Turn Every Shopper Into a Known Customer

Brij Signal Compliance Guide: CCPA, CIPA, and Cookie Consent Explained

Audrey Buck
July 30, 2026
Compliance Guide
Takeaways
  • Brij Signal is built to help brands meet CCPA and CIPA requirements by only sending a purchase event to Meta, Google, or TikTok once the consent signals those laws require have been recorded, extending a brand's existing cookie consent setup to its ad platform destinations.
  • Under the CCPA, sending purchase data to ad platforms for retargeting or lookalike audiences is generally treated as "sharing" personal information, which requires a consumer opt-out mechanism, and Brij Signal's consent-gated sending is designed to honor that opt-out automatically.
  • Brij Signal uses a brand's existing cookie consent platform, such as OneTrust, Cookiebot, or Shopify's customer privacy API, tracking the same consent preferences a shopper can set on the brand's website.
  • Brij Signal uses those consent preferences to compliantly silence events per the CMP's configuration, so purchase data only reaches an ad platform when the region's consent requirement is met.

Brands sending retail purchase data to Meta, Google, or TikTok through Brij Signal are operating under two legal regimes (CCPA and CIPA) plus platform requirements like Google Consent Mode. This guide walks through what each one requires, what that means for your own setup, and how Brij Signal is built to support a compliant configuration.

Brij Signal is engineered so a compliant setup is easy: consent-gated sending, compatibility with standard cookie management platforms, and hashed match data. It does not, by itself, guarantee that your brand's cookie banner, privacy policy, or opt-out flow meets these requirements. That determination is always yours to make, with your own legal counsel.

CCPA: "Sharing" Purchase Data with Ad Platforms

The CCPA defines "sharing" as disclosing a consumer's personal information to a third party for cross-context behavioral advertising, meaning using someone's data across sites and channels to target or model ads, whether or not any money changes hands (Source: California Attorney General, oag.ca.gov). Consumers have had an opt-out right specifically for sharing, separate from selling, since January 1, 2023.

What's required of brands: if purchase events are flowing to Meta, Google, or TikTok for retargeting, lookalike modeling, or conversion optimization, that flow is very likely a "share" under the CCPA. Your privacy policy and your do-not-sell-or-share mechanism need to account for it, the same way they already account for pixels on your main site.

How Brij Signal supports this: Brij Signal sends events on a per-destination, consent-gated basis. A brand configures which consent categories are required before an event reaches each ad platform, so when a consumer opts out through your own banner, that choice is what determines whether the event sends, not a default setting Brij controls.

CIPA: Pixel Timing and Recorded Consent

Separately from the CCPA, plaintiffs' firms are using CIPA, largely Section 638.51, to argue that ad-platform tracking pixels function as illegal "pen registers" when they fire before a visitor has made a recorded consent choice (Source: Loeb & Loeb, April 2026).

What's required of brands: pixels and server-side sends need to wait for, and then honor, the consent choice a visitor actually made. A banner that displays but doesn't stop tracking underneath it is the exact pattern driving this litigation.

How Brij Signal supports this: Brij Signal doesn't forward a purchase event by default. It sends only when it has a recorded consent signal for the categories a given destination requires. If a brand hasn't enabled a cookie banner at all, there's no signal to check against, so the event is blocked rather than sent.

Google Consent Mode: The Signals Relevant to Ad Platforms

Consent Mode v2 exists because of EU/UK requirements (GDPR and the ePrivacy Directive); if you have EU/UK traffic, GDPR applies directly and is a separate obligation beyond the US laws covered here.

Google Consent Mode v2 standardizes consent into four parameters relevant to ad platforms: ad_storage, analytics_storage, ad_user_data, and ad_personalization (Source: Google Tag Manager Help). Without all four passed correctly, remarketing lists shrink, lookalike and Demand Gen audiences stop qualifying, and campaigns that depend on them stop running.

What's required of brands: your CMP needs to actually push all four parameters, not just display a banner. This is a configuration step inside your consent platform, not something that happens automatically once a banner is installed.

How Brij Signal supports this: Brij Signal reads Google Consent Mode signals and obeys them per ad platform destination, translating them into a send or no-send decision for each one, so Meta, Google, and TikTok can each have independent requirements without extra setup work on your end.

Cookie Categories and How They Map to Ad Platform Requirements

Every cookie banner, whether it's a dedicated CMP like OneTrust or Cookiebot, Shopify's customer privacy API, or a built-in banner, sorts a visitor's choice into standard categories: essential, functionality, personalization, analytics, and advertising (sometimes labeled "targeting" or "marketing"). Those categories are what get translated into Google Consent Mode's parameters.

What's required of brands: you need a working CMP that correctly categorizes visitor choices and passes them through, and you need to know which categories each ad platform actually requires.

How Brij Signal supports this: Brij Signal integrates with standard CMPs via our "Custom Code" feature. Brij captures the user consent preferences and uses them to compliantly silence events when consent does not meet the regional requirement, per the CMPs’ configuration.

Hashed Data and the CCPA "Personal Information" Test

Hashing a phone number or email before it reaches an ad platform's Conversions API reduces exposure, but it doesn't exempt the data from the CCPA. If a hashed identifier can still be matched back to a real person, which is the entire point of a match key, regulators generally treat it as personal information rather than de-identified data. That's the general posture privacy counsel tends to take; specifics vary by jurisdiction, so confirm your own exposure with your own counsel rather than treating this as legal advice.

What's required of brands: don't treat hashing as a compliance shortcut in your own disclosures. Hashed match data sent to an ad platform should still be described as personal information being shared, not as de-identified data.

How Brij Signal supports this: Brij Signal hashes identifiers like phone numbers and emails before they reach an ad platform's Conversions API, which reduces exposure in transit. That's a security control, not a substitute for your own CCPA disclosures.

Compliance Is Always the Brand's Responsibility

Brij Signal is built with the tools to make a compliant setup possible: consent-gated sending per ad platform, compatibility with standard CMPs and Google Consent Mode, and hashed match data. These are commonly used, well-tested configurations. 

However, legal compliance under the CCPA, CIPA, and every other applicable law is always the brand's responsibility, not Brij's. Using Brij Signal does not, by itself, mean your cookie banner, privacy policy, or opt-out flow is correctly configured. That determination, and the risk of getting it wrong, stays with the brand and its own legal counsel.

If you want to see how Brij Signal's consent controls work for your brand, schedule time with us here



Sources