GDPR compliance in digital advertising is not optional. It's not as complex as many publishers fear. The core requirement is consent: users must actively agree to have their data collected and used for advertising purposes.

The challenge is building a consent architecture that is both legally robust and commercially viable. Here's how European publishers can do it.

The consent requirement under GDPR

Article 6 of GDPR requires a legal basis for processing personal data. For advertising, the two relevant bases are:

  • Consent (Art. 6(1)(a)): The user explicitly opts in to advertising data processing
  • Legitimate interest (Art. 6(1)(f)): Processing is necessary for legitimate interests, balanced against user rights

For most advertising use cases, particularly behavioral targeting and audience profiling. Consent is required. Legitimate interest cannot be used as a shortcut for commercial data processing where consent is feasible.

IAB TCF 2.x: The industry standard

The IAB's Transparency and Consent Framework (TCF) version 2.x is the de facto standard for consent management in European advertising. It defines:

  • Purposes: Specific data processing purposes users can consent to (e.g., "Store and/or access information on a device", "Create profiles for personalised advertising")
  • Vendors: Registered advertising technology vendors with specific data processing declarations
  • Signals: Standardized consent strings passed in bid requests

Publishers implementing a CMPs (Consent Management Platform) that is TCF 2.x registered can signal user consent to all downstream advertising partners via standard bid request parameters.

Choosing and configuring your CMP

The IAB maintains a list of registered CMPs. Our publisher partners use primarily Didomi and OneTrust, both offer robust TCF 2.x support with high consent rates (typically 65-80% for well-configured banners in France).

Key configuration principles for maximizing consent rates:

  1. Legitimate interest by default, consent on opt-out: For purposes where legitimate interest applies, configure them as default-on. Users who object can opt out.

  2. Layered consent UI: Use a two-layer UI: a concise first layer summarizing data usage, a detailed second layer for granular controls. CNIL guidance (France) and ICO guidance (UK) provide jurisdiction-specific requirements.

  3. A/B test your consent banner: Consent rate is a commercial metric. Test banner copy, button placement, and color schemes to optimize for both compliance and consent rate.

  4. Refresh consent signals appropriately: Under GDPR, consent must be renewed periodically. Most CMPs handle this automatically.

First-party data: What requires consent?

Not all first-party data requires explicit consent. The key distinction:

  • Technical data (session logs, error tracking, security): Legitimate interest or necessary for contract performance
  • Analytics (page views, scroll depth, aggregate audience metrics): Legitimate interest in most jurisdictions
  • Profile building (declared data, behavioral profiles for advertising targeting): Consent required

For publishers building first-party CRM profiles for advertising purposes, consent is mandatory. However, with a well-configured CMP, 65-80% of readers will consent, providing a substantial addressable first-party audience.

Data governance: the operational layer

Compliance doesn't end with consent. Publishers must implement:

  • Data minimization: Collect only what you need for declared purposes
  • Retention limits: Delete or anonymize data after the retention period (typically 13 months for analytics, 6 months for behavioral profiles)
  • Data subject rights: Implement processes for access, rectification, erasure, and portability requests
  • Vendor contracts: Ensure all advertising technology vendors are under DPA (Data Processing Agreement)
  • Breach notification: 72-hour breach notification to supervisory authority (CNIL in France)

Practical checklist for publishers

✓ TCF 2.x registered CMP deployed and configured
✓ Consent banner A/B tested for optimal consent rate
✓ Data processing register (ROPA) maintained
✓ Vendor DPAs in place
✓ Data retention policy implemented
✓ DSR (Data Subject Request) process documented
✓ Privacy policy updated to reflect actual processing
✓ Staff training completed

GDPR compliance is an ongoing operational commitment, not a one-time configuration. Publishers who invest in proper consent infrastructure will be commercially better positioned as the industry shifts to first-party data models.