SlideShare a Scribd company logo
1 of 29
Download to read offline
1
© 2022 TrustArc Inc. Proprietary and Confidential Information.
Cross-Contextual Advertising:
Rethinking How Consumer Data Is Managed
2
Speakers
Janalyn Schreiber
Privacy Consulting
TrustArc
Sal Tripi
Vice President - Digital Operations &
Compliance
Publishers Clearing House
3
Agenda
● The laws and regulations governing advertising technologies
● How advertising and data privacy can work together
● How to address the privacy issues related to cross-contextual
advertising
● Q&A
4
Poll Questions
5
Privacy management is complex.
Laws
Storage
Collection
Processing
Compliance
People
6
How is your Brand Ensuring Digital Privacy for
Customers, Leads, and Website Visitors?
● Consumers are empowered with the knowledge about how
their data is stored, shared, and collected during
interactions with businesses.
● Consumers have to provide their consent before data can
be obtained.
● Consumers have the right to request that a company stop
using their data for marketing, commonly referred to as a
"right to be forgotten" in all systems.
Privacy laws are moving towards providing
individuals more control than even over their
personal data, requiring:
7
Regulators Are Adding Pressure
8
Action at the State Level
● 2018: 2 bills were introduced from 2 states
● 2019: 16 bills were introduced from 13 states
● 2020: 25 bills were introduced from 16 states
● 2021: 29 bills were introduced from 23 states
● 2022: ~60 bills were introduced or carried over from 2021 in 29 states + DC:
○ 23 states held committee hearings.
○ 14 states passed bills out of committee.
○ 7 states passed a bill through one chamber.
○ 2 states passed laws:
■ Connecticut
■ Utah
The number of state privacy legislation bills introduced since 2018 makes it
clear that states are getting increasingly serious about data privacy:
9
Which Regulations Address Digital Marketing?
● California - California Privacy Rights Act (CPRA):
○ Adds rights - correction, restriction of use, and opt-out of the use and
disclosure of sensitive personal information.
○ Requires opt-out for sharing data for use in cross-context behavioral
advertising:
■ Add the “Do Not Sell or Share My Personal Information” link on all digital
locations (e.g., web pages) where personal information is collected OR
■ Comply with a global opt-out signal (details to follow)
● Virginia - Consumer Data Protection Act (CDPA):
○ Required rights - access, correct, delete, data portability, to opt out from sales
of data to third parties, targeted advertising, and certain profiling, to opt-in to
processing “sensitive” data, and right to appeal.
○ Requires data protection assessments to evaluate risks associated with
processing activities related to sensitive data, targeted advertising and
profiling, and the sale of personal data.
■ Goes into effect January 2023.
10
Which Regulations Address Digital Marketing?
● Colorado - Colorado Privacy Act (CPA):
○ Requires the right to opt-out of personal data targeting and a
universal opt-out mechanism.
○ Requires data protection assessments for any personal data
processing that may have risk to individuals.
○ Goes into effect July 2023.
● Connecticut - Connecticut Data Privacy Act (CTDPA):
○ Requires opt-in for processing “sensitive data” and opt-out for
targeted advertising, data sale and profiling.
○ Goes into effect July 2023.
● Utah - Utah Consumer Privacy Act (UCPA):
○ Requires opt-out of processing for targeted advertising and the
selling of personal information.
○ Goes into effect December 2023.
11
CCPA in the News
● On August 24, the Office of the Attorney General (OAG) first settlement under the
CCPA, alleging that Sephora failed to:
○ Disclose to consumers that it was selling their personal information
○ Process user requests to opt out of sale requests via user-enabled global
privacy controls
○ Provide a clear and conspicuous “Do Not Sell My Personal Information” link
enabling consumers to opt -out of the sale of their personal information; and
○ Provide two or more designated methods for submitting requests to opt -out.
● The OAG also alleged Sephora violated California’s Unfair Competition Law by
“making false or misleading statements of facts concerning Defendants’ sale of
consumers’ personal information and unfairly depriving consumers of the ability to
opt-out of this sale.”
Sephora Fined $1.2 Million in California AG’s First CCPA Settlement
12
CCPA in the News
● Sephora installed third-party software on its website and app to track online consumer
activity - the OAG notably called it “commercial surveillance.”
● The OAG asserted the software could track all types of data and could build behavioral
profiles of users, allowing Sephora to more effectively target potential customers.
○ By receiving this data, Sephora engaged in selling - benefitting from “other
valuable consideration” in the CCPA’s definition of “sale”.
● The OAG also asserted there were no valid service-provider contracts in place, which is
one exception to “sale” – contractually limiting the third-party tracking companies to
processing requirements to establish them as “service providers” under the CCPA.
● What’s next? CPRA may provide more risk to online tracking activities – bringing the
right to opt out of the sale of personal information AND of the transfer of personal
information to a third party for cross-context behavioral advertising.
What Happened?
13
Game Changers
14
Cross Contextual Advertising
“The targeting of advertising to a consumer based
on the consumer's personal information obtained
from the consumer’s activity across businesses,
distinctly-branded websites, application or services,
other than the business, distinctly-branded websites,
application or services which the consumer
