SlideShare a Scribd company logo
1 of 117
Download to read offline
@johnnyryan
RTB
“Demand side” “Supply side”
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
“Demand side” “Supply side”
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Store data
“Demand side” “Supply side”
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Request segment
Store data
“Demand side” “Supply side”
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Request segment
Deliver segment
Store data
“Demand side” “Supply side”
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Request page
Request segment
Deliver segment
Store data
“Demand side” “Supply side”
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Serve page
Request page
Request segment
Deliver segment
Store data
“Demand side” “Supply side”
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Serve page
Request page
Request segment
Deliver segment
Ad request
Store data
“Demand side” “Supply side”
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Serve page
Request page
Request segment
Cookie to SSP
Deliver segment
Ad request
Store data
“Demand side” “Supply side”
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Serve page
Request page
Request segment
Request bid
Cookie to SSP
Deliver segment
Ad request
Store data
“Demand side” “Supply side”
(one or many)
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Serve page
Request page
Request bid
Request segment
Request bid
Cookie to SSP
Deliver segment
Ad request
Store data
“Demand side” “Supply side”
(one or many)
(10s or 100s or 1000s?)
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Serve page
Request page
Request bid
Request segment
Request bid
Cookie to SSP
Deliver ad
Deliver segment
Ad request
Store data
“Demand side” “Supply side”
(one or many)
(10s or 100s or 1000s?)
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Serve page
Request page
Request bid
Request segment
Request bid
Cookie to SSP
Deliver ad
Deliver segment
Sync
Ad request
Store data
“Demand side” “Supply side”
(one or many)
(10s or 100s or 1000s?)
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Serve page
Request page
Request bid
Request segment
Request bid
Cookie to SSP
Deliver ad
Sync
Deliver segment
Sync
Ad request
Store data
“Demand side” “Supply side”
(one or many)
(10s or 100s or 1000s?)
The Daily Bugle
The Daily Bugle
ExchangeExchange
Exchange
Exchange
The Daily Bugle
ExchangeExchange
Exchange
Exchange
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSPDSP
DSP DSP
DSP
The Daily Bugle
ExchangeExchange
Exchange
Exchange
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSPDSP
DSP DSP
DSP
ADVERTISEMENT
?
?
The Daily Bugle
ExchangeExchange
Exchange
Exchange
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSPDSP
DSP DSP
DSP
?
?
?
?
ADVERTISEMENT
?
?
?
The Daily Bugle
ExchangeExchange
Exchange
Exchange
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSPDSP
DSP DSP
DSP
?
?
?
?
ADVERTISEMENT
?
?
?
The Daily Bugle
ExchangeExchange
Exchange
Exchange
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSPDSP
DSP DSP
DSP
?
?
?
?
ADVERTISEMENT
?
French regulator caught it with
68 million illegal RTB records.
Example
Vectaury: a small DSP/DMP/
trading desk in France. €3.5M
annual turnover in 2017 (though
subsequently won a €20M
investment).
DSP
Is 68 million
just 30%?
Then this small company
was sent personal data
¼ BILLION times via RTB
(in just one year)
website.com
This is the current process of
real-time bidding that is used in
online behavioural advertising.
Channel of data leakage
Legend
Money
DATA LEAKAGE
IN ONLINE
ADVERTISING
website.com
This is the current process of
real-time bidding that is used in
online behavioural advertising.
Channel of data leakage
Legend
Money
DATA LEAKAGE
IN ONLINE
ADVERTISING
Ad server
website.com
Ad server
javascript
Step 1.
User requests
webpageThis is the current process of
real-time bidding that is used in
online behavioural advertising.
Channel of data leakage
Legend
Money
DATA LEAKAGE
IN ONLINE
ADVERTISING
Ad server SSP
Step 2.
Ad server
selects an SSP
website.com
Ad server
javascript
SSP
javascript
Step 1.
User requests
webpageThis is the current process of
real-time bidding that is used in
online behavioural advertising.
Channel of data leakage
Legend
Money
DATA LEAKAGE
IN ONLINE
ADVERTISING
Ad server SSP
Step 2.
Ad server
selects an SSP
Step 3.
SSP selects an
exchange
website.com
Ad server
javascript
SSP
javascript
Step 1.
User requests
webpage
Ad exchange
This is the current process of
real-time bidding that is used in
online behavioural advertising.
Channel of data leakage
Legend
Money
DATA LEAKAGE
IN ONLINE
ADVERTISING
Ad server SSP
Step 2.
Ad server
selects an SSP
Step 3.
SSP selects an
exchange
MARKETERS
website.com
Ad server
javascript
SSP
javascript
Step 1.
User requests
webpage
Ad exchange
Step 4.
Exchange sends
bid requests to
hundreds of
partners
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
This is the current process of
real-time bidding that is used in
online behavioural advertising.
Channel of data leakage
Legend
Money
DATA LEAKAGE
IN ONLINE
ADVERTISING
Ad server SSP
Step 2.
Ad server
selects an SSP
Step 3.
SSP selects an
exchange
MARKETERS
website.com
Winningbid
Ad server
javascript
SSP
javascript
Step 1.
User requests
webpage
Ad exchange
Step 4.
Exchange sends
bid requests to
hundreds of
partners
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
This is the current process of
real-time bidding that is used in
online behavioural advertising.
Channel of data leakage
Legend
Money
DATA LEAKAGE
IN ONLINE
ADVERTISING
Ad server SSP
Step 2.
Ad server
selects an SSP
Step 3.
SSP selects an
exchange
MARKETERS
website.com
Winningbid
Ad server
javascript
SSP
javascript
DMP
DMP
DMP DMP
DSP
DSP
DSP
DSP
DSP
Step 1.
User requests
webpage
Ad exchange
Step 4.
Exchange sends
bid requests to
hundreds of
partners
Step 5.
Exchange lets
some DMPs/
DSPs to refresh
cookie sync
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
This is the current process of
real-time bidding that is used in
online behavioural advertising.
Channel of data leakage
Legend
Money
DATA LEAKAGE
IN ONLINE
ADVERTISING
Ad server SSP
Step 2.
Ad server
selects an SSP
Step 3.
SSP selects an
exchange
MARKETERS
website.com
Winningbid
Ad server
javascript
SSP
javascript
DMP
DMP
DMP DMP
DSP
DSP
DSP
DSP
DSP
DSP
javascript
Step 6.
Exchange serves
winning bid
Winning DSP
Step 1.
User requests
webpage
Ad exchange
Step 4.
Exchange sends
bid requests to
hundreds of
partners
Step 5.
Exchange lets
some DMPs/
DSPs to refresh
cookie sync
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
This is the current process of
real-time bidding that is used in
online behavioural advertising.
Channel of data leakage
Legend
Money
DATA LEAKAGE
IN ONLINE
ADVERTISING
Ad server SSP
Step 2.
Ad server
selects an SSP
Step 3.
SSP selects an
exchange
Step 7.
DSP serves
agency creative
MARKETERS
website.com
Winningbid
Ad server
javascript
SSP
javascript
DMP
DMP
DMP DMP
DSP
DSP
DSP
DSP
DSP
DSP
javascript
Ad server
javascript
Step 6.
Exchange serves
winning bid
Agency
ad server
Winning DSP
Step 1.
User requests
webpage
Ad exchange
Step 4.
Exchange sends
bid requests to
hundreds of
partners
Step 5.
Exchange lets
some DMPs/
DSPs to refresh
cookie sync
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
This is the current process of
real-time bidding that is used in
online behavioural advertising.
DATA LEAKAGE
IN ONLINE
ADVERTISING
Channel of data leakage
Legend
Money
Ad server SSP
Step 2.
Ad server
selects an SSP
Step 3.
SSP selects an
exchange
Step 7.
DSP serves
agency creative
Step 8.
Assets load
from CDN
MARKETERS
website.com
AD
Winningbid
Ad server
javascript
SSP
javascript
DMP
DMP
DMP DMP
DSP
DSP
DSP
DSP
DSP
DSP
javascript
Ad server
javascript
Step 6.
Exchange serves
winning bid
Agency
ad server
Winning DSP
Step 1.
User requests
webpage
Ad exchange
Step 4.
Exchange sends
bid requests to
hundreds of
partners
Step 5.
Exchange lets
some DMPs/
DSPs to refresh
cookie sync
CDN
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
DSP
This is the current process of
real-time bidding that is used in
online behavioural advertising.
DATA LEAKAGE
IN ONLINE
ADVERTISING
Channel of data leakage
Legend
Money
What’s in a
bid request?
IAB OpenRTB Google Authorized Buyers
The website this specific person is currently viewing
Various ID codes that identify this
specific person, and can tie them to
existing profiles
Distinctive characteristics of this specific person
This specific person’s IP address
Distinctive information about
this specific person’s device
Distinctive information about this specific
person’s device
This young woman’s GPS coordinates!
Natural persons may be associated with
online identifiers … such as internet protocol
addresses, cookie identifiers or other
identifiers… This may leave traces which, in
particular when combined with unique
identifiers and other information received by
the servers, may be used to create profiles of
the natural persons and identify them.
GDPR, Recital 30
Index Exchange 50 billion
1. “Tour IX’s Amsterdam and Frankfurt Data Centers”, Index Exchange, 2 July 2018 (URL: https://www.indexexchange.com/tour-ix-amsterdam-frankfurt-data-centers/).
2. "OpenX Ad Exchange", OpenX (URL: https://www.openx.com/uk_en/products/ad-exchange/).
3. “Buyers”, Rubicon Project (URL: https://rubiconproject.com/buyers/).
4. "How PubMatic Is Learning Machine Learning", PubMatic, 25 January 2019 (URL: https://pubmatic.com/blog/learning-machine-learning/)
5. "Maximize yield with Oath's publisher offerings", Oath, 3 April 2018 (URL: https://www.oath.com/insights/maximize-yield-with-oath-s-publisher-offerings/)
6. 500 Billion / 29.6 = 18.6 billion impressions per day. Using AppNexus 1:11.5 ratio, this is 214 auctions per day. 500+ impressions figure cited in “Optimize your mobile
strategy”, Smaato (URL: https://www.smaato.com/).
7. “Transacting at a peak of 11.4 billion daily impressions, our marketplace handles more traffic each day than Visa, Nasdaq, and the NYSE combined” at https://
www.appnexus.com/sell. Note that in 2017, AppNexus said in “AppNexus Scales with DriveScale”, 2017 (URL: http://go.drivescale.com/rs/451-ESR-800/images/
DRV_Case_Study_AppNexus-final.v1.pdf) that 10.7 billion "impressions transacted" came as a result of running 123 billion auctions. The impressions transacted to
auctions ratio appears to be roughly 1:11.5. Therefore, the 11.4 daily impressions reported in 2018 equates to 131 billion auctions per day.
8. DoubleClick.Net Usage Statistics (URL: https://trends.builtwith.com/ads/DoubleClick.Net).
Real-time bidding bid requests per day
OpenX 60 billion2
Rubicon Project Unknown, 1 billion people’s devices3
PubMatic 70 billion4
Oath/AOL 90 billion5
AppNexus 131 billion6
Smaato 214 billion7
Google Unknown, live on 8.4 million websites8
1
Index Exchange 50 billion
The biggest
Index Exchange 50 billion
