Home Data-Driven Thinking GDPR: The Death Knell For Programmatic Advertising?

GDPR: The Death Knell For Programmatic Advertising?

SHARE:

Data-Driven Thinking” is written by members of the media community and contains fresh ideas on the digital revolution in media.

Today’s column is written by Mark Roy, founder and chairman at REaD Group.

In a little under a year, the EU General Data Protection Regulation (GDPR) will come into force, and for programmatic advertisers, it foretells an end to the concept of automating relationship building.

The GDPR has been developed to directly address customers’ concerns about the safety of their personal data. Like it or not, anyone in possession of customer data will need to be compliant by next May, when the regulation comes into effect. GDPR contains strict new rules around individual data, including customer consent and their “right to be forgotten.” GDPR will be unforgiving to those who fail to comply; organizations will face astronomical fines of 20 million euros ($24 million) or 4% of annual global turnover, whichever is greater.

I cannot see how programmatic can ever be GDPR-compliant unless it is limited to a small number of organizations, rather like a prospect pool. The GDPR will require advertisers to obtain active consent from customers, which will involve them specifically opting in to, rather than out of, a deal.

While some organizations may be able to circumvent this by limiting premium services to those who opt in for data collection, such as customers agreeing to the collection of cookies, obtaining consent for programmatic advertising is going to cause a real headache. As of next May, if advertisers have not obtained specific consent from individuals, they cannot market to them in any shape or form. 

The “right to be forgotten” rule, in which an individual can have their historic data removed from a database, will leave the programmatic industry with a significant conundrum. In order to be “forgotten,” we must be able to know what needs to be forgotten. Every click, path, transaction, request or click-through must be recorded and be deletable. Therefore, by putting data assets into the ether and allowing thousands of organizations to use it, it is nigh on impossible to comply with the GDPR.

GDPR Doesn’t Just Apply To The EU

The EU’s new privacy rules are likely to disrupt the global digital marketing scene by preventing companies from using an EU citizen’s data unless they have obtained their direct consent. This will apply to the data of every EU citizen, regardless of where in the world their data is being used or stored. This means that US companies, such as Facebook and Google, which no doubt possess a large amount of EU citizen data, will have to pay attention to the regulation across the pond and take the same steps as everyone else to become compliant.

The target in the crosshairs of the EU rifle has always been and will be the US tech behemoths. When I first engaged with the EU on this years ago and was talking to legislators in Brussels, it was shortly after Mark Zuckerberg had decided that all those pictures, stories and photos on Facebook belonged to the company and not the millions of EU citizens who had posted them. Legislators were apoplectic, but even more determined to tackle the issue head-on.

What Does The Future Hold For Advertisers?

Subscribe

AdExchanger Daily

Get our editors’ roundup delivered to your inbox every weekday.

Overall, it is clear that every organization in possession of customer data will be affected by the GDPR. The programmatic advertising sector will feel the regulation the most due to the data requirements it needs for targeting. The GDPