What GDPR and other privacy regulations were supposed to do, what the industry actually did, and why nobody stopped the dance

By Luca Passani, @Scientia_CTO, August 2026

Note: The audience activation machinery I toured in the lastthreearticles rests on three assurances: that the user consented (the consent string riding in every bid request), that nobody knows who the user isย  (the hashed email), and that nobody targets the user individually โ€” only as a member of a group (the cohort). This article examines whether the foundation it stands on actually holds up to regulatory scrutiny.
I mentioned that ad tech companies should treat personal data with the same care reserved for hazmat, but never explained why in significant detail. Yet, this is a foundational topic for everyone working in programmatic. Itโ€™s time for the deep dive.

Important: Grab a coffee โ€” this is a long article.

In case you didnโ€™t read the previous installments of this series and still donโ€™t know what behavioral targeting is, itโ€™s the practice of tracking what you do online โ€” the articles you read, the products you browse, the searches you run โ€” and using that history to serve you ads that reflect what advertisers think they know about you. The profile that emerges over time can include inferred details about your health, your finances, your political views, and your personal circumstances, none of which you explicitly provided to anyone. The next time an ad for a mortgage refinancing service follows you around the internet for a week after you looked up interest rates once, thatโ€™s behavioral targeting at work. Itโ€™s useful to advertisers, invisible to most users, and โ€” depending on who you ask โ€” either the engine of the free internet or a surveillance apparatus that would have made Cold War intelligence agencies jealous.

Note: the Frada scenario from the previous articles is behavioral advertising. Sloane gets targeted because of her purchase history. We showed how targeting can be further split into deterministic and probabilistic, i.e. two aspects of behavioral targeting.

Now that you know what behavioral targeting is, should governments do something about it?

We have a lot of ground to cover. I will get back to this later in this long article. To answer it properly, we need to understand why regulation happened, what the industry did with it, and why tracking survived anyway. Each of those is a shorter story than you think.

Letโ€™s backtrack.

Why regulation happened โ€” The Snowden revelations and Cambridge Analytica

GDPR โ€” EUโ€™s General Data Protection Regulation, arguably the mother of all privacy laws โ€”  didn’t appear out of nowhere. The European Union had been working on updating its 1995 Data Protection Directive for years, driven by a growing unease about what the internet had become โ€” a vast, largely unregulated machine for harvesting personal data at industrial scale.

From a US perspective, everything Europeans do is often excruciatingly complicated. The logic โ€œwe donโ€™t know if it hurts. Letโ€™s try and see for ourselvesโ€ just doesnโ€™t apply to Europe. They are more like โ€œThis might hurt. Letโ€™s err on the side of not doing itโ€.

If you are American, donโ€™t rush to pass a judgment on the inhabitants of the Old World. That mindset is rooted in Europe’s 20th-century history. The Gestapo, the Stasi, the OVRA, Franco’s secret police โ€” all ran on index cards, registries, and census data. The EUโ€™s attitude toward mass data collection is shaped by the knowledge that the infrastructure of surveillance has been used, on European soil, within living memory, to round people up and kill them. Americans generally donโ€™t have that reference point; Europeans do. This is why the EU treats โ€œwho has your dataโ€ as a question of a fundamentally different kind than โ€œwho has your credit scoreโ€. For Europeans, data protection is a fundamental human right. For Americans, well, not so much.

In that context, the Snowden revelations of 2013 accelerated everything. Suddenly it was clear to everyone that the data commercial platforms collected about you could be freely accessed by a foreign power. In a worst-case, kind of dystopic future, personal data could be turned against European citizens.

But that wasnโ€™t the end of it. In late 2016 and throughout 2017, the Cambridge Analytica story was slowly coming into focus. Brexit and Trumpโ€™s first election depicted the power of personal data very vividly โ€” the synergy of behavioral psychology, social media data harvesting and advertising targeting had created a machine that could change election results. The company had largely operated within the loose rules and technical permissions that existed at the time, yet something mind-boggling had happened.

The Cambridge Analytica scandal was the most vivid possible demonstration of why GDPR existed, arriving at the exact moment the regulation was about to take effect (GDPR was adopted in 2016 and came into force in May 2018). If you were trying to build public support for a sweeping privacy law, you couldnโ€™t have scripted the timing better.

If you are a white-collar professional, chances are that you already associate GDPR with โ€œthe European take on user privacyโ€. For this reason, I have put a short primer into an appendix of its own. The rest of this article stands on its own, but I still recommend that you have a look at it later. It will prepare you to endure privacy law discussions without looking foolish.

Note:  A patientโ€™s diagnosis and an IP address in a log file are both personal data, but they are obviously not the same problem. Yet, hereโ€™s the part that often gets lost in my personal experience: GDPR is risk-based, and it says so itself. Special categories get a near-prohibition, security has to match the risk, impact assessments are triggered by high risk, and breach-notification thresholds are graded.

One important clarification before continuing: the cookie banners you encounter on every European website are not primarily a GDPR requirement. They are a requirement of the ePrivacy Directive โ€” a separate EU law, originally from 2002 and amended in 2009, that specifically governs the use of cookies and tracking technologies. GDPR governs the processing of personal data broadly. ePrivacy governs the specific act of accessing or storing information on a userโ€™s device. The two laws work in combination: ePrivacy requires consent for placing a cookie, and GDPR governs what you do with the data that cookie collects.

