GDPR is coming, and data management platforms are in the crosshairs

3 min read
Curated from digiday.com →

Data management platforms play an increasingly important role in helping digital marketers find high-value audiences, largely based on third-party data collection without much transparency. But with the General Data Protection Regulation being enforced in May, DMPs may face a tough battle to obtain third-party data.

DMPs mainly process third-party data through cookies for lookalike targeting, and under the existing laws, consent isn’t necessarily required to use cookies. But the GDPR will change that, as it demands that personal data — including data collected through cookies — can only be used with explicit consent from individuals. That means DMPs will face more legal obligations under the GDPR, and since the GDPR will make it harder for companies to obtain third-party data, DMPs may have to rely more on first-party and second-party data than third-party data, according to ad tech executives and legal counsels.

“There is much more legal work ahead for DMPs, especially between them and their data providers,” said Maciej Zawadzinski, CEO of Poland-headquartered ad tech firm Clearcode. “Third-party data will become less accessible because of GDPR, which is likely to cause DMPs to focus more on first-party and second-party data. But it doesn’t mean that third-party data will become irrelevant, or DMPs will stop relying on it.”

Becky Burr, chief privacy officer for Neustar, believes that GDPR will have a significant impact on DMPs and ad tech companies in general. This is because ad tech companies are known to process data based on inferred consent through opt-out mechanisms, but GDPR makes reliance on individuals’ consent as the lawful basis for processing data, according to Burr. “In addition, enhanced data subject rights in the form of access, correction, erasure, and portability will require more robust consumer-facing portals and may create additional processing overhead [for DMPs] in some situations,” said Burr.

Douglas McPherson, chief legal officer for OpenX, thinks that whether — and how — the GDPR will affect DMP operations boils down to how a company defines its role under the regulation: Is it a “data controller” that “determines the purposes and means of the processing of personal data?” Is it a “data processor” that “processes personal data on behalf of the controller?” Or is it a “data subprocessor” that a data processor engages to conduct further processing in addition to what the data processor is doing? The role determines how and why a company collects personal data, said McPherson. For instance, the data processor can’t engage the subprocessor without informing the data controller.

McPherson believes that while DMPs typically act like data processors, they will also be viewed under the GDPR as data controllers in some cases, like when they collect data from credit card companies, look for users’ purchase patterns, create user profiles and then create data products to sell, for instance.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at digiday.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.