The Marketing Data Problem

Modern marketing depends on data. Knowing who your customers are, what they have purchased, what they have looked at online, what they are likely interested in buying, and how to reach them with targeted communications is the foundation of digital marketing. The data that enables this capability — purchase history, browsing behavior, demographic information, location data, and the profile data assembled by data brokers and advertising platforms — is subject to an increasingly complex web of legal restrictions that govern how it can be collected, used, and shared.

The fundamental tension in data-driven marketing is between the commercial value of rich consumer data and the consumer’s interest in controlling how their personal information is used. Privacy laws attempt to resolve this tension by giving consumers specified rights over their data and requiring businesses to be transparent about how they use it. Understanding what these laws require is not optional for any business that engages in targeted advertising, operates an email marketing program, uses tracking technologies on its website, or shares customer data with advertising partners.

CCPA and CPRA: The California Privacy Framework

The California Consumer Privacy Act, amended and expanded by the California Privacy Rights Act, is the most comprehensive US state privacy law and has had significant nationwide impact because of California’s size and the practical difficulties of operating different data practices for California residents versus those in other states. The CPRA applies to businesses that do business in California and meet one of three size thresholds: annual gross revenues over $25 million; annually buy, sell, or share personal information of 100,000 or more consumers or households; or derive 50 percent or more of annual revenues from selling personal information.

For marketing purposes, the CPRA’s most significant provisions address the sale and sharing of personal information. Selling personal information — which under CCPA/CPRA means any exchange for monetary or other valuable consideration — requires that consumers be given notice and an opportunity to opt out through a Do Not Sell or Share My Personal Information link. Sharing personal information for cross-context behavioral advertising purposes — even without monetary exchange — is also covered by the opt-out right. This sharing definition captures the common practice of sharing customer data with advertising platforms like Google and Meta for targeted advertising, which many businesses had not previously considered a sale of personal information.

The CPRA also imposes restrictions on the use of sensitive personal information for advertising purposes. Sensitive personal information includes precise geolocation data, racial or ethnic origin, religious beliefs, health information, and certain other categories. Businesses that use sensitive personal information for advertising must provide consumers with the right to limit its use, and the CPRA restricts the purposes for which sensitive personal information may be used.

Other State Privacy Laws

Following California’s lead, numerous states have enacted or are in the process of enacting comprehensive privacy laws. Virginia’s Consumer Data Protection Act, Colorado’s Privacy Act, Connecticut’s Data Privacy Act, Texas’s Data Privacy and Security Act, and laws in Florida, Montana, Oregon, and other states have created a growing patchwork of state privacy requirements. While these laws share many common elements — rights to access, correct, delete, and opt out of sale — they differ in important ways including their applicability thresholds, their definitions of sensitive data, and their specific requirements for targeted advertising.

For businesses that engage in targeted advertising, the most practically significant requirement across most state privacy laws is the right to opt out of targeted advertising, which is defined in most statutes as advertising based on personal data obtained from the consumer’s activity across non-affiliated websites, applications, or online services. This definition is broad enough to capture most forms of third-party cookie-based targeting, device fingerprinting, and behavioral advertising based on purchased data profiles. Businesses must provide a clear and conspicuous mechanism for consumers to exercise this opt-out right.

Tracking Technologies and Consent Requirements

The use of cookies, pixels, beacons, and other tracking technologies on websites implicates privacy law requirements in multiple ways. Under the CPRA and most other comprehensive state privacy laws, the collection of personal information through tracking technologies is subject to the privacy notice requirements and, where the information is used for targeted advertising, the opt-out right. The California Privacy Protection Agency has issued regulations addressing the use of dark patterns in consent interfaces, specifically prohibiting user interfaces that are designed to cause consumers to abandon their privacy rights rather than exercise them.

Businesses that serve the European market are also subject to the EU’s General Data Protection Regulation and the ePrivacy Directive, which require affirmative opt-in consent for most tracking cookies. Even businesses based entirely in the United States may face GDPR obligations if they have European customers or website visitors, and the GDPR’s consent standards are significantly more demanding than US law. Many businesses have implemented cookie consent management platforms to handle the varying consent requirements across jurisdictions.

Email Marketing and Data Privacy

CAN-SPAM governs commercial email at the federal level, but it does not restrict how a business uses customer data to determine who to email — it focuses on the content of the email and the opt-out mechanism, not on the lawfulness of the sender’s data practices. State privacy laws add a layer of data use restrictions that CAN-SPAM does not address. Under the CPRA, for example, if a business shares its email subscriber list with a third-party email marketing service, that sharing may constitute a sale of personal information that requires consumer opt-out rights. A business that purchases an email list from a data broker and uses it for marketing may be engaging in use of purchased personal information in ways that require disclosure in the business’s privacy policy.

State privacy laws also give consumers the right to know what personal information a business has collected about them and how it has been used, the right to correct inaccurate information, and in many states the right to delete their personal information. For email marketing programs, this means that a business must be able to fulfill consumer rights requests related to email addresses and marketing profiles, including identifying all data associated with a consumer’s email address, providing it upon request, correcting it if inaccurate, and deleting it if requested.

Building a Privacy-Compliant Marketing Program

For businesses that engage in data-driven marketing, building a privacy-compliant program requires addressing several foundational elements. Privacy notices must accurately describe the categories of personal information collected, the purposes for which it is used, and whether it is sold or shared with third parties for advertising purposes. The notice must be updated when data practices change and must be presented in a way that consumers can understand.

Opt-out mechanisms must be functional and easy to use. The CPRA and most other state privacy laws require that opt-out requests be honored within specific time periods — typically 15 to 45 days — and that the business stop using opted-out consumers’ data for the requested purpose promptly. Data service agreements with advertising partners, analytics providers, and other third parties who receive consumer data must include appropriate provisions ensuring that those parties handle the data consistently with the business’s privacy obligations. Regular privacy audits that map data flows, identify consent and notice gaps, and verify that contractual and technical controls are functioning as intended are an essential component of maintaining ongoing compliance in a dynamic regulatory environment.

See Also