Privacy Regulations in the U.S.

The US doesnโ€™t really have a โ€œprivacy lawโ€ in the European sense. It has a patchwork. And that patchwork reflects a fundamentally different starting philosophy. European privacy law starts from the person: data about you is an extension of you, and you retain rights in it regardless of who holds it. 

American privacy law starts from the relationship between the parties and the context: is there a contract, a tort (a civil wrong one can sue over), a specific sectoral harm? The seminal Warren & Brandeis article from 1890 framed privacy as โ€œthe right to be let aloneโ€, i.e. a liberty against the state, not a property right in personal information held by private companies. That framing has stuck. Interestingly, even the First Amendment cuts hard against European-style data rules: in the US, information (and that includes information about you) is speech, and restricting its flow triggers serious constitutional scrutiny. This is why a generalized, GDPR-style โ€œright to be forgottenโ€ might be declared unconstitutional in the US; itโ€™s compelled suppression of truthful information by private publishers.

Yet, with the advent of the Internet, and then machine learning, the need to regulate at least some aspects of personal information has become clear. The federal governmentโ€™s failure to regulate the sector has brought the individual states to act, leading to a sectoral patchwork of privacy regulations. Instead of one omnibus (comprehensive) law, the US regulates privacy industry by industry, each statute born of a specific scandal or lobbying episode. The following table provides an overview.


Regulation

Purpose
HIPAA (1996)  Health data, but only when held by โ€œcovered entitiesโ€ (providers, insurers, clearinghouses). Your Fitbit data is not HIPAA-protected.
GLBA (1999)  Financial institutions.
FERPA (1974) Educational records.
COPPA (1998)  Protects children under 13.
VPPA (1988)  Video rental records, passed in a panic after a reporter obtained Robert Bork’s Blockbuster history during his Supreme Court nomination. Still on the books, now awkwardly applied to streaming.
FCRA (1970)
Credit reporting.
TCPA, CAN-SPAM, ECPA Telemarketing, email, wiretapping.

Table 1: Sectoral patchwork of US privacy regulations.

Nothing covers the general category of โ€œa company has data about youโ€. An ad tech firm profiling your browsing isnโ€™t a covered entity under any of these. In fact, thereโ€™s no privacy enforcement federal agency with this name, though the Federal Trade Commission (FTC) has become the de facto US privacy regulator via Section 5 of the FTC Act, which prohibits โ€œunfair or deceptiveโ€ practices. 

The FTC canโ€™t make rules easily, but it can bring enforcement actions when companies violate their own posted privacy policies.

Note: This creates a strange incentive: the less a company promises, the less liability it has. A company with no privacy policy is in a better legal position than one with a detailed one it slightly breaches. This is roughly the opposite of the GDPR incentive structure.

Because of US Congressโ€™s repeated failure to pass an omnibus federal privacy law (ADPPA came closest in 2022 and died), states have filled the vacuum. In addition to the GDPR-likes, some other state laws are worth mentioning.


Regulation
Purpose
CCPA/CPRA
California, others followed.
Californiaโ€™s law is the closest thing to GDPR, with rights of access, deletion, and opt-out of โ€œsaleโ€. Virginia, Colorado, Connecticut, Utah, Texas, and about 15 others at the time of this writing have followed with variations. 
BIPA Illinois This is a US privacy law that covers biometric data. It can hurt companies that donโ€™t pay enough attention: private right of action (anyone can file a lawsuit) and statutory damages (no need to demonstrate actual economic damage) brought Meta to pay $650M. Itโ€™s no coincidence that most biometric class actions in the US are filed in Illinois.

Table 2: Major US state-level regulations dealing with personal data.

The California Invasion of Privacy Act (CIPA) also deserves a special mention. Enacted in 1967 to prevent wiretapping, this statute is being reinterpreted by class action attorneys to cover analytics pixels, session replay tools, and identity graph lookups. Under CIPA, you donโ€™t need a regulator to bring a case and you donโ€™t need to prove you were actually hurt. Any affected user can sue directly and collect a fixed cash payout per violation. Multiply that across a class of millions of users and the numbers get very large, very fast. As of 2026, CIPA claims are reaching even small and mid-sized adtech players, and recent rulings have opened the door to challenges against hashed email addresses and UID2 tokens.

Note: One way to look at this is that the US is catching up to Europe on consent requirements faster than most of the industry acknowledges, driven by litigation, not legislation. Then again, this observation might age poorly if the California legislature shuts down the novel interpretation of CIPA six months from now (August 2026). 

For tech titans this situation is pretty bad: a growing patchwork of 20-ish state regimes plus GDPR plus sectoral federal laws. For smaller companies itโ€™s even worse โ€” they face the same maze without the legal armies the giants throw at it. Serving a global internet audience is an absolute nightmare for them.

In fairness to Americans, GDPR is not a monolith either. A number of milestone rulings shaped how GDPR is interpreted and enforced in practice, and made complying with GDPR a lot harder for US companies that serve European customers. Hereโ€™s a list of the main rulings.