1. “Tour IX’s Amsterdam and Frankfurt Data Centers”, Index Exchange, 2 July 2018 (URL: https://www.indexexchange.com/tour-ix-amsterdam-frankfurt-data-centers/).
2. "OpenX Ad Exchange", OpenX (URL: https://www.openx.com/uk_en/products/ad-exchange/).
3. “Buyers”, Rubicon Project (URL: https://rubiconproject.com/buyers/).
4. "How PubMatic Is Learning Machine Learning", PubMatic, 25 January 2019 (URL: https://pubmatic.com/blog/learning-machine-learning/)
5. "Maximize yield with Oath's publisher offerings", Oath, 3 April 2018 (URL: https://www.oath.com/insights/maximize-yield-with-oath-s-publisher-offerings/)
6. 500 Billion / 29.6 = 18.6 billion impressions per day. Using AppNexus 1:11.5 ratio, this is 214 auctions per day. 500+ impressions figure cited in “Optimize your mobile
strategy”, Smaato (URL: https://www.smaato.com/).
7. “Transacting at a peak of 11.4 billion daily impressions, our marketplace handles more traffic each day than Visa, Nasdaq, and the NYSE combined” at https://
www.appnexus.com/sell. Note that in 2017, AppNexus said in “AppNexus Scales with DriveScale”, 2017 (URL: http://go.drivescale.com/rs/451-ESR-800/images/
DRV_Case_Study_AppNexus-final.v1.pdf) that 10.7 billion "impressions transacted" came as a result of running 123 billion auctions. The impressions transacted to
auctions ratio appears to be roughly 1:11.5. Therefore, the 11.4 daily impressions reported in 2018 equates to 131 billion auctions per day.
8. DoubleClick.Net Usage Statistics (URL: https://trends.builtwith.com/ads/DoubleClick.Net).
Real-time bidding bid requests per day
OpenX 60 billion2
Rubicon Project Unknown, 1 billion people’s devices3
PubMatic 70 billion4
Oath/AOL 90 billion5
AppNexus 131 billion6
Smaato 214 billion7
Google Unknown, live on 8.4 million websites8
1
Index Exchange 50 billion
The biggest
Hundreds of billions
of data leaks a day.
(The biggest data breach yet recorded)
Everybody you
have ever known
OK
Security
Publishers recognize there is no technical
way to limit the way data is used after the
data is received by a vendor for decisioning/
bidding on/after delivery of an ad…
“
”
there is no technical
way to limit the way data is used after
Surfacing thousands of vendors with broad
rights to use data w/out tailoring those
rights may be too many vendors/permissions
“
”
thousands of vendors
“pubvendors.json v1.0: Transparency & Consent Framework”,
IAB, May 2018
The MO may adopt procedures for
periodically reviewing and verifying a
Vendor’s compliance with the Policies.
“Transparency & Consent Framework Policies, 2019-08-21.3”
IAB, August 2019
“
”
may adopt
Management Organisation (the IAB)
Buyer will regularly monitor your
compliance with this obligation, and
immediately notify Google in writing if
Buyer can no longer meet … this obligation...
“
”
“
”
must not: (i) use callout data ... to create
user lists or profile users; (ii) associate
callout data ... with third party data...
Buyer will
“Authorized Buyers Programme Guidelines”,
Google, August 2018
GDPR, Article 5 (1)
(f) processed in a manner that ensures
appropriate security of the personal data,
including protection against unauthorised or
unlawful processing and against accidental
loss, destruction or damage, using
appropriate technical or organisational
measures (‘integrity and confidentiality’).
EU privacy regulators are like “ents”.
Terrifying, once awoken.
4
We list our concerns - that the creation and sharing of personal data profiles
about people, to the scale we’ve seen, feels disproportionate, intrusive and
unfair, particularly when people are often unaware it is happening.
We outline that one visit to a website, prompting one auction among
advertisers, can result in a person’s personal data being seen by hundreds of
organisations, in ways that suggest data protection rules have not been
sufficiently considered.
Our report will be passed to the adtech sector for their response. We are
clear about the areas where we have initial concerns, and we expect to see
change. But we understand this is an extremely complex market involving
many organisations and many technologies. We want to take a measured
and iterative approach, before undertaking a further industry review in six
months’ time.
With that in mind, we’ll continue engaging with the sector, further exploring
the data protection implications of the real time bidding system. We’ll
continue collaborating with Data Protection Authorities in other European
countries too, who are also looking at complaints in this area.
Innovation in technology has the potential to enhance all of our lives. The
internet is central to that, and we understand that advertisements fund much
of what we enjoy online. We understand the need for a system that allows
revenue for publishers and audiences for advertisers. We understand a need
for the process to happen in a heartbeat. Our aim is to prompt changes that
reflect this reality, but also to ensure respect for internet users’ legal rights.
The rules that protect people’s personal data must be followed. Companies
do not need to choose between innovation and privacy.
Elizabeth Denham
Information Commissioner
Information Commissioner’s Office
Update report
into adtech and
real time bidding
20 June 2019
4
We list our concerns - that the creation and sharing of personal data profiles
about people, to the scale we’ve seen, feels disproportionate, intrusive and
unfair, particularly when people are often unaware it is happening.
We outline that one visit to a website, prompting one auction among
advertisers, can result in a person’s personal data being seen by hundreds of
organisations, in ways that suggest data protection rules have not been
sufficiently considered.
Our report will be passed to the adtech sector for their response. We are
clear about the areas where we have initial concerns, and we expect to see
change. But we understand this is an extremely complex market involving
many organisations and many technologies. We want to take a measured
and iterative approach, before undertaking a further industry review in six
months’ time.
With that in mind, we’ll continue engaging with the sector, further exploring
the data protection implications of the real time bidding system. We’ll
continue collaborating with Data Protection Authorities in other European
countries too, who are also looking at complaints in this area.
Innovation in technology has the potential to enhance all of our lives. The
internet is central to that, and we understand that advertisements fund much
of what we enjoy online. We understand the need for a system that allows
revenue for publishers and audiences for advertisers. We understand a need
for the process to happen in a heartbeat. Our aim is to prompt changes that
reflect this reality, but also to ensure respect for internet users’ legal rights.
The rules that protect people’s personal data must be followed. Companies
do not need to choose between innovation and privacy.
Elizabeth Denham
Information Commissioner
Information Commissioner’s Office
Update report
into adtech and
real time bidding
20 June 2019
one visit to a website, prompting one
auction among advertisers, can result in
a person’s personal data being seen by
hundreds of organisations, in ways that
suggest data protection rules have not
been sufficiently considered. page 4
23
4 Summary and conclusions
Overall, in the ICO’s view the adtech industry appears immature in its
understanding of data protection requirements. Whilst the automated
delivery of ad impressions is here to stay, we have general, systemic
concerns around the level of compliance of RTB:
1. Processing of non-special category data is taking place unlawfully at
the point of collection due to the perception that legitimate interests
can be used for placing and/or reading a cookie or other technology
(rather than obtaining the consent PECR requires).
2. Any processing of special category data is taking place unlawfully as
explicit consent is not being collected (and no other condition applies).
In general, processing such data requires more protection as it brings
an increased potential for harm to individuals.
3. Even if an argument could be made for reliance on legitimate interests,
participants within the ecosystem are unable to demonstrate that they
have properly carried out the legitimate interests tests and
implemented appropriate safeguards.
4. There appears to be a lack of understanding of, and potentially
compliance with, the DPIA requirements of data protection law more
broadly (and specifically as regards the ICO’s Article 35(4) list). We
therefore have little confidence that the risks associated with RTB have
been fully assessed and mitigated.
5. Privacy information provided to individuals lacks clarity whilst also
being overly complex. The TCF and Authorized Buyers frameworks are
insufficient to ensure transparency and fair processing of the personal
data in question and therefore also insufficient to provide for free and
informed consent, with attendant implications for PECR compliance.
6. The profiles created about individuals are extremely detailed and are
repeatedly shared among hundreds of organisations for any one bid
request, all without the individuals’ knowledge.
7. Thousands of organisations are processing billions of bid requests in
the UK each week with (at best) inconsistent application of adequate
technical and organisational measures to secure the data in transit and
at rest, and with little or no consideration as to the requirements of
data protection law about international transfers of personal data.
8. There are similar inconsistencies about the application of data
minimisation and retention controls.
9. Individuals have no guarantees about the security of their personal
data within the ecosystem.
4
We list our concerns - that the creation and sharing of personal data profiles
about people, to the scale we’ve seen, feels disproportionate, intrusive and
unfair, particularly when people are often unaware it is happening.
We outline that one visit to a website, prompting one auction among
advertisers, can result in a person’s personal data being seen by hundreds of
organisations, in ways that suggest data protection rules have not been
sufficiently considered.
Our report will be passed to the adtech sector for their response. We are
clear about the areas where we have initial concerns, and we expect to see
change. But we understand this is an extremely complex market involving
many organisations and many technologies. We want to take a measured
and iterative approach, before undertaking a further industry review in six
months’ time.
With that in mind, we’ll continue engaging with the sector, further exploring
the data protection implications of the real time bidding system. We’ll
continue collaborating with Data Protection Authorities in other European
countries too, who are also looking at complaints in this area.
Innovation in technology has the potential to enhance all of our lives. The
internet is central to that, and we understand that advertisements fund much
of what we enjoy online. We understand the need for a system that allows
revenue for publishers and audiences for advertisers. We understand a need
for the process to happen in a heartbeat. Our aim is to prompt changes that
reflect this reality, but also to ensure respect for internet users’ legal rights.
The rules that protect people’s personal data must be followed. Companies
do not need to choose between innovation and privacy.
Elizabeth Denham
Information Commissioner
Information Commissioner’s Office
Update report
into adtech and
real time bidding
20 June 2019The TCF and Authorized Buyers
frameworks are insufficient to ensure
transparency and fair processing of the
personal data in question and therefore
also insufficient to provide for free and
informed consent… page 23
suspected infringement
CMO
PublishersMarketer
$
Shared liability under GDPR Article 82Legend Money Channel of data leakage
Marketer risk from programmatic advertising
PublishersSSPsDSPDMPMarketer Ad Exchanges
AAgency
$
Shared liability under GDPR Article 82Legend Money Channel of data leakage
Marketer risk from programmatic advertising
Data protection-free zone
PublishersSSPsDSPDMPMarketer Ad Exchanges
AAgency
Personal data widely broadcast in “RTB” bid requests
$
Insurer and
reinsurer risk?
Shared liability under GDPR Article 82Legend Money Channel of data leakage
Marketer risk from programmatic advertising
WHAT TO DO
Conventional
“Broadcast” Behavioral
Conventional
“Broadcast” Behavioral
Conventional
“Broadcast” Behavioral
Safe data
“Broadcast” Behavioral
• What you are reading, or watching, or listening to.
• Categories of the content.
• Unique pseudonymous ID.
• Unique ID matched to ad buyer’s existing profile of you.
• Your location (can be your exact latitude and longitude).
• Granular description of your device.
• Unique tracking IDs / cookie match.
• Your IP address.*
• Data broker segment ID* when available.
*Depending on the version of “real time bidding” system
Conventional
“Broadcast” Behavioral
• What you are reading, or watching, or listening to.
• Categories of the content.
• Your approximate location.
• General description of your device.
• Your approximate IP address.
• Impression ID for buyer transparency.
Person in Cologne (District 1: Köln-Innenstadt) is
reading an article about ad fraud on WSJ’s CMO
roundup. Using Safari on an iPhone X or higher.
Safe data
“Broadcast” Behavioral
RTB
MARKET
PROBLEMS
How RTB data leakage supports untrustworthy websites
The Daily Bugle
How RTB data leakage supports untrustworthy websites
The Daily Bugle
///
Step 1.
User “John” visits
The Daily Bugle
How RTB data leakage supports untrustworthy websites
The Daily Bugle
///
Step 1.
User “John” visits
The Daily Bugle
Step 2.
Bid request
broadcasts personal
data about John
How RTB data leakage supports untrustworthy websites
The Daily Bugle
///
Step 3.
100s of companies in the ad
auction can now re-identify
John as a Daily Bugle reader
Step 1.
User “John” visits
The Daily Bugle
Step 2.
Bid request
broadcasts personal
data about John
John
Step 4.
The Daily Bugle is
paid €1 to show ad
to John
How RTB data leakage supports untrustworthy websites
The Daily Bugle
///
Step 3.
100s of companies in the ad
auction can now re-identify
John as a Daily Bugle reader
Step 1.
User “John” visits
The Daily Bugle
€1 advertisement
Step 2.
Bid request
broadcasts personal
data about John
John
Step 4.
The Daily Bugle is
paid €1 to show ad
to John
How RTB data leakage supports untrustworthy websites
The Daily Bugle
Step 5.
Later, John visits a
low quality website
Step 3.
100s of companies in the ad
auction can now re-identify
John as a Daily Bugle reader
Step 1.
User “John” visits
The Daily Bugle
€1 advertisement
De5troyTru5t.com
///
Step 2.
Bid request
broadcasts personal
data about John
John
Step 4.
The Daily Bugle is
paid €1 to show ad
to John
How RTB data leakage supports untrustworthy websites
The Daily Bugle
Step 5.
Later, John visits a
low quality website
Step 6.
Bid request
announces John is
here
Step 3.
100s of companies in the ad
auction can now re-identify
John as a Daily Bugle reader
Step 1.
User “John” visits
The Daily Bugle
€1 advertisement
De5troyTru5t.com
///
Step 2.
Bid request
broadcasts personal
data about John
John
Step 4.
The Daily Bugle is
paid €1 to show ad
to John
Step 7.
De5troyTru5t.com is paid
€0.01 to show ad to John
How RTB data leakage supports untrustworthy websites
The Daily Bugle
Step 5.
Later, John visits a
low quality website
Step 6.
Bid request
announces John is
here
Step 3.
100s of companies in the ad
auction can now re-identify
John as a Daily Bugle reader
Step 1.
User “John” visits
The Daily Bugle
€1 advertisement
De5troyTru5t.com
€0.01 advertisement
///
Step 2.
Bid request
broadcasts personal
data about John
John
Step 4.
The Daily Bugle is
paid €1 to show ad
to John
Step 7.
De5troyTru5t.com is paid
€0.01 to show ad to John
How RTB data leakage supports untrustworthy websites
The Daily Bugle
Step 5.
Later, John visits a
low quality website
Step 6.
Bid request
announces John is
here
Step 3.
100s of companies in the ad
auction can now re-identify
John as a Daily Bugle reader
Step 1.
User “John” visits
The Daily Bugle
€1 advertisement
De5troyTru5t.com
€0.01 advertisement
///
Step 2.
Bid request
broadcasts personal
data about John
Worthy sites lose their unique audience, and feed
a business model for the bottom of the Web.
John
The Daily Bugle
How RTB enables to steal from publishers and
advertisers.
fraudsters
The Daily Bugle
Step 1.
A bot masquerading
as a human visits
The Daily Bugle ///
Fake
How RTB enables to steal from publishers and
advertisers.
fraudsters
The Daily Bugle
Step 1.
A bot masquerading
as a human visits
The Daily Bugle
Step 2.
Bid request
broadcasts personal
data about Bot///
Fake
How RTB enables to steal from publishers and
advertisers.
fraudsters
The Daily Bugle
Step 3.
100s of companies in the ad
auction can now re-identify
Bot as a Daily Bugle reader
Step 1.
A bot masquerading
as a human visits
The Daily Bugle
Step 2.
Bid request
broadcasts personal
data about Bot
Bot
///
Fake
How RTB enables to steal from publishers and
advertisers.
fraudsters
Step 4.
The Daily Bugle is
paid €1 to show ad
The Daily Bugle
Step 3.
100s of companies in the ad
auction can now re-identify
Bot as a Daily Bugle reader
Step 1.
A bot masquerading
as a human visits
The Daily Bugle
€1 advertisement
Step 2.
Bid request
broadcasts personal
data about Bot
Bot
///
Fake
How RTB enables to steal from publishers and
advertisers.
fraudsters
Step 4.
The Daily Bugle is
paid €1 to show ad
The Daily Bugle
Step 5.
Later, an
untrustworthy website
buts bot traffic
Step 3.
100s of companies in the ad
auction can now re-identify
Bot as a Daily Bugle reader
Step 1.
A bot masquerading
as a human visits
The Daily Bugle
€1 advertisement
De5troyTru5t.com
Step 2.
Bid request
broadcasts personal
data about Bot
Bot
///
Fake
///
Fake
How RTB enables to steal from publishers and
advertisers.
fraudsters
Step 4.
The Daily Bugle is
paid €1 to show ad
The Daily Bugle
Step 5.
Later, an
untrustworthy website
buts bot traffic
Step 6.
Bid request
announces Bot is
here
Step 3.
100s of companies in the ad
auction can now re-identify
Bot as a Daily Bugle reader
Step 1.
A bot masquerading
as a human visits
The Daily Bugle
€1 advertisement
De5troyTru5t.com
Step 2.
Bid request
broadcasts personal
data about Bot
Bot
///
Fake
///
Fake
How RTB enables to steal from publishers and
advertisers.
fraudsters
Step 4.
The Daily Bugle is
paid €1 to show ad
Step 7.
De5troyTru5t.com is paid
€0.01 to show ad to Bot
The Daily Bugle
Step 5.
Later, an
untrustworthy website
buts bot traffic
Step 6.
Bid request
announces Bot is
here
Step 3.
100s of companies in the ad
auction can now re-identify
Bot as a Daily Bugle reader
Step 1.
A bot masquerading
as a human visits
The Daily Bugle
€1 advertisement
De5troyTru5t.com
€0.01 advertisement
Step 2.
Bid request
broadcasts personal
data about Bot
Bot
///
Fake
///
Fake
How RTB enables to steal from publishers and
advertisers.
fraudsters
$ ///
VisitorSiteSupply-side
platform (SSP)
Demand-side
platform (DSP)
Data management
platform (DMP)
Marketer Ad Exchange
Serve page
Request page
Request bid
Request segment
Request bid
Cookie to SSP
Deliver ad
Sync
Deliver segment
Sync
Ad request
Store data
“Demand side” “Supply side”
(one or many)
(10s or 100s or 1000s?)
DSPDMP SSP
Buyer Seller
Extracts 70-55% of
buyer’s media budget.
Distribution
Marketer
$ DMP DSP Ad Exchange SSP
Site
Unique audience
commodified and
arbitraged.
Untrustworthy sites
business model
enabled.
Bot fraud boosted.
70% figure from the Guardian
and Rubicon case in 2017. 55%
figure from “The Programmatic
Supply Chain: Deconstructing the
Anatomy of a Programmatic
CPM”, IAB, March 2016.
MARKET OVERVIEW (NOW)
PERSONAL DATA IN IAB / GOOGLE RTB
Victims of massive
fraud.
2019 estimates range from $5.7B
(ANA) - $42B (Juniper Research).
Extracts much lower %
of buyer’s media budget.
Unique audience
become immune to
commodification and
arbitrage.
No opportunity for
untrustworthy sites.
Bot fraud reduced.
Bot fraud opportunity
reduced.
MARKET OVERVIEW (POST-FIX)
NON-PERSONAL DATA IN IAB / GOOGLE RTB
Marketer
$ DMP DSP Ad Exchange SSP
Site
Buyer SellerDistribution
Conventional
“Broadcast” Behavioral
Safe data
“Broadcast” Behavioral
Conventional
“Broadcast” Behavioral
“Local” Behavioral
Safe data
“Broadcast” Behavioral
Conventional
“Broadcast” Behavioral
“Local” Behavioral
Safe data
“Broadcast” Behavioral
///
Conventional
“Broadcast” Behavioral
“Local” Behavioral
Safe data
“Broadcast” Behavioral
///
Private profiles.
If you opt-in, the Browser builds a
profile that stays private on the
device. No one (including Brave)
ever gets it.
Machine learning on the device
decides what ad is shown, and
when it is best to show it to you.
“Local” Behavioral
///
Browser user visits various websites
Today’s ad catalog is sent
to the device.
Browser user visits various websites
Today’s ad catalog is sent
to the device.
Brave Browser on the device
selects an ad based on profile
on the device.
70% of ad revenue goes to user.
Browser user visits various websites
Today’s ad catalog is sent
to the device.
Brave Browser on the device
selects an ad based on profile
on the device.
70% of ad revenue goes to user.
By default, websites are paid
from the user’s wallet at the end
of the month. (This can not be
attributed to an individual user.)
Browser user visits various websites
Conventional
“Broadcast” Behavioral
“Local” Behavioral
Safe data
“Broadcast” Behavioral
///
1 2 3
N20
C02
Fossil Fuel Renewable Energy
N20
C02
Regulatory incentive
CLEAN INDUSTRY
Regulatory disincentive
DIRTY INDUSTRY
Ads (Ethical Data)Ads (Conventional Data)
Regulatory incentive
CLEAN INDUSTRY
Regulatory disincentive
DIRTY INDUSTRY
Personal data Non-personal data
Fossil Fuel Renewable Energy
N20
C02
Summary
1. Regulators will force change. 