intentionally interacts.”
CPRA defines Cross Contextual Advertising as…..
15
Cross Contextual Advertising
“It means….. “The digital ad industry must adhere to a far higher regulatory standard as it relates
to targeting and retargeting”
What does that mean?
16
Business Purpose
A business that uses personal information for
“cross-context behavioral advertising” and relies on a
vendor to process the data, now falls outside the
scope of a permitted “business purpose”.
What does that mean?
17
Business Purpose
● Auditing
● Data Security
● Debugging
● Internal research
● Quality Control
● Advertising and Marketing services (THAT ARE NOT CROSS CONTEXT BEHAVORIAL
ADVERTISING).
18
Fundamentals Are The Same
● Transparency
● Choice
● Data Classification
● Contractual Obligations
● Collecting and using data securely
● Understanding what vendors, partners and others are doing
19
Understand Data Collection/Use
● Know what is being collect
● Know how it is being used
● Understand what data is being shared and with whom
● Roles are included in agreements (business, service providers and third parties)
● Vet all!!
● Data security, transparency and choice
20
CPRA New Contractual Requirements
1. Limited and specified purposes.
2. Comply with applicable obligations of the CPRA
3. Grants right to ensure that the third party, service provider or contractor uses the personal
information transferred in a manner consistent with the business's obligations.
4. Requires the third party, service provider or contractor to notify the business if it decides it
can no longer meet its obligations under this title.
5. Grants the business the right, upon notice to take reasonable and appropriate steps to stop
and remediate unauthorized use of personal information.
6. As noted, this new requirement extends the duty to contract to third-party transfers, which
is currently not required
21
How Can Digital Marketing Coexist With Data Privacy?
Legal
IT
Marketing
3rd Party
Partners
● Learning
● Collaborating
● Leveraging Technology
22
Poll Questions
23
What is a Cookie?
● Information saved by web browsers that helps sites recognize a user’s
device in the future - sites read cookies to remember the previous visit(s)
and track behaviour over time.
● Privacy-driven changes to the technology landscape:
○ Google plans to phase out and ban cookies extended to late 2024
○ Safari and Firefox already did so in 2020
○ However! The ban only applies to third-party data cookies - so not all targeting hope is lost.
● First-party cookies are still fair game! – so what’s the difference between
the two:
○ Third-party cookies are cookies that are set by a website other than the one you are
currently on.
■ They are mostly used to track users between websites and display more relevant
ads between websites.
○ First-party cookies allow site owners to collect basic analytics data to create a
better user experience.
■ A website remembering login information and language settings, but not sharing
the user’s information with other platforms – all data is siloed by domain.
24
Cookie Alternatives?
● Leverage First-Party Data:
○ First party cookies - useful tool in retargeting, as it provides valuable information
about who interacts with your business most - basic demographic information
about visitors and how they interact with your content.
○ First-party data can also be collected through:
■ Surveys
■ Customer feedback
■ Social media insights
■ Email lists
■ Not the most technologically advanced, but still give a clear glimpse into
wants, needs and tendencies.
● Contextual Advertising - matches ads to specific users based on keywords to put the
right content in front of the right user at the right time.
○ Token-based approach
Now is the time to consider some alternatives:
25
Marketing & Privacy
● Consent & Opting Out
○ Consent must be granular, affirmative, and freely given - ask for consent for
each marketing effort individually using a consent mechanism, like a
checkbox.
○ Marketing consent must be distinct from any consent to a Terms and
Condition agreement or Privacy Policy.
○ Make it as easy to opt-out as it was to opt-in – consent is freely given at all
times during the customer relationship, not just within your sign-up
mechanism.
○ Manage direct marketing consent with an Unsubscribe function on texts
or emails and by using a communication preference page within the
customer's account – track the time, date, country, and source through
which individuals opt-in and opt-out.
26
Marketing & Privacy
● The Risks of Lists
○ Generally, users must knowingly consent to be contacted via email before a company can
legally do so.
○ Relying on purchased email lists as a cornerstone of email marketing is a risky move -
instead, gather email addresses directly, e.g., through a subscription form on your website.
○ Email on a purchased list could be inactive or outdated – don’t risk a regulatory violation just
to contact an inactive inbox!
● Data Retention, Purpose Limitation & Minimization
○ Personal data may only be kept for as long as necessary to carry out the particular purpose.
○ A data retention policy should outline:
■ Data collected
■ Why it was collected
■ How long it will be retained for
■ How it will be securely destroyed
27
Consent and Preference
Management is a single source of
trust enabling organizations to
capture and manage real-time
customer consent and
preferences.
Save time, increase quality
conversions, comply with
privacy laws.
28
28
Q&A
29
Thank You!
See http://www.trustarc.com/insightseries for
the 2022 Privacy Insight Series and past
webinar recordings.
If you would like to learn more about how TrustArc can support
you with compliance, please reach out to sales@trustarc.com for a
free demo.

