The bids were live when the alert hit. A new ruling landed in the EU, and our retargeting had to stop at once. Spend fell. Eyes turned to the dashboard. We did not panic. We leaned on context, cleaned up our consent flow, and turned on modeled conversions. Forty‑eight hours later the line rose again. Not the same mix, but steady. This is what that shift looks like, in clear steps, with the legal rails marked in bold ink.
Let’s say it plain. You cross the line when you track people without a clear, lawful reason; when you trick users into “yes”; when you use data for a new goal they did not expect; or when you target by a sensitive trait. You also cross it if you ignore a “do not sell/share” or Global Privacy Control signal. Good consent must be clear, free, and informed. For a simple, shared base, read the EDPB guidelines on consent. If your program fails that test, stop and fix it before you run another bid.
Here is the good news. A lot still works, and it can work well:
When you use cookies or similar tech, follow your local rules. Two helpful guides: the UK’s ICO guidance on cookies and France’s CNIL guidance on cookies. These are simple to read and map well to day‑to‑day ad ops.
Think of targeting like a set of gears. Each gear needs a lawful basis, the right signals, and a way to measure. Your consent stack should pass a signal string across tools. In the EU, many teams rely on IAB Europe’s TCF v2.2. In the US, a common way to carry user choices is the IAB Tech Lab’s GPP. The table below maps the main options so you can choose fast and stay safe.
| Contextual targeting | Legitimate interests (often) or no personal data | Page/topic taxonomy, query intent, time, device type | Low — avoid linking to a user profile; watch for sensitive topics | On‑site conversions, brand lift, modeled ROAS by taxonomy | Do not infer health, religion, or minors’ interests from context. |
| First‑party audiences | Consent for ads; Contract for service use | CMP string, login ID, hashed email, on‑site events | Medium — consent quality and scope matter; respect opt‑out | Observed + modeled conversions; server‑side tagging | Keep data maps and retention limits; secure transfers. |
| Clean‑room lookalikes | Consent for profiling; DPIA if high risk | Aggregated group traits; no raw IDs | Medium — design for k‑anonymity; no re‑ID | Incrementality or lift tests; geo splits | Vendor DPA and logs are key; document queries run. |
| Topics API (Privacy Sandbox) | Consent where required by region | Browser‑shared topics; no cross‑site IDs | Low to Medium — follow browser rules; explain to users | Modeled conversions; topic‑level CTR and CPA | Limited topic set; avoid sensitive themes. |
| Protected Audiences (on‑site remarketing) | Consent in most regions | On‑device interest groups; event triggers | Medium — scope to same‑site use; document purpose | A/B tests; incrementality vs. contextual | Use for short windows; cap frequency at cohort level. |
| Publisher‑declared cohorts | Legitimate interests or consent, per use | Section, subscription tier, content habits | Low to Medium — avoid sensitive inferences | On‑site goals; cohort lift over baseline | Let users see and change cohort membership if possible. |
| Geo / Time targeting | Legitimate interests (coarse); Consent (precise) | IP to region, time of day, day of week | Low when coarse; High if precise GPS without consent | Compare by region/time cells; MMM support | Avoid precise location for sensitive ads; honor device settings. |
How to use this: start with the tactic. Check if it needs consent in your region. Pass user choices end to end. Log proof. Measure with methods that do not force IDs when you lack them. Most stacks need a CMP, server‑side tagging, and consent‑aware audiences at the core.
Goal: Keep performance for EU visits while staying inside GDPR lines.
Stack: A registered CMP with TCF support, server‑side tagging, Consent Mode, and Sandbox APIs where fit.
How: Use a clean, plain consent UI. Map each tag to the right purpose. Turn on Google Consent Mode v2 documentation so tags react to user choice. For reach, test the Topics API to add light interest signals. For on‑site remarketing without cross‑site IDs, try Protected Audiences for cart or content viewers.
Measure: Use modeled conversions in your analytics. Run an A/B cell with context‑only as a holdout. Track consent rate and bounce from the CMP.
Pitfall to avoid: Retargeting that fires when consent is not given. Build a blocklist for tags by default and allow only after consent.
