July's Privacy Law Changes: A Checklist for Health and Finance Publishers
Connecticut, Arkansas and Virginia changes took effect July 1, and IAB Tech Lab just proposed GPP updates. What health, finance and other sensitive-content publishers should check.
U.S. privacy compliance for ad-supported publishers keeps getting more granular. A set of state law changes took effect on July 1, and on August 11 IAB Tech Lab opened updates to the Global Privacy Platform (GPP) for public comment. Taken together, they matter most for publishers whose content attracts sensitive audiences: health, personal finance, parenting and anything with a large teen readership.
What changed on July 1
Connecticut. Amendments to the Connecticut Data Privacy Act (SB 1295) took effect July 1. As summarized by Wiley, the law now applies to controllers handling data on at least 35,000 consumers, down from 100,000, and applies regardless of volume to anyone processing sensitive data or selling personal data. The sensitive data definition expands to include items such as government identifiers and financial account information, and sensitive data cannot be sold without consent. The amendments also prohibit targeted advertising and the sale of personal data for consumers aged 13 to 17 when the controller has actual knowledge of, or willfully disregards, their age.
Arkansas. The Arkansas Children and Teens' Online Privacy Protection Act (HB 1717) also took effect July 1. It applies to operators directed to children or teens, or with actual knowledge that they collect minors' data, and prohibits targeted advertising based on minors' personal data.
Virginia. SB 338, signed in April, amends the Virginia Consumer Data Protection Act to prohibit selling consumers' precise geolocation data, defined as location within a radius of 1,750 feet. It took effect July 1. Virginia is the third state to ban the sale of precise geolocation outright, after Maryland and Oregon. Unlike most state rules, this is not an opt-out right. There is no sale to opt out of.
What IAB Tech Lab proposed on August 11
IAB Tech Lab opened updates to its privacy standards for comment through September 11. The proposed GPP changes support the Fifth Amended and Restated Multi-State Privacy Agreement (MSPA). They include removing MSPA coverage for the previous state-by-state approach, eliminating the Service Provider and Opt-Out Option modes, removing secondary usage consents and simplifying notice and choice fields. Tech Lab also released version 2.0 of its Data Deletion Request Framework (DDRF), finalized after a public comment period in fall 2025. The new version clarifies how identity and deletion requests are defined, improves the feedback vendors return about the result of a request and supports implementation-specific extensions. For publishers, DDRF is the plumbing that carries a reader's deletion request to the ad tech vendors that received their data. If you pass identifiers to partners, ask whether they support it.
If adopted, these changes will alter what GPP strings look like and how downstream vendors read them. Publishers do not implement GPP by hand, but they do own the result: their CMP writes the string, and every bid request carries it.
Why sensitive-content publishers carry more risk
A health or finance article does not by itself make a reader's data sensitive under these laws. But the context of the page, combined with identifiers and location in the bid stream, can create inferences that regulators treat seriously. The same applies to teen audiences: a gaming, education or entertainment site with a large under-18 readership may be closer to "actual knowledge" than it assumes, especially if it collects ages at signup.
A checklist for the next 30 days
- Map your audiences by state. Know what share of traffic comes from Connecticut, Virginia, Arkansas and other states with comprehensive privacy laws, and whether your CMP applies the right experience in each.
- Audit precise location in bid requests. Check whether latitude and longitude, or other precise location signals, leave your pages or apps in bid requests. For web inventory, coarse location is usually enough for buyers. Reduce precision where you can, and pay particular attention to app inventory, where device location is more likely to be available.
- Identify teen exposure. If you know a user is under 18, through registration, age gates or account data, make sure that knowledge flows into ad decisions so targeted advertising is not applied.
- Review sensitive-content signals. On health and finance pages, check which data segments and identifiers are passed and whether any vendor might treat them as sensitive data. Contextual targeting based on page content is the safer default for these sections.
- Talk to your CMP about GPP versions. Ask how and when your CMP will adopt the updated MSPA-related GPP sections once finalized, and how the transition will be tested.
- Confirm downstream support. Ask your SSPs and wrapper provider whether they read and pass GPP strings correctly, including the U.S. national and state sections.
- Document decisions. Write down what you pass, where and why. If a regulator or partner asks, a clear record is worth more than a perfect setup nobody can explain.
Contextual is the durable answer
Each new rule narrows what can be done with personal data in advertising, especially for sensitive topics and younger audiences. The steady answer for health and finance publishers is to make context do more of the work: accurate page categorization, clean content metadata in bid requests and private marketplace deals built around topics rather than individuals. Buyers in these categories often prefer that approach anyway, because it lowers their own compliance risk.
Privacy compliance is ultimately a legal question, and publishers should get advice from counsel on how these laws apply to them. The ad ops side, making sure signals are correct and nothing leaks that should not, is where a partner like HBDR can help.
Related Articles
Privacy Sandbox Is Winding Down in Chrome. Time to Clean Up Your Wrapper
Chrome 150 is now rejecting Protected Audience calls as Google retires most Privacy Sandbox APIs. Here is what to remove from your ad stack and what stays the same.
July 1 Privacy Deadlines: Connecticut and Arkansas Tighten Teen Ad Rules
On July 1, Connecticut's amended privacy law and Arkansas's children's and teens' privacy law take effect, both restricting targeted ads to minors. What publishers should change first.
Buyers Now Rank Targeting Over Content Quality: A First-Party Data Plan
IAB's new video spend report shows targeting overtaking content quality as buyers' top criterion. Finance publishers can answer with seller-defined audiences they already have the data for.