Privacy Compliance in Ad Tech: GDPR, CCPA, and Consent Management Explained

Privacy law used to be something only the legal department worried about. Today it directly affects your fill rate, your CPMs, your targeting options, and the size of the audience you can actually reach. If you buy or sell traffic programmatically, understanding how consent flows through the supply chain is no longer optional. In this post we'll explain what GDPR and CCPA actually require, how consent signals travel through an RTB auction, and what advertisers and publishers should each be doing about it.

A note before we start: this is a practical overview, not legal advice. Regulations vary by jurisdiction and change over time — consult a qualified attorney for guidance on your specific situation.

Why Privacy Regulation Reached Ad Tech First

Programmatic advertising runs on data. A bid request typically carries an IP address, a device or browser identifier, a user agent string, the page being viewed, and often location and interest signals. Under most modern privacy frameworks, much of that qualifies as personal data — information that can identify a person directly or in combination with other data.

That's why ad tech sits at the center of privacy enforcement. Every impression involves a handful of companies receiving data about a user, usually within milliseconds and usually without the user consciously thinking about it. Regulators have focused on making that flow visible and controllable.

GDPR: The European Standard

The General Data Protection Regulation (GDPR) applies to the personal data of people in the European Economic Area, regardless of where the company processing it is based. A few concepts matter most for advertising:

Lawful basis. You can't process personal data just because it's useful. You need a legal justification — most commonly consent for advertising purposes, or legitimate interest in narrower cases like fraud prevention.

Consent must be freely given and specific. A pre-ticked box or a banner that only offers "Accept" is not valid consent. Users need a genuine choice, and rejecting should be as easy as accepting.

Purpose limitation. Data collected for one stated purpose can't quietly be reused for another.

User rights. Individuals can request access to their data, ask for deletion, and withdraw consent at any time — and withdrawal has to be as easy as granting.

Controllers and processors. Whoever decides why and how data is processed is the controller and carries primary responsibility. In programmatic, multiple parties can be joint controllers, which is why contracts between publishers, networks, and advertisers matter.

CCPA/CPRA: The California Approach

California's Consumer Privacy Act, expanded by the Privacy Rights Act, takes a different shape. Instead of requiring opt-in consent before collection, it gives residents the right to opt out of the "sale" or "sharing" of their personal information — and that definition of sharing explicitly covers cross-context behavioral advertising.

Practically, this means a business in scope needs a clear "Do Not Sell or Share My Personal Information" mechanism, must honor opt-out signals, and must disclose what categories of data it collects and who receives them. Several other U.S. states have since passed laws following broadly similar opt-out models, which is why most publishers now implement a framework that handles multiple states at once rather than building one-off solutions.

The key mental model: GDPR is opt-in, CCPA is opt-out. A compliant setup has to handle both, because your traffic doesn't arrive sorted by jurisdiction.

This is the part most people find confusing. A consent choice made on a publisher's site has to reach every downstream partner, and it does that through standardized signals attached to the bid request.

The IAB's Transparency and Consent Framework (TCF) is the dominant mechanism in Europe. When a user interacts with a consent banner, the consent management platform generates an encoded TC string that records which purposes were consented to and which vendors were approved. That string is passed into the ad request and forwarded through the supply chain, so each platform can check whether it has permission to process data for a given purpose.

In the U.S., the equivalent role is played by Global Privacy Platform (GPP) strings and, historically, the simpler US Privacy string. Some browsers and extensions also emit a Global Privacy Control (GPC) signal, which several state laws treat as a valid opt-out request.

If those signals are missing or malformed, well-behaved buyers will typically bid lower or not bid at all — because they can't verify they're allowed to use the data. This is a real revenue issue, not just a legal one: broken consent plumbing looks identical to low-value traffic from the buy side.

What Publishers Should Do

Deploy a proper consent management platform (CMP). Choose one that supports both TCF and U.S. frameworks, and register it correctly. A homemade cookie banner that doesn't emit standardized signals gives you the compliance overhead without the revenue benefit.

Geo-detect and serve the right experience. European visitors need an opt-in flow; U.S. visitors generally need an accessible opt-out. Our post on geographic targeting strategies covers the same detection logic you'll use here.

Test that the signal actually reaches your ad calls. Load your own site, make a consent choice, and inspect the outgoing ad request to confirm the string is present. Missing consent strings are one of the quieter causes of unexplained CPM drops.

Keep your supply chain documented. Well-maintained ads.txt and sellers.json files sit alongside privacy compliance as part of the same trust story buyers evaluate.

Have a fallback for non-consented traffic. Users who decline shouldn't mean zero revenue. Contextual and non-personalized ads still monetize — see our guide to contextual targeting.

What Advertisers Should Do

Understand what your targeting depends on. Behavioral targeting and retargeting rely on identifiers that require consent in some regions. Contextual, geographic, device, and domain targeting generally don't. Knowing which of your tactics are consent-dependent tells you where your reach will shrink.

Diversify beyond identifier-based tactics. Our guide to cookieless advertising walks through approaches that hold up as identifiers become less available.

Audit your own tracking. Your landing pages, pixels, and analytics tools are your responsibility, not your ad network's. If you're running server-to-server tracking, review our postback conversion tracking guide — S2S setups often reduce reliance on browser-side identifiers.

Work with transparent partners. Ask your networks how they handle consent signals, where data is stored, and what contractual terms apply. Vague answers are a warning sign.

The framing that helps most: privacy compliance isn't a tax on your advertising business, it's part of the infrastructure. Clean consent signals mean buyers bid confidently on your inventory. Documented data practices mean advertisers trust your traffic. Diversified targeting means your campaigns keep performing as identifiers erode. The publishers and advertisers who treat this as plumbing to maintain — rather than a banner to bolt on — consistently end up with steadier revenue and fewer unpleasant surprises.

Conclusion

GDPR requires opt-in consent, CCPA and its successors require accessible opt-outs, and both depend on standardized signals traveling correctly through the bid stream. Publishers need a real CMP and a plan for non-consented traffic; advertisers need to know which targeting tactics depend on consent and to build alternatives that don't. Getting this right protects you legally and keeps your inventory and campaigns competitive.

Squren operates a transparent RTB platform with clear reporting, fraud filtering, and a targeting toolkit that works across consented and non-consented traffic alike. Sign up at Squren.com as an advertiser or publisher, or reach out to our 24/7 support team with questions about how we handle data in the supply chain.