As the era of self-regulation comes to an end, companies worry that data privacy is entering uncharted waters of risk
U.S. data privacy regulation is shifting from industry self-regulation to mandatory legislation, with the California Consumer Privacy Act (CCPA) set to take effect next year, and similar bills proposed in states like New Jersey and Washington. The marketing industry is worried about the ambiguity of the regulations and is calling for a unified federal privacy law. Companies face challenges such as rising compliance costs and increased risk of fines, while consumer demands for control over their data are growing stronger.

As state data privacy legislation accelerates across the U.S., marketers are scrambling to prepare for the upcoming California Consumer Privacy Act (CCPA). The law, which takes effect next year, could impose hefty fines on non-compliant companies. Although major industry associations have criticized the law for being hastily drafted and vaguely worded, its passage has already prompted states like New Jersey and Washington to follow suit, signaling a more complex legal environment for digital advertising.
"This is the core issue of the moment, and it's certainly our top government affairs priority," said Dan Jaffe, Executive Vice President of Government Relations at the Association of National Advertisers (ANA). "Things are moving very quickly, and it's not just California." The introduction of CCPA and other state laws marks a chaotic end to the internet industry's long era of self-regulation. In response, major advertising industry groups, including the ANA, as well as prominent executives like Apple CEO Tim Cook, are calling for a unified federal privacy law, which could be modeled more closely on the European Union's General Data Protection Regulation (GDPR).
Critics point out that a patchwork of state laws would create unprecedented compliance challenges: marketers would need to have complete control over data and establish internal or external compliance teams to ensure data collection and use meet varying state standards. "Even if the state laws have only subtle differences—though in reality, many are not subtle—when I operate in such a tight market, every additional set of different rules multiplies the risk of violation," said Alison Pepper, Senior Vice President of Government Relations at the 4A's (American Association of Advertising Agencies). Furthermore, while these state laws often target controversies involving large digital advertising platforms like Facebook, they could ultimately affect small and medium-sized businesses that lack the time, resources, or budget, replaying the issues seen in the early days of GDPR implementation.
Currently, CCPA is the key battleground shaping marketers' influence. Jaffe warned: "Under CCPA, even without proving harm, a single violation could expose companies to fines in the hundreds of millions or more. For many companies, one mistake could likely put them out of business."
Focus on California
CCPA has become the most urgent concern for marketers not only because of its approaching effective date but also due to its legislative process. The law began as a California ballot initiative and passed in just five days with almost no opposition in the state Senate and Assembly, with little industry involvement in the discussions. This contrasts sharply with similar U.S. laws or the GDPR, which gave marketers years to prepare and allowed them to provide input before its implementation in May 2018. As a result, many marketers believe some of the wording in CCPA is too vague and could inadvertently harm consumer interests.
Advertising industry groups, including the 4A's, ANA, IAB, AAF, and NAI, recently sent a joint letter to the California Attorney General requesting clarification on the scope of "personal information" and how the law's non-discrimination provisions would affect services like loyalty programs. Currently, CCPA prohibits businesses from discriminating in price or service against consumers who opt out of data sharing, but it is data sharing that underpins many loyalty programs. Pepper asked: "As a retailer, if it's a one-way exchange and the customer provides no value in return, what's the incentive to offer a discount? Why do it if there's only obligation and no benefit?" Additionally, organizations like the 4A's, IAB, and the Digital Advertising Alliance have called for clarification on whether treating pseudonymous data as personal information is reasonable—which is how CCPA currently handles it.
"We're not opposed to the law's goal—giving consumers more control over their data—but as we dig deeper, we have more questions," said the ANA's Jaffe. "We can't even advise our members on how to comply." The ANA has over 1,100 member companies, including top advertisers like Procter & Gamble, PepsiCo, and Visa.
Time is short
The ANA has testified twice, in San Diego and Sacramento, proposing suggestions to simplify CCPA's wording. Ashok Chandra, Senior Partner and Privacy Director at WPP's GroupM, believes the numerous public hearings indicate the Attorney General is willing to listen to industry input. But even as marketers crave more clarity from CCPA, with only months until its official implementation, they must act immediately, including working with internal or external legal teams to develop opt-out disclosure mechanisms and prepare for consumer data requests. "We have to operate based on the law as passed," Chandra said in a phone interview. "The benefit of other state bills is that a longer legislative process benefits everyone because the industry we're in is very complex."
Legal experts warn that companies that believe they are already prepared for GDPR should not be complacent. Jaffe noted: "GDPR is opt-in, CCPA is opt-out, and they collect different data. Even if you've spent millions or even hundreds of millions to comply with GDPR, it by no means guarantees you comply with CCPA."
Weaving a complex web
Although GDPR had a longer preparation time, it still exposed challenges of broad scope and interpretive leeway. In Europe, national data protection authorities can adjudicate violations independently. France's CNIL recently fined Google €50 million for violating GDPR rules on transparency and the legal basis for processing ad data. This is the largest fine since GDPR took effect, and the 4A's Pepper sees it as a warning to other companies: "Google didn't take GDPR lightly—they took it very seriously. Look at Google's resources... If Google can't achieve full compliance, how can small and medium-sized enterprises cope?"
Additionally, GDPR complaints have been filed against advertising frameworks like IAB Tech Lab's OpenRTB, although the IAB strongly denies violations. Another risk is that marketers might mistakenly believe laws like GDPR and CCPA apply only to digital realms, but they may broadly touch on privacy issues. For example, a recent GDPR fine in Austria involved surveillance cameras capturing a public sidewalk, and such real-world impacts could also arise under CCPA. Jaffe said: "CCPA is not limited to the internet and mobile devices; it covers both online and offline data collection. For example, at a retailer's checkout counter, how do you provide CCPA-required disclosures?"
Rethinking data
While navigating the increasingly complex legal landscape, marketers must also recognize consumers' higher demands for accountability. A recent ExpressVPN report showed that 82% of surveyed Americans believe Congress should strengthen regulation of tech companies' data collection and use in 2019; 89% believe they should have the right to decide who can share their personal data. These anxieties stem from incidents like Facebook's Cambridge Analytica scandal, and GroupM's Chandra says such scandals have "definitely" influenced the current regulatory environment. He said: "It's important to let lawmakers know we're not lax. Cambridge Analytica was not the norm in the industry; it was an extreme case that, unfortunately, was widely publicized."
Despite the many obstacles, marketers committed to repairing trust in the digital ecosystem can view new regulations as an opportunity for education and deeper collaboration. Chandra suggests these discussions help demonstrate to consumers and governments the industry's self-regulatory efforts, such as anti-ad fraud initiatives like TAG, which have proven effective. Keith Weed, outgoing Chief Marketing and Communications Officer at Unilever, said at the January Consumer Electronics Show: "I don't think anyone has all the solutions, but collectively, we certainly do. In Europe, I do think GDPR is a positive step. Going forward, proactive collaboration between industry and government is the right path."
In this uncertain period, one thing seems clear: marketers must rethink data and how it supports their businesses, or risk endangering the entire enterprise. The 4A's Pepper concluded: "The most practical approach is to examine the data you're collecting: Do you need it? Does it have value? The days of collecting everything first and deciding what to use later are over."
