General Data Protection Regulation (GDPR)
The EU's data-protection law. It governs how personal data — including the cookie IDs and device IDs ad tech runs on — may be collected and used.
The General Data Protection Regulation (Regulation (EU) 2016/679) sets the rules for processing personal data about people in the European Union. It was adopted on 27 April 2016 and has applied since 25 May 2018.
Why it matters in advertising. The regulation names online identifiers — including IP addresses and cookie identifiers — as information that can identify a person. Ad targeting, measurement and frequency capping all run on identifiers like these, so they fall under the GDPR's rules on when and how personal data may be processed, including its conditions for consent.
The industry's consent standard. IAB Europe's Transparency & Consent Framework (TCF) is, in its own words, "an accountability tool that relies on standardisation to facilitate compliance with certain provisions of the ePrivacy Directive and the GDPR". It gives publishers and their advertising technology partners a common way to present choices to users and pass them along. Its current version responds to an action plan validated by Belgium's data-protection authority.
Penalties. For the most serious infringements — including breaches of the conditions for consent — fines can reach €20 million or 4% of a company's total worldwide annual turnover, whichever is higher.
Key dates
GDPR adopted
In ATDb
Sources
Written with AI assistance from the sources below and reviewed on . Spot an error? How we check facts.
- Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex
- Data protection — European Commission
- Transparency & Consent Framework — IAB Europe