
Open the visual model ↗
Four questions before choosing a banner
What audience and geography are in scope? What information does each component read, store, or transmit? Why is each party processing it? Which entity is responsible for the resulting obligations? A banner cannot answer these questions by itself.
The imported research contains federal, selected US state, UK, and EU developments. It is not an exhaustive worldwide map. We checked the primary sources below for this guide; other legal deadlines, proposals, litigation predictions, and claimed exceptions in the original remain research leads.
- Advertising disclosure: can the reader recognise a paid message?
- Device access: are cookies, storage, pixels, or similar technologies involved?
- Personal-data processing: what happens after collection, including sharing, inference, retention, and rights?
- Audience and service scope: do children, sensitive topics, platform features, or regulated advertisers add obligations?
A map for questions, not a universal rule
Assess the service and each activity against the relevant rules. A publication’s editorial pages, comments, email, event registration, and advertising stack may need different analyses.
| Area | Primary-source anchor | Question for the publisher |
|---|---|---|
| United States: commercial messages | FTC native-ad and endorsement guidance | Does the format or undisclosed relationship mislead? |
| United States: children | FTC COPPA rule scope | Is the service directed to under-13s, or does it have actual knowledge of collection from them? |
| California | CCPA regulation update package, effective 1 January 2026 | Is the business in scope, and how do its opt-out and assessment duties apply? |
| United Kingdom | ICO storage/access and advertising guidance | What purposes use device information, and which requirements or narrow exceptions apply? |
| European Union | EDPB Article 5(3) technical-scope guidance and national ePrivacy implementation | What device information is accessed, and what additional data-protection analysis is needed? |
US state coverage is selective. EU national implementation and UK rules must be checked independently.
Source notes: FTC: Native Advertising — A Guide for Businesses · FTC: Endorsement Guides — What People Are Asking · FTC: Children’s Online Privacy Protection Rule · CPPA: 2026 CCPA regulation updates · ICO: Guidance on storage and access technologies · EDPB Guidelines 2/2023: Technical scope of Article 5(3)
A preference must change behaviour
CalPrivacy’s 2026 explainer describes a means for consumers to confirm the status of an opt-out request, including one received through a preference signal such as Global Privacy Control. It also describes assessment duties for certain processing activities. Applicability and staged obligations require the underlying regulation, not a headline.
For an implementation review, record the preference presented, the state recorded, which tags were eligible to run, and what was transmitted. A visible confirmation and actual downstream behaviour should agree. A stored consent string is not proof that every partner followed it.
Source notes: CalPrivacy: Seven things to know before the 2026 updates
Children and sensitive context need a separate design review
COPPA’s scope includes child-directed online services and services with actual knowledge of collecting personal information from a child under 13. That is a US scope statement; do not extend its age threshold to every jurisdiction. The uploaded document discusses additional youth and sensitive-data restrictions that require their own current source and applicability review.
A page URL can reveal something sensitive before an audience segment is deliberately created. Map health, religious, political, and youth-related contexts alongside identifiers, ad calls, and redirects. An internal tag saying “contextual” does not demonstrate that a recipient cannot combine the data.
Our proposed operating sequence is to identify the affected pages, reduce unnecessary collection and recipients, test the resulting behaviour, and have qualified counsel resolve the market-specific questions before enabling a commercial use. This article does not label any live stack compliant.
Source notes: FTC: Children’s Online Privacy Protection Rule
Sources & limits
General educational research. Scope, exceptions, contractual roles, children’s rules, and legal deadlines require qualified jurisdiction-specific review.
Adapted from supplied research. See the evidence and review method. Section source notes identify supporting references; operational suggestions remain editorial judgment.
- FTC: Native Advertising — A Guide for Businesses
Primary guidance · Publication date not stated · Primary source checked · 15 September 2026 - FTC: Endorsement Guides — What People Are Asking
Primary guidance · Publication date not stated · Primary source checked · 15 September 2026 - FTC: Children’s Online Privacy Protection Rule
Primary guidance · Publication date not stated · Primary source checked · 15 September 2026 - CPPA: 2026 CCPA regulation updates
Primary guidance · Publication date not stated · Primary source checked · 15 September 2026 - CalPrivacy: Seven things to know before the 2026 updates
Primary guidance · Publication date not stated · Primary source checked · 15 September 2026 - ICO: Guidance on storage and access technologies
Primary guidance · Source updated 29 April 2026 · Primary source checked · 15 September 2026 - EDPB Guidelines 2/2023: Technical scope of Article 5(3)
Primary guidance · Source published 16 October 2024 · Primary source checked · 15 September 2026
Source claims and editorial judgments remain separate. Send a correction with the passage and supporting evidence.

