{"id":15147,"date":"2019-07-12T09:57:23","date_gmt":"2019-07-12T07:57:23","guid":{"rendered":"https:\/\/yieldbird.com\/?p=15147"},"modified":"2024-07-22T19:27:14","modified_gmt":"2024-07-22T17:27:14","slug":"one-year-after-gdpr","status":"publish","type":"post","link":"https:\/\/yieldbird.com\/research-hub\/one-year-after-gdpr\/","title":{"rendered":"One Year After GDPR \u2013 What Have We Learned?"},"content":{"rendered":"\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">May 25, 2018, is one of this century&#8217;s most important and controversial dates for online advertising \u2014 it was the day when the General Data-Protection Regulation (GDPR) went into effect in the European Union. When the law was adopted in 2016, many did not realize it\u2019s full scope and repercussions.<br><\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide\" style=\"grid-template-columns:35% auto\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/yieldbird.com\/wp-content\/uploads\/2019\/07\/0143-GDPR-03-1024x640.png\" alt=\"\" class=\"wp-image-15152\" srcset=\"https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/0143-GDPR-03-1024x640.png 1024w, https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/0143-GDPR-03-300x188.png 300w, https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/0143-GDPR-03-150x94.png 150w, https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/0143-GDPR-03-768x480.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\"><br>The GDPR replaced the 1995 Data-Protection Directive which was founded when the internet was in its infancy. Both initiatives intended to strengthen data protection for individual citizens within the EU but the new regulation generated many more doubts and apprehensions due to the vast level of changes and limitations.<\/p>\n<\/div><\/div>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\"> In 2019 to process any personal data, you must comply with the GDPR. This means that you need to base the processing on one of the lawful grounds laid out in the regulation. Without lawful grounds, it is illegal to process personal data. High penalties are possible for those who do not obey the new requirements (e.g. consent from every user to use his data). <\/p>\n\n\n\n<h2 style=\"font-size: 20px;\"><strong>Different strategies of publishers<\/strong> <\/h2>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\"><br>Considering that specifics of GDPR implementation were still not clear weeks before it came to life, publishers started looking for the low hanging fruits. Legitimate interest is the most common for publishers in Europe. It may be used when businesses identify a compelling justification for using personal information, including commercial interests, which cannot be achieved without processing data and will have a minimal impact on privacy.<\/p>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">\u201c<em>Some publishers feel there is an argument for legitimate interest because they need revenue to create and distribute free content for their audiences and they can only make that revenue through advertising, which requires the processing of personal data<\/em>.\u201d<br><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" style=\"color:crimson\" href=\"https:\/\/www.pubexec.com\/post\/legitimate-interest-vs-publisher-consent-two-routes-to-gdpr-compliance\/\" target=\"_blank\"><strong>Pubexec.com<\/strong><\/a><\/p>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">As a result of the mentioned uncertainties, many publishers decided to apply legitimate interest as a legal basis for the handling of personal data. But there were also many who have chosen a fully compliant way and applied very specific consent boxes. As a result in some of the second scenario cases, they have lost a great amount of ad traffic and thus revenue. One of the publishers, who have been in contact with us, lost up to 40% of its ad requests on May 25, when he launched his pop-up <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" style=\"color:crimson\" href=\"https:\/\/yieldbird.com\/consent-management-platform\/\" target=\"_blank\"><strong>consent box.<\/strong><\/a> <\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide has-media-on-the-right\" style=\"grid-template-columns:auto 33%\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/yieldbird.com\/wp-content\/uploads\/2019\/07\/0143-GDPR-05-1024x640.png\" alt=\"\" class=\"wp-image-15156\" srcset=\"https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/0143-GDPR-05-1024x640.png 1024w, https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/0143-GDPR-05-300x188.png 300w, https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/0143-GDPR-05-150x94.png 150w, https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/0143-GDPR-05-768x480.png 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">\n\nThis new requirement has been a challenge for many companies, as data privacy is a major concern of the public. However, several publishers with whom we have been working faced only a few days of declined revenues after the launch of the GDPR. It has been mostly due to the advertisers&#8217; strategy. They have decided to limit the spending to let the first wave of confusion pass.