5.3 Online Tracking, Profiling, and Digital Advertising Basics

Key Takeaways

  • First-party cookies are set by the site the user is visiting; third-party cookies are set by another domain — pixels, SDKs, device fingerprinting, customer match, and probabilistic IDs continue tracking after third-party-cookie restrictions
  • State comprehensive laws typically grant opt-outs of sale, sharing (California's cross-context behavioral advertising term), and targeted advertising, plus consent-style limits on sensitive data
  • Global Privacy Control is a 2026 exam fact: California recognizes it as a CCPA opt-out preference signal (honor duty since 1 January 2023; 2026 regulations require showing the signal was processed), Colorado designated it as a UOOM effective 1 July 2024, and Connecticut and other adopting states require universal opt-out mechanisms
  • Device fingerprinting and hashed customer-match lists are personal-data / sale-share-targeted-ad facts, not anonymous technical logs
  • TCPA and CAN-SPAM still apply when tracking feeds marketing texts or commercial email; those statutes are Domain II — a cookie banner is not TCPA consent
Last updated: August 2026

Online Tracking, Profiling, and Digital Advertising Basics

Domain I.C performance indicator 5 asks you to identify privacy issues unique to the online environment, and the Body of Knowledge's parenthetical is the syllabus: tracking and profiling. This section is the technical and state-law map. Federal marketing statutes — the Telephone Consumer Protection Act (TCPA), the Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM), and the Telemarketing Sales Rule — get their own Domain II chapter. Know they overlap. Do not try to litigate consent language here. Domain V later tests the full state cookie-and-tracking rule set; here you need the basics that every I.C question assumes.

The tracking toolkit

Cookies are small files a site or its partners store in the browser.

  • A first-party cookie is set by the domain the user is visiting. It can be necessary (session, load balancing) or used for analytics and advertising on that site.
  • A third-party cookie is set by a different domain — historically an ad network present on thousands of publishers. Browser restrictions have reduced third-party cookies. That did not end tracking. It shifted spend to first-party identifiers, pixels, software development kits, fingerprinting, and uploaded customer lists.

A pixel (web beacon) is typically a 1×1 image or script that causes the browser to request a URL on a tracker. Opening an email or loading a checkout page can fire a pixel that reports the event, a cookie identifier, and often a hashed email.

An SDK (software development kit) is code a mobile app embeds. The SDK can collect device identifiers, location, and in-app events and send them to an analytics or advertising company. An app-store nutrition label does not replace a privacy notice or a vendor contract.

Device fingerprinting identifies a browser or device from a combination of attributes — user-agent, fonts, canvas rendering, time zone, IP address — without storing a cookie. It is harder for the user to see or delete. Comprehensive state laws still treat the resulting identifier as personal data when it can reasonably be linked to a person or household. "We do not use cookies" is not a defense if you fingerprint.

Customer match (a customer-list upload) is the practice of hashing emails, phone numbers, or other identifiers and sending them to an advertising platform so the platform can find those people in its logged-in user base. It is first-party data leaving the company and becoming a targeting input. Under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), that can be a sale or a share — California's term for disclosing personal information for cross-context behavioral advertising — depending on the commercial terms. Under Colorado/Connecticut-style statutes, it is often targeted advertising or a sale.

Probabilistic identification infers that two devices belong to the same person from behavior and attributes (same Wi-Fi, similar locations). Deterministic identification uses a login or another confirmed identifier. Probabilistic graphs are less accurate and harder to explain in a notice, which is why they are a favorite "what did we actually disclose?" fact pattern.

Profiling and targeted advertising under state laws

Profiling is automated processing of personal data to evaluate, analyze, or predict aspects of a person — preferences, location, health, economic situation, reliability. Targeted advertising (definitions vary by statute) is generally displaying ads based on personal data obtained from the consumer's activities across nonaffiliated websites or applications.

