Luca Passani, CTO @ScientiaMobile, August 2026
This appendix provides a plain-language overview of GDPR for readers who want the legal foundation before engaging with the argument in the main piece.
What GDPR Is
The General Data Protection Regulation, or GDPR, is the European Union’s main legal framework for the processing of personal data. It has applied since May 2018 and extends beyond organizations established in the EU: in many circumstances, it also applies to organizations outside the Union when they offer goods or services to individuals in the EU or monitor their behavior there.
It is often described simply as a ‘privacy law’, but that is only partly accurate. More broadly, GDPR is a framework for determining when personal data may be collected, how it may be used, how long it may be retained, with whom it may be shared, and what rights individuals have in relation to it. It is therefore concerned not only with secrecy or confidentiality, but with the overall governance of personal data.
Personal Data and PII (Two False Synonyms Used Interchangeably)
One reason GDPR matters so much is that its notion of personal data is broad. The term does not refer only to obvious identifiers such as a name, home address, or email address. It can also include online identifiers and data points that, alone or in combination, relate to an identifiable person.
Examples may include:
- cookie IDs
- mobile advertising IDs
- device identifiers
- location data
- profiles associated with those identifiers
- IP addresses
The term “personally identifiable information” — or PII — is widely used in the technology and advertising industries, but it is not a GDPR term. GDPR uses “personal data” throughout, and the two concepts do not map cleanly onto each other. Having said this, the two names are often used interchangeably in the industry. Yet, keeping the distinction clear will go a long way into avoiding confusion when lawyers get involved. One reality of programmatic advertising is that companies need to handle GDPR and US-style privacy laws at one time. The potential for confusion should not be underestimated.
PII, as typically used in industry contexts, often implies a narrower set of directly identifying information: name, email address, social security number, and similar data points. GDPR’s “personal data” is broader; it extends to any information that relates to an identified or identifiable person, which can include indirect identifiers and combinations of data points that, taken together, allow identification.
In practice, this means that data which an organization might not consider PII under its internal policies may still constitute personal data under GDPR, with all the compliance obligations that follow. The two terms are sometimes used interchangeably in industry conversations, but a lawyer might point out that they are not equivalent. Notably, PII is not a GDPR term.
A note on IP addresses: while GDPR’s broad definition of personal data can encompass IP addresses — particularly where they can be linked to an individual through other means — not all privacy frameworks treat them the same way. Virginia’s Consumer Data Protection Act (CDPA) and California’s CCPA/CPRA, for example, take a more contextual approach: an IP address in isolation, without additional signals that would allow identification of a specific individual, may not meet the threshold for personal data under those frameworks. The principle that identifiability is what matters — not the data point in isolation — is increasingly recognized across jurisdictions, even if the precise threshold varies. This distinction is relevant in practice: a server that logs IP addresses purely for network security purposes, without combining them with behavioral data or other identifiers, occupies a different legal position from one that uses IP addresses as part of a persistent user profile.
This broad definition means that many ordinary digital practices can fall within GDPR’s scope, including analytics, personalization, audience measurement, fraud prevention, and online advertising. The absence of a person’s name from a dataset does not, by itself, place the activity outside the law.
Having said that, it’s also fair to observe that not all personal data carries the same risk from a liability standpoint. GDPR applies to personal data as a single category, but it does not treat every kind of personal data identically. The regulation is risk-based, and that gradient is written into its structure. Special categories such as health, biometric and political data face a near-prohibition lifted only by specific conditions. Security measures must be appropriate to the risk, which means the standard expected for a database of medical records is not the standard expected for a server log. A Data Protection Impact Assessment is required only where processing is likely to result in high risk. Breach notification is triggered by risk to individuals, and notifying the individuals themselves is required only where that risk is high.
The practical consequence is that an IP address in a web server log and a patient’s diagnosis are both personal data, and both sit within GDPR’s scope, but the obligations attaching to them differ substantially. The question the regulation asks is not simply whether data is personal, but what could happen to a person if it were misused. Treating every data point as though it carried the same exposure is not what GDPR requires, and it tends to obscure the cases that genuinely warrant care.
