Lena Cohen's piece for the EFF on real-time bidding (RTB) is worth reading. It brings together a series of cases that are too often treated as separate problems: Mobilewalla collecting bidstream data on a billion people, Near Intelligence selling data to the Department of Defense, Rayzone and Patternz turning advertising data into government tracking tools, and Google sending bid requests to a sanctioned Russian company.

The FTC's action against Mobilewalla matters because it was the commission's first case focused directly on the abuse of bidstream data. The settlement says, in effect, that a company cannot collect this data when it is not genuinely participating in the advertising auction. That is a useful boundary, but it does not address the larger problem.

The Problem Is Built Into the System

RTB works by sending information about a person and the page they are viewing to a large group of potential buyers. That information can include a device identifier, IP address, location, interests, and inferred demographic details. The auction happens in milliseconds, and most of the companies that receive the request will never place the winning ad.

In other words, the privacy risk is not simply that a few companies misuse the data after receiving it. The system depends on distributing the data in the first place. The collection and disclosure are part of the design.

The EFF argues that online behavioral advertising should be banned. I understand the appeal of that position. After working in governance for many years, however, I am cautious about rules that are clear in principle but difficult to implement across a complicated market. Behavioral advertising is embedded throughout the open web, and a poorly defined ban could lead to years of litigation over what counts as behavioral, contextual, or something in between.

A more practical starting point is to treat RTB for what it is: a large, automated, cross-border system for processing personal data. We already have laws and governance tools designed for that kind of activity. The problem is that we have not applied them consistently to the advertising supply chain.

"RTB is an advertising system built on the widespread distribution of personal data."

Start With Purpose Limitation and Data Minimization

Two familiar privacy principles offer a useful way forward: purpose limitation and data minimization. Both appear in Article 5 of the GDPR and in the UK data protection framework. California's privacy rules are moving in the same general direction. These principles are not abstract statements of intent. They are meant to shape what an organization collects, why it collects it, and how long it keeps it.

Applied to RTB, they lead to two straightforward questions:

Contextual Advertising Is a Practical Alternative

The standard defense of behavioral advertising is that it funds the free internet. That argument treats extensive tracking as if it were the only way to support publishers. It is not. Contextual advertising matches an ad to the content of a page rather than to a detailed profile of the person reading it. Major publishers have expanded their use of contextual advertising, particularly since the GDPR took effect, without abandoning advertising as a source of revenue.

From a governance perspective, the difference is important. Contextual advertising can operate with little or no personal data in the bid request. It reduces the need for profile building and removes much of the bidstream that data brokers want to collect. That is what privacy by design should look like: reducing the underlying data flow instead of trying to control every possible misuse after the fact.

This Is Also a National Security Problem

The Irish Council for Civil Liberties report cited by Cohen describes RTB as a hidden security crisis in the United States. The concern is not theoretical. Bidstream data can reveal the locations and movements of military personnel, intelligence officers, elected officials, and other people in sensitive roles. When that information reaches foreign-owned advertising companies or data brokers, a commercial data flow becomes a supply-chain vulnerability.

We already recognize that telecommunications metadata, financial records, and health information can create national security risks. Bidstream data can reveal location, movement, associations, interests, and health-related inferences, yet it often receives less protection. That is a gap in policy and governance, not an unavoidable feature of the internet.

What a Workable Regulatory Framework Could Include

A useful framework would focus on the processing activity rather than on a particular company or technology. It could include the following:

  1. Clear treatment of RTB as regulated data processing. Publishers, supply-side platforms, exchanges, demand-side platforms, and data providers should be accountable for their respective roles. That includes identifying a lawful basis, documenting processing, conducting impact assessments where required, and designing systems around data protection.
  2. Data minimization in the technical standards. Regulators and standards bodies should define which OpenRTB fields are necessary for particular advertising purposes. Exchanges should reject requests that include data beyond that defined need.
  3. Purpose restrictions that follow the data. Each step in the chain should carry an enforceable restriction on how the data may be used. Contracts are part of the answer, but technical controls matter as well: audit logs, access controls, retention limits, and automatic deletion. A rule against collecting data without bidding is much stronger when the exchange can enforce it.
  4. Stronger protection for sensitive bidstream data. Precise location and inferences about health, protest attendance, or union activity should not be treated like ordinary advertising data. Regulators should make clear when this information falls within existing sensitive-data protections and what legal basis is required to process it.
  5. National security review of foreign data access. Advertising exchanges and platforms with foreign ownership, or data flows into adversarial jurisdictions, deserve the same kind of scrutiny applied to other businesses that hold sensitive information about Americans.
  6. A meaningful remedy for unauthorized collection and resale. Where companies collect or sell bidstream data without authorization, individuals need an effective way to seek relief. Regulatory settlements are important, but they should not be the only consequence.

The Practical Test: Can an Organization Implement It?

I have built privacy programs at Fortune 50 scale. That experience has taught me to ask a simple question about any regulatory proposal: can a privacy officer, security leader, and product team translate it into specific work without having to guess what the rule means?

The Rules Must Apply Across the Market

Industry groups will argue that tighter rules will hurt small publishers, limit innovation, and strengthen the large platforms that already operate closed advertising systems. The last concern is legitimate. Rules that apply only to the open web could give Google, Meta, and Amazon another competitive advantage.

The answer is not to leave the open-web system unchanged. It is to apply the same standards to comparable processing wherever it occurs. If a closed advertising platform uses personal data for targeting, it should be subject to the same rules on purpose, minimization, sensitive data, and accountability. Regulation should follow the activity, not the corporate structure.

What This Means for Your Organization

Organizations do not need to wait for a new regulatory framework to begin reducing their risk. If you are a privacy officer, security leader, or general counsel, there are several practical steps you can take now:

The Bottom Line

The EFF is right about the central problem: RTB has created a surveillance system inside the advertising market. The Mobilewalla action shows that regulators can act when bidstream data is collected and repurposed. The next step is to address the design of the market rather than waiting for one company at a time to cross an obvious line.

Purpose limitation, data minimization, sensitive-data protections, supply-chain accountability, and technical enforcement are not new ideas. They are familiar governance tools. Applying them consistently would make behavioral advertising less invasive and create stronger incentives for contextual approaches that require less personal data.

We do not need to invent an entirely new privacy framework for real-time bidding. We need to use the one we already have.