NAI State Contracting Addendum
Home NAI State Contracting Addendum
NAI State Contracting Addendum
With newly enacted privacy state laws coming into effect, it is more important than ever for industry leaders to have a clear and comprehensive agreement in place for signatories acting as both service providers and third parties.
To help advertising and publisher partners address new contracting requirements, the Network Advertising Initiative has developed sample contracting language. The NAI State Law Processing Addendum Version 2.0 addresses key issues in the industry and provides a solid foundation to cover disclosures for advertising-related transactions within the United States.
Using this template
The NAI publishes this template as a free public resource. Any company may use it, member or not. There is no cost, no registration, and no permission to request.
Frequently asked questions (FAQs)
The growing set of state consumer privacy laws impose numerous requirements for contracting with both service providers/processors and third parties. In addition, those transacting in the ad-tech space sometimes act as service providers/processors (such as when a user is opted out, or to perform basic ads functions) and sometimes act as third parties (such as where they engage in targeted advertising) and need a consistent set of rules and contractual obligations for signaling where they play each role and what obligations they undertake for each. The set of terms below is intended to be a model that NAI members and others can use to address these state law contracting requirements with respect to transfers of personal data to other entities.
Version 2.0 of the NAI Template State Law Processing Addendum (the “Addendum”) is the first update since 2023. The core architecture is unchanged: each party acts as a controller by default, and the receiving party acts as a processor when a Restricted Processing Signal accompanies the data. Within that general architecture, the changes incorporated into the updated Addendum are:
- A durable definition of “State Privacy Laws” (Section 2.8). The definition now names the full current set of comprehensive state laws and adds criteria-based language that reaches future laws of the same kind as they take effect, rather than requiring a new version each time a state acts.
- A clearer Restricted Processing Signal definition (Section 2.6). The definition now describes the signal as a business-to-business signal that travels with the data, names the IAB Tech Lab Global Privacy Protocol (GPP) as one non-exclusive option, and distinguishes the signal from a consumer’s own opt-out preference signal.
- Signal transmission (Section 4.4). Signals pass downstream in the form received.
- Strengthened lawful-basis terms and a new transmission requirement (Sections 4.6.1–4.6.3). See below.
- Third party terms are no longer California-only (Section 5). See below.
- Verification and remediation stated as grants of right (Sections 5.4, 5.5, 6.7 and 6.8.2). The terms now grant the disclosing party the rights that the state contracting provisions require the contract to confer. See below.
- Consumer request assistance (Section 6.3.1). The processor-assistance obligation now accounts for state-administered request and deletion mechanisms, including California’s Delete Request and Opt-Out Platform (DROP).
- An optional template auto-update provision (Section 7.3). Parties may elect to have NAI-published updates apply prospectively, on at least 30 days’ notice, with no material expansion of the parties’ obligations, liability allocation, or data categories absent their written agreement.
- Duration of processing (Attachment 1, Section 1.3), an element required by many of the state controller-processor contracting provisions.
When Version 1.1 was drafted, California was the only state that imposed specific contract terms on disclosures of personal data to third parties, so those terms in the Addendum were written as CCPA terms. That is no longer the case. Delaware’s amendments to its Personal Data Privacy Act (HB 380, 85 Del. Laws, c. 463), signed September 2, 2026 and effective January 1, 2027, require binding contracts with third parties to whom personal data is disclosed, including in a sale or for targeted advertising, with a specified set of terms.
Rather than add a state-specific section, Version 2.0 keys Section 5 to any State Privacy Law that requires a contract containing specified terms for disclosures of personal data to third parties.
Section 5.2 also now specifies that the Advertising Purposes do not include decisions producing legal or similarly significant effects. Delaware requires the contract to state whether the disclosure is for such a purpose (§ 12D-106(a)(10)a.). It also imposes a separate regime on a controller that discloses a report used in a decision with such an effect — contract terms requiring, among other things, adverse-action notice, a description of the data relied on, and, where technically feasible, an opportunity for human review (§ 12D-106(f)(1)), together with direct duties on the controller to produce the data and profiling sources on request and to allow correction (§ 12D-106(f)(2)–(3)). Specifying that the Advertising Purposes exclude those decisions is intended to meet the first requirement and keeps the parties outside the second.
Members who have already adopted the prior version of the Addendum or otherwise papered these terms for California will find most of the substance familiar. The purposes specification in Section 5.2 is the one element without a CCPA counterpart. Delaware also imposes related duties that a contract alone does not discharge. Controllers must conduct reasonable due diligence of the third parties to whom they disclose personal data — at a minimum a questionnaire and a review of their relevant documents, scaled up with the sensitivity of the data (§ 12D-106(a)(11)) — and must assist with assessments.