More Related Content

Similar to TrustArc-Webinar-Slides-2022-09-20-Cross-Contextual-Advertising

TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdfTrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdfTrustArc
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...TrustArc
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...TrustArc
 
CCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st EnforcementCCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st EnforcementTrustArc
 
CCPA and the Future of Privacy-First Digital Advertising
CCPA and the Future of Privacy-First Digital AdvertisingCCPA and the Future of Privacy-First Digital Advertising
CCPA and the Future of Privacy-First Digital AdvertisingThe Media Kitchen
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc
 
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc
 
Criteo CCPA project
Criteo CCPA project Criteo CCPA project
Criteo CCPA project Gerry L. H.
 
GDPR's Impact on Social Media - Everything You Need to Know
GDPR's Impact on Social Media - Everything You Need to KnowGDPR's Impact on Social Media - Everything You Need to Know
GDPR's Impact on Social Media - Everything You Need to KnowVisitor Analytics
 
Everything B2B Tech Marketers Need to Know About Privacy + Consent
Everything B2B Tech Marketers Need to Know About Privacy + ConsentEverything B2B Tech Marketers Need to Know About Privacy + Consent
Everything B2B Tech Marketers Need to Know About Privacy + ConsentKiwi Creative
 
Data opportunities mini whitepaper
Data opportunities mini whitepaperData opportunities mini whitepaper
Data opportunities mini whitepaperRobert Bowstead
 
Joint ad trade letter to ag becerra re ccpa 1.31.2019
Joint ad trade letter to ag becerra re ccpa 1.31.2019Joint ad trade letter to ag becerra re ccpa 1.31.2019
Joint ad trade letter to ag becerra re ccpa 1.31.2019Greg Sterling
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementTrustArc
 
Deck for Chardan conference call on ePrivacy and GDPR
Deck for Chardan conference call on ePrivacy and GDPR Deck for Chardan conference call on ePrivacy and GDPR
Deck for Chardan conference call on ePrivacy and GDPR Johnny Ryan
 
CCPA - Sephora Case Highlights
CCPA - Sephora Case HighlightsCCPA - Sephora Case Highlights
CCPA - Sephora Case HighlightsTrustArc
 
When consumers control data whitepaper
When consumers control data whitepaperWhen consumers control data whitepaper
When consumers control data whitepaperDuy, Vo Hoang
 
Time to slow down? Measured respondes to the fake news crisis
Time to slow down? Measured respondes to the fake news crisisTime to slow down? Measured respondes to the fake news crisis
Time to slow down? Measured respondes to the fake news crisismrleiser
 