Who the Rules Apply To: Controllers and Processors
GDPR’s obligations do not attach to everyone who touches personal data in the same way. The regulation distinguishes between the party that decides what happens to the data and the party that merely acts on those decisions. The distinction between Data Controller and Data Processor is crucial.
Data Controller
Example: an online retail company collects personal data from customers (for example, names, addresses, emails, phone numbers, payment information) to process orders and improve its services. The company determines the purpose and means of processing this data.
The controller is the party that decides why personal data is processed and how. It is the role that carries the primary legal obligations under GDPR: establishing a lawful basis, informing users, honoring their rights and answering to a supervisory authority when something goes wrong. A publisher running a website decides what data to collect from its readers and what to do with it, so the publisher is a controller. Crucially, the role is not assigned by contract. It follows from who actually exercises decision-making power, which means a company can be a controller without ever having called itself one.
Data Processor
Example: a cloud storage provider that the hospital uses to store patient records processes the data solely based on the hospital’s guidelines and does not have any control over how the patient information is utilized.
The processor handles personal data on behalf of a controller and only on that controller’s documented instructions. This applies to handling of personal information as sensitive as health records, as well as a cloud provider storing a publisher’s log files. Both are examples of data processors. Notably, a Consent Management Platform (CMP) is also a data processor in most configurations: the publisher decides which vendors to disclose and what the banner says, and the CMP executes.
While processors have their own obligations — a written contract (the DPA, Data Processing Agreement), adequate security, no sub-processors without authorization —, their liability is narrower than a controller’s. The line is not fixed, though. A processor that starts deciding purposes for itself, for example by reusing a client’s data for its own product development, becomes a controller for that processing and inherits the full obligations along with it.
NOTE: mentioning Joint Controllers here would be borderline too much information, if it wasn’t that the nature and the handling of user consent (TC strings) were foundational concepts in rulings that involved IAB Europe and CJEU (EU Court of Justice). Where two or more parties jointly determine the purposes and means of processing, they are joint controllers and must have an arrangement setting out who does what. Users can exercise their rights against any of them. Joint control does not require equal responsibility or equal access to the data; it requires only that the parties genuinely decide together.
The Core Principles
GDPR is built around a set of principles that apply to all processing of personal data. These principles are foundational: the more detailed obligations in the regulation can largely be understood as efforts to give them practical effect.
Lawfulness, Fairness, and Transparency
Personal data may not be processed simply because doing so is useful or commercially attractive. Organizations must identify a lawful basis for processing. Under GDPR, the main lawful bases include:
- consent
- performance of a contract
- compliance with a legal obligation
- protection of vital interests
- performance of a task carried out in the public interest
- legitimate interests, where those interests are not overridden by the rights and freedoms of the individual
Lawfulness, however, is only part of the picture. GDPR also requires fairness and transparency. Fairness means, in general terms, that processing should not be unduly unexpected, misleading, or exploitative. Transparency means that individuals should be informed, in accessible language, about what data is being processed, for what purposes, on what basis, by whom, and with what consequences.
Purpose Limitation
Personal data must be collected for specified, explicit, and legitimate purposes, and it must not later be used in ways that are incompatible with those purposes.
This principle is meant to prevent the gradual expansion of data use after collection. It does not mean that every secondary use is automatically unlawful, but it does mean that organizations may not treat personal data as an indefinitely reusable resource for any future objective that later becomes attractive. The individual should be able to understand, with reasonable clarity, why the data was collected and the general boundaries within which it will be used.
Data Minimization
Organizations should process only personal data that is adequate, relevant, and limited to what is necessary for the purpose at hand.
This principle rejects a common tendency in digital systems: to collect broadly first and determine usefulness later. Under GDPR, necessity matters. The fact that data might become useful in the future is not, by itself, sufficient. Data minimization may affect:
- what categories of data are collected
- how detailed that data is
- how often it is collected
- who can access it internally
- whether it is shared onward
Accuracy
Personal data should be accurate and, where necessary, kept up to date. Organizations are expected to take reasonable steps to correct or erase inaccurate data.
This principle is straightforward in some contexts, such as account details or billing information, but it can become more complex where systems generate scores, classifications, or inferences. In those cases, the question is not only whether recorded facts are correct, but also whether the information being maintained is sufficiently reliable and current for the purpose for which it is being used.
