The ICO’s new adtech report to the UK government contains important lessons, also for legislators & regulators from all over Europe.
Its suggestion is to foresee a consent exemption under ePrivacy rules (PECR in the UK) for “first-party” use of storage & processing capabilities of a device for the following purposes, if certain safeguards are met:
– ad delivery
– targeting
– measurement and billing
– attribution
– frequency capping
– brand safety
– ad fraud prevention and detection
Data sharing with third parties “would be only permitted for controlled use cases and restricted compared to typical data sharing in programmatic advertising”, says the ICO.
Not quite sure how realistic a pure first-party option is, though, especially at scale, and the ICO appears to recognise this issue.
It discusses an alternative which would “permit more data sharing with third parties under the legitimate interests lawful basis (assuming a legitimate interests assessment could be passed)”, but with limitations so that “the information shared would be restricted to what is required to deliver online advertising”. This would then include “widely sharing the user’s IP address and device information (eg for ad fraud prevention and detection purposes)”.
The ICO’s arguments against this alternative are a bit weak, though. They do not explain the GDPR / data protection risks and fail to even handle the first, fundamental question: is it really personal data? (hello SRB & Breyer)
And alleging enforcement difficulties re “purpose limitation where data points permitted for one purpose (eg ad fraud prevention and detection) may be misused by any party receiving that information for non-permitted purposes (eg targeting)”? This criticism is valid for *EVERY* processing by any organisation on the planet.
It tackles its consent exemption suggestions per topic, e.g.:
– “scalable and viable ad delivery could be permitted without consent” in certain cases
– no consent would be required for first-party or PET-powered cross-site frequency capping if purpose limitation & necessity are complied with
– pre- & post-bid ad fraud prevention & detection could be permitted in certain cases
– targeting could be permitted without consent if limited to certain data (device/OS, city/regional geolocation, date & time of day, broad contextual taxonomy)
– anonymised, cross-site attribution could be consent-free if technical and organisational measures prevent cross-site tracking
etc.
It contains broader considerations too, such as stating that “[i]n circumstances where organisations deliver online advertising without consent that is deemed to be outside the scope of direct marketing, the absolute right to object would not apply” when discussing less targeted advertising.
I may disagree with some of their legal considerations, but the message is positive: the ICO sees a way for digital advertising to work even without consent. To be seen whether it’s realistic – and whether others take note.
Did this analysis get you thinking? Reach out!
DataLaws.net is entirely open-access, and instead of getting your data in exchange for this content, how about another trade? If this commentary saved you research time or sparked an idea, feel free to invite me over for tea, chai or a hot chocolate next time you are around Brussels or Antwerp - or invite me over to your offices for a chat!
Get in touch ↗ Let's connect on LinkedIn ↗