Ruling Description
Schrems I (2015) The CJEU (EU Court of Justice) invalidated the EU-US Safe Harbour Decision, the original mechanism that allowed US companies to self-certify compliance with EU data protection standards. Max Schrems (an Austrian lawyer and privacy law activist) argued that US surveillance laws made Safe Harbour meaningless. The court agreed.
Schrems II (2020) The CJEU ruled the EU-US Privacy Shield was invalid, while upholding Standard Contractual Clauses but with significantly stricter conditions. The core argument: US surveillance programs such as PRISM and UPSTREAM are not limited to what is strictly necessary and represent a disproportionate interference with EU privacy rights. This is the one that hit the ad tech industry hardest. It forced US ad tech companies handling EU personal data to reassess their data transfer mechanisms (Standard Contractual Clauses, supplementary measures, and their hosting and processing architecture) in ways that had significant operational and commercial consequences across the industry.
IAB Europe TCF ruling (2022-2026) The Belgian DPA found IAB Europeโ€™s Transparency and Consent Framework (TCF) non-compliant with GDPR in 2022, and four years of appeals narrowed it to this: TC strings are personal data, and IAB Europe is a joint controller for the string because it designed how consent gets encoded. โ‚ฌ250,000, still under appeal as I write this. The paradox is that Google, which controls consent end-to-end, didnโ€™t have the same problem. The takeaway is uncomfortable: publish your consent architecture and you become a defendant, keep it in-house and youโ€™re fine.

Little aside: CNIL, the French privacy agency, still fined (pun intended) Google โ‚ฌ325 million over cookie consent and advertising, but thatโ€™s a different story.
Meta/legitimate interests ruling (October 2024) The CJEU clarified that the GDPR imposes limits on Metaโ€™s use of personal data collected outside the Facebook social network for advertising purposes, and separately found that Meta could not rely on its overall user relationship to process personal data for targeted advertising without restriction as to time or data type.
The Data Privacy Framework (2023) The current framework (the Data Privacy Framework, adopted in 2023) survived its first legal challenge when the EU General Court upheld it in September 2025. An appeal path to the CJEU remains open, and the same court that struck down Safe Harbour and Privacy Shield would hear any future challenge. The legal thread is thinner than the industry would like โ€” and thinner still given the Trump administrationโ€™s moves to dismantle the independent oversight bodies the DPF depends on โ€” but, as of August 2026, it has not yet snapped.

Table 3: Major rulings that shaped how GDPR is interpreted and enforced in practice, making the lives of US players somewhat complicated.

Note: Max Schremsโ€™s story warrants an additional note. As an Austrian law student on exchange in California in 2011, he was appalled to discover that Facebookโ€™s own privacy lawyer didnโ€™t know beans about EU privacy regulations and their severity (or he probably did, but knew that European fines were chump change for his client). Max filed a subject access request (it was already possible at the time) and got back a CD-ROM from Facebook with over 1,200 pages, including material he thought he had deleted. Next thing we know, he turned into a privacy activist who challenged the legality of data transfers between the EU and the US successfully (Schrems I and Schrems II invalidated transatlantic data exchange rules in force at the time). US companies did โ€” and in many cases still do โ€” treat EU privacy regulations as an inconvenience rather than a fundamental constraint. Schremsโ€™s shock at the complacency in 2011 was emblematic.

If a US company is processing any user data on behalf of an EU entity โ€” even something as simple as an analytics pixel embedded in a website โ€”, this makes the US entity a data processor under GDPR, i.e. they are handling the personal data of European citizens.

Any US company that processes personal data on behalf of a European entity is operating under a legal framework that has already been invalidated twice by Europeโ€™s highest court. Safe Harbour, the original EU-US data transfer agreement, was struck down in 2015. Privacy Shield, its replacement, was struck down in 2020. The current framework โ€” the Data Privacy Framework (DPF), adopted in 2023 โ€” survived its first legal challenge in September 2025, but the appeal is already before the Court of Justice of the EU, the same court that invalidated the two prior frameworks. The core problem has never changed: US surveillance law gives American intelligence agencies access to data held by US companies, and European courts have repeatedly found that this access is incompatible with EU privacy rights. Max Schrems himself has suggested he may not even need to bring a formal challenge โ€” that the Trump administrationโ€™s dismantling of the independent oversight bodies that underpin the current framework may be enough for the European Commission to suspend the deal on its own. Experts who worked on the current framework have said the US has gone as far as it believes it can go to meet EU standards, making another round of negotiations unlikely if the DPF falls. Which means any US ad tech company telling a European publisher โ€œyour data is safe with usโ€ is making a promise whose legal foundation has a documented habit of disappearing.

History of the legal basis for transatlantic data transfers

Figure: The legal basis for transatlantic data transfers being struck down, replaced, and challenged again over the years.

In short, at this moment, any US companyโ€™s ambition to act as the data processor for a European entity is walking on legally thin ice.

Note: In spite of all this, the cycle continues. And the industry keeps running regardless.

Skeletons in the closet 

At this point, you might have the impression that whoever designed GDPR was driven by specific social and political causes. And this is partly true, but itโ€™s not the whole story. A more cynical view would also look at the geopolitical-economic layer that brought GDPR to its current interpretation.