Storage Limitation
Personal data should not be kept longer than necessary for the purposes for which it was collected or processed.
Even where collection was lawful at the outset, indefinite retention is not automatically permissible. Organizations are generally expected to define and apply retention periods, deletion policies, and, where appropriate, anonymization practices. In effect, this principle treats time itself as a limit on the use of personal data.
Integrity and Confidentiality
Personal data must be processed in a manner that ensures appropriate security. This includes protection against unauthorized access, unlawful processing, accidental loss, destruction, or damage.
Appropriate measures may include:
- access controls
- encryption
- logging and monitoring
- backup procedures
- vendor oversight
- incident response processes
What counts as ‘appropriate’ depends on context, including the sensitivity of the data, the risks to individuals, and the nature and scale of the processing.
Accountability
GDPR requires not only compliance, but also the ability to demonstrate compliance. This is the principle of accountability.
In practice, accountability may involve:
- records of processing activities
- internal policies
- staff training
- contractual controls
- risk assessments
- Data Protection Impact Assessments
- the appointment of a Data Protection Officer where required
The practical effect is that GDPR expects compliance to be structured, documented, and reviewable, rather than informal or purely declaratory.
Lawful Bases for Processing
A central feature of GDPR is that organizations may not process personal data without identifying a legal basis for doing so. The lawful basis matters because it shapes both the justification for the processing and, in some cases, the rights available to the individual.
The principal lawful bases are:
- consent
- contract
- legal obligation
- vital interests
- public task
- legitimate interests
In programmatic, the most discussed bases are consent and legitimate interests.
Consent
Where consent is relied upon, it must be freely given, specific, informed, and unambiguous. It must also be capable of being withdrawn.
Consent under GDPR is therefore not merely a formal gesture. It is intended to reflect a real and sufficiently informed choice by the individual, although exactly how that standard applies in particular settings is often a matter of legal and regulatory interpretation.
Legitimate Interests
Legitimate interests can serve as a lawful basis where:
- the organization has a genuine interest
- the processing is necessary for that interest
- the individual’s rights and freedoms do not override it
This basis requires a balancing exercise. It is not enough simply for an organization to assert that processing is useful or normal within its industry.
Rights of the Individual
GDPR gives individuals a number of rights in relation to their personal data. These rights are an important part of the regulation’s structure because they recognize that personal data is not simply under the exclusive control of the organization that happens to hold it.
These rights include, among others:
- the right to be informed
- the right of access
- the right to rectification
- the right to erasure in certain circumstances
- the right to restriction of processing
- the right to data portability
- the right to object to certain forms of processing
GDPR also includes protections in relation to certain forms of automated decision-making, especially where those decisions produce legal effects or similarly significant consequences for the individual.
Special Categories of Personal Data
Not all personal data is treated in the same way. GDPR recognizes certain categories of data as especially sensitive and subjects them to stricter conditions.
These include data revealing:
- racial or ethnic origin
- political opinions
- religious or philosophical beliefs
- trade union membership
They also include:
- genetic data
- biometric data used for identification
- health data
- data concerning a person’s sex life or sexual orientation
Even where such information is not collected explicitly, regulatory concerns may arise where ordinary data points can support sensitive inferences.
Governance and Compliance
From an organizational standpoint, GDPR requires more than the publication of a privacy policy. It requires a working model of data governance.
In practical terms, organizations may need to know:
- what personal data they hold
- where it came from
- why it is being processed
- on what legal basis it is being processed
- who has access to it
- how long it is retained
- with whom it is shared
- what risks attach to it
- how individuals may exercise their rights
For that reason, compliance often involves a combination of legal analysis, operational design, procurement controls, contractual review, security measures, and internal documentation.
GDPR and Digital Advertising
GDPR does not prohibit all advertising, analytics, personalization, or audience measurement. It does, however, require that these activities be evaluated within the same legal framework as any other processing of personal data.
In the advertising context, recurring issues include:
- lawful basis
- transparency
- purpose specification
- retention
- profiling
- third-party sharing
- international transfers
- the practical ability of individuals to understand and exercise control
The regulation’s relevance to advertising lies not in any sector-specific prohibition, but in the fact that advertising systems often involve large-scale data collection, multiple intermediaries, persistent identifiers, and forms of inference that can be difficult to describe or delimit clearly.