California Consumer Privacy Act and the Role of IAM
California Consumer Privacy Act and the Role of IAMCalifornia Consumer Privacy Act and the Role of IAM
California Consumer Privacy Act and the Role of IAMWSO2
 
Maximizing & Exploiting Big Data in Digital Media....Legally
Maximizing & Exploiting Big Data in Digital Media....LegallyMaximizing & Exploiting Big Data in Digital Media....Legally
Maximizing & Exploiting Big Data in Digital Media....LegallyMediaPost
 
Abbie Clement — GDPR, CCPA, ePrivacy: Which Data Laws Are Next and How the Ne...
Abbie Clement — GDPR, CCPA, ePrivacy: Which Data Laws Are Next and How the Ne...Abbie Clement — GDPR, CCPA, ePrivacy: Which Data Laws Are Next and How the Ne...
Abbie Clement — GDPR, CCPA, ePrivacy: Which Data Laws Are Next and How the Ne...Semrush
 

Similar to TrustArc-Webinar-Slides-2022-09-20-Cross-Contextual-Advertising (20)

TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdfTrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
TrustArc Webinar_ How Data Privacy Demands Impact Your Marketing Team.pdf
 
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
Your Guide to Understanding the Global Privacy Control (GPC): Preparing for C...
 
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
How to Leverage Your GDPR Compliance for CCPA, Privacy Shield & More New Requ...
 
CCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st EnforcementCCPA Update: What You Need to Know about CPRA & July 1st Enforcement
CCPA Update: What You Need to Know about CPRA & July 1st Enforcement
 
CCPA and the Future of Privacy-First Digital Advertising
CCPA and the Future of Privacy-First Digital AdvertisingCCPA and the Future of Privacy-First Digital Advertising
CCPA and the Future of Privacy-First Digital Advertising
 
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
TrustArc Webinar - Managing Online Tracking Technology Vendors_ A Checklist f...
 
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working TogetherTrustArc Webinar-Advertising, Privacy, and Data Management Working Together
TrustArc Webinar-Advertising, Privacy, and Data Management Working Together
 
Criteo CCPA project
Criteo CCPA project Criteo CCPA project
Criteo CCPA project
 
GDPR's Impact on Social Media - Everything You Need to Know
GDPR's Impact on Social Media - Everything You Need to KnowGDPR's Impact on Social Media - Everything You Need to Know
GDPR's Impact on Social Media - Everything You Need to Know
 
Everything B2B Tech Marketers Need to Know About Privacy + Consent
Everything B2B Tech Marketers Need to Know About Privacy + ConsentEverything B2B Tech Marketers Need to Know About Privacy + Consent
Everything B2B Tech Marketers Need to Know About Privacy + Consent
 
Data opportunities mini whitepaper
Data opportunities mini whitepaperData opportunities mini whitepaper
Data opportunities mini whitepaper
 
Joint ad trade letter to ag becerra re ccpa 1.31.2019
Joint ad trade letter to ag becerra re ccpa 1.31.2019Joint ad trade letter to ag becerra re ccpa 1.31.2019
Joint ad trade letter to ag becerra re ccpa 1.31.2019
 
Building Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR ManagementBuilding Consumer Trust through Individual Rights / DSAR Management
Building Consumer Trust through Individual Rights / DSAR Management
 
Deck for Chardan conference call on ePrivacy and GDPR
Deck for Chardan conference call on ePrivacy and GDPR Deck for Chardan conference call on ePrivacy and GDPR
Deck for Chardan conference call on ePrivacy and GDPR
 
CCPA - Sephora Case Highlights
CCPA - Sephora Case HighlightsCCPA - Sephora Case Highlights
CCPA - Sephora Case Highlights
 
When consumers control data whitepaper
When consumers control data whitepaperWhen consumers control data whitepaper
When consumers control data whitepaper
 
Time to slow down? Measured respondes to the fake news crisis
Time to slow down? Measured respondes to the fake news crisisTime to slow down? Measured respondes to the fake news crisis
Time to slow down? Measured respondes to the fake news crisis
 