Hyperscalers (and lack thereof)

Hyperscalers are massive companies that build and run digital infrastructure at such an extreme scale that it reshapes the whole economy.  Iโ€™m sure you are already familiar with their names. Amazon/AWS, Microsoft/Azure and Google/GCP are cloud hyperscalers and, together, they control about 65% of the global cloud. Meta, Google and Amazon are social media (and hence ad tech) hyperscalers. NVIDIA, a hyperscaler in AI hardware, is worth ~2x the Italian GDP by itself. If I was to look at Asia, TikTok, Alibaba and Tencent also fully deserve the hyperscaler title.

Note: hereโ€™s a quick test: If a company can crash 5% or more of the internet by turning off its servers, itโ€™s a hyperscaler.

Some historical analogues would be Standard Oil, US Steel and AT&T.

If we count Europeโ€™s hyperscalers, we will soon discover that United Europe is an economic powerhouse that, over the past 30 years, has egregiously failed to create globally relevant Internet companies. The reality โ€” the unflattering motivation behind GDPR โ€” was never purely about protecting individual privacy. It was also about power. Europe watched the rise of Google, Facebook, Amazon, and Microsoft and recognized that it had allowed the most valuable resource of the 21st century โ€” data โ€” to be harvested from European citizens and monetized by American companies, generating enormous economic value that flowed entirely outside the EU. 

Note: Some EU policymakers were openly explicit about this โ€” Andreas Schwab, one of the architects of the Digital Markets Act, stated early on his desire to counter the dominance of US firms. The GDPR, the DMA (Digital Markets Act), the DSA (Digital Services Act) and the AI Act are not a disconnected series of consumer protection measures. They are, taken together, a deliberate industrial and geopolitical strategy. The US dominates global data traffic via its digital platforms and, thanks to the CLOUD Act, has extensive access rights to data from US tech companies even when they operate outside the US. GDPR was Europeโ€™s answer to that asymmetry โ€” an attempt to reassert sovereignty over data flows that had been quietly leaving the continent for two decades.

This is not a conspiracy theory or an outside interpretation. The European Commissionโ€™s own January 2026 Call for Evidence on digital ecosystems stated plainly that the EU faces โ€œa significant problem of dependence on non-EU countries in the digital sphereโ€ that creates vulnerabilities in critical sectors โ€” language that would have been unthinkable in an official Commission document a decade ago. The privacy framing is real and sincere. But it has always coexisted with something that looks a great deal like industrial policy.

A few notes about the DMA, DSA and AI act

The DMA and DSA, both adopted in 2022, are worth distinguishing from GDPR. Where GDPR protects individualsโ€™ personal data and applies to any organization that processes it, the DMA and DSA target a specific problem: the structural dominance of a handful of platforms. The DMA designates walled garden companies as โ€œgatekeepersโ€ โ€” Google, Meta, Amazon, Apple, Microsoft, ByteDance (TikTok) โ€” and specifically restricts how they can combine user data across their services, self-preference their own products, or use data obtained in one service to target users in another. 

For behavioral advertising, the practical consequence is significant: the DMA is why Meta was forced to introduce its โ€œconsent or payโ€ model in Europe. The DSA goes further in a different direction โ€” it adds transparency requirements for algorithmic recommendation systems and bans certain targeting categories entirely across all platforms, not just gatekeepers: religion, sexual orientation and, notably, political opinion. The ban on targeting based on political opinion was a direct regulatory response to the Cambridge Analytica scandal I mentioned at the beginning of the article. 

The AI Act, the most recent addition to this regulatory stack, extends oversight to automated decision-making systems including those used for ad targeting and profiling. Taken together these four instruments โ€” GDPR, DMA, DSA, AI Act โ€” form a regulatory architecture that no other jurisdiction has attempted at this scale.

Note: Of course, the US perspective on all this is somewhat less flattering: Europeโ€™s response to each successive wave of technological disruption has been consistent: regulate what you cannot build.

The Americansโ€™ skeleton in the closet

If GDPR is partly industrial policy for a bloc without hyperscalers, the absence of a US GDPR is the mirror image: the US has the hyperscalers, and an omnibus privacy law would hobble them. This isnโ€™t cynical speculation. Rather, itโ€™s visible in the lobbying record against attempts to pass ADPPA, i.e. GDPR-style privacy regulation at the federal level. Silicon Valley prefers the current patchwork because itโ€™s navigable by firms with large legal departments and because sectoral law leaves the ad tech and data broker industries almost entirely unregulated. The consumer-data industry in the US (Acxiom, LiveRamp, Experianโ€™s marketing arm, etc.) essentially could not exist in its current form under GDPR.

What the industry built

So, should governments do something about behavioral targeting?

The honest answer is: they already did, and the results are instructive. GDPR is the most ambitious attempt to regulate behavioral targeting at scale. It has been in force for seven years. In those seven years, the cookie banner has become the universal symbol of the lawโ€™s practical effect: a piece of UX theater that most users click through in under three seconds without reading. It is a performance that resolves nothing, staged for an audience that decides nothing. Its primary function is to generate a consent signal that travels through the bid stream as a legal fig leaf. We already met the cookie banner (AKA Consent Management Platform, or CMP) back in the supply-side article as a working part of the publisherโ€™s machinery. The regulation that was supposed to give users meaningful control over their data produced, in practice, a compliance industry worth billions of euros and a user experience that is almost universally despised (you click on those dialog boxes dozens of times every day, or more if you are in Europe).

This is not because GDPR was poorly written. Itโ€™s because the incentives of the parties responsible for implementing it were never aligned with its stated goals. Publishers need revenue. CMPs are paid by publishers. Consent rates are how CMPs are evaluated. 

