ICO claims AdTech industry 'violating data protection laws'

Privacy group welcomes the ICO report but accuses the regulator of proceeding slowly on "massive illegality"

A graphic of individuals engaging with online ads

The online advertising industry is operating unlawfully with respect to strict data protection regulations and has an "immature" understanding of its obligations, the Information Commissioner's Office (ICO) has claimed.

The multi-billion pound AdTech industry, which is overwhelmingly dominated by Google and Facebook, is not gaining consent from users when processing personal data that includes information on sexuality, political leaning, or race, among others.

This represents a violation of standards set under the General Data Protection Regulation (GDPR), and the UK's Data Protection Act (DPA) 2018, according to a report published by the UK data regulator.

The companies are doing this through a mechanism known as real-time bidding (RTB). This set of technologies allow advertisers to compete for available digital space by automatically placing billions of ads on webpages and apps in the UK every day.

Processing non-special category data, too, risks violating the Privacy and Electronic Communications Regulations (PECR). Although handling this sort of data doesn't normally require consent, the industry's use of cookies to process information means consent is still needed at the initial point of processing.

"Under data protection law, using people's sensitive personal data to serve adverts requires their explicit consent, which is not happening right now," said the ICO's executive director for technology policy and innovation Simon McDougall.

"Sharing people's data with potentially hundreds of companies, without properly assessing and addressing the risk of these counterparties, raises questions around the security and retention of this data."

The privacy-centric organisation Open Rights Group (ORG), which initially co-authored the complaint that spurred the ICO to investigate the issue, welcomed the report. But the group added the regulator is proceeding slowly and not insisting on immediate changes "despite the massive scale of the data breach".

"The ICO's conclusions are strong and very welcome but we are worried about the slow pace of action and investigation," said the ORG's executive director Jim Killock. "The ICO has confirmed massive illegality on behalf of the adtech industry. They should be insisting on remedies and fast."

The data regulator highlighted a number of additional concerns around data protection laws and RTB. For example, the ICO has seen no evidence that requirements under GDPR to conduct data protection impact assessments (DPIA) are being recognised by companies involved in this mechanism.

This means the personal data risks associated with RTB have not likely been understood and mitigated. Moreover, the profiles created about individuals are highly details and repeatedly shared among hundreds of organisations without their knowledge or consent.

The ICO will continue to gather more information and engage with the AdTech industry, McDougall added, to enhance its knowledge, and share this with European regulators.

Featured Resources

Managing security risk and compliance in a challenging landscape

How key technology partners grow with your organisation

Download now

Evaluate your order-to-cash process

15 recommended metrics to benchmark your O2C operations

Download now

AI 360: Hold, fold, or double down?

How AI can benefit your business

Download now

Getting started with Azure Red Hat OpenShift

A developer’s guide to improving application building and deployment capabilities

Download now

Recommended

Misconfigured Git servers lead to Nissan data leak
hacking

Misconfigured Git servers lead to Nissan data leak

7 Jan 2021
BackupAssist teams with Wasabi to offer cheaper backup for businesses
backup

BackupAssist teams with Wasabi to offer cheaper backup for businesses

6 Jan 2021
Data: A resource much too valuable to leave unprotected
Whitepaper

Data: A resource much too valuable to leave unprotected

2 Dec 2020
Webhose and Signal Corp boost data breach detection
Security

Webhose and Signal Corp boost data breach detection

7 Oct 2020

Most Popular

IT retailer faces €10.4m GDPR fine for employee surveillance
General Data Protection Regulation (GDPR)

IT retailer faces €10.4m GDPR fine for employee surveillance

18 Jan 2021
Citrix buys Slack competitor Wrike in record $2.25bn deal
collaboration

Citrix buys Slack competitor Wrike in record $2.25bn deal

19 Jan 2021
Should IT departments call time on WhatsApp?
communications

Should IT departments call time on WhatsApp?

15 Jan 2021