2. Prepare for when the IAB & Google are
forced to reform RTB. It is likely to use
only non-personal data. 

3. Experiment with safe adtech. 

4. Connect: BRAVE.com/INSIGHT/
johnny@brave.com

More Related Content

What's hot

Sequoia Pitch Deck Template
Sequoia Pitch Deck TemplateSequoia Pitch Deck Template
Sequoia Pitch Deck Templatestartuphome
 
Facebook Pitch Deck
Facebook Pitch DeckFacebook Pitch Deck
Facebook Pitch Deckstartuphome
 
For Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCFFor Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCFAurélie Pols
 
데이터야놀자발표_데이터로토이서비스만들기_조동민 (2).pdf
데이터야놀자발표_데이터로토이서비스만들기_조동민 (2).pdf데이터야놀자발표_데이터로토이서비스만들기_조동민 (2).pdf
데이터야놀자발표_데이터로토이서비스만들기_조동민 (2).pdfDONGMIN CHO
 
The 10 most interesting slides that helped our SaaS company raise 9 million
The 10 most interesting slides that helped our SaaS company raise 9 millionThe 10 most interesting slides that helped our SaaS company raise 9 million
The 10 most interesting slides that helped our SaaS company raise 9 millionGoCanvas
 
Automated Background Removal Using PyTorch
Automated Background Removal Using PyTorchAutomated Background Removal Using PyTorch
Automated Background Removal Using PyTorchDatabricks
 
RedisConf18 - Redis on Google Cloud Platform
RedisConf18 - Redis on Google Cloud PlatformRedisConf18 - Redis on Google Cloud Platform
RedisConf18 - Redis on Google Cloud PlatformRedis Labs
 
500’s Demo Day Batch 15 >> Barn and Willow
500’s Demo Day Batch 15 >> Barn and Willow500’s Demo Day Batch 15 >> Barn and Willow
500’s Demo Day Batch 15 >> Barn and Willow500 Startups
 
Thoughtspot Pitch Deck
Thoughtspot Pitch DeckThoughtspot Pitch Deck
Thoughtspot Pitch DeckEwanDoyle
 
Go4Grocery - Startup Pitch
Go4Grocery - Startup PitchGo4Grocery - Startup Pitch
Go4Grocery - Startup PitchFahad Ramzan
 
Y Combinator Pitch Deck Template For Startup Founders
Y Combinator Pitch Deck Template For Startup FoundersY Combinator Pitch Deck Template For Startup Founders
Y Combinator Pitch Deck Template For Startup FoundersAA BB
 
All about Programmatic buying(RTB), DSP,SSP, DMP & DCT - A complete digital ...
All about Programmatic buying(RTB), DSP,SSP, DMP & DCT -  A complete digital ...All about Programmatic buying(RTB), DSP,SSP, DMP & DCT -  A complete digital ...
All about Programmatic buying(RTB), DSP,SSP, DMP & DCT - A complete digital ...Karunakar Ravirala
 
Surge Pricing: 0 to 1 by fmr Lyft Product Leader
Surge Pricing: 0 to 1 by fmr Lyft Product LeaderSurge Pricing: 0 to 1 by fmr Lyft Product Leader
Surge Pricing: 0 to 1 by fmr Lyft Product LeaderProduct School
 
Confluent Partner Tech Talk with BearingPoint
Confluent Partner Tech Talk with BearingPointConfluent Partner Tech Talk with BearingPoint
Confluent Partner Tech Talk with BearingPointconfluent
 
Castle: $30K VC investment, eventually raising $3.3M. Castle's initial pitch ...
Castle: $30K VC investment, eventually raising $3.3M. Castle's initial pitch ...Castle: $30K VC investment, eventually raising $3.3M. Castle's initial pitch ...
Castle: $30K VC investment, eventually raising $3.3M. Castle's initial pitch ...AA BB
 
YouTube Pitch Deck
YouTube Pitch DeckYouTube Pitch Deck
YouTube Pitch Deckstartuphome
 

What's hot (20)

Butlr
ButlrButlr
Butlr
 
Pitch deck
Pitch deckPitch deck
Pitch deck
 
Sequoia Pitch Deck Template
Sequoia Pitch Deck TemplateSequoia Pitch Deck Template
Sequoia Pitch Deck Template
 
Facebook Pitch Deck
Facebook Pitch DeckFacebook Pitch Deck
Facebook Pitch Deck
 
For Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCFFor Superweek 2022: discussing risk using IAB's TCF
For Superweek 2022: discussing risk using IAB's TCF
 
Popping Pitch Deck
Popping Pitch DeckPopping Pitch Deck
Popping Pitch Deck
 
데이터야놀자발표_데이터로토이서비스만들기_조동민 (2).pdf
데이터야놀자발표_데이터로토이서비스만들기_조동민 (2).pdf데이터야놀자발표_데이터로토이서비스만들기_조동민 (2).pdf
데이터야놀자발표_데이터로토이서비스만들기_조동민 (2).pdf
 
The 10 most interesting slides that helped our SaaS company raise 9 million
The 10 most interesting slides that helped our SaaS company raise 9 millionThe 10 most interesting slides that helped our SaaS company raise 9 million
The 10 most interesting slides that helped our SaaS company raise 9 million
 
Automated Background Removal Using PyTorch
Automated Background Removal Using PyTorchAutomated Background Removal Using PyTorch
Automated Background Removal Using PyTorch
 
RedisConf18 - Redis on Google Cloud Platform
RedisConf18 - Redis on Google Cloud PlatformRedisConf18 - Redis on Google Cloud Platform
RedisConf18 - Redis on Google Cloud Platform
 
500’s Demo Day Batch 15 >> Barn and Willow
500’s Demo Day Batch 15 >> Barn and Willow500’s Demo Day Batch 15 >> Barn and Willow
500’s Demo Day Batch 15 >> Barn and Willow
 
Thoughtspot Pitch Deck
Thoughtspot Pitch DeckThoughtspot Pitch Deck
Thoughtspot Pitch Deck
 
매쉬업엔젤스 미디어킷 (2019) Mashupangels
매쉬업엔젤스 미디어킷 (2019) Mashupangels매쉬업엔젤스 미디어킷 (2019) Mashupangels
매쉬업엔젤스 미디어킷 (2019) Mashupangels
 
Go4Grocery - Startup Pitch
Go4Grocery - Startup PitchGo4Grocery - Startup Pitch
Go4Grocery - Startup Pitch
 
Y Combinator Pitch Deck Template For Startup Founders
Y Combinator Pitch Deck Template For Startup FoundersY Combinator Pitch Deck Template For Startup Founders
Y Combinator Pitch Deck Template For Startup Founders
 
All about Programmatic buying(RTB), DSP,SSP, DMP & DCT - A complete digital ...
All about Programmatic buying(RTB), DSP,SSP, DMP & DCT -  A complete digital ...All about Programmatic buying(RTB), DSP,SSP, DMP & DCT -  A complete digital ...
All about Programmatic buying(RTB), DSP,SSP, DMP & DCT - A complete digital ...
 
Surge Pricing: 0 to 1 by fmr Lyft Product Leader
Surge Pricing: 0 to 1 by fmr Lyft Product LeaderSurge Pricing: 0 to 1 by fmr Lyft Product Leader
Surge Pricing: 0 to 1 by fmr Lyft Product Leader
 
Confluent Partner Tech Talk with BearingPoint
Confluent Partner Tech Talk with BearingPointConfluent Partner Tech Talk with BearingPoint
Confluent Partner Tech Talk with BearingPoint
 
Castle: $30K VC investment, eventually raising $3.3M. Castle's initial pitch ...
Castle: $30K VC investment, eventually raising $3.3M. Castle's initial pitch ...Castle: $30K VC investment, eventually raising $3.3M. Castle's initial pitch ...
Castle: $30K VC investment, eventually raising $3.3M. Castle's initial pitch ...
 
YouTube Pitch Deck
YouTube Pitch DeckYouTube Pitch Deck
YouTube Pitch Deck
 

Similar to Briefing on adtech, RTB, and the GDPR at dmexco Brave event.

Johnny Ryan, Presentation at Data Protection Leadership Day, Arthur Cox Solic...
Johnny Ryan, Presentation at Data Protection Leadership Day, Arthur Cox Solic...Johnny Ryan, Presentation at Data Protection Leadership Day, Arthur Cox Solic...
Johnny Ryan, Presentation at Data Protection Leadership Day, Arthur Cox Solic...Johnny Ryan
 
Presentation to FTC technology taskforce
Presentation to FTC technology taskforce Presentation to FTC technology taskforce
Presentation to FTC technology taskforce Johnny Ryan
 
Presentation to European Political Strategy Centre at the European Commission
Presentation to European Political Strategy Centre at the European CommissionPresentation to European Political Strategy Centre at the European Commission
Presentation to European Political Strategy Centre at the European CommissionJohnny Ryan
 
The Adtech Crisis and Disinformation
The Adtech Crisis and DisinformationThe Adtech Crisis and Disinformation
The Adtech Crisis and DisinformationJohnny Ryan
 
Judiciary Committee Senate staffer briefing 8 September 2019
Judiciary Committee Senate staffer briefing 8 September 2019Judiciary Committee Senate staffer briefing 8 September 2019
Judiciary Committee Senate staffer briefing 8 September 2019Johnny Ryan
 
See updated slidedeck at https://www.slideshare.net/JohnnyRyan/brief-for-worl...
See updated slidedeck at https://www.slideshare.net/JohnnyRyan/brief-for-worl...See updated slidedeck at https://www.slideshare.net/JohnnyRyan/brief-for-worl...
See updated slidedeck at https://www.slideshare.net/JohnnyRyan/brief-for-worl...Johnny Ryan
 
Presentation to ANFO, Norwegian Advertisers Association
Presentation to ANFO, Norwegian Advertisers Association Presentation to ANFO, Norwegian Advertisers Association
Presentation to ANFO, Norwegian Advertisers Association Johnny Ryan
 
Presentation at UK Direct Marketing Association Data Protection Conference 2019
Presentation at UK Direct Marketing Association Data Protection Conference 2019Presentation at UK Direct Marketing Association Data Protection Conference 2019
Presentation at UK Direct Marketing Association Data Protection Conference 2019Johnny Ryan
 
Presentation at CPDP
Presentation at CPDP Presentation at CPDP
Presentation at CPDP Johnny Ryan
 
Brief for World Federation of Advertisers Digital Executive Group, December 2018
Brief for World Federation of Advertisers Digital Executive Group, December 2018Brief for World Federation of Advertisers Digital Executive Group, December 2018
Brief for World Federation of Advertisers Digital Executive Group, December 2018Johnny Ryan
 