The result is a market for consent UI that optimizes relentlessly for acceptance rather than genuine informed choice. The dark patterns we already saw in this article โ€” pre-ticked boxes, buried reject options, asymmetric button sizes, endless layered menus โ€” are not accidents. They are the rational output of a system where the entity collecting consent profits from its volume.

Underlying all of this is a concept that sits at the heart of every regulatory dispute in this space: profiling. 

Note: Under GDPR, profiling means any automated processing of personal data used to evaluate, analyze, or predict aspects of a personโ€™s behavior. Behavioral targeting is profiling by definition, but the term identifies a wider set. Profiling includes automated processing of personal data to evaluate, analyze or predict aspects of a person: behavior, preferences, interests, health, economic situation, reliability, location, movements. Credit scoring is profiling. Insurance risk rating is profiling. Fraud detection is profiling. A hospital predicting readmission risk is profiling. None of those are advertising. 

The moment identification stops being an analytics tool and starts being an input into a model that predicts what you might buy, where you might travel, or what political message might move you โ€” thatโ€™s profiling. And profiling for advertising purposes is precisely the processing that courts have found cannot be justified under legitimate interests, cannot be buried in a third-level consent menu, and cannot be delegated to a publisher contract. It is the specific activity that the entire consent infrastructure exists to authorize. And as weโ€™ve seen, it does so imperfectly at best. 

The regulationโ€™s architects were not naive. IAB Europeโ€™s Transparency and Consent Framework (TCF) is an attempt to systematize consent across the programmatic supply chain โ€” a shared language for communicating user choices downstream to every SSP and DSP in the chain. 

The Belgian DPAโ€™s finding that the TCF was non-compliant with GDPR in important respects was the regulation eating its own implementation. And if the TCF was to fall, the darkly ironic consequence is that Googleโ€™s parallel consent infrastructure would become the only viable alternative. This is the (arguably predictable) outcome of a system where the largest player has the resources to build compliant infrastructure and smaller players do not.

So should governments regulate behavioral targeting? And if so, has GDPR done it effectively? Weโ€™ll see about that. The gap between the lawโ€™s stated purpose and its practical effect is the space that the industry calls โ€œcomplianceโ€ and regulators call โ€œenforcement failureโ€. Closing that gap would require either much heavier enforcement โ€” the kind that actually threatens business models, not the kind that results in fines Google pays out of a weekโ€™s revenue โ€” or a fundamentally different regulatory approach that starts from the incentive structure rather than the โ€œconsent interfaceโ€.

More on Consent Management Platforms (CMP) and TCF: the infrastructure of the performance

As you know, a CMP is the technology that sits between a user arriving on a publisherโ€™s page and the advertising ecosystem waiting to bid on that userโ€™s impression. When you land on a news site and a banner appears asking whether you accept cookies, that banner was served by a CMP. When you click accept (or reject), the CMP records your choice, encodes it into a standardized string called a TC (Transparency and Consent) string โ€” defined by IAB Europeโ€™s Transparency and Consent Framework โ€” and makes that string available to every piece of ad tech running on the page. SSPs, DSPs, identity providers, measurement vendors โ€” all of them read the TC string to determine what they are and are not permitted to do with your data.

A TC string is encoded and opaque, and could look something like:

CQliWsAQliWsAEsABBENCiFoAPLA AELAAAYgGMwAwAOALzAYyBecAEBeYAAA .IGMwAwAOALzAYyAA

It travels in the euconsent-v2 cookie, comes out of the CMP’s JS API as tcString, and reaches the bid stream in user.ext.consent alongside regs.ext.gdpr=1 โ€” user.consent and regs.gdpr in OpenRTB 2.6.

The Global Vendor List (GVL) is a list of approved vendors that CMPs obtain from IAB Europe. It lists all registered and approved Vendors as well as the categories of data collected in conjunction with the purposes. CMPs rely on the GVL to determine what legal disclosures must be made to the user.

Decoded bit by bit, the following will give you an idea of what information a TC string carries in cleartext.

FieldValueWhat it means
Version2TCF v2 string
Created2026-06-09 00:00:00 UTC
Last updated2026-06-09 00:00:00 UTCnever revisited
CMP ID300Which CMP generated it
CMP version1
Consent screen1Which banner screen the user was on
Consent languageEN
Vendor list version162The GVL edition in force
TCF policy version5i.e. TCF v2.3
Service specificyesScoped to this site, not global
Non-standard textsno
Special feature opt-ins1Precise geolocation
Purposes consented (*)1, 2, 3, 4, 7, 9, 10TCF purposes
Purposes, legitimate interest2, 7, 9, 10
Purpose 1 treatment0
Publisher countryDE
Vendor consent28, 755, 793
Vendor legitimate interest755
Publisher restrictionsnone
Disclosed vendors segment28, 755, 793Which vendors the banner actually showed

(*) The purpose numbers are the part worth spelling out: 1 store and/or access information on a device, 2 use limited data to select advertising, 3 create profiles for personalized advertising, 4 use profiles to select personalized advertising, 7 measure advertising performance, 9 understand audiences through statistics, 10 develop and improve services.
So in plain English: a German publisherโ€™s English-language banner, screen one, on 9 June 2026, recorded that this user agreed to have a profile built about them and used to pick ads, agreed to be geolocated precisely, and agreed to three named vendors. Purposes 3 and 4 are behavioral targeting itself. That pair is the consent the whole apparatus exists to produce.

