Lena Cohen's piece for the EFF on real-time bidding (RTB) is worth reading. It brings together a series of cases that are too often treated as separate problems: Mobilewalla collecting bidstream data on a billion people, Near Intelligence selling data to the Department of Defense, Rayzone and Patternz turning advertising data into government tracking tools, and Google sending bid requests to a sanctioned Russian company.
The FTC's action against Mobilewalla matters because it was the commission's first case focused directly on the abuse of bidstream data. The settlement says, in effect, that a company cannot collect this data when it is not genuinely participating in the advertising auction. That is a useful boundary, but it does not address the larger problem.
The Problem Is Built Into the System
RTB works by sending information about a person and the page they are viewing to a large group of potential buyers. That information can include a device identifier, IP address, location, interests, and inferred demographic details. The auction happens in milliseconds, and most of the companies that receive the request will never place the winning ad.
In other words, the privacy risk is not simply that a few companies misuse the data after receiving it. The system depends on distributing the data in the first place. The collection and disclosure are part of the design.
The EFF argues that online behavioral advertising should be banned. I understand the appeal of that position. After working in governance for many years, however, I am cautious about rules that are clear in principle but difficult to implement across a complicated market. Behavioral advertising is embedded throughout the open web, and a poorly defined ban could lead to years of litigation over what counts as behavioral, contextual, or something in between.
A more practical starting point is to treat RTB for what it is: a large, automated, cross-border system for processing personal data. We already have laws and governance tools designed for that kind of activity. The problem is that we have not applied them consistently to the advertising supply chain.
Start With Purpose Limitation and Data Minimization
Two familiar privacy principles offer a useful way forward: purpose limitation and data minimization. Both appear in Article 5 of the GDPR and in the UK data protection framework. California's privacy rules are moving in the same general direction. These principles are not abstract statements of intent. They are meant to shape what an organization collects, why it collects it, and how long it keeps it.
Applied to RTB, they lead to two straightforward questions:
- Is the data being used for the purpose that justified collecting it? A bid request may be created to select and deliver an ad. When the same request is stored, combined with other information, resold, or used to build profiles by companies that never intended to bid, the purpose has changed. The Mobilewalla settlement recognizes part of this problem, but it applies to one company. Every participant in the chain should have to state a specific purpose and remain bound to it.
- Is every field in the request necessary? Bid requests can contain precise location, device information, inferred demographics, and behavioral categories. Much of that is unnecessary for contextual advertising. The OpenRTB specification makes many fields optional, but the commercial incentive is to include more data because more detailed profiles can attract higher bids. Data minimization reverses that incentive: if a field is not necessary for the stated purpose, it should not be included.
Contextual Advertising Is a Practical Alternative
The standard defense of behavioral advertising is that it funds the free internet. That argument treats extensive tracking as if it were the only way to support publishers. It is not. Contextual advertising matches an ad to the content of a page rather than to a detailed profile of the person reading it. Major publishers have expanded their use of contextual advertising, particularly since the GDPR took effect, without abandoning advertising as a source of revenue.
From a governance perspective, the difference is important. Contextual advertising can operate with little or no personal data in the bid request. It reduces the need for profile building and removes much of the bidstream that data brokers want to collect. That is what privacy by design should look like: reducing the underlying data flow instead of trying to control every possible misuse after the fact.
This Is Also a National Security Problem
The Irish Council for Civil Liberties report cited by Cohen describes RTB as a hidden security crisis in the United States. The concern is not theoretical. Bidstream data can reveal the locations and movements of military personnel, intelligence officers, elected officials, and other people in sensitive roles. When that information reaches foreign-owned advertising companies or data brokers, a commercial data flow becomes a supply-chain vulnerability.
We already recognize that telecommunications metadata, financial records, and health information can create national security risks. Bidstream data can reveal location, movement, associations, interests, and health-related inferences, yet it often receives less protection. That is a gap in policy and governance, not an unavoidable feature of the internet.
