All prompts
Analyze
Analyze a statute against the conduct you actually have
Breaks a statute into elements, exceptions, and definitional traps, then says plainly whether your client's conduct is covered, clear, or a genuine close call.
Your prompt
2
Pressure-test it
3
Go deeper
Before you run it
What to gather first
Watch for
What comes back
See an example of what you’ll get
*(After you answer the four questions: you are working from the enacted CCPA as amended by the CPRA rather than the CPPA's regulations, the client is already a covered business so threshold coverage is not the question, you hold no agency guidance or enforcement action on conduct like this, and the decision is "how do we do this defensibly" rather than "can we do this at all.")*
Bottom line. Close call, leaning covered. The transfer is almost certainly a "share" for cross-context behavioral advertising even though no money changes hands, and the aggregation carve-out does not survive the hashed email addresses.
Citation. Cal. Civ. Code §§ 1798.100, 1798.120, 1798.140 (CCPA as amended by CPRA, eff. Jan. 1, 2023).
Scope. A "business" doing business in California that meets one of three thresholds: over $25M gross annual revenue, personal information of 100,000+ consumers or households, or 50%+ of revenue from selling or sharing personal information. § 1798.140(d)(1). At $40M revenue the client clears the first threshold on its own.
Elements of "share."
1. *Personal information*: "information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household." § 1798.140(v)(1).
2. *Disclosure to a third party*: "sharing, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means." § 1798.140(ah)(1).
3. *For cross-context behavioral advertising*: targeting based on activity across nonaffiliated sites. § 1798.140(k).
4. Consideration is not an element of "share," unlike "sell." § 1798.140(ah)(1) ("whether or not for monetary or other valuable consideration").
Definitional traps.
- "Share" does not require payment. The client's belief that receiving no money keeps them out of scope is the single biggest error in the current posture.
- "Personal information" expressly includes "inferences drawn" and household-level data, § 1798.140(v)(1)(K), so the returned audience segments are themselves personal information coming back in.
- "Deidentified" under § 1798.140(m) requires reasonable measures plus a public commitment plus contractual downstream obligations. A hash is a pseudonym, not deidentification.
Text versus agency position. The CPPA's rulemaking on ADMT and risk assessments treats hashed identifiers as personal information; no California court has squarely held so [UNVERIFIED - confirm current CPPA regulation text before advising].
Enforcement. CPPA administrative enforcement plus AG civil actions: up to $2,500 per violation, $7,500 per intentional violation or violation involving a minor. § 1798.155(a). Private right of action limited to data breaches under § 1798.150, not to sharing violations.
Application. Element 1 met (hashed email is reasonably linkable). Element 2 met. Element 3 turns on whether the vendor uses the data to target on nonaffiliated properties: the one fact that flips this. If the vendor's use is confined to measurement of the client's own site, this falls outside "share" and inside the § 1798.140(ag) service-provider path, but only if the contract carries the required restrictions.
Assumptions. The vendor contract was not provided [verify - service-provider status lives or dies on its terms]. I assumed the hashes are SHA-256 of raw email without salting [verify].
What your answers changed. "Already a covered business" is what let this memo spend itself on the meaning of "share" instead of on the § 1798.140(d)(1) thresholds. If coverage were the open question, the $40M revenue line would be the whole analysis and everything after it would be conditional. "How do we do this defensibly" is why the application ends on the service-provider path and the vendor contract rather than on a recommendation to stop the transfer; on "can we do this at all" the answer to you is simply yes, with exposure. Your answer that you hold no agency guidance changed nothing except to leave the CPPA line marked [UNVERIFIED]. I had nothing to check it against either way.
Why this prompt is built the way it is
## Framework
1. **Elements from the operative text.** A numbered list, each element quoted with its subsection cite. Where an element comes from a definition rather than the prohibition, say so. That is where coverage usually turns.
2. **Scope in three parts.** Who is a covered party, what conduct triggers the obligation, and what territorial or transactional nexus the jurisdiction needs to reach it.
3. **Exceptions and safe harbors.** Quoted, with section number, plus who carries the burden of establishing each one.
4. **Definitional traps.** Defined terms whose statutory meaning is broader or narrower than the ordinary word. Name at least two, or say honestly there are none.
5. **Text versus agency position.** Where guidance, an FAQ, or an enforcement posture extends past the text, label it as the agency's view, not as law.
6. **Enforcement in numbers.** Agency, civil or criminal, penalty per violation and per day, aggregate caps, cure periods, and whether there is a private right of action.
7. **Apply and commit.** Covered / Not covered / Close call. A close call must name the single fact that would move it either direction.