\n\n<\/p>\n<\/div><\/div>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">In recent years, we have become accustomed to closing pop-ups on the sites we have visited, but these should not be associated with GDPR-consent boxes. The EU has demands on how a consent box should look. Above all, the user must approve each of all third-party services with whom the publisher shares his data, and these entities must not be pre-selected. But you don&#8217;t see many of 100% compliant pop-ups yet in the EU. What is more interesting \u2013 the United States has taken the regulation a bit more seriously. US companies have implemented compliant pop-ups for visitors from the EU, using their IP addresses to determine who to show the consent box. <\/p>\n\n\n\n<h3 class=\"wp-block-heading\" style=\"text-align:center\" id=\"mce_0\"><br><strong>Do you like what you&#8217;re reading? Subscribe our newsletter for more content like this!<\/strong><\/h3>\n\n\n<p>[mc4wp_form id=&#8221;407&#8243;]<\/p>\n\n\n\n<h2 style=\"font-size: 20px;\"><br><strong>Third-party data future<\/strong><\/h2>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\"><br>Another big issue tackled by the GDPR is the usage of third-party data, which means selling and buying for audiences, for example, users interested in sports. In the past, the agency\/advertiser used a third-party provider, often bundled into the demand-side platform, that provided the third-party segments. Third-party data, in general, has become less and less popular, especially after the Cambridge Analytica incident. However, I believe that the scale of the third-party data negative publicity is a little overrated.<br><\/p>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">Nevertheless, as the effect of those changes, some providers of third-party data have closed their businesses in Europe. One of them is Addthis. The company owned by Oracle, who acquired it two years ago for around 200M USD. At that time, AddThis claimed that it tracked 1.9 billion users. The third-party audience service relied on the third-party data collected without consent.<\/p>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">\u201c<em>European publishers could still access AddThis tools for free, but not with data originating from Europe.<\/em>\u201d <br><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" style=\"color:crimson\" href=\"https:\/\/adexchanger.com\/privacy\/oracle-data-cloud-kills-off-its-addthis-audience-business-in-europe\/\" target=\"_blank\"><strong>The VP of Product Management, Cecilia Mao for AdExchanger.<\/strong><\/a><\/p>\n\n\n\n<h2 style=\"font-size: 20px;\"><strong>Will first- and second-party data be a lifesaver for publishers?<\/strong><\/h2>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\"><br>First-party is a kind of data that the publisher has gathered about his clients\/users. This information may be a new holy grail in light of the GDPR, also because many publishers around the world are switching to a paid-content strategy. This strategy also aligns very well with selling advertising based on the first-party data. When you get logged-in users who also approve of using the data, you get the consent much easier, even for a little wider use of data.<\/p>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\"> Publishers can also cross-identify segmented users against offline data sources which are called Second-party data. They can thus create interesting and relevant target groups to whom they may sell for higher prices, due to their unique and precise recognition. <\/p>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">Different countries have different access to offline data sources. For example, in Nordic countries, there are about 300 data points on every individual, and with an ID number or an address, these offline data points can be linked to the logged-in user. Then, the publisher can start selling qualitative ads for segments such as families with villas, sport car owners, etc. The limitation is the number of logged-in users, which is low among a few publishers. Some publishers have increased their login strategy since the implementation of the GDPR and the results are promising.<br><\/p>\n\n\n\n<h2 style=\"font-size: 20px;\"><strong>The login collectives<\/strong><\/h2>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\"><br>From a first- and second-party data perspective, it\u2019s very exciting to look at the issues which the Germans are discussing. In light of the GDPR and the upcoming ePrivacy Directive, they suggest a login collective.<br><\/p>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">\u201c<em>The favored approach is login collectives made up of major publishing groups and non-publisher partners. The reason: one publisher\u2019s single login strategy doesn\u2019t likely have the necessary scale to rival the login platforms of Google, Facebook, and Amazon. However, a combined login structure that spans multiple publishers, IP firms, and other e-commerce brands potentially could<\/em>.