Because that is how the statutes and regulations express the requirement. Cal. Civ. Code § 1798.100(d)(3) requires the agreement to grant the business rights to take reasonable and appropriate steps to help ensure consistent use. Section 1798.100(d)(5) requires the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use. The CCPA regulations repeat this for third parties at 11 CCR § 7053(a)(4)–(5), and for service providers and contractors at § 7051(a)(7) and (a)(9). Delaware’s § 12D-106(a)(10)c. and e. use nearly identical words.
Version 2.0 states these terms as the statutes state them. The verification options in Sections 5.4.1, 5.4.2 and 6.7 are retained, as is the parties’ good-faith cooperation. Remediation will still be a cooperative exercise. What the grant adds is the explicit right the statutes require the contract to confer.
Several states now appear to prohibit certain transfers of certain personal data outright, in terms that consent does not cure. Section 4.6.3 provides that a disclosing party will not transmit personal data where applicable State Privacy Laws prohibit the transmission or the contemplated processing notwithstanding consent, or where a required consent or condition has not been satisfied.
The provision is keyed to the law rather than to a fixed list of data categories, so it continues to operate as states add or change these restrictions. It sits with the disclosing party, which is the party in a better position to know how the data was collected.
They operate at different points. A Global Privacy Control signal is sent by a consumer directly to a business. A Restricted Processing Signal travels between two businesses, alongside the data, and tells the receiving party that the data must be processed on a restricted basis. A business may well be responding to a consumer’s opt-out preference signal when it transmits a Restricted Processing Signal — but the two are not the same instrument, and the obligations that attach to each are different.
Version 2.0 states this expressly in Section 2.6 so that the contractual signal is not read as displacing a party’s independent obligations with respect to consumer-initiated signals.
The terms are limited to use for advertising-related transactions in the United States including RTB transactions, upload of or collection of personal information for purposes of showing targeted ads on other sites or services or for ad measurement purposes and showing of ads on a publisher’s site. The terms do not address the use of sensitive information, including processes for obtaining or passing consent to process sensitive information.
- These terms are intended to supplement an underlying agreement between the parties and not to cover the full scope of the parties’ relationship, to impose commercial terms, or to allocate liability.
- While the parties may update the names of the parties as they wish, the default phrasing allows either party to act as either a disclosing party or a receiving party.
It is not designed to be a standalone agreement, and adopting it does not require adding a negotiation step to a deal. The template is an addendum drafted to attach to whatever agreement the parties already have — an insertion order, a master services agreement, platform terms — and it addresses only the state law contract requirements that apply to the data flowing under that agreement.
Members may use it in several ways. Some may attach it as-is to their standard terms. Some use it as the starting point when a counterparty proposes its own data terms, since a common structure shortens review. Some use it as a reference against which to check terms they have already papered. The value of a shared template is that a receiving party encountering it does not need to re-evaluate it deal by deal.
- This document is not intended to be used: 1) for other forms of sales of personal information, such as providing personal information to a data broker for non-advertising purposes in return for money; nor 2) for EU data or for compliance with any other jurisdiction’s laws.
- This document does not address the use of sensitive information, including processes for obtaining or passing consent to process such information. To the extent the parties share such information, obligations related to such information should be addressed independent of these terms. However, the template does include a transmission requirement (Section 4.6.3) under which a party agrees not to transmit personal data where applicable State Privacy Laws prohibit the transmission or the contemplated processing notwithstanding consent, or where a required consent or condition has not been satisfied. Consent does not substitute for other statutory prerequisites, which in some states include necessity, notice, documentation and retention requirements.
- It does not create contractual privity between all signatories that use the template. It is a template that creates privity between the two counterparties that adopt it as an addendum to existing contracts; but, unlike the IAB Multi-State Privacy Agreement (MSPA), does not create privity beyond those two signatories. Members with questions about how this template interacts with other industry frameworks can contact the NAI.
The Addendum is intentionally high-level and agnostic as to the type of parties involved, contemplating one or both being the disclosing party or the receiving party. While the parties may update the names to “Disclosing Party” and “Receiving Party” for one-way flows of data, the intent of such terms is to allow for two-way flows.
The template addendum continues to be structured similarly to terms previously published by major social media platforms in light of updates to state laws: 1) general obligations that apply to both parties under the state laws; 2) terms that govern the transfer of personal information to “Third Parties” where a state law imposes them; 3) processor terms that apply only when the Restricted Processing Signal is present; and 4) other general contractual terms — i.e. amendment and conflicts. Some key concepts reflected in the template addendum:
- Under these terms, the default state is to transfer data to others as “third parties” or as independent controllers, wherein the receiving party may use the data for purposes that are considered “selling,” “sharing,” or “targeted advertising” under the state laws (but not for any non-advertising purposes such as eligibility decisions).
- Where the parties wish to have the other entity act as a processor or service provider (because the individual consumer has opted out of “sales,” “sharing,” or “targeted advertising”), they must signal such designation.