Table 4TC string demystified.

In principle, this is an elegant piece of infrastructure. A single consent event at the moment of page load propagates the userโ€™s choices throughout the entire supply chain. No SSP needs to ask for consent independently. The publisherโ€™s CMP handles it once, and everyone downstream trusts the result.

In practice, the system has three structural problems.

First, the consent interface is not neutral. CMPs are evaluated and chosen by publishers partly on the basis of consent rates โ€” the percentage of users who click accept. This creates a direct commercial incentive to design interfaces that maximize acceptance rather than informed choice. The IABโ€™s own research has shown that the way choices are presented has a dramatic effect on outcomes, which is precisely why regulators have focused on dark patterns. A consent rate of 85% on a banner that buries the reject option in a third-level menu is not evidence of user preference. It is evidence of interface design.

Figure: CMPโ€™s dark patterns in action (see the supply-side article for details). 

Second, the TC string is self-reported and non-binding. A publisher or CMP that generates a TC string claiming full user consent has no independent verification mechanism checking that claim. The string travels through the bid stream and is trusted by every downstream system. To be fair, โ€œunpolicedโ€ would be too strong: IAB Europe runs a compliance program โ€” CMPs must pass validation before receiving an ID, live implementations are monitored, unresolved breaches can end in suspension from the framework, and a compliance report is published. But this is contractual self-regulation, not law, and none of it verifies the thing that matters most: whether the stringโ€™s content faithfully reflects what the human actually chose. The enforcement checks the plumbing; the claim itself remains an assertion.

Third, the consent signal degrades as it moves through the stack. A TC string generated by a CMP on a publisherโ€™s page may reflect a consent choice made weeks or months ago. Users who consented once and then changed their mind, cleared their cookies, or simply forgot they had a choice are still represented in the bid stream by their original string. The consent is technically present. The human behind it may have long since moved on.

None of this is solved, and thereโ€™s no sign it will be. What the market has produced instead is consolidation: a handful of platforms compete on positioning, not on fixing the consent problem.

CMP Vendor Description
OneTrust  Market leader by revenue, built initially for enterprise compliance rather than publisher monetization. Its strength is breadth โ€” it handles consent across web, mobile, and CTV, integrates with legal and compliance workflows, and is the default choice for large organizations that need to manage privacy obligations across multiple jurisdictions. It is not primarily built around maximizing consent rates, which makes it popular with legal departments and less popular with ad ops teams.
Didomi / Sourcepoint  In July 2025 Didomi acquired its longtime rival Sourcepoint. The two CMPs are now being merged into a single platform over time while keeping both brands for now.

Sourcepoint is the more programmatic-native of the two. Itโ€™s closely integrated with the ad tech stack and built around the consent-yield optimization problem. Its analytics tools for measuring consent rate impact on revenue are more sophisticated than most competitors. It is the dominant choice among large publishers and Publisher Monetization Platforms.

Didomi is European-founded, strong in France and across the EU, and favored by publishers who need deep IAB TCF compliance and strong DPA relationships in European markets. Together they now cover both the programmatic and the EU-compliance ends of the market.
Quantcast Choice (InMobi) Quantcast Choice was one of the most widely deployed free CMPs; InMobi acquired it in 2023 and now markets it as InMobi CMP.
consentmanager German-founded CMP, widely used across the EU and strong in German-speaking countries. It supports the full range of global privacy frameworks (TCF, GDPR, CCPA and others) and is a common choice among mid-market European publishers who need multi-jurisdiction compliance.
Google’s CMP certification program As of early 2024, publishers using Google Ad Manager in European countries must use a Google-certified CMP. Google maintains its own list of certified providers and has built its own CMP for publishers who want to use it. The effect is that Google now sits at the center of the consent infrastructure for a large share of European programmatic inventory โ€” certifying the tools that generate the signals that its own ad exchange then trades on. Whether this is a necessary standardization effort or a significant conflict of interest is a question the industry has not fully resolved.

Table 5: Main Consent Management Platform (CMP) vendors in 2026.

A quick note on how things are for real out there

If a user rejects cookies on every site they visit for weeks but clicks โ€œAcceptโ€ once in a distracted moment, that single lapse generates a valid consent string that travels through the entire programmatic stack โ€” and may still be doing so months later. But there is more. Anyone who has spent time reading publishersโ€™ privacy policies โ€” including those of major ones โ€” will find policies that claim no data is shared with third parties while simultaneously running a full programmatic stack with dozens of SSPs, DSPs, and data vendors. You will find CCPA disclosure tables marking every data category as โ€˜not collectedโ€™ on sites that demonstrably collect all of it. You will find GDPR boilerplate bolted onto decade-old policies written before real-time bidding existed. This is not the behavior of companies trying to comply and falling short. It is the rational output of a system where the probability of enforcement is low, the cost of genuine compliance is high, and the competitive disadvantage of being more transparent than your peers is real. Even Google, which imposes technical consent requirements on publishers using its ad stack, has no mechanism โ€” and no incentive โ€” to ensure that what those publishers tell their users in a privacy policy matches what actually happens on their pages. The gap between what publishers tell their users and what actually happens on their pages is not an edge case. Itโ€™s the norm. Once consent is obtained one way or another, the identity graph kicks in.

