U.S. State Privacy Obligations for AI Advertising
Tags: Regulatory
Landscape Overview
Comprehensive privacy laws have been enacted in twenty U.S. states. These statutes do not carve out AI and therefore apply when AI systems process personal information. Core privacy principles remain central to assessing AI risk in digital advertising.
Core Principles
- Privacy disclosures: Businesses must disclose categories of personal information collected and the purposes of use; regulators actively enforce noncompliance.
- Data subject rights: Access, correction, deletion, and opt-out of sale, sharing, targeted advertising, and some profiling activities (scope varies by state). Contracts with model providers should address these rights.
- Data minimization: Collect only what is reasonably necessary and proportionate. Nuances include:
- California (CCPA/CPRA): Limit collection to what is needed for the original purpose; consider consumer expectations and potential negative impacts.
- Maryland: Similar proportionality, focused on providing/maintaining a specifically requested product or service.
Profiling and Assessment Triggers
Many states require Data Protection Assessments for profiling that presents a heightened risk of harm. States including DE, FL, IN, KY, MD, MN, MT, NE, NH, NJ, OR, TN, TX, VA, and RI impose such obligations, with transparency requirements and opt-out rights (e.g., CT) for automated decision-making and certain profiling.
Relevant Case Signal
A January 2025 California District Court dismissed a lawsuit alleging LinkedIn used users’ private messages to train its generative AI, noting LinkedIn demonstrated it did not disclose users’ private messages. The case underscores the importance of clear terms and fact patterns around data use in AI training.
Practical Considerations for AdTech
- Ensure disclosures reflect AI usage where personal data is ingested.
- Validate vendors’ capabilities to facilitate deletions, access requests, and potential unlearning.
- Align segmentation/targeting practices with sensitive data restrictions and profiling opt-outs.
State privacy laws’ consistency on principles and variance on details necessitate flexible, documented governance across the ad lifecycle.
Sources:- IAB_AI_Governance_and_Risk_Management_Playbook_August_2025.pdf
← Back to Knowledge Base