In the past couple of years, the pandemic has brought a lot of drastic changes to the ad tech market and the majority of them revolved around data privacy and security. Popular browser developers (Chrome and, earlier, Safari) announced cookies shut down, Apple announced IDFA restriction, and, finally, GDPR and CCPA established new privacy regulations across entire continents. These changes will affect websites, mobile applications, targeting on advertising platforms – in fact, they will affect the entire digital environment where user data is involved.
For many participants in the advertising market, especially SMBs, these new changes can be devastating unless they suit their technologies to the new requirements. Let’s start with the basics to understand what will change for the major ad tech players and see how to prepare if you run a platform like an ad exchange.
The world moves towards privacy and data security
The stories related to user data leakages and misuse are never-ending. Even such advertising giants like Facebook and Google, with the best professionals onboard, are seemingly failing to protect data from breaches and notify users in a timely manner. Systematic sharing, reselling the data to a third party without user consent (Cambridge Analytica case, China ‘spy chip’ scandal) also illustrated how little power users had over their data during the last decade. Without a robust legal framework for data protection and collection, these issues grew at an exponential rate; thus, it was only a matter of time before the world realized that things needed to change.
Why this is important for your advertising business
According to data protection regulations, your technology needs to fully correspond to the established data privacy and data security standards. For instance, if you process the data of European citizens (no matter where your business is located), you are obliged to provide them with all necessary consent-giving and withdrawing mechanisms. As well, you are in charge of user data protection and security, so all technical and organizational security measures in place must be compliant with GDPR. If you work with the personal data of Californians, you’ll also have to prepare technology according to the measures and mechanisms described by CCPA.
Meanwhile, the shutdown of cookies and IDFA restrictions are something that will change the targeting, attribution and measurement for all advertising businesses in the coming years. These initiatives aim to protect the fundamental privacy rights of users; however, without those mechanisms, all ad businesses (ad exchanges in particular) will have to redefine their approach to targeting and build better data strategies wrapped around first-party data.
New privacy-friendly targeting and attribution mechanisms to look for
To this moment, the ad tech industry has developed several alternatives to IDFA and cookies. Some of them are still being developed and polished, since there are a lot of aspects that need to be improved to provide the desired level of targeting and measurement precision. What characterizes them all is that now there will be no identification of the particular user; instead, this will be possible on the cohort and segmentation level.
- Floc. According to Google, Floc technology provides at least 95% of conversions. This means that using FLOC will allow you to achieve up to 95% of the results that third-party cookies used to provide. This alternative is based on machine learning algorithms, and its key feature is that it does not identify users for targeting but automatically distributes them into cohorts.
- SKAdNetwork. As a replacement for IDFA, Apple introduced a privacy-centered SKAdNetwork. The principle of this operation is similar – you cannot drill down on reports at the user level; rather, analytics and targeting are built around user groups. Thus, impressions, clicks or installs are measured on an aggregated level.
- Fingerprinting. This is a long-known method of obtaining a device identifier (for mobile) or a browser (for computers). It relies on various indirect clues: IP addresses, operating systems, installed extensions/plugins, screen resolutions, color depth and so on. Having processed such an array of features, you can collect a unique identifier that will be different for every user.
Many things will depend on technology giants, like Google or Apple (and the tracking technologies they allow in their browsers and devices). At this point, ad platforms and ad exchange owners should focus their efforts on finding unified solutions for privacy-friendly user identification. Recently, IAB created a DigiTrust ID Working Group (that includes many renowned ad tech companies), which is a good example of an initiative that moves towards unified ID and replaces a multitude of proprietary tracking mechanisms.
How to adjust your ad exchange to the new requirements?
In this race to privacy and data security, advertising platforms that have to transform all their technological processes will, unfortunately, face substantial expenses. After GDPR came into action, much advertising ended up under scrutiny, because budgets didn’t allow system customization according to the requirements posed by regulations. As a result, certain market players had to shut down entire business branches altogether, as it was economically justified. The others (who could afford technology adjustments) also started collaborating with direct publishers as a way to connect to the data source (which is now in great scarcity).
Transitioning to privacy-friendly technologies is not easy and it takes time; however, it’s perfectly doable if you have the resources. There are several things you should keep in mind in case you are running your own advertising business like ad exchange:
- Justify the amount of user data you collect and process, regularly revising and erasing it according to regulations. For this, you’ll have to invite an expert who will audit the technology and assess the scope of necessary preparations.
- Together with a privacy expert and assigned in-house specialist, develop the roadmap of preparation, including the technical and organizational measures for making your ad exchange compliant.
- Audit all your partners and connections, making sure they are compliant, too (as it is also necessary according to GDPR).
- Reduce damage from data theft by implementing end-to-end encryption. If you use frameworks, e.g., NIST or CIS, then your security preparation should be at a high level.
Meanwhile, implementing consent management mechanisms is also a must; however, in this case, it rather appeals to publishers, since they are defined as controllers of information. If you have an ad exchange to operate, it means you act as an information processor, and, thus, you have to implement all of the measures required from data processors.
How white-label helps to overcome these challenges
For a while now, white-label technologies have been known in the ad tech market. In simple words, it is a business model that enables companies to “borrow” the technological platforms from ad tech providers and label those with their own brand. More so, these technological providers oftentimes assist the newly-created ad tech businesses and share with them their own expertise and ad ops (based on the outstaffed model). This approach is especially beneficial for businesses that have only just started their path in ad tech and need additional support. The main purpose of such solutions is to give a new business a chance to enter a programmatic niche and capitalize on a new ad tech platform as soon as possible and with minimum investments (installation is way more affordable since the core is already pre-built).
However, everything doesn’t just boil down to money-saving. White-label technologies can facilitate the adaptation and transition to privacy-friendly standards. For example, in Smart-hub.io, ad request parameters must pass consent verification in accordance with IAB GDPR transparency and consent framework. This way, businesses can operate in a compliant way under the GDPR by providing a standard format to collect and communicate user consent signals to process their personal information. With this, the owner of the platform and integrated partners have to be registered as processor vendors in TCF 2.0. global vendor list (the registration process is standard). Hourly, the system verifies the vendor’s permissions to disclose user data based on user consent. The platform hides personal data in case the user didn’t provide consent and DSPs won’t bid on such requests. Requests can also be automatically dropped by the platform if the owner enables the TCF in the checkbox (inside of the platform settings when configuring endpoints).
This way, white-label platforms make it possible to create marketplaces that are privacy-compliant by design. However, it is their responsibility to ensure that all integrated vendors are also compliant.
To wrap it up
User data is the main asset that drives every advertising business forward, enabling appropriate targeting, attribution and campaign measurement. Still, because of recurring data misuse and leakages, the world has realized that privacy should be protected better; that’s why, in the upcoming year, we will see fundamental changes in the advertising market. For ad platform owners, it is a turbulent time; however, those businesses that manage to adapt will gain a competitive advantage, as they will differentiate their service through transparency and privacy. By investing in white-label technologies, like ad exchanges, many entrepreneurs can save effort as these systems have enough leverage to make media trading privacy-compliant.