General Significance
GDPR is best understood not as a narrow rule about notices or consent interfaces, but as a broader framework for imposing structure, justification, and limits on the processing of personal data.
Its central premises are that processing should be:
- “purposive” rather than open-ended
- proportionate rather than excessive
- time-bound rather than indefinite
- secure rather than casual
- intelligible rather than obscure
Whether a particular practice satisfies those requirements depends on context, implementation, and legal interpretation. The underlying objective, however, is clear: organizations must be able to explain why their processing of personal data is lawful, necessary, and fair.
Key Terms and Acronyms
| Acronym | Full Term | Description |
| GDPR | General Data Protection Regulation | The EU’s primary privacy regulation, in force since May 2018 |
| Profiling | Profiling | Any automated processing of personal data used to evaluate, analyze, or predict aspects of a person’s behavior, preferences, or circumstances. Note: Behavioral advertising is profiling by definition under GDPR, which is why it faces stricter consent requirements than basic analytics processing |
| DPA (1) | Data Protection Authority | The national supervisory body responsible for enforcing GDPR in each EU member state (e.g. the ICO in the UK, the CNIL in France, the DPC in Ireland) |
| DPA (2) (contract) | Data Processing Agreement | A contract between a controller and a processor governing how personal data is handled on the controller’s behalf — note this abbreviation is shared with Data Protection Authority, which can cause confusion |
| DPO | Data Protection Officer | A designated individual within an organization responsible for overseeing data protection compliance; mandatory in certain circumstances |
| DPC | Data Protection Commission | Ireland’s DPA; significant because most large US tech companies have their EU headquarters in Ireland |
| ePD | ePrivacy Directive (Directive 2002/58/EC) | EU legislation aimed at the privacy and protection of personal data in electronic communications. It predates GDPR and focuses specifically on the privacy rights of individuals in the context of electronic communication services. |
| ICO | Information Commissioner’s Office | The UK’s data protection supervisory authority; operates under UK GDPR post-Brexit |
| CNIL | Commission Nationale de l’Informatique et des Libertés | France’s DPA |
| DSR | Data Subject Request | A formal request by an individual exercising their rights under GDPR, such as access, erasure, or portability |
| DSAR | Data Subject Access Request | A specific type of DSR requesting access to personal data held about an individual |
| DPIA | Data Protection Impact Assessment | A structured risk assessment required before undertaking high-risk processing activities |
| RoPA | Records of Processing Activities | Documentation organizations must maintain describing their data processing operations |
| LIA | Legitimate Interests Assessment | A documented balancing exercise conducted when relying on legitimate interests as a lawful basis |
| SCCs | Standard Contractual Clauses | Pre-approved contract clauses used to legitimize transfers of personal data from the EEA to third countries |
| BCRs | Binding Corporate Rules | An internal data transfer mechanism for multinational organizations, approved by a lead DPA |
| TCF | Transparency and Consent Framework | The IAB’s industry framework for managing consent and legitimate interest signals in digital advertising |
| CMP | Consent Management Platform | Technology used by publishers to collect, record, and communicate user consent choices |
| GVL | Global Vendor List | The IAB’s register of certified ad tech vendors participating in the TCF |
| EEA | European Economic Area | The EU member states plus Iceland, Liechtenstein, and Norway; the primary geographic scope of GDPR |
| UK GDPR | United Kingdom General Data Protection Regulation | The version of GDPR retained in UK law following Brexit; largely mirrors EU GDPR |
| CCPA | California Consumer Privacy Act | California’s primary privacy law; shares concepts with GDPR but differs in structure and scope |
| CPRA | California Privacy Rights Act | The 2023 update to CCPA, strengthening individual rights and establishing the CPPA |
| CPPA | California Privacy Protection Agency | California’s dedicated privacy enforcement authority, created by CPRA |
| CDPA | Consumer Data Protection Act | Virginia’s privacy law; takes a more contextual approach to personal data than GDPR |
| PII | Personally Identifiable Information | An industry term, not a GDPR term, often used more narrowly than GDPR’s “personal data” |