\u201d  <br><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" style=\"color:crimson\" href=\"https:\/\/digiday.com\/media\/eprivacy-looming-german-publishers-scramble-get-users-logged\/\" target=\"_blank\"><strong>Digiday<\/strong><\/a> <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/yieldbird.com\/wp-content\/uploads\/2019\/07\/GDPR-WYKRES-1024x871.png\" alt=\"\" class=\"wp-image-15154\" width=\"402\" height=\"341\" srcset=\"https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/GDPR-WYKRES-1024x871.png 1024w, https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/GDPR-WYKRES-300x255.png 300w, https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/GDPR-WYKRES-150x128.png 150w, https:\/\/yieldbird.com\/research-hub\/wp-content\/uploads\/2019\/07\/GDPR-WYKRES-768x653.png 768w\" sizes=\"auto, (max-width: 402px) 100vw, 402px\" \/><\/figure><\/div>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">This is a concept. For the individual publisher, this means the number of identified users on his site may increase significantly if the visitor has already logged in to one of the other sites in the collective. In this strategy, the volume of identified users may increase to a sufficiently large base. This also clearly places demands on how to design a technical solution so that it is legal under the GDPR.<\/p>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">It is obvious that the large walled-garden companies, Google and Facebook, have gained competitive advantages at the expense of European publishers. Both companies have relationships with their visitors and can thereby get a legal basis for processing personal data from their visitors much easier, it\u2019s possible that the local alliances will change the odds but today it\u2019s to soon to tell.<br><\/p>\n\n\n\n<h2 style=\"font-size: 20px;\"><strong>ePrivacy on the horizon <\/strong><\/h2>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\"><br>\u201c<em>53 percent of the respondents claimed they estimate the changes they\u2019d have to make for the ePrivacy Regulation compliance would cost their annual sales to the tank by at least 30 percent. An even higher percentage \u2014 67 percent of publishers said they\u2019d expect to lose more than 30 percent of sales on all programmatic advertising that uses retargeting, according to the same research.<\/em>\u201d   <br><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" style=\"color:crimson\" href=\"https:\/\/digiday.com\/media\/eprivacy-looming-german-publishers-scramble-get-users-logged\/\" target=\"_blank\"><strong>Digiday<\/strong><\/a> <\/p>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\">The GDPR has surely led to a revival in the contextual advertising trend. At the beginning of digital advertising, this type of targeting was widely popular. At that time, the article was manually tagged by the writers but today site analysis is performed by external technologies, which, with the help of bots, crawl the pages and segment its content. Thanks to this method, new user packages can be created and the publisher can continue with GDPR-safe targeting. Unfortunately, contextual campaigns are usually relevantly cheaper.<br><\/p>\n\n\n\n<h2 style=\"font-size: 20px;\"><strong>It\u2019s just getting started<\/strong><\/h2>\n\n\n\n<p class=\"has-text-color has-normal-font-size has-very-dark-gray-color wp-block-paragraph\"><br>The idea and purpose of the GDPR are surely positive. Now we are in a period before the market stabilizes and finds a good and steady path. In the future, it will be particularly interesting to follow the local data inspections applying the GDPR like ICO from the United Kingdom. After some analysis and consideration, they are pointing out issues with Ad Tech industry compliance, which publishers and advertisers will need to take care of soon if they want to avoid penalties.<\/p>\n\n\n\n\n<p>[simple-author-box]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>May 25, 2018, is one of this century&#8217;s most important and controversial dates for online advertising \u2014 it was the day when the General Data-Protection Regulation (GDPR) went into effect in the European Union. When the law was adopted in 2016, many did not realize it\u2019s full scope and repercussions. The GDPR replaced the 1995 [&hellip;]<\/p>\n","protected":false},"author":16,"featured_media":15153,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[28],"tags":[],"content-category":[],"class_list":["post-15147","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ad-tech"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/posts\/15147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/comments?post=15147"}],"version-history":[{"count":1,"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/posts\/15147\/revisions"}],"predecessor-version":[{"id":33468,"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/posts\/15147\/revisions\/33468"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/media\/15153"}],"wp:attachment":[{"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/media?parent=15147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/categories?post=15147"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/tags?post=15147"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/yieldbird.com\/research-hub\/wp-json\/wp\/v2\/content-category?post=15147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}