Once the CMP has recorded a consent string, the identity machinery we spent an entire article on performs the actual work of tracking users. This is the work of companies such as The Trade Desk (UID2), LiveRamp (RampID), ID5 and their kin. Where third-party cookies are still available, these systems use them alongside other signals. Where cookies are blocked or unavailable, they fall back to persistent identifiers built on hashed email addresses and other deterministic and probabilistic signals.

The industry has built databases that link various identifiers to create a single, unified view of a consumer across different devices and โ€œtouchpointsโ€. These databases are, of course, the Identity Graphs (or ID graphs) we have already met.

Note: One way to look at it is that the identity graph is not so much a replacement for the cookie as a hedge against its unreliability.

We already mentioned that cookies โ€” the quintessential deterministic signal that made behavioral targeting possible at scale โ€” are blocked in some browsers and unreliable in others. The third-party cookieโ€™s decline was driven not by regulators but by browsers. Apple’s Safari and Mozilla’s Firefox blocked third-party cookies years ago. 

Note: the ad tech crowd refers to this development as signal loss.

Google announced it would follow, then walked back its deprecation plans in 2025: Chrome โ€” still the dominant browser โ€” keeps cookies for the foreseeable future. So the cookie is not dead, but the machinery is blind in entire browsers regardless of what Chrome does.

Pseudonymization and PETs (Privacy Enhancing Technologies) 

While identity graph providers could easily store direct identifiers like the names and physical addresses of users, they typically discard that information. This is called pseudonymization and, in their expectations, this aligns them with privacy regulations.  However, from a regulatory perspective (especially under GDPR), simply removing a name doesnโ€™t automatically make the data โ€œcompliantโ€ or non-personal. 

In an identity graph, the goal is to link different signals to the same person. This inherent purpose โ€” linkability โ€” is exactly what regulators look for when determining if data is still โ€œpersonalโ€.

  • The AdTech Argument: โ€œWe donโ€™t know this is Luca Passani; we just know itโ€™s ID_88329_X. Therefore, his privacy is protectedโ€.
  • The Regulatory Reality: If you can distinguish ID_88329_X from every other person in the graph and target them with a specific ad, you have โ€œsingled them outโ€. Under GDPR, if a person can be singled out, the data is still personal, even if you don’t have their name in the database.

To navigate this, graph providers use several technical layers to distance themselves from direct identifiers.  

These techniques are called PETs or Privacy Enhancing Technologies. PETsโ€™ scope goes beyond advertising and covering them here is outside the scope of this document. The following list will give you an approximate idea of the main PET parts that apply to programmatic.

TechniqueHow it works in the GraphPrivacy Perception and Regulatory Reality
One-Way Hashing / pseudonymizationConverting an email into a SHA-256 hash before it even enters the graph.The graph never โ€œseesโ€ the raw email, but the hash still acts as a persistent fingerprint.
K-AnonymityEnsuring that any โ€œsegmentโ€ or โ€œvibeโ€ created contains at least k number of people.If a group is large enough (e.g. 100+ people), individuals cannot be โ€œsingled outโ€.
Differential PrivacyAdding mathematical โ€œnoiseโ€ to the data so that individual patterns are obscured while aggregate trends remain clear.High protection, but can degrade the accuracy of the โ€œsmart computer algorithmsโ€ used for targeting.
Secure Data Sharing / Data Clean RoomsDCRs are the machinery of two articles ago. Using environments where two parties (like a publisher and an advertiser) can match data without either side ever seeing the otherโ€™s raw PII.The advertising industry considers DCRs the โ€œgold standardโ€ for privacy-safe identity matching. As discussed, whether this cuts the mustard at the regulatory level isnโ€™t a settled matter.

Table 6: (partial) list of main PETs (Privacy Enhancing Technologies).

Note: whether PETs count as real privacy protection depends on who you ask. They are cleaner than cookies, but they do not stop tracking โ€” they make it harder to trace. That distinction is exactly where EU regulators and the ad tech industry disagree

Identity graphs and the EU: a polite fiction with legal consequences

The EU situation for identity graph vendors is where the rubber meets the road โ€” and where the gap between marketing language and regulatory reality becomes hardest to ignore.

UID2, the identity solution developed by The Trade Desk and widely adopted across the US programmatic ecosystem, could not be deployed in Europe. The GDPRโ€™s requirements around consent, data minimization, and purpose limitation are strict enough that The Trade Desk and LiveRamp had to build an entirely separate product โ€” the European Unified ID (EUID) โ€” specifically for the EU and UK markets. EUID was designed to account for specific market requirements in Europe, including GDPR regulations and consent framework limitations. The fact that a major US company had to fork its flagship identity product for the European market is telling. Itโ€™s not a localization exercise. Itโ€™s an acknowledgment that the underlying architecture of UID2 doesnโ€™t survive GDPR scrutiny without significant modification.