Quick 10 minute overview of RTB problems to be fixed at ICO stakeholders' ses...
Quick 10 minute overview of RTB problems to be fixed at ICO stakeholders' ses...Quick 10 minute overview of RTB problems to be fixed at ICO stakeholders' ses...
Quick 10 minute overview of RTB problems to be fixed at ICO stakeholders' ses...Johnny Ryan
 
Discussion starter at Future of Privacy Forum in Washington, DC.
Discussion starter at Future of Privacy Forum in Washington, DC. Discussion starter at Future of Privacy Forum in Washington, DC.
Discussion starter at Future of Privacy Forum in Washington, DC. Johnny Ryan
 
Ethical digital marketing (Trinity College Dublin)
Ethical digital marketing (Trinity College Dublin)Ethical digital marketing (Trinity College Dublin)
Ethical digital marketing (Trinity College Dublin)Johnny Ryan
 
ANTS Programmatic Agency - Credential
ANTS Programmatic Agency - CredentialANTS Programmatic Agency - Credential
ANTS Programmatic Agency - CredentialANTS
 
Briefing for World Federation of Advertisers Media Buyers
Briefing for World Federation of Advertisers Media Buyers  Briefing for World Federation of Advertisers Media Buyers
Briefing for World Federation of Advertisers Media Buyers Johnny Ryan
 

Similar to Briefing on adtech, RTB, and the GDPR at dmexco Brave event. (20)

Johnny Ryan, Presentation at Data Protection Leadership Day, Arthur Cox Solic...
Johnny Ryan, Presentation at Data Protection Leadership Day, Arthur Cox Solic...Johnny Ryan, Presentation at Data Protection Leadership Day, Arthur Cox Solic...
Johnny Ryan, Presentation at Data Protection Leadership Day, Arthur Cox Solic...
 
Presentation to FTC technology taskforce
Presentation to FTC technology taskforce Presentation to FTC technology taskforce
Presentation to FTC technology taskforce
 
Presentation to European Political Strategy Centre at the European Commission
Presentation to European Political Strategy Centre at the European CommissionPresentation to European Political Strategy Centre at the European Commission
Presentation to European Political Strategy Centre at the European Commission
 
The Adtech Crisis and Disinformation
The Adtech Crisis and DisinformationThe Adtech Crisis and Disinformation
The Adtech Crisis and Disinformation
 
Judiciary Committee Senate staffer briefing 8 September 2019
Judiciary Committee Senate staffer briefing 8 September 2019Judiciary Committee Senate staffer briefing 8 September 2019
Judiciary Committee Senate staffer briefing 8 September 2019
 
See updated slidedeck at https://www.slideshare.net/JohnnyRyan/brief-for-worl...
See updated slidedeck at https://www.slideshare.net/JohnnyRyan/brief-for-worl...See updated slidedeck at https://www.slideshare.net/JohnnyRyan/brief-for-worl...
See updated slidedeck at https://www.slideshare.net/JohnnyRyan/brief-for-worl...
 
Presentation to ANFO, Norwegian Advertisers Association
Presentation to ANFO, Norwegian Advertisers Association Presentation to ANFO, Norwegian Advertisers Association
Presentation to ANFO, Norwegian Advertisers Association
 
Ofcom briefing
Ofcom briefing Ofcom briefing
Ofcom briefing
 
Presentation at UK Direct Marketing Association Data Protection Conference 2019
Presentation at UK Direct Marketing Association Data Protection Conference 2019Presentation at UK Direct Marketing Association Data Protection Conference 2019
Presentation at UK Direct Marketing Association Data Protection Conference 2019
 
Presentation at CPDP
Presentation at CPDP Presentation at CPDP
Presentation at CPDP
 
Brief for World Federation of Advertisers Digital Executive Group, December 2018
Brief for World Federation of Advertisers Digital Executive Group, December 2018Brief for World Federation of Advertisers Digital Executive Group, December 2018
Brief for World Federation of Advertisers Digital Executive Group, December 2018
 
Quick 10 minute overview of RTB problems to be fixed at ICO stakeholders' ses...
Quick 10 minute overview of RTB problems to be fixed at ICO stakeholders' ses...Quick 10 minute overview of RTB problems to be fixed at ICO stakeholders' ses...
Quick 10 minute overview of RTB problems to be fixed at ICO stakeholders' ses...
 
Discussion starter at Future of Privacy Forum in Washington, DC.
Discussion starter at Future of Privacy Forum in Washington, DC. Discussion starter at Future of Privacy Forum in Washington, DC.
Discussion starter at Future of Privacy Forum in Washington, DC.
 
Ethical digital marketing (Trinity College Dublin)
Ethical digital marketing (Trinity College Dublin)Ethical digital marketing (Trinity College Dublin)
Ethical digital marketing (Trinity College Dublin)
 
Overview RTB ecosystem
Overview RTB ecosystemOverview RTB ecosystem
Overview RTB ecosystem
 
Overview RTB ecosystem
Overview RTB ecosystemOverview RTB ecosystem
Overview RTB ecosystem
 
ANTS Programmatic Agency - Credential
ANTS Programmatic Agency - CredentialANTS Programmatic Agency - Credential
ANTS Programmatic Agency - Credential
 
Welcome DSPs and RTB!
Welcome DSPs and RTB!Welcome DSPs and RTB!
Welcome DSPs and RTB!
 
Progmmatic Buying
Progmmatic Buying Progmmatic Buying
Progmmatic Buying
 
Briefing for World Federation of Advertisers Media Buyers
Briefing for World Federation of Advertisers Media Buyers  Briefing for World Federation of Advertisers Media Buyers
Briefing for World Federation of Advertisers Media Buyers
 

More from Johnny Ryan

Brief presentation to UCD 17 December 2020
Brief presentation to UCD 17 December 2020 Brief presentation to UCD 17 December 2020
Brief presentation to UCD 17 December 2020 Johnny Ryan
 
Presentation to world news publishers, November 2020
Presentation to world news publishers, November 2020Presentation to world news publishers, November 2020
Presentation to world news publishers, November 2020Johnny Ryan
 
Kryptonite, neglected
Kryptonite, neglected Kryptonite, neglected
Kryptonite, neglected Johnny Ryan
 
Brave2020報告書:データ保護当局の執行能力
Brave2020報告書:データ保護当局の執行能力Brave2020報告書:データ保護当局の執行能力
Brave2020報告書:データ保護当局の執行能力Johnny Ryan
 
Talk at IAPP London May 2020: Competition, and why the GDPR is failing
Talk at IAPP London May 2020: Competition, and why the GDPR is failing Talk at IAPP London May 2020: Competition, and why the GDPR is failing
Talk at IAPP London May 2020: Competition, and why the GDPR is failing Johnny Ryan
 
Purpose limitation in data protection law as a protection against "cascading ...
Purpose limitation in data protection law as a protection against "cascading ...Purpose limitation in data protection law as a protection against "cascading ...
Purpose limitation in data protection law as a protection against "cascading ...Johnny Ryan
 
IVIR summer school slides
IVIR summer school slidesIVIR summer school slides
IVIR summer school slidesJohnny Ryan
 
Brendan Eich's letter to Senator Thune and Senator Nelson, Senate Committee o...
Brendan Eich's letter to Senator Thune and Senator Nelson, Senate Committee o...Brendan Eich's letter to Senator Thune and Senator Nelson, Senate Committee o...
Brendan Eich's letter to Senator Thune and Senator Nelson, Senate Committee o...Johnny Ryan
 
Talk to Norwegian CMOs about the folly of adtech
Talk to Norwegian CMOs about the folly of adtech Talk to Norwegian CMOs about the folly of adtech
Talk to Norwegian CMOs about the folly of adtech Johnny Ryan
 
Tech stole your audience. Take it back.
Tech stole your audience. Take it back. Tech stole your audience. Take it back.
Tech stole your audience. Take it back. Johnny Ryan
 
Johnny Ryan PageFair slide deck from SIINDA (search industry trade body) conf...
Johnny Ryan PageFair slide deck from SIINDA (search industry trade body) conf...Johnny Ryan PageFair slide deck from SIINDA (search industry trade body) conf...
Johnny Ryan PageFair slide deck from SIINDA (search industry trade body) conf...Johnny Ryan
 
GDPR solution for websites and apps. Digital Content Next (DCN) webinar, Apri...
GDPR solution for websites and apps. Digital Content Next (DCN) webinar, Apri...GDPR solution for websites and apps. Digital Content Next (DCN) webinar, Apri...
GDPR solution for websites and apps. Digital Content Next (DCN) webinar, Apri...Johnny Ryan
 
Slides from PageFair presentation in Athens, GDPR for Marketers Conference, 1...
Slides from PageFair presentation in Athens, GDPR for Marketers Conference, 1...Slides from PageFair presentation in Athens, GDPR for Marketers Conference, 1...
Slides from PageFair presentation in Athens, GDPR for Marketers Conference, 1...Johnny Ryan
 
Deck at GDPR Summit at Croke Park.
Deck at GDPR Summit at Croke Park. Deck at GDPR Summit at Croke Park.
Deck at GDPR Summit at Croke Park. Johnny Ryan
 

More from Johnny Ryan (15)

CPDP 2022
CPDP 2022CPDP 2022
CPDP 2022
 
Brief presentation to UCD 17 December 2020
Brief presentation to UCD 17 December 2020 Brief presentation to UCD 17 December 2020
Brief presentation to UCD 17 December 2020
 
Presentation to world news publishers, November 2020
Presentation to world news publishers, November 2020Presentation to world news publishers, November 2020
Presentation to world news publishers, November 2020
 
Kryptonite, neglected
Kryptonite, neglected Kryptonite, neglected
Kryptonite, neglected
 
Brave2020報告書:データ保護当局の執行能力
Brave2020報告書:データ保護当局の執行能力Brave2020報告書:データ保護当局の執行能力
Brave2020報告書:データ保護当局の執行能力
 
Talk at IAPP London May 2020: Competition, and why the GDPR is failing
Talk at IAPP London May 2020: Competition, and why the GDPR is failing Talk at IAPP London May 2020: Competition, and why the GDPR is failing
Talk at IAPP London May 2020: Competition, and why the GDPR is failing
 
Purpose limitation in data protection law as a protection against "cascading ...
Purpose limitation in data protection law as a protection against "cascading ...Purpose limitation in data protection law as a protection against "cascading ...
Purpose limitation in data protection law as a protection against "cascading ...
 
IVIR summer school slides
IVIR summer school slidesIVIR summer school slides
IVIR summer school slides
 
Brendan Eich's letter to Senator Thune and Senator Nelson, Senate Committee o...
Brendan Eich's letter to Senator Thune and Senator Nelson, Senate Committee o...Brendan Eich's letter to Senator Thune and Senator Nelson, Senate Committee o...
Brendan Eich's letter to Senator Thune and Senator Nelson, Senate Committee o...
 