What a Workable Regulatory Framework Could Include
A useful framework would focus on the processing activity rather than on a particular company or technology. It could include the following:
- Clear treatment of RTB as regulated data processing. Publishers, supply-side platforms, exchanges, demand-side platforms, and data providers should be accountable for their respective roles. That includes identifying a lawful basis, documenting processing, conducting impact assessments where required, and designing systems around data protection.
- Data minimization in the technical standards. Regulators and standards bodies should define which OpenRTB fields are necessary for particular advertising purposes. Exchanges should reject requests that include data beyond that defined need.
- Purpose restrictions that follow the data. Each step in the chain should carry an enforceable restriction on how the data may be used. Contracts are part of the answer, but technical controls matter as well: audit logs, access controls, retention limits, and automatic deletion. A rule against collecting data without bidding is much stronger when the exchange can enforce it.
- Stronger protection for sensitive bidstream data. Precise location and inferences about health, protest attendance, or union activity should not be treated like ordinary advertising data. Regulators should make clear when this information falls within existing sensitive-data protections and what legal basis is required to process it.
- National security review of foreign data access. Advertising exchanges and platforms with foreign ownership, or data flows into adversarial jurisdictions, deserve the same kind of scrutiny applied to other businesses that hold sensitive information about Americans.
- A meaningful remedy for unauthorized collection and resale. Where companies collect or sell bidstream data without authorization, individuals need an effective way to seek relief. Regulatory settlements are important, but they should not be the only consequence.
The Practical Test: Can an Organization Implement It?
I have built privacy programs at Fortune 50 scale. That experience has taught me to ask a simple question about any regulatory proposal: can a privacy officer, security leader, and product team translate it into specific work without having to guess what the rule means?
- A broad ban leaves important terms unsettled. What counts as behavioral advertising? Where is the boundary between behavioral and contextual targeting? Which party is responsible when several companies contribute data to the same auction? Those questions would take years to resolve.
- Specific processing requirements can be translated into controls. Organizations know how to conduct data protection impact assessments, reduce the fields in a request, add purpose restrictions to contracts, build retention controls, and classify sensitive data. The frameworks, tools, and regulatory precedents already exist.
The Rules Must Apply Across the Market
Industry groups will argue that tighter rules will hurt small publishers, limit innovation, and strengthen the large platforms that already operate closed advertising systems. The last concern is legitimate. Rules that apply only to the open web could give Google, Meta, and Amazon another competitive advantage.
The answer is not to leave the open-web system unchanged. It is to apply the same standards to comparable processing wherever it occurs. If a closed advertising platform uses personal data for targeting, it should be subject to the same rules on purpose, minimization, sensitive data, and accountability. Regulation should follow the activity, not the corporate structure.
What This Means for Your Organization
Organizations do not need to wait for a new regulatory framework to begin reducing their risk. If you are a privacy officer, security leader, or general counsel, there are several practical steps you can take now:
- Map your bidstream exposure. If your websites or applications use programmatic advertising, document what information they send, which companies receive it, and what role each company plays.
- Review your SSP and DSP contracts. Look for clear purpose restrictions, deletion requirements, audit rights, and obligations that continue through the rest of the supply chain. Where those terms are missing, address them.
- Assess the programmatic advertising stack. Determine whether a data protection impact assessment or similar risk assessment is required. The Belgian DPA's decision involving IAB Europe's Transparency and Consent Framework is an important reference point.
- Reduce the data in your OpenRTB configuration. Disable optional fields that are not needed. Make data minimization a contractual and procurement requirement, not simply a technical preference.
- Participate in rulemaking and standards work. Regulators and standards bodies need input from people who understand how these systems operate. Clear, technically realistic requirements are more likely when practitioners take part.
The Bottom Line
The EFF is right about the central problem: RTB has created a surveillance system inside the advertising market. The Mobilewalla action shows that regulators can act when bidstream data is collected and repurposed. The next step is to address the design of the market rather than waiting for one company at a time to cross an obvious line.
Purpose limitation, data minimization, sensitive-data protections, supply-chain accountability, and technical enforcement are not new ideas. They are familiar governance tools. Applying them consistently would make behavioral advertising less invasive and create stronger incentives for contextual approaches that require less personal data.
We do not need to invent an entirely new privacy framework for real-time bidding. We need to use the one we already have.