- Such signal may be a commonly used, recognized format — such as the IAB Tech Lab Global Privacy Protocol (GPP) — or any other signaling format agreed to by the parties and is referred to in these terms as a Restricted Processing Signal.
- Where such signal is present, the receiving party agrees to act as a processor/service provider with all the attendant obligations provided by the state laws and to use the data for more limited purposes, referred to as “Restricted Purposes” in this document. Of note, the terms reflect a concept of joint processing similar to that adopted in the MSPA in an attempt to address concerns about service providers/processors “combining” personal information collected across clients reflected in the CCPA regulations.
The NAI’s goal in drafting these terms was to keep them as short and simple as possible while also addressing the numerous and detailed obligations imposed by the state laws. We have heard from most members that they prefer a single, national approach rather than state-by-state systems that are complicated to implement and yield little advantage as a practical matter. As a result, wherever the state laws reflect minor and likely inconsequential differences in their definitions or treatment of a topic, the terms abstract that concept into a simple and yet compliant obligation still intended to meet the underlying obligations. Similarly, rather than porting over defined terms from state laws, these terms refer out to the terms used in the laws. The terms are intended to allow for seamless negotiation and consistent terms across the ecosystem (similar to how the IAB’s Standard Media Buying terms are used, with companies familiar with the concepts in those documents and able to agree to them without having lawyers re-review or re-negotiate them for each deal).
The template is designed to cover comprehensive state consumer privacy laws that grant consumers a right to opt out of targeted advertising, the sale of personal data, or both, as those laws take effect — extending automatically to new laws of that kind. It does not cover category-specific laws (such as those addressing health, biometric, or minors’ data), and it applies to Florida’s Digital Bill of Rights only where a party is subject to it.
This Addendum is separate and distinct from the MSPA. This template aims to help companies comply with state law contractual requirements with respect to their advertising related transactions in the United States. This can be used independently to help companies satisfy these obligations, or serve as the backstop where a party has signed onto the MSPA but a) is contracting with a party that has not signed onto the MSPA, or b) when both parties have signed the MSPA and elect to not have the MSPA apply to a given transaction.
Use the Restricted Processing Signal. When it accompanies the data, Section 6 applies and the receiving party acts as a processor limited to the Restricted Purposes — which Section 2.7 defines to include measurement, frequency capping, fraud detection and prevention, and viewability, each only to the extent a processor may perform it under applicable State Privacy Laws and it does not result in a Sale or Sharing or amount to Targeted Advertising.
This matters most in California. Most state definitions of “targeted advertising” exclude processing solely to measure or report advertising performance, reach, or frequency. California’s definitions of “sale,” “cross-context behavioral advertising,” and “sharing” contain no such explicit exclusion. California instead treats ad measurement as an enumerated business purpose — counting ad impressions and verifying ad positioning and quality (Cal. Civ. Code § 1798.140(e)(1)) — which permits a service provider to process for that purpose but does not explicitly take the activity outside the sale and share opt-out. Without contractual restrictions in place regarding an ad-tech provider’s use or disclosure of personal information, there is a risk that entities cannot perform these activities as a service provider such that disclosures for that purpose would risk being considered a sale under California law. Section 6 is that contractual restriction, and Section 6.8.4 addresses the CCPA regulations’ concerns about “combining” personal information across clients through the Joint Processor concept in Section 2.4. California regulators’ interpretation of this issue is still not clear.
Legal notices:
Permission to use and adapt. The NAI grants everyone permission to download, copy, distribute, and adapt this template and its FAQ, including in commercial agreements. Please keep the NAI’s copyright notice on unmodified copies. If you modify the template, do not present the result as the NAI’s template and do not state or imply that the NAI drafted, reviewed, endorsed, or approved it. “NAI” and “Network Advertising Initiative” are trademarks of the Network Advertising Initiative, Inc. This permission governs this template and its FAQ, notwithstanding anything to the contrary in the NAI’s Terms of Use.
Not legal advice. This template is general information, not legal advice, and its use does not create an attorney-client relationship with the NAI. State privacy laws differ and continue to change. Whether these terms are appropriate, sufficient, or complete for a particular relationship depends on facts the NAI does not know. Consult your own counsel before using them. The NAI provides the template “as is,” without warranty of any kind, and disclaims liability arising from its use.
Voluntary; not a compliance determination. Use of this template is voluntary and non-exclusive. It sets no pricing, indemnity, or liability terms; those belong in the parties’ own agreement, and companies remain free to negotiate any terms they choose. Using the template does not establish compliance with any state privacy law, and it is not an NAI certification, endorsement, or safe harbor under the NAI Code of Conduct or the NAI Privacy Review Program.
© 2026 Network Advertising Initiative, Inc. NAI Template State Privacy Law Processing Addendum, Version 2.0 (September 2026).