Talk to Norwegian CMOs about the folly of adtech
Talk to Norwegian CMOs about the folly of adtech Talk to Norwegian CMOs about the folly of adtech
Talk to Norwegian CMOs about the folly of adtech
 
Tech stole your audience. Take it back.
Tech stole your audience. Take it back. Tech stole your audience. Take it back.
Tech stole your audience. Take it back.
 
Johnny Ryan PageFair slide deck from SIINDA (search industry trade body) conf...
Johnny Ryan PageFair slide deck from SIINDA (search industry trade body) conf...Johnny Ryan PageFair slide deck from SIINDA (search industry trade body) conf...
Johnny Ryan PageFair slide deck from SIINDA (search industry trade body) conf...
 
GDPR solution for websites and apps. Digital Content Next (DCN) webinar, Apri...
GDPR solution for websites and apps. Digital Content Next (DCN) webinar, Apri...GDPR solution for websites and apps. Digital Content Next (DCN) webinar, Apri...
GDPR solution for websites and apps. Digital Content Next (DCN) webinar, Apri...
 
Slides from PageFair presentation in Athens, GDPR for Marketers Conference, 1...
Slides from PageFair presentation in Athens, GDPR for Marketers Conference, 1...Slides from PageFair presentation in Athens, GDPR for Marketers Conference, 1...
Slides from PageFair presentation in Athens, GDPR for Marketers Conference, 1...
 
Deck at GDPR Summit at Croke Park.
Deck at GDPR Summit at Croke Park. Deck at GDPR Summit at Croke Park.
Deck at GDPR Summit at Croke Park.
 

Recently uploaded

The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechNewman George Leech
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
Socio-economic-Impact-of-business-consumers-suppliers-and.pptx
Socio-economic-Impact-of-business-consumers-suppliers-and.pptxSocio-economic-Impact-of-business-consumers-suppliers-and.pptx
Socio-economic-Impact-of-business-consumers-suppliers-and.pptxtrishalcan8
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Lviv Startup Club
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdfOrient Homes
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayNZSG
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...noida100girls
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Roomdivyansh0kumar0
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessAggregage
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 

Recently uploaded (20)

The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman Leech
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Socio-economic-Impact-of-business-consumers-suppliers-and.pptx
Socio-economic-Impact-of-business-consumers-suppliers-and.pptxSocio-economic-Impact-of-business-consumers-suppliers-and.pptx
Socio-economic-Impact-of-business-consumers-suppliers-and.pptx
 
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
Yaroslav Rozhankivskyy: Три складові і три передумови максимальної продуктивн...
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdf
 
It will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 MayIt will be International Nurses' Day on 12 May
It will be International Nurses' Day on 12 May
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for Success
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)
 
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517
Nepali Escort Girl Kakori \ 9548273370 Indian Call Girls Service Lucknow ₹,9517
 

Briefing on adtech, RTB, and the GDPR at dmexco Brave event.

