Longer Reads

Privacy and real-time bidding: An updated guide for adtech vendors and publishers

Our Data Privacy team is featured in MarketingTech News outlining what adtech participants need to know about real-time bidding and use of cookies.

2 minute read

Published 3 December 2019

Share

Key information

Until the summer of 2019, the Information Commissioner’s Office (ICO), the UK’s privacy regulator, had not been particularly pro-active in enforcing the law on data protection in respect of the use of cookies and programmatic advertising based on real-time bidding (RTB). This all changed in June and July of this year, when the ICO published respectively a detailed report into RTB practices and an updated guidance note on the use of cookies. This article considers some key points raised in these publications that are likely to affect the adtech landscape.

Data protection impact assessments are mandatory for RTB

The ICO’s report states that many adtech organisations have yet to carry out any data protection impact assessments (DPIAs) in respect of the personal data they control. The EU General Data Protection Regulation (GDPR), which came into force last year, requires DPIAs to be undertaken where new technologies are used to process personal data and the processing is likely to pose a high risk to the rights and freedoms of the individuals concerned. By their very nature, RTB activities trigger the requirement. If your organisation operates within the digital advertising ecosystem, it should (if it hasn’t already done so) carry out a DPIA as soon as possible. This can then be used to consider how best to minimise any disproportionate or intrusive data sharing.

Individuals’ consent is required to process their personal data in RTB

RTB involves processing user data falling within the scope of the GDPR’s definition of ‘personal data’. This definition includes ‘online identifiers’ and therefore covers website users who could potentially be identified from the bid-request information sent by a webpage to its advertising suppliers.

The GDPR only permits processing personal data on the basis of certain lawful grounds. Many website publishers that use RTB have been relying on the ‘legitimate interests’ ground, but the ICO’s adtech report states that the nature of RTB processing make the criteria for relying on this ground impossible to satisfy. Instead, the ICO considers obtaining users’ consent to be the only appropriate lawful basis in this context. The GDPR standard for consent, however, is high: it must be a ‘freely given, specific, informed and unambiguous indication’ communicated ‘by a clear affirmative action’. This standard also now applies to the consent required under the Privacy and Electronic Communications Regulations (PECR) to place the non-essential cookies on users’ devices that are needed for RTB advertising.

Website publishers will therefore need to ensure that they obtain GDPR-standard consent via express opt-ins from users; otherwise, there will be no lawful basis on which to remit the relevant data to adtech suppliers. The ICO’s report particularly emphasises the importance of obtaining explicit consent from users where their ‘special category’ (sensitive) personal data is processed – for example, in relation to their health or political views. Adtech participants will need to modify their existing consent mechanisms to obtain explicit consent in respect of this data or refrain altogether from processing such ‘special category’ data.

Obtaining explicit consent in adtech is, however, no easy task. The ICO is clear that using a ‘cookie wall’, where users are required to agree to the processing of their personal data as a condition of accessing a website, is no solution. It is therefore difficult to see how website publishers that use RTB-based programmatic advertising can meet the GDPR standard of consent without having to present users with detailed consent wordings and multiple opt-in tickboxes. This could risk ‘consent fatigue’ among individuals who visit several websites each day and don’t have the time to read multiple lengthy privacy and cookie notices. Further industry engagement is needed to determine how to prevent data protection compliance from becoming counterproductive to the goal of providing transparency to users on how their data is used.

What should adtech participants do now?

While the ICO did not mince its words in its report into RTB, calling the adtech industry ‘immature in its understanding of data protection’, it is seeking to engage with industry rather than simply to penalise it. The regulator is all too aware that simply hamstringing adtech would inevitably diminish advertising’s funding of free online services when there is still little increase in demand for paid-for, ad-free content.

An update report from the ICO is expected next year, following a further industry review. In the meantime, the ICO expects all data controllers in the adtech industry to re-evaluate their approach to using personal data. Given the potential fines for non-compliance with the GDPR (up to €20 million or 4% of worldwide turnover, whichever is greater), industry participants should use this grace period as an opportunity not only to revisit their existing privacy and cookie notices and to re-evaluate the way in which they obtain user consent to data processing, but also to focus on data quality – after all, it makes little commercial sense to process large volumes of personal data without fully understanding whether this brings any meaningful return of investment.

This article was originally published by MarketingTech News on 29 November 2019: https://www.marketingtechnews.net/news/2019/nov/29/privacy-and-real-time-bidding-updated-guide-adtech-vendors-and-publishers/

Related latest updates
PREV NEXT

Arrow Back to Insights

Longer Reads

Privacy and real-time bidding: An updated guide for adtech vendors and publishers

Our Data Privacy team is featured in MarketingTech News outlining what adtech participants need to know about real-time bidding and use of cookies.

Published 3 December 2019

Associated sectors / services

Until the summer of 2019, the Information Commissioner’s Office (ICO), the UK’s privacy regulator, had not been particularly pro-active in enforcing the law on data protection in respect of the use of cookies and programmatic advertising based on real-time bidding (RTB). This all changed in June and July of this year, when the ICO published respectively a detailed report into RTB practices and an updated guidance note on the use of cookies. This article considers some key points raised in these publications that are likely to affect the adtech landscape.