LiveRampโ€™s RampID tells a similar story from a different angle. A 2024 technical report by Cracked Labs concluded that the RampID system may be considered a thin compliance layer over LiveRampโ€™s offline identity databases, which contain names, postal addresses, email addresses and phone numbers โ€” and that LiveRamp’s data practices may disproportionately affect the rights and freedoms of hundreds of millions of people in the UK, France, and other countries, raising questions about the lawfulness of its practices under GDPR. LiveRamp contests this characterization, but the report landed in a regulatory environment that was already looking hard at identity infrastructure. In practice, for EU users, LiveRampโ€™s Authenticated Traffic Solution (ATS) requires explicit TCF consent before generating a RampID envelope. When consent is rejected or the CMP fails to load in time, ATS treats this as no consent and removes all envelopes from storage. Which sounds reassuring until you remember that the TCF itself โ€” whose legal troubles we saw earlier โ€” was found non-compliant with GDPR in important respects by the Belgian DPA in 2022, and its legal status remains contested. 

The practical consequences of all this are visible in the market. Identity graph solutions that depend on email-based deterministic matching operate at significantly reduced scale in Europe compared to the US, because authenticated traffic โ€” users who log in and provide an email โ€” is a smaller share of European inventory, and the consent requirements make that share even smaller. The result is that a meaningful portion of European programmatic inventory goes into every auction with no reliable user identity signal at all. Not because the technology doesn’t exist, but because the legal ground it would need to stand on keeps shifting.

This is the gap that neither regulation nor identity infrastructure has cleanly solved. A meaningful share of every auction โ€” unauthenticated users, anonymous browsers, CTV inventory where login events barely exist โ€” arrives with no reliable signal about who or what is on the other end.

So, is privacy protected?

The answer to this question is No. At least, not in the way ordinary users imagine. The tension at the heart of this entire discussion has never been resolved โ€” and it wonโ€™t be resolved by regulation alone, because the regulation is written by people who, ultimately, need the digital advertising economy to keep functioning. Hundreds of billions of dollars a year and hundreds of thousands of jobs globally are on the line.

For most people, this entire machine is invisible except for one moment: the retargeting โ€” that pair of shoes that follows you around the web and beyond, for a week or more, after you glanced at them once. That is the part we notice, and it is the part we judge the whole system by, which is precisely why the questions around user privacy are not the real questions. All stakeholders โ€” politicians on both sides of the Atlantic included โ€” are dodging the primary question because facing it directly would force uncomfortable choices no one wants to own. 

So, should behavioral targeting be banned? 

Behavioral targeting funds the free internet. The free internet is politically sacred. The fines get paid. The banners get clicked. The consent strings travel through the bid stream. The ecosystem keeps running.

GDPR was an attempt to give users control over something that had been taken from them without their knowledge. It produced, in practice, the most sophisticated compliance theater in the history of commercial law. Whether thatโ€™s a failure of regulation, a failure of enforcement, or simply proof that you cannot legislate your way out of an economic incentive structure this powerful, Iโ€™ll let you, the reader, decide.

What nobody disagrees about is that the current situation satisfies nobody completely โ€” not users, not regulators, and not even an industry that would prefer clear rules to the permanent threat of the next Schrems case, the next DPA ruling, the next adequacy decision that unravels everything.

Hereโ€™s a little thought experiment for you. Roughly 90% of users click Accept and move on when rejecting requires more than one click. Iโ€™m sure youโ€™re not surprised. Nobody reads the terms of service and privacy policies that confront us every day.  And not because we are uninformed, but simply because weโ€™re busy, because the alternative is not being able to use the service, and because no human being can meaningfully evaluate the privacy implications of a decision they are asked to make dozens of times a day.

Assume for a moment that everything works. Assume CMPs are correctly configured to collect and handle usersโ€™ consent. Assume a federal US privacy law passes and EU enforcement gets teeth. Every consent banner is perfectly compliant. Now, would the percentage of users who click Accept change? I argue that it wouldnโ€™t. The result would still be the same. From a regular user’s perspective, being forced to click โ€œAcceptโ€ multiple times a day just to dismiss those obnoxious dialog boxes may satisfy โ€œEuropean regulatorsโ€™ consent fetishโ€ (copyright Alan Chapell), but itโ€™s straight-up counterproductive if the goal is to protect personal data.

Conclusion

The consent model was always theater. GDPR didnโ€™t create it; it just built a more elaborate stage. Individual informed consent is not a meaningful mechanism for keeping data collection and profiling in check in the age of the internet and AI. Forcing millions of people to constantly click those Accept buttons does not serve any purpose โ€” with one important exception: cleaning the conscience of regulators who couldnโ€™t do better than this.

The theatrical performance continues. Samuel Beckett would have recognized the consent model immediately. The characters perform. Godot never arrives. Nothing is done.


A Brief Breath of Fresh Air (Before We Move On)

If your brain feels slightly bruised after our dive into GDPR, ePrivacy directives, CIPA class-action lawsuits, and Samuel Beckett-style consent theaterโ€”take a deep breath. You survived the heaviest, most legally suffocating stretch of this series.

Now for the good news: we are officially stepping out of the regulatory hazmat facility.

In the next installment, we arrive at the programmatic equivalent of a breezy, tropical vacation: Contextual Advertising. No tracking cookies, no identity tokens, no clean rooms, and zero risk of Max Schrems invalidating your entire business model over breakfast.

{"email":"Email address invalid","url":"Website address invalid","required":"Required field missing"}

Want access to the latest mobile device trends?

Download the Mobile Overview Report.

>