy rights and offers tools such as complaint handling and the “Delete Request and Opt-out Platform.” Meta’s data processing options documentation confirms that California is one of the states covered under Limited Data Use.
What Is CCPA/CPRA?
CCPA is a law that defines the rights of California residents over their personal data, including the right to access information, request deletion, and opt out of the sale/sharing of their data. CPRA expanded these rights and added a sensitive personal information category.
An opt-out model, not consent
While GDPR generally requires consent before processing data, under CCPA data processing can continue by default. The user has to exercise the right to decline — this is the most fundamental difference between the two laws.
Scope depends on specific thresholds
The law doesn’t cover every business — only those that exceed certain revenue or data volume thresholds. A small local business and a large advertiser may not carry the same obligations.
Why Does the “Sell/Share” Definition Matter?
CCPA’s most direct impact on ad measurement comes from how broadly the concepts of “sale” and “sharing” are defined.
Data sharing for advertising purposes can fall under this definition
Sending a user’s data to an ad platform (Meta, Google) may not be a “sale” in the traditional sense, but it can fall under CCPA’s definition of “sharing.” That’s why ad measurement setups also fall within the scope of the law.
For example, for a California-based e-commerce site with 10,000 monthly visitors, the behavioral data of these visitors sent to Meta or Google through an ad pixel may be subject to the opt-out right because it falls under the “sharing” definition.
The business must provide an opt-out mechanism
The site must have a visible link such as “Do Not Sell or Share My Personal Information,” and this request must actually be processed. A visible but non-functional link may look like compliance, but it doesn’t eliminate the risk. The marketing team needs to build a process that removes this request from both ad campaigns and the email list within a week.
What’s the Impact on Ad Measurement?
When a user files an opt-out request, ad-related data sharing for that user stops.
Its connection to Meta’s Limited Data Use
Meta Limited Data Use (LDU) is designed for compliance with state laws like CCPA. California is one of the states covered; that’s why enabling LDU also targets CCPA compliance.
The impact applies to opt-outs, not all traffic
Measurement narrowing caused by CCPA can remain limited to a smaller group of users who filed opt-out requests, rather than the broad consent-decline rate seen under GDPR. Even so, this group still needs to be factored into data quality considerations.
Pre-Launch Checklist
When evaluating CCPA/CPRA compliance from a measurement standpoint:
- Does the site have a “Do Not Sell or Share My Personal Information” link, and does it actually work?
- Does the opt-out request genuinely stop the data flow sent to ad platforms?
- Has Meta Limited Data Use or a similar option been enabled for California traffic?
A Common Mistake
The most common mistake is treating CCPA purely as a text notice (a privacy policy update) without ever testing whether the opt-out request is actually reflected in the ad platforms.
Summary
CCPA/CPRA grants California residents the right to opt out of the sale/sharing of their data. Unlike GDPR, it’s built on an opt-out model rather than consent — but it still directly affects data sharing for advertising purposes. Options like Meta’s Limited Data Use are among the concrete tools for complying with this law.