Nearly every B2C brand advertises online. However, many are not fully prepared to tackle the ever-increasing complexities that come with digital advertising under U.S. state privacy laws.
For example, do advertisers disclose consumer personal information to adtech companies for retargeting? Of course they do—and that requires a contract with special terms dictated by the California Consumer Privacy Act (CCPA). How about disclosures to service providers for measurement purposes? The CCPA (and other state privacy laws) requires different terms for that. And these aren’t empty requirements; we’ve already seen six- and seven-figure settlements from the California Attorney General and the California Privacy Protection Agency (CPPA) for companies that couldn’t produce these contracts, among other issues.
When disclosing personal information to adtech partners, how do advertisers ensure their partners process it lawfully? Advertisers can, in certain circumstances, be held liable for unlawful downstream processing by recipients. Indeed, the California Attorney General’s $1.55 million settlement with Healthline Media included an allegation that Healthline did not impose proper limitations on downstream use of its visitors’ personal information.
We know how difficult this problem can be. Finding a scalable solution that accounts for the requirements of a patchwork of state privacy laws (each with varying degrees of idiosyncrasies) and doesn’t introduce unreasonable amounts of deal friction is a serious challenge with real dollars at stake. The IAB has a solution to the advertiser privacy compliance challenge: the Fifth Amended and Restated Multi-State Privacy Agreement (MSPA), which takes effect on June 2, 2026.
The MSPA Solves Advertisers’ Contractual Privity Issues
Whenever advertisers disclose their customers’ personal information to adtech intermediaries for targeting purposes (e.g., retargeting, targeting as part of a segment), they engage in a “sale” or “share” of personal information under the CCPA, with very limited exceptions. These disclosures require a contract with limitations set by law, including the “limited and specified” purposes for which the downstream entity can use the personal information.
When advertisers disclose personal information for measurement purposes (a near-ubiquitous activity), they typically enter into “service provider/processor” terms to ensure their data is used solely on their behalf. Those contracts also require similar purpose specifications.
Advertisers face two issues here. First, they often do not have direct privity with the adtech vendor. Second, even if they do have privity, their standard Data Processing Addenda (DPAs) may not contain the level of detail required under the CCPA and implementing regulations.
On the first issue, advertisers often rely on agency contracts with adtech vendors to receive services. In this case, when an advertiser sends its customer data to a vendor (e.g., a demand-side platform or measurement vendor), it may outsource privacy protection to its agency’s agreement with that adtech company—an agreement it may not always have insight into. The CCPA and regulations are clear that this does not suffice; disclosing entities need direct privacy-related terms with the vendor itself. The MSPA is a set of privacy-protective terms that spring into place between all signatories that receive personal data, creating direct privity with each entity as required under applicable U.S. state privacy laws and solving the “agency contract” issue that advertisers frequently face.
Other contractual privity gaps also exist. For example, advertisers typically enter into processor/service provider relationships with many adtech partners, including measurement companies. When pixels associated with those partners are included in ad creatives and fire on a publisher’s page, the resulting data flow can constitute a “sale” from the publisher to the advertiser—often without the contract required under the CCPA. The MSPA addresses this contracting gap as well.
On the second issue, advertisers might be surprised to find that their DPAs with adtech vendors used for targeting purposes do not include the level of detail required under the CCPA. As seen in Healthline, DPAs with these third parties must list the specific use cases for which they can process data. Many DPAs include vague language, such as permitting the third party to use the data for purposes contemplated under the agreement, for internal uses, any business purpose, or “as otherwise agreed to in writing by the parties.” None of these suffice.
Consistent with the CCPA and related enforcement actions, the MSPA lists each “limited and specified” digital advertising activity for which signatories may process personal information. It also includes all other required terms under U.S. state privacy laws, including those required when engaging processors/service providers for measurement purposes.
This requirement has real teeth. In Healthline, Honda, and Todd Snyder, California regulators requested copies of agreements with adtech vendors, and each company was fined, among other things, for failing to produce legally compliant agreements or for lacking required terms.
The MSPA Helps Advertisers Meet Diligence Requirements
State privacy laws include diligence requirements that apply to advertisers’ disclosures of personal information. Advertisers must take “reasonable and appropriate steps” to ensure that their adtech partners use personal data in a manner consistent with the law—for example, by including mandatory audit provisions in their contracts.
Most significantly, the CPPA promulgated a regulation stating that whether a business conducts diligence of partners with whom it discloses personal information is a material factor in determining liability for those partners’ wrongdoing.
The IAB has been at the forefront of efforts to help companies with privacy compliance through the release of the IAB Diligence Platform, powered by Safeguard Privacy. The MSPA also supports diligence by providing a transparent set of privacy terms that attach to the personal information advertisers disclose. Any other adtech partner receiving that information—even if not directly from the advertiser—agrees to the same terms. This relieves advertisers of the burden of requesting downstream contracts from counterparties, which are often resisted for confidentiality and other reasons.
The MSPA Enables a National Approach to Compliance, Reducing Costs and Deal Friction
It is no longer practical to take a state-by-state approach to compliance. In our experience, advertisers recognize this but often struggle to operationalize a national strategy.
The MSPA makes nationwide compliance with state privacy laws more efficient and scalable by providing all required contract terms to effectuate compliance, eliminating the need for separate DPAs among MSPA signatories. In doing so, it unburdens legal departments and provides a scaled contracting solution.
Furthermore, the MSPA aligns with market realities:
- By default, all MSPA signatories that receive personal information from an advertiser are “processors/service providers” to that advertiser, except when a disclosure is for targeted advertising purposes (in which case they are a “third party” under the CCPA for that use case only).
- When a consumer opts out of “sales,” “shares,” or “targeted advertising” on the advertiser’s digital property, the advertiser must suppress that consumer’s personal information from disclosure unless the disclosure is for a non-targeted advertising purpose (e.g., brand or sales lift, attribution measurement, anti-fraud, suppression/“negative targeting”).
- Advertisers do not need to send Global Privacy Platform signals or make engineering changes.
Digital advertising compliance is no longer theoretical. Regulators are requesting contracts. They are scrutinizing use-case specificity. And they are imposing meaningful penalties when businesses cannot demonstrate that downstream disclosures are properly governed.
The MSPA offers advertisers what the market has long needed: a uniform, scalable, privacy-forward contracting framework that addresses privity gaps, meets state-law specificity requirements, supports diligence obligations, and reduces friction across the ecosystem. Rather than renegotiating bespoke DPAs across dozens of partners—and hoping they satisfy evolving regulatory expectations—advertisers can rely on a standardized set of enforceable terms tailored to digital advertising.