Goal: Grow iOS app installs and in‑app spend without device IDs.
Stack: ATT prompt design, SKAN set‑up, on‑device signals, contextual inventory, creative testing.
How: Respect Apple’s AppTrackingTransparency. If users say no, do not try to work around it. Use SKAdNetwork for install and post‑install signals. Lean on contextual placements (app genre, content tags) and creative that speaks to the session.
Measure: SKAN postbacks, on‑device events rolled up, MMM or geo tests for top‑line lift.
Pitfall to avoid: Fingerprinting or device hacks. This is high risk and can get your app blocked.
Goal: Use shopper signals and keep trust in states with new rules.
Stack: Consent and opt‑out tools, GPP string pass‑through, clean‑room joins with brands, strict data maps.
How: Capture “do not sell/share” and GPC once and pass it to every partner. Join first‑party sets in a clean room, then build cohorts for on‑site and off‑site reach. Follow state rules and the CPRA regulations for notices and choice.
Measure: Sales lift tests by aisle or region, on‑site conversion by cohort, brand MMM with retail signals.
Pitfall to avoid: Using shopper data for off‑site ads when users opted out of “share.” Build separate pipes and audits.
To stress test your plan, compare it to the NAI Code of Conduct and the US DAA principles. They give clean, simple rules you can map to your day‑to‑day setup.
Gambling sits in a tight box in many markets. The ad rules are strict, and they differ by place. Age gates, clear terms, and jurisdiction blocks are not “nice to have.” They are the cost of entry. Start with platform rules like the Google Ads Gambling and games policy. Then layer local rules. In the UK, see the ASA/CAP guidance on gambling ads. For operators and their partners, check the UKGC LCCP marketing provisions. In the US, the AGA Responsible Marketing Code is a helpful base for sports betting.
How to build a safe plan in this space:
One example: a gambling review publisher that works across markets. The team writes independent operator reviews, gates age‑sensitive pages, and shows clear labels when a link is an affiliate link. They use a CMP for consent and run mostly on contextual signals. Offers do not show in blocked regions. This model keeps trust and keeps the ads inside the rules. For instance, insights from KE-Bet.com analysts show how editorial rankings, license checks, and geo controls can guide users to safe, legal options while staying policy‑aligned.
Walk in with a plan, not a pitch. Keep it short and clear:
It helps to frame your program to known models like the NIST Privacy Framework, and to aim for a mature cert such as ISO/IEC 27701. These give shared language so teams move fast together.
Put these on one page. Review them side by side. When trust and spend both move the right way, you know the system is sound.
Yes, if you do not use personal data. Contextual ads do not need cookies. If you profile or measure a user across sites, you likely need consent. Always explain your methods in your policy and CMP.
For basic first‑party analytics, many teams use legitimate interests with strong rights and easy opt‑outs. For ads or cross‑site tracking, consent is the safer base. Do a DPIA when risk is high.
Read the GPC signal on each page view. Set a flag in your tag manager. Block ad calls that “sell/share” data for those users. Run contextual and on‑site cohorts that do not rely on that data flow.
No. Use SKAN and on‑device signals. Buy context, not IDs. Test creative and placements more. Many teams still hit goals this way.
Clear labels build trust and reduce risk. The FTC Endorsement Guides show how to disclose well. Good sites see no long‑term loss, and you lower legal risk.
Pick one region and one high‑impact surface. Map tags and vendors. Turn on consent‑aware logic. Set guardrails: block by default, allow by choice. Run for two weeks. Track consent rate, modeled vs. observed conversions, and CTR by context. Share results with legal and product. Fix weak spots, then scale to more lines of business.
Good ads do not need to cross lines. When you design for consent first, you gain stable reach that survives the next rule change. You also gain user trust, which raises the floor for every campaign you run. Start small, ship the playbooks above, and keep your logs clean. This is how teams win the long game in ad tech.
Written by a Head of Ad Ops with 10+ years in ad measurement and privacy programs across web and app. Led audits in EU and US; shipped Consent Mode and clean‑room rollouts for global brands. Last reviewed: . Not legal advice — please consult counsel for your region.