Data protection impact assessments are mandatory for RTB

The ICO’s report states that many adtech organisations have yet to carry out any data protection impact assessments (DPIAs) in respect of the personal data they control. The EU General Data Protection Regulation (GDPR), which came into force last year, requires DPIAs to be undertaken where new technologies are used to process personal data and the processing is likely to pose a high risk to the rights and freedoms of the individuals concerned. By their very nature, RTB activities trigger the requirement. If your organisation operates within the digital advertising ecosystem, it should (if it hasn’t already done so) carry out a DPIA as soon as possible. This can then be used to consider how best to minimise any disproportionate or intrusive data sharing.

Individuals’ consent is required to process their personal data in RTB

RTB involves processing user data falling within the scope of the GDPR’s definition of ‘personal data’. This definition includes ‘online identifiers’ and therefore covers website users who could potentially be identified from the bid-request information sent by a webpage to its advertising suppliers.

The GDPR only permits processing personal data on the basis of certain lawful grounds. Many website publishers that use RTB have been relying on the ‘legitimate interests’ ground, but the ICO’s adtech report states that the nature of RTB processing make the criteria for relying on this ground impossible to satisfy. Instead, the ICO considers obtaining users’ consent to be the only appropriate lawful basis in this context. The GDPR standard for consent, however, is high: it must be a ‘freely given, specific, informed and unambiguous indication’ communicated ‘by a clear affirmative action’. This standard also now applies to the consent required under the Privacy and Electronic Communications Regulations (PECR) to place the non-essential cookies on users’ devices that are needed for RTB advertising.

Website publishers will therefore need to ensure that they obtain GDPR-standard consent via express opt-ins from users; otherwise, there will be no lawful basis on which to remit the relevant data to adtech suppliers. The ICO’s report particularly emphasises the importance of obtaining explicit consent from users where their ‘special category’ (sensitive) personal data is processed – for example, in relation to their health or political views. Adtech participants will need to modify their existing consent mechanisms to obtain explicit consent in respect of this data or refrain altogether from processing such ‘special category’ data.

Obtaining explicit consent in adtech is, however, no easy task. The ICO is clear that using a ‘cookie wall’, where users are required to agree to the processing of their personal data as a condition of accessing a website, is no solution. It is therefore difficult to see how website publishers that use RTB-based programmatic advertising can meet the GDPR standard of consent without having to present users with detailed consent wordings and multiple opt-in tickboxes. This could risk ‘consent fatigue’ among individuals who visit several websites each day and don’t have the time to read multiple lengthy privacy and cookie notices. Further industry engagement is needed to determine how to prevent data protection compliance from becoming counterproductive to the goal of providing transparency to users on how their data is used.

What should adtech participants do now?

While the ICO did not mince its words in its report into RTB, calling the adtech industry ‘immature in its understanding of data protection’, it is seeking to engage with industry rather than simply to penalise it. The regulator is all too aware that simply hamstringing adtech would inevitably diminish advertising’s funding of free online services when there is still little increase in demand for paid-for, ad-free content.

An update report from the ICO is expected next year, following a further industry review. In the meantime, the ICO expects all data controllers in the adtech industry to re-evaluate their approach to using personal data. Given the potential fines for non-compliance with the GDPR (up to €20 million or 4% of worldwide turnover, whichever is greater), industry participants should use this grace period as an opportunity not only to revisit their existing privacy and cookie notices and to re-evaluate the way in which they obtain user consent to data processing, but also to focus on data quality – after all, it makes little commercial sense to process large volumes of personal data without fully understanding whether this brings any meaningful return of investment.

This article was originally published by MarketingTech News on 29 November 2019: https://www.marketingtechnews.net/news/2019/nov/29/privacy-and-real-time-bidding-updated-guide-adtech-vendors-and-publishers/

Associated sectors / services

Need some more information? Make an enquiry below.

    Subscribe

    Please add your details and your areas of interest below

    Specialist sectors:

    Legal services:

    Other information:

    Jurisdictions of interest to you (other than UK):



    Enjoy reading our articles? why not subscribe to notifications so you’ll never miss one?

    Subscribe to our articles

    Message us on WhatsApp (calling not available)

    Please note that Collyer Bristow provides this service during office hours for general information and enquiries only and that no legal or other professional advice will be provided over the WhatsApp platform. Please also note that if you choose to use this platform your personal data is likely to be processed outside the UK and EEA, including in the US. Appropriate legal or other professional opinion should be taken before taking or omitting to take any action in respect of any specific problem. Collyer Bristow LLP accepts no liability for any loss or damage which may arise from reliance on information provided. All information will be deleted immediately upon completion of a conversation.

    I accept Close

    Close
    Scroll up
    ExpandNeed some help?Toggle

    < Back to menu

    I have an issue and need your help

    Scroll to see our A-Z list of expertise

    Get in touch

    Get in touch using our form below.



      Business Close
      Private Wealth Close
      Hot Topics Close