California Consumer Privacy Act and the Role of IAM
California Consumer Privacy Act and the Role of IAMCalifornia Consumer Privacy Act and the Role of IAM
California Consumer Privacy Act and the Role of IAM
 
Maximizing & Exploiting Big Data in Digital Media....Legally
Maximizing & Exploiting Big Data in Digital Media....LegallyMaximizing & Exploiting Big Data in Digital Media....Legally
Maximizing & Exploiting Big Data in Digital Media....Legally
 
Abbie Clement — GDPR, CCPA, ePrivacy: Which Data Laws Are Next and How the Ne...
Abbie Clement — GDPR, CCPA, ePrivacy: Which Data Laws Are Next and How the Ne...Abbie Clement — GDPR, CCPA, ePrivacy: Which Data Laws Are Next and How the Ne...
Abbie Clement — GDPR, CCPA, ePrivacy: Which Data Laws Are Next and How the Ne...
 

More from TrustArc

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...TrustArc
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...TrustArc
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesTrustArc
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceTrustArc
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfTrustArc
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsTrustArc
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsTrustArc
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...TrustArc
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdfTrustArc
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceTrustArc
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023TrustArc
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining TrustTrustArc
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowTrustArc
 
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?TrustArc
 
Why Your Company Needs A Privacy Culture & Where To Start
Why Your Company Needs A Privacy Culture & Where To StartWhy Your Company Needs A Privacy Culture & Where To Start
Why Your Company Needs A Privacy Culture & Where To StartTrustArc
 

More from TrustArc (20)

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie WorldTrustArc Webinar - How to Live in a Post Third-Party Cookie World
TrustArc Webinar - How to Live in a Post Third-Party Cookie World
 
TrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI InnovationsTrustArc Webinar - TrustArc's Latest AI Innovations
TrustArc Webinar - TrustArc's Latest AI Innovations
 
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data SecurityTrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
TrustArc Webinar - Privacy in Healthcare_ Ensuring Data Security
 
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
Unlocking AI Potential: Leveraging PIA Processes for Comprehensive Impact Ass...
 
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
Mitigating Third-Party Risks: Best Practices for CISOs in Ensuring Robust Sec...
 
Nymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 StatesNymity Framework: Privacy & Data Protection Update in 7 States
Nymity Framework: Privacy & Data Protection Update in 7 States
 
CBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy ComplianceCBPR - Navigating Cross-Border Data Privacy Compliance
CBPR - Navigating Cross-Border Data Privacy Compliance
 
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdfEverything You Need to Know about DPF But Are Afraid to Ask.pdf
Everything You Need to Know about DPF But Are Afraid to Ask.pdf
 
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and RecommendationsPrivacy Enhancing Technologies: Exploring the Benefits and Recommendations
Privacy Enhancing Technologies: Exploring the Benefits and Recommendations
 
Building Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy CertificationsBuilding Trust and Competitive Advantage: The Value of Privacy Certifications
Building Trust and Competitive Advantage: The Value of Privacy Certifications
 
The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...The California Age Appropriate Design Code Act Navigating the New Requirement...
The California Age Appropriate Design Code Act Navigating the New Requirement...
 
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
2023 Global Privacy Benchmarks Survey - Webinar May 30 2023.pdf
 
Artificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI GovernanceArtificial Intelligence Bill of Rights: Impacts on AI Governance
Artificial Intelligence Bill of Rights: Impacts on AI Governance
 
How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023How To Do Data Transfers Between EU-US in 2023
How To Do Data Transfers Between EU-US in 2023
 
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act:  Using Consumer Data and Maintaining TrustThe Ultimate Balancing Act:  Using Consumer Data and Maintaining Trust
The Ultimate Balancing Act: Using Consumer Data and Maintaining Trust
 
The Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To KnowThe Cost of Privacy Teams: What Your Business Needs To Know
The Cost of Privacy Teams: What Your Business Needs To Know
 
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
TrustArc Webinar - Rise of Information Technology: How Does it Impact Privacy?
 