  • 1.
  • 3. RTB
  • 4. “Demand side” “Supply side” $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange
  • 5. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange “Demand side” “Supply side”
  • 6. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Store data “Demand side” “Supply side”
  • 7. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Request segment Store data “Demand side” “Supply side”
  • 8. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Request segment Deliver segment Store data “Demand side” “Supply side”
  • 9. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Request page Request segment Deliver segment Store data “Demand side” “Supply side”
  • 10. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Serve page Request page Request segment Deliver segment Store data “Demand side” “Supply side”
  • 11. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Serve page Request page Request segment Deliver segment Ad request Store data “Demand side” “Supply side”
  • 12. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Serve page Request page Request segment Cookie to SSP Deliver segment Ad request Store data “Demand side” “Supply side”
  • 13. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Serve page Request page Request segment Request bid Cookie to SSP Deliver segment Ad request Store data “Demand side” “Supply side” (one or many)
  • 14. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Serve page Request page Request bid Request segment Request bid Cookie to SSP Deliver segment Ad request Store data “Demand side” “Supply side” (one or many) (10s or 100s or 1000s?)
  • 15. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Serve page Request page Request bid Request segment Request bid Cookie to SSP Deliver ad Deliver segment Ad request Store data “Demand side” “Supply side” (one or many) (10s or 100s or 1000s?)
  • 16. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Serve page Request page Request bid Request segment Request bid Cookie to SSP Deliver ad Deliver segment Sync Ad request Store data “Demand side” “Supply side” (one or many) (10s or 100s or 1000s?)
  • 17. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Serve page Request page Request bid Request segment Request bid Cookie to SSP Deliver ad Sync Deliver segment Sync Ad request Store data “Demand side” “Supply side” (one or many) (10s or 100s or 1000s?)
  • 25. French regulator caught it with 68 million illegal RTB records. Example Vectaury: a small DSP/DMP/ trading desk in France. €3.5M annual turnover in 2017 (though subsequently won a €20M investment). DSP
  • 26.
  • 27.
  • 28. Is 68 million just 30%? Then this small company was sent personal data ¼ BILLION times via RTB (in just one year)
  • 29. website.com This is the current process of real-time bidding that is used in online behavioural advertising. Channel of data leakage Legend Money DATA LEAKAGE IN ONLINE ADVERTISING
  • 30. website.com This is the current process of real-time bidding that is used in online behavioural advertising. Channel of data leakage Legend Money DATA LEAKAGE IN ONLINE ADVERTISING
  • 31. Ad server website.com Ad server javascript Step 1. User requests webpageThis is the current process of real-time bidding that is used in online behavioural advertising. Channel of data leakage Legend Money DATA LEAKAGE IN ONLINE ADVERTISING
  • 32. Ad server SSP Step 2. Ad server selects an SSP website.com Ad server javascript SSP javascript Step 1. User requests webpageThis is the current process of real-time bidding that is used in online behavioural advertising. Channel of data leakage Legend Money DATA LEAKAGE IN ONLINE ADVERTISING
  • 33. Ad server SSP Step 2. Ad server selects an SSP Step 3. SSP selects an exchange website.com Ad server javascript SSP javascript Step 1. User requests webpage Ad exchange This is the current process of real-time bidding that is used in online behavioural advertising. Channel of data leakage Legend Money DATA LEAKAGE IN ONLINE ADVERTISING
  • 34. Ad server SSP Step 2. Ad server selects an SSP Step 3. SSP selects an exchange MARKETERS website.com Ad server javascript SSP javascript Step 1. User requests webpage Ad exchange Step 4. Exchange sends bid requests to hundreds of partners DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP This is the current process of real-time bidding that is used in online behavioural advertising. Channel of data leakage Legend Money DATA LEAKAGE IN ONLINE ADVERTISING
  • 35. Ad server SSP Step 2. Ad server selects an SSP Step 3. SSP selects an exchange MARKETERS website.com Winningbid Ad server javascript SSP javascript Step 1. User requests webpage Ad exchange Step 4. Exchange sends bid requests to hundreds of partners DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP This is the current process of real-time bidding that is used in online behavioural advertising. Channel of data leakage Legend Money DATA LEAKAGE IN ONLINE ADVERTISING
  • 36. Ad server SSP Step 2. Ad server selects an SSP Step 3. SSP selects an exchange MARKETERS website.com Winningbid Ad server javascript SSP javascript DMP DMP DMP DMP DSP DSP DSP DSP DSP Step 1. User requests webpage Ad exchange Step 4. Exchange sends bid requests to hundreds of partners Step 5. Exchange lets some DMPs/ DSPs to refresh cookie sync DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP This is the current process of real-time bidding that is used in online behavioural advertising. Channel of data leakage Legend Money DATA LEAKAGE IN ONLINE ADVERTISING
  • 37. Ad server SSP Step 2. Ad server selects an SSP Step 3. SSP selects an exchange MARKETERS website.com Winningbid Ad server javascript SSP javascript DMP DMP DMP DMP DSP DSP DSP DSP DSP DSP javascript Step 6. Exchange serves winning bid Winning DSP Step 1. User requests webpage Ad exchange Step 4. Exchange sends bid requests to hundreds of partners Step 5. Exchange lets some DMPs/ DSPs to refresh cookie sync DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP This is the current process of real-time bidding that is used in online behavioural advertising. Channel of data leakage Legend Money DATA LEAKAGE IN ONLINE ADVERTISING
  • 38. Ad server SSP Step 2. Ad server selects an SSP Step 3. SSP selects an exchange Step 7. DSP serves agency creative MARKETERS website.com Winningbid Ad server javascript SSP javascript DMP DMP DMP DMP DSP DSP DSP DSP DSP DSP javascript Ad server javascript Step 6. Exchange serves winning bid Agency ad server Winning DSP Step 1. User requests webpage Ad exchange Step 4. Exchange sends bid requests to hundreds of partners Step 5. Exchange lets some DMPs/ DSPs to refresh cookie sync DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP This is the current process of real-time bidding that is used in online behavioural advertising. DATA LEAKAGE IN ONLINE ADVERTISING Channel of data leakage Legend Money
  • 39. Ad server SSP Step 2. Ad server selects an SSP Step 3. SSP selects an exchange Step 7. DSP serves agency creative Step 8. Assets load from CDN MARKETERS website.com AD Winningbid Ad server javascript SSP javascript DMP DMP DMP DMP DSP DSP DSP DSP DSP DSP javascript Ad server javascript Step 6. Exchange serves winning bid Agency ad server Winning DSP Step 1. User requests webpage Ad exchange Step 4. Exchange sends bid requests to hundreds of partners Step 5. Exchange lets some DMPs/ DSPs to refresh cookie sync CDN DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP DSP This is the current process of real-time bidding that is used in online behavioural advertising. DATA LEAKAGE IN ONLINE ADVERTISING Channel of data leakage Legend Money
  • 40. What’s in a bid request?
  • 41. IAB OpenRTB Google Authorized Buyers
  • 42.
  • 43.
  • 44.
  • 45. The website this specific person is currently viewing Various ID codes that identify this specific person, and can tie them to existing profiles Distinctive characteristics of this specific person This specific person’s IP address Distinctive information about this specific person’s device Distinctive information about this specific person’s device This young woman’s GPS coordinates!
  • 46. Natural persons may be associated with online identifiers … such as internet protocol addresses, cookie identifiers or other identifiers… This may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of the natural persons and identify them. GDPR, Recital 30
  • 47.
  • 48. Index Exchange 50 billion 1. “Tour IX’s Amsterdam and Frankfurt Data Centers”, Index Exchange, 2 July 2018 (URL: https://www.indexexchange.com/tour-ix-amsterdam-frankfurt-data-centers/). 2. "OpenX Ad Exchange", OpenX (URL: https://www.openx.com/uk_en/products/ad-exchange/). 3. “Buyers”, Rubicon Project (URL: https://rubiconproject.com/buyers/). 4. "How PubMatic Is Learning Machine Learning", PubMatic, 25 January 2019 (URL: https://pubmatic.com/blog/learning-machine-learning/) 5. "Maximize yield with Oath's publisher offerings", Oath, 3 April 2018 (URL: https://www.oath.com/insights/maximize-yield-with-oath-s-publisher-offerings/) 6. 500 Billion / 29.6 = 18.6 billion impressions per day. Using AppNexus 1:11.5 ratio, this is 214 auctions per day. 500+ impressions figure cited in “Optimize your mobile strategy”, Smaato (URL: https://www.smaato.com/). 7. “Transacting at a peak of 11.4 billion daily impressions, our marketplace handles more traffic each day than Visa, Nasdaq, and the NYSE combined” at https:// www.appnexus.com/sell. Note that in 2017, AppNexus said in “AppNexus Scales with DriveScale”, 2017 (URL: http://go.drivescale.com/rs/451-ESR-800/images/ DRV_Case_Study_AppNexus-final.v1.pdf) that 10.7 billion "impressions transacted" came as a result of running 123 billion auctions. The impressions transacted to auctions ratio appears to be roughly 1:11.5. Therefore, the 11.4 daily impressions reported in 2018 equates to 131 billion auctions per day. 8. DoubleClick.Net Usage Statistics (URL: https://trends.builtwith.com/ads/DoubleClick.Net). Real-time bidding bid requests per day OpenX 60 billion2 Rubicon Project Unknown, 1 billion people’s devices3 PubMatic 70 billion4 Oath/AOL 90 billion5 AppNexus 131 billion6 Smaato 214 billion7 Google Unknown, live on 8.4 million websites8 1 Index Exchange 50 billion The biggest
  • 49. Index Exchange 50 billion 1. “Tour IX’s Amsterdam and Frankfurt Data Centers”, Index Exchange, 2 July 2018 (URL: https://www.indexexchange.com/tour-ix-amsterdam-frankfurt-data-centers/). 2. "OpenX Ad Exchange", OpenX (URL: https://www.openx.com/uk_en/products/ad-exchange/). 3. “Buyers”, Rubicon Project (URL: https://rubiconproject.com/buyers/). 4. "How PubMatic Is Learning Machine Learning", PubMatic, 25 January 2019 (URL: https://pubmatic.com/blog/learning-machine-learning/) 5. "Maximize yield with Oath's publisher offerings", Oath, 3 April 2018 (URL: https://www.oath.com/insights/maximize-yield-with-oath-s-publisher-offerings/) 6. 500 Billion / 29.6 = 18.6 billion impressions per day. Using AppNexus 1:11.5 ratio, this is 214 auctions per day. 500+ impressions figure cited in “Optimize your mobile strategy”, Smaato (URL: https://www.smaato.com/). 7. “Transacting at a peak of 11.4 billion daily impressions, our marketplace handles more traffic each day than Visa, Nasdaq, and the NYSE combined” at https:// www.appnexus.com/sell. Note that in 2017, AppNexus said in “AppNexus Scales with DriveScale”, 2017 (URL: http://go.drivescale.com/rs/451-ESR-800/images/ DRV_Case_Study_AppNexus-final.v1.pdf) that 10.7 billion "impressions transacted" came as a result of running 123 billion auctions. The impressions transacted to auctions ratio appears to be roughly 1:11.5. Therefore, the 11.4 daily impressions reported in 2018 equates to 131 billion auctions per day. 8. DoubleClick.Net Usage Statistics (URL: https://trends.builtwith.com/ads/DoubleClick.Net). Real-time bidding bid requests per day OpenX 60 billion2 Rubicon Project Unknown, 1 billion people’s devices3 PubMatic 70 billion4 Oath/AOL 90 billion5 AppNexus 131 billion6 Smaato 214 billion7 Google Unknown, live on 8.4 million websites8 1 Index Exchange 50 billion The biggest Hundreds of billions of data leaks a day. (The biggest data breach yet recorded)
  • 51. OK
  • 52.
  • 54. Publishers recognize there is no technical way to limit the way data is used after the data is received by a vendor for decisioning/ bidding on/after delivery of an ad… “ ” there is no technical way to limit the way data is used after Surfacing thousands of vendors with broad rights to use data w/out tailoring those rights may be too many vendors/permissions “ ” thousands of vendors “pubvendors.json v1.0: Transparency & Consent Framework”, IAB, May 2018
  • 55. The MO may adopt procedures for periodically reviewing and verifying a Vendor’s compliance with the Policies. “Transparency & Consent Framework Policies, 2019-08-21.3” IAB, August 2019 “ ” may adopt Management Organisation (the IAB)
  • 56. Buyer will regularly monitor your compliance with this obligation, and immediately notify Google in writing if Buyer can no longer meet … this obligation... “ ” “ ” must not: (i) use callout data ... to create user lists or profile users; (ii) associate callout data ... with third party data... Buyer will “Authorized Buyers Programme Guidelines”, Google, August 2018
  • 57. GDPR, Article 5 (1) (f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (‘integrity and confidentiality’).
  • 58. EU privacy regulators are like “ents”. Terrifying, once awoken.
  • 59. 4 We list our concerns - that the creation and sharing of personal data profiles about people, to the scale we’ve seen, feels disproportionate, intrusive and unfair, particularly when people are often unaware it is happening. We outline that one visit to a website, prompting one auction among advertisers, can result in a person’s personal data being seen by hundreds of organisations, in ways that suggest data protection rules have not been sufficiently considered. Our report will be passed to the adtech sector for their response. We are clear about the areas where we have initial concerns, and we expect to see change. But we understand this is an extremely complex market involving many organisations and many technologies. We want to take a measured and iterative approach, before undertaking a further industry review in six months’ time. With that in mind, we’ll continue engaging with the sector, further exploring the data protection implications of the real time bidding system. We’ll continue collaborating with Data Protection Authorities in other European countries too, who are also looking at complaints in this area. Innovation in technology has the potential to enhance all of our lives. The internet is central to that, and we understand that advertisements fund much of what we enjoy online. We understand the need for a system that allows revenue for publishers and audiences for advertisers. We understand a need for the process to happen in a heartbeat. Our aim is to prompt changes that reflect this reality, but also to ensure respect for internet users’ legal rights. The rules that protect people’s personal data must be followed. Companies do not need to choose between innovation and privacy. Elizabeth Denham Information Commissioner Information Commissioner’s Office Update report into adtech and real time bidding 20 June 2019