What 2026 comprehensive state laws typically give consumers — the exact verbs depend on the statute:

Right or limitWhat to look for on the exam
Opt out of saleMoney or other valuable consideration for personal data
Opt out of share (California)Cross-context behavioral advertising, even without money changing hands
Opt out of targeted advertisingColorado, Connecticut, and the Virginia-style statutes
Opt out of certain profilingProfiling in furtherance of decisions that produce legal or similarly significant effects
Sensitive-data limitsPrecise geolocation, health, race or ethnicity, religion, sex life or orientation, biometric, genetic, and similar categories — often consent before sale or targeted advertising

A first-party product-recommendation engine on the retailer's own site is usually not "targeted advertising" under those statutes. A pixel that follows the user from the retailer to a news site and then shows the abandoned cart is.

GPC and universal opt-out — a 2026 exam fact

A universal opt-out mechanism (UOOM) — California regulations also use opt-out preference signal (OOPS) — is a browser or device setting that tells every site "opt me out" so the consumer does not have to click each privacy link.

Global Privacy Control (GPC) is the signal the exam expects you to name.

  • The California Attorney General has recognized GPC as a valid CCPA opt-out preference signal. California's duty to honor such signals has been in force since 1 January 2023. Revised CCPA regulations effective 1 January 2026 add an operational requirement: covered businesses must be able to show the consumer that the signal was processed, not merely claim they honor it.
  • The Colorado Attorney General formally designated GPC as a UOOM under the Colorado Privacy Act. Covered controllers must treat a valid GPC signal from a Colorado consumer as an opt-out of sale and targeted advertising beginning 1 July 2024.
  • The Connecticut Data Privacy Act and a growing list of other comprehensive state privacy laws require controllers to honor universal opt-out or preference signals. States that have adopted such duties include, among others, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, and Texas. Do not memorize an unofficial "N states" headline as if IAPP published a single official count. Do memorize that California, Colorado, and Connecticut are the teaching core, and that a 2026 exam treats GPC as a real legal signal, not a browser novelty.

Where required, a GPC signal is a preference. It should write to the same source of truth as the "Do Not Sell or Share" link. It generally does not opt the consumer out of strictly necessary processing, and some statutes allow a later consent to override.

Overlap with federal marketing statutes — keep it light

Tracking that feeds an email campaign still has to satisfy CAN-SPAM (truthful headers, a working unsubscribe). Tracking that feeds a marketing text or autodialed call still has to satisfy TCPA (prior express consent; prior express written consent for autodialed or prerecorded marketing to wireless numbers). Those statutes are Domain II. The Domain I point is: a cookie banner, a GPC signal, and a TCPA consent checkbox are different legal instruments. Honoring one does not satisfy the others.

Scenario. A national retailer drops a third-party pixel on checkout, uploads hashed emails for customer match, and later texts "you left something in your cart." A California or Colorado resident with GPC enabled has already sent an opt-out of sale, share, and/or targeted advertising. Using the pixel and the match list for cross-context ads without honoring that signal is a state-law opt-out failure. The cart text is a TCPA question. The privacy notice that said "we do not share your email with advertisers" is a Section 5 question. One checkout, three theories. That is the exam.

Exam traps. Do not say third-party-cookie deprecation ended online tracking. Do not treat fingerprinting or hashed customer-match lists as anonymous. Do not call GPC optional in California or Colorado in 2026. Do not use a cookie banner as a substitute for TCPA consent. Do not dump the full Domain V cookie-rule matrix into an I.C answer.

Loading diagram...
Online Tracking Tools and the Opt-Out Fork
Test Your Knowledge

Which statement correctly distinguishes a first-party cookie from device fingerprinting?

A
B
C
D
Test Your Knowledge

As of 2026, how should a CIPP/US candidate treat Global Privacy Control?

A
B
C
D
Test Your Knowledge

A retailer uploads hashed customer emails to an ad platform for customer match and also plans a marketing text campaign. Which pairing is most accurate?

A
B
C
D