Join our Newsletter — 33% off our NHI Course

How should organisations classify data sharing under the CPRA when third parties use consumer data for targeted advertising?

Under the CPRA, data sharing happens when personal information is disclosed to a third party for cross-context behavioural advertising. Organisations should distinguish that from disclosures to service providers or contractors, which are governed by tighter use limits and are not treated the same way. The practical test is whether the disclosure supports targeted advertising based on activity across distinct businesses or services.

How CPRA treats targeted advertising disclosures

Under the CPRA, the key distinction is not simply that data leaves the organisation, but why it is disclosed and how the recipient uses it. If a third party receives consumer data and uses it for cross-context behavioural advertising, that is treated as data sharing. If the recipient is a service provider or contractor acting within tighter contractual limits, the disclosure is handled differently.

What makes a disclosure “sharing” instead of a limited business disclosure?

The practical test is whether the disclosure enables targeted advertising based on activity across distinct businesses or services. That makes the recipient’s use central to the classification. If the transfer is designed to support ad targeting across contexts, the organisation should expect the CPRA sharing analysis to apply, even when the data flow looks operational on the surface.

That distinction matters because the same dataset can be handled in very different ways depending on the recipient’s role. A disclosure to a service provider or contractor is meant to support a defined business purpose, not independent ad use. A disclosure for targeted advertising is closer to a secondary use case that changes the legal character of the transfer.

How organisations should operationalise the distinction

Classification should start with the recipient’s permitted use, then move to the actual commercial purpose of the disclosure. If the third party is allowed to combine or use the data for advertising across separate services, the organisation should treat the transfer as sharing and document that decision in its privacy governance. If the recipient is restricted to processing on behalf of the business, the disclosure should be documented and controlled as a service-provider or contractor relationship.

That means privacy teams, ad-tech owners, and contract owners need the same underlying facts: who receives the data, what they can do with it, whether the data supports cross-context ad targeting, and whether the arrangement preserves the tighter limits expected of a processor-like relationship. Without that evidence, classification becomes inconsistent and hard to defend.

Risk and Threat Considerations

Misclassifying targeted-advertising disclosures can create legal exposure, notice failures, and weak consent or opt-out handling. It can also hide the real downstream use of consumer data, which makes vendor oversight and privacy controls harder to trust.

Failure mechanism: The organisation treats an advertising disclosure as a limited operational transfer, so the recipient’s broader use for cross-context behavioural advertising is not surfaced in notices, contracts, or preference handling.

Impact: Consumers may lose the ability to understand or control data sharing, and the organisation may face compliance gaps, inaccurate records, and avoidable enforcement or remediation work.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022, GDPR and SOC 2 (AICPA) define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OC-01 — Organizational Context CPRA sharing decisions depend on business context and third-party roles.
Recommendation — Document who receives consumer data and what advertising use is permitted.
ISO/IEC 27001:2022 A.5.34 — Privacy and Protection of PII The question concerns lawful handling and disclosure of personal information.
Recommendation — Classify disclosures and align notices, contracts, and retention with privacy obligations.
GDPR Art. 5 — Principles relating to processing of personal data Data-use purpose and disclosure limits are central to privacy classification.
Recommendation — Tie each disclosure to a clearly stated purpose and limit downstream use.
SOC 2 (AICPA) CC6.1 — Logical Access Security Software, Infrastructure, and Architecture Third-party access limits and monitoring support controlled disclosure decisions.
Recommendation — Restrict third-party data access to the intended business purpose and review it regularly.

Practitioner Guidance

What to verify: Confirm the recipient’s actual use rights, not just the data flow label. If the third party can use consumer data for ad targeting across separate businesses or services, classify the arrangement as sharing and test the contract and notice language against that fact.

Decision rule: If the recipient only processes data on the organisation’s behalf under strict use limits, keep it in the service-provider or contractor lane. If the recipient can use the data to influence advertising outside the original business context, treat the disclosure as CPRA sharing and align the governance model accordingly.

Practitioner takeaway: The safest classification is the one that follows the recipient’s permitted use, because CPRA analysis turns on whether the disclosure supports cross-context advertising, not just whether data was handed to a third party.