  • 60. 4 We list our concerns - that the creation and sharing of personal data profiles about people, to the scale we’ve seen, feels disproportionate, intrusive and unfair, particularly when people are often unaware it is happening. We outline that one visit to a website, prompting one auction among advertisers, can result in a person’s personal data being seen by hundreds of organisations, in ways that suggest data protection rules have not been sufficiently considered. Our report will be passed to the adtech sector for their response. We are clear about the areas where we have initial concerns, and we expect to see change. But we understand this is an extremely complex market involving many organisations and many technologies. We want to take a measured and iterative approach, before undertaking a further industry review in six months’ time. With that in mind, we’ll continue engaging with the sector, further exploring the data protection implications of the real time bidding system. We’ll continue collaborating with Data Protection Authorities in other European countries too, who are also looking at complaints in this area. Innovation in technology has the potential to enhance all of our lives. The internet is central to that, and we understand that advertisements fund much of what we enjoy online. We understand the need for a system that allows revenue for publishers and audiences for advertisers. We understand a need for the process to happen in a heartbeat. Our aim is to prompt changes that reflect this reality, but also to ensure respect for internet users’ legal rights. The rules that protect people’s personal data must be followed. Companies do not need to choose between innovation and privacy. Elizabeth Denham Information Commissioner Information Commissioner’s Office Update report into adtech and real time bidding 20 June 2019 one visit to a website, prompting one auction among advertisers, can result in a person’s personal data being seen by hundreds of organisations, in ways that suggest data protection rules have not been sufficiently considered. page 4
  • 61. 23 4 Summary and conclusions Overall, in the ICO’s view the adtech industry appears immature in its understanding of data protection requirements. Whilst the automated delivery of ad impressions is here to stay, we have general, systemic concerns around the level of compliance of RTB: 1. Processing of non-special category data is taking place unlawfully at the point of collection due to the perception that legitimate interests can be used for placing and/or reading a cookie or other technology (rather than obtaining the consent PECR requires). 2. Any processing of special category data is taking place unlawfully as explicit consent is not being collected (and no other condition applies). In general, processing such data requires more protection as it brings an increased potential for harm to individuals. 3. Even if an argument could be made for reliance on legitimate interests, participants within the ecosystem are unable to demonstrate that they have properly carried out the legitimate interests tests and implemented appropriate safeguards. 4. There appears to be a lack of understanding of, and potentially compliance with, the DPIA requirements of data protection law more broadly (and specifically as regards the ICO’s Article 35(4) list). We therefore have little confidence that the risks associated with RTB have been fully assessed and mitigated. 5. Privacy information provided to individuals lacks clarity whilst also being overly complex. The TCF and Authorized Buyers frameworks are insufficient to ensure transparency and fair processing of the personal data in question and therefore also insufficient to provide for free and informed consent, with attendant implications for PECR compliance. 6. The profiles created about individuals are extremely detailed and are repeatedly shared among hundreds of organisations for any one bid request, all without the individuals’ knowledge. 7. Thousands of organisations are processing billions of bid requests in the UK each week with (at best) inconsistent application of adequate technical and organisational measures to secure the data in transit and at rest, and with little or no consideration as to the requirements of data protection law about international transfers of personal data. 8. There are similar inconsistencies about the application of data minimisation and retention controls. 9. Individuals have no guarantees about the security of their personal data within the ecosystem. 4 We list our concerns - that the creation and sharing of personal data profiles about people, to the scale we’ve seen, feels disproportionate, intrusive and unfair, particularly when people are often unaware it is happening. We outline that one visit to a website, prompting one auction among advertisers, can result in a person’s personal data being seen by hundreds of organisations, in ways that suggest data protection rules have not been sufficiently considered. Our report will be passed to the adtech sector for their response. We are clear about the areas where we have initial concerns, and we expect to see change. But we understand this is an extremely complex market involving many organisations and many technologies. We want to take a measured and iterative approach, before undertaking a further industry review in six months’ time. With that in mind, we’ll continue engaging with the sector, further exploring the data protection implications of the real time bidding system. We’ll continue collaborating with Data Protection Authorities in other European countries too, who are also looking at complaints in this area. Innovation in technology has the potential to enhance all of our lives. The internet is central to that, and we understand that advertisements fund much of what we enjoy online. We understand the need for a system that allows revenue for publishers and audiences for advertisers. We understand a need for the process to happen in a heartbeat. Our aim is to prompt changes that reflect this reality, but also to ensure respect for internet users’ legal rights. The rules that protect people’s personal data must be followed. Companies do not need to choose between innovation and privacy. Elizabeth Denham Information Commissioner Information Commissioner’s Office Update report into adtech and real time bidding 20 June 2019The TCF and Authorized Buyers frameworks are insufficient to ensure transparency and fair processing of the personal data in question and therefore also insufficient to provide for free and informed consent… page 23
  • 62.
  • 63.
  • 65. CMO
  • 66.
  • 67.
  • 68. PublishersMarketer $ Shared liability under GDPR Article 82Legend Money Channel of data leakage Marketer risk from programmatic advertising
  • 69. PublishersSSPsDSPDMPMarketer Ad Exchanges AAgency $ Shared liability under GDPR Article 82Legend Money Channel of data leakage Marketer risk from programmatic advertising
  • 70. Data protection-free zone PublishersSSPsDSPDMPMarketer Ad Exchanges AAgency Personal data widely broadcast in “RTB” bid requests $ Insurer and reinsurer risk? Shared liability under GDPR Article 82Legend Money Channel of data leakage Marketer risk from programmatic advertising
  • 75. • What you are reading, or watching, or listening to. • Categories of the content. • Unique pseudonymous ID. • Unique ID matched to ad buyer’s existing profile of you. • Your location (can be your exact latitude and longitude). • Granular description of your device. • Unique tracking IDs / cookie match. • Your IP address.* • Data broker segment ID* when available. *Depending on the version of “real time bidding” system Conventional “Broadcast” Behavioral
  • 76. • What you are reading, or watching, or listening to. • Categories of the content. • Your approximate location. • General description of your device. • Your approximate IP address. • Impression ID for buyer transparency. Person in Cologne (District 1: Köln-Innenstadt) is reading an article about ad fraud on WSJ’s CMO roundup. Using Safari on an iPhone X or higher. Safe data “Broadcast” Behavioral
  • 78. How RTB data leakage supports untrustworthy websites The Daily Bugle
  • 79. How RTB data leakage supports untrustworthy websites The Daily Bugle /// Step 1. User “John” visits The Daily Bugle
  • 80. How RTB data leakage supports untrustworthy websites The Daily Bugle /// Step 1. User “John” visits The Daily Bugle Step 2. Bid request broadcasts personal data about John
  • 81. How RTB data leakage supports untrustworthy websites The Daily Bugle /// Step 3. 100s of companies in the ad auction can now re-identify John as a Daily Bugle reader Step 1. User “John” visits The Daily Bugle Step 2. Bid request broadcasts personal data about John John
  • 82. Step 4. The Daily Bugle is paid €1 to show ad to John How RTB data leakage supports untrustworthy websites The Daily Bugle /// Step 3. 100s of companies in the ad auction can now re-identify John as a Daily Bugle reader Step 1. User “John” visits The Daily Bugle €1 advertisement Step 2. Bid request broadcasts personal data about John John
  • 83. Step 4. The Daily Bugle is paid €1 to show ad to John How RTB data leakage supports untrustworthy websites The Daily Bugle Step 5. Later, John visits a low quality website Step 3. 100s of companies in the ad auction can now re-identify John as a Daily Bugle reader Step 1. User “John” visits The Daily Bugle €1 advertisement De5troyTru5t.com /// Step 2. Bid request broadcasts personal data about John John
  • 84. Step 4. The Daily Bugle is paid €1 to show ad to John How RTB data leakage supports untrustworthy websites The Daily Bugle Step 5. Later, John visits a low quality website Step 6. Bid request announces John is here Step 3. 100s of companies in the ad auction can now re-identify John as a Daily Bugle reader Step 1. User “John” visits The Daily Bugle €1 advertisement De5troyTru5t.com /// Step 2. Bid request broadcasts personal data about John John
  • 85. Step 4. The Daily Bugle is paid €1 to show ad to John Step 7. De5troyTru5t.com is paid €0.01 to show ad to John How RTB data leakage supports untrustworthy websites The Daily Bugle Step 5. Later, John visits a low quality website Step 6. Bid request announces John is here Step 3. 100s of companies in the ad auction can now re-identify John as a Daily Bugle reader Step 1. User “John” visits The Daily Bugle €1 advertisement De5troyTru5t.com €0.01 advertisement /// Step 2. Bid request broadcasts personal data about John John
  • 86. Step 4. The Daily Bugle is paid €1 to show ad to John Step 7. De5troyTru5t.com is paid €0.01 to show ad to John How RTB data leakage supports untrustworthy websites The Daily Bugle Step 5. Later, John visits a low quality website Step 6. Bid request announces John is here Step 3. 100s of companies in the ad auction can now re-identify John as a Daily Bugle reader Step 1. User “John” visits The Daily Bugle €1 advertisement De5troyTru5t.com €0.01 advertisement /// Step 2. Bid request broadcasts personal data about John Worthy sites lose their unique audience, and feed a business model for the bottom of the Web. John
  • 87. The Daily Bugle How RTB enables to steal from publishers and advertisers. fraudsters
  • 88. The Daily Bugle Step 1. A bot masquerading as a human visits The Daily Bugle /// Fake How RTB enables to steal from publishers and advertisers. fraudsters
  • 89. The Daily Bugle Step 1. A bot masquerading as a human visits The Daily Bugle Step 2. Bid request broadcasts personal data about Bot/// Fake How RTB enables to steal from publishers and advertisers. fraudsters
  • 90. The Daily Bugle Step 3. 100s of companies in the ad auction can now re-identify Bot as a Daily Bugle reader Step 1. A bot masquerading as a human visits The Daily Bugle Step 2. Bid request broadcasts personal data about Bot Bot /// Fake How RTB enables to steal from publishers and advertisers. fraudsters
  • 91. Step 4. The Daily Bugle is paid €1 to show ad The Daily Bugle Step 3. 100s of companies in the ad auction can now re-identify Bot as a Daily Bugle reader Step 1. A bot masquerading as a human visits The Daily Bugle €1 advertisement Step 2. Bid request broadcasts personal data about Bot Bot /// Fake How RTB enables to steal from publishers and advertisers. fraudsters
  • 92. Step 4. The Daily Bugle is paid €1 to show ad The Daily Bugle Step 5. Later, an untrustworthy website buts bot traffic Step 3. 100s of companies in the ad auction can now re-identify Bot as a Daily Bugle reader Step 1. A bot masquerading as a human visits The Daily Bugle €1 advertisement De5troyTru5t.com Step 2. Bid request broadcasts personal data about Bot Bot /// Fake /// Fake How RTB enables to steal from publishers and advertisers. fraudsters
  • 93. Step 4. The Daily Bugle is paid €1 to show ad The Daily Bugle Step 5. Later, an untrustworthy website buts bot traffic Step 6. Bid request announces Bot is here Step 3. 100s of companies in the ad auction can now re-identify Bot as a Daily Bugle reader Step 1. A bot masquerading as a human visits The Daily Bugle €1 advertisement De5troyTru5t.com Step 2. Bid request broadcasts personal data about Bot Bot /// Fake /// Fake How RTB enables to steal from publishers and advertisers. fraudsters
  • 94. Step 4. The Daily Bugle is paid €1 to show ad Step 7. De5troyTru5t.com is paid €0.01 to show ad to Bot The Daily Bugle Step 5. Later, an untrustworthy website buts bot traffic Step 6. Bid request announces Bot is here Step 3. 100s of companies in the ad auction can now re-identify Bot as a Daily Bugle reader Step 1. A bot masquerading as a human visits The Daily Bugle €1 advertisement De5troyTru5t.com €0.01 advertisement Step 2. Bid request broadcasts personal data about Bot Bot /// Fake /// Fake How RTB enables to steal from publishers and advertisers. fraudsters
  • 95. $ /// VisitorSiteSupply-side platform (SSP) Demand-side platform (DSP) Data management platform (DMP) Marketer Ad Exchange Serve page Request page Request bid Request segment Request bid Cookie to SSP Deliver ad Sync Deliver segment Sync Ad request Store data “Demand side” “Supply side” (one or many) (10s or 100s or 1000s?) DSPDMP SSP
  • 96. Buyer Seller Extracts 70-55% of buyer’s media budget. Distribution Marketer $ DMP DSP Ad Exchange SSP Site Unique audience commodified and arbitraged. Untrustworthy sites business model enabled. Bot fraud boosted. 70% figure from the Guardian and Rubicon case in 2017. 55% figure from “The Programmatic Supply Chain: Deconstructing the Anatomy of a Programmatic CPM”, IAB, March 2016. MARKET OVERVIEW (NOW) PERSONAL DATA IN IAB / GOOGLE RTB Victims of massive fraud. 2019 estimates range from $5.7B (ANA) - $42B (Juniper Research).
  • 97. Extracts much lower % of buyer’s media budget. Unique audience become immune to commodification and arbitrage. No opportunity for untrustworthy sites. Bot fraud reduced. Bot fraud opportunity reduced. MARKET OVERVIEW (POST-FIX) NON-PERSONAL DATA IN IAB / GOOGLE RTB Marketer $ DMP DSP Ad Exchange SSP Site Buyer SellerDistribution
  • 102. Private profiles. If you opt-in, the Browser builds a profile that stays private on the device. No one (including Brave) ever gets it. Machine learning on the device decides what ad is shown, and when it is best to show it to you. “Local” Behavioral ///
  • 103.
  • 104. Browser user visits various websites
  • 105. Today’s ad catalog is sent to the device. Browser user visits various websites
  • 106. Today’s ad catalog is sent to the device. Brave Browser on the device selects an ad based on profile on the device. 70% of ad revenue goes to user. Browser user visits various websites
  • 107. Today’s ad catalog is sent to the device. Brave Browser on the device selects an ad based on profile on the device. 70% of ad revenue goes to user. By default, websites are paid from the user’s wallet at the end of the month. (This can not be attributed to an individual user.) Browser user visits various websites
  • 108. Conventional “Broadcast” Behavioral “Local” Behavioral Safe data “Broadcast” Behavioral /// 1 2 3
  • 109.
  • 110.
  • 111.
  • 112.
  • 114. Fossil Fuel Renewable Energy N20 C02 Regulatory incentive CLEAN INDUSTRY Regulatory disincentive DIRTY INDUSTRY
  • 115. Ads (Ethical Data)Ads (Conventional Data) Regulatory incentive CLEAN INDUSTRY Regulatory disincentive DIRTY INDUSTRY Personal data Non-personal data Fossil Fuel Renewable Energy N20 C02
  • 117. 1. Regulators will force change. 
 2. Prepare for when the IAB & Google are forced to reform RTB. It is likely to use only non-personal data. 
 3. Experiment with safe adtech. 
 4. Connect: BRAVE.com/INSIGHT/ johnny@brave.com