Why Your Company Needs A Privacy Culture & Where To Start
Why Your Company Needs A Privacy Culture & Where To StartWhy Your Company Needs A Privacy Culture & Where To Start
Why Your Company Needs A Privacy Culture & Where To Start
 

Recently uploaded

Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxnull - The Open Security Community
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):comworks
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxOnBoard
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Allon Mureinik
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraDeakin University
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking MenDelhi Call girls
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024BookNet Canada
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetEnjoy Anytime
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 3652toLead Limited
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitecturePixlogix Infotech
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?XfilesPro
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024Scott Keck-Warren
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Hyundai Motor Group
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsMemoori
 

Recently uploaded (20)

Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptxMaking_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
Making_way_through_DLL_hollowing_inspite_of_CFG_by_Debjeet Banerjee.pptx
 
Pigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food ManufacturingPigging Solutions in Pet Food Manufacturing
Pigging Solutions in Pet Food Manufacturing
 
CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):CloudStudio User manual (basic edition):
CloudStudio User manual (basic edition):
 
Maximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptxMaximizing Board Effectiveness 2024 Webinar.pptx
Maximizing Board Effectiveness 2024 Webinar.pptx
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)Injustice - Developers Among Us (SciFiDevCon 2024)
Injustice - Developers Among Us (SciFiDevCon 2024)
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Artificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning eraArtificial intelligence in the post-deep learning era
Artificial intelligence in the post-deep learning era
 
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
08448380779 Call Girls In Diplomatic Enclave Women Seeking Men
 
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
Transcript: #StandardsGoals for 2024: What’s new for BISAC - Tech Forum 2024
 
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your BudgetHyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
Hyderabad Call Girls Khairatabad ✨ 7001305949 ✨ Cheap Price Your Budget
 
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
Tech-Forward - Achieving Business Readiness For Copilot in Microsoft 365
 
Understanding the Laravel MVC Architecture
Understanding the Laravel MVC ArchitectureUnderstanding the Laravel MVC Architecture
Understanding the Laravel MVC Architecture
 
How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?How to Remove Document Management Hurdles with X-Docs?
How to Remove Document Management Hurdles with X-Docs?
 
Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024SQL Database Design For Developers at php[tek] 2024
SQL Database Design For Developers at php[tek] 2024
 
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptxVulnerability_Management_GRC_by Sohang Sengupta.pptx
Vulnerability_Management_GRC_by Sohang Sengupta.pptx
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2Next-generation AAM aircraft unveiled by Supernal, S-A2
Next-generation AAM aircraft unveiled by Supernal, S-A2
 
AI as an Interface for Commercial Buildings
AI as an Interface for Commercial BuildingsAI as an Interface for Commercial Buildings
AI as an Interface for Commercial Buildings
 

TrustArc-Webinar-Slides-2022-09-20-Cross-Contextual-Advertising

  • 1. 1 © 2022 TrustArc Inc. Proprietary and Confidential Information. Cross-Contextual Advertising: Rethinking How Consumer Data Is Managed
  • 2. 2 Speakers Janalyn Schreiber Privacy Consulting TrustArc Sal Tripi Vice President - Digital Operations & Compliance Publishers Clearing House
  • 3. 3 Agenda ● The laws and regulations governing advertising technologies ● How advertising and data privacy can work together ● How to address the privacy issues related to cross-contextual advertising ● Q&A
  • 5. 5 Privacy management is complex. Laws Storage Collection Processing Compliance People
  • 6. 6 How is your Brand Ensuring Digital Privacy for Customers, Leads, and Website Visitors? ● Consumers are empowered with the knowledge about how their data is stored, shared, and collected during interactions with businesses. ● Consumers have to provide their consent before data can be obtained. ● Consumers have the right to request that a company stop using their data for marketing, commonly referred to as a "right to be forgotten" in all systems. Privacy laws are moving towards providing individuals more control than even over their personal data, requiring:
  • 8. 8 Action at the State Level ● 2018: 2 bills were introduced from 2 states ● 2019: 16 bills were introduced from 13 states ● 2020: 25 bills were introduced from 16 states ● 2021: 29 bills were introduced from 23 states ● 2022: ~60 bills were introduced or carried over from 2021 in 29 states + DC: ○ 23 states held committee hearings. ○ 14 states passed bills out of committee. ○ 7 states passed a bill through one chamber. ○ 2 states passed laws: ■ Connecticut ■ Utah The number of state privacy legislation bills introduced since 2018 makes it clear that states are getting increasingly serious about data privacy:
  • 9. 9 Which Regulations Address Digital Marketing? ● California - California Privacy Rights Act (CPRA): ○ Adds rights - correction, restriction of use, and opt-out of the use and disclosure of sensitive personal information. ○ Requires opt-out for sharing data for use in cross-context behavioral advertising: ■ Add the “Do Not Sell or Share My Personal Information” link on all digital locations (e.g., web pages) where personal information is collected OR ■ Comply with a global opt-out signal (details to follow) ● Virginia - Consumer Data Protection Act (CDPA): ○ Required rights - access, correct, delete, data portability, to opt out from sales of data to third parties, targeted advertising, and certain profiling, to opt-in to processing “sensitive” data, and right to appeal. ○ Requires data protection assessments to evaluate risks associated with processing activities related to sensitive data, targeted advertising and profiling, and the sale of personal data. ■ Goes into effect January 2023.
  • 10. 10 Which Regulations Address Digital Marketing? ● Colorado - Colorado Privacy Act (CPA): ○ Requires the right to opt-out of personal data targeting and a universal opt-out mechanism. ○ Requires data protection assessments for any personal data processing that may have risk to individuals. ○ Goes into effect July 2023. ● Connecticut - Connecticut Data Privacy Act (CTDPA): ○ Requires opt-in for processing “sensitive data” and opt-out for targeted advertising, data sale and profiling. ○ Goes into effect July 2023. ● Utah - Utah Consumer Privacy Act (UCPA): ○ Requires opt-out of processing for targeted advertising and the selling of personal information. ○ Goes into effect December 2023.
  • 11. 11 CCPA in the News ● On August 24, the Office of the Attorney General (OAG) first settlement under the CCPA, alleging that Sephora failed to: ○ Disclose to consumers that it was selling their personal information ○ Process user requests to opt out of sale requests via user-enabled global privacy controls ○ Provide a clear and conspicuous “Do Not Sell My Personal Information” link enabling consumers to opt -out of the sale of their personal information; and ○ Provide two or more designated methods for submitting requests to opt -out. ● The OAG also alleged Sephora violated California’s Unfair Competition Law by “making false or misleading statements of facts concerning Defendants’ sale of consumers’ personal information and unfairly depriving consumers of the ability to opt-out of this sale.” Sephora Fined $1.2 Million in California AG’s First CCPA Settlement
  • 12. 12 CCPA in the News ● Sephora installed third-party software on its website and app to track online consumer activity - the OAG notably called it “commercial surveillance.” ● The OAG asserted the software could track all types of data and could build behavioral profiles of users, allowing Sephora to more effectively target potential customers. ○ By receiving this data, Sephora engaged in selling - benefitting from “other valuable consideration” in the CCPA’s definition of “sale”. ● The OAG also asserted there were no valid service-provider contracts in place, which is one exception to “sale” – contractually limiting the third-party tracking companies to processing requirements to establish them as “service providers” under the CCPA. ● What’s next? CPRA may provide more risk to online tracking activities – bringing the right to opt out of the sale of personal information AND of the transfer of personal information to a third party for cross-context behavioral advertising. What Happened?
  • 14. 14 Cross Contextual Advertising “The targeting of advertising to a consumer based on the consumer's personal information obtained from the consumer’s activity across businesses, distinctly-branded websites, application or services, other than the business, distinctly-branded websites, application or services which the consumer intentionally interacts.” CPRA defines Cross Contextual Advertising as…..
  • 15. 15 Cross Contextual Advertising “It means….. “The digital ad industry must adhere to a far higher regulatory standard as it relates to targeting and retargeting” What does that mean?
  • 16. 16 Business Purpose A business that uses personal information for “cross-context behavioral advertising” and relies on a vendor to process the data, now falls outside the scope of a permitted “business purpose”. What does that mean?
  • 17. 17 Business Purpose ● Auditing ● Data Security ● Debugging ● Internal research ● Quality Control ● Advertising and Marketing services (THAT ARE NOT CROSS CONTEXT BEHAVORIAL ADVERTISING).
  • 18. 18 Fundamentals Are The Same ● Transparency ● Choice ● Data Classification ● Contractual Obligations ● Collecting and using data securely ● Understanding what vendors, partners and others are doing
  • 19. 19 Understand Data Collection/Use ● Know what is being collect ● Know how it is being used ● Understand what data is being shared and with whom ● Roles are included in agreements (business, service providers and third parties) ● Vet all!! ● Data security, transparency and choice
  • 20. 20 CPRA New Contractual Requirements 1. Limited and specified purposes. 2. Comply with applicable obligations of the CPRA 3. Grants right to ensure that the third party, service provider or contractor uses the personal information transferred in a manner consistent with the business's obligations. 4. Requires the third party, service provider or contractor to notify the business if it decides it can no longer meet its obligations under this title. 5. Grants the business the right, upon notice to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information. 6. As noted, this new requirement extends the duty to contract to third-party transfers, which is currently not required
  • 21. 21 How Can Digital Marketing Coexist With Data Privacy? Legal IT Marketing 3rd Party Partners ● Learning ● Collaborating ● Leveraging Technology
  • 23. 23 What is a Cookie? ● Information saved by web browsers that helps sites recognize a user’s device in the future - sites read cookies to remember the previous visit(s) and track behaviour over time. ● Privacy-driven changes to the technology landscape: ○ Google plans to phase out and ban cookies extended to late 2024 ○ Safari and Firefox already did so in 2020 ○ However! The ban only applies to third-party data cookies - so not all targeting hope is lost. ● First-party cookies are still fair game! – so what’s the difference between the two: ○ Third-party cookies are cookies that are set by a website other than the one you are currently on. ■ They are mostly used to track users between websites and display more relevant ads between websites. ○ First-party cookies allow site owners to collect basic analytics data to create a better user experience. ■ A website remembering login information and language settings, but not sharing the user’s information with other platforms – all data is siloed by domain.
  • 24. 24 Cookie Alternatives? ● Leverage First-Party Data: ○ First party cookies - useful tool in retargeting, as it provides valuable information about who interacts with your business most - basic demographic information about visitors and how they interact with your content. ○ First-party data can also be collected through: ■ Surveys ■ Customer feedback ■ Social media insights ■ Email lists ■ Not the most technologically advanced, but still give a clear glimpse into wants, needs and tendencies. ● Contextual Advertising - matches ads to specific users based on keywords to put the right content in front of the right user at the right time. ○ Token-based approach Now is the time to consider some alternatives:
  • 25. 25 Marketing & Privacy ● Consent & Opting Out ○ Consent must be granular, affirmative, and freely given - ask for consent for each marketing effort individually using a consent mechanism, like a checkbox. ○ Marketing consent must be distinct from any consent to a Terms and Condition agreement or Privacy Policy. ○ Make it as easy to opt-out as it was to opt-in – consent is freely given at all times during the customer relationship, not just within your sign-up mechanism. ○ Manage direct marketing consent with an Unsubscribe function on texts or emails and by using a communication preference page within the customer's account – track the time, date, country, and source through which individuals opt-in and opt-out.
  • 26. 26 Marketing & Privacy ● The Risks of Lists ○ Generally, users must knowingly consent to be contacted via email before a company can legally do so. ○ Relying on purchased email lists as a cornerstone of email marketing is a risky move - instead, gather email addresses directly, e.g., through a subscription form on your website. ○ Email on a purchased list could be inactive or outdated – don’t risk a regulatory violation just to contact an inactive inbox! ● Data Retention, Purpose Limitation & Minimization ○ Personal data may only be kept for as long as necessary to carry out the particular purpose. ○ A data retention policy should outline: ■ Data collected ■ Why it was collected ■ How long it will be retained for ■ How it will be securely destroyed
  • 27. 27 Consent and Preference Management is a single source of trust enabling organizations to capture and manage real-time customer consent and preferences. Save time, increase quality conversions, comply with privacy laws.
  • 29. 29 Thank You! See http://www.trustarc.com/insightseries for the 2022 Privacy Insight Series and past webinar recordings. If you would like to learn more about how TrustArc can support you with compliance, please reach out to sales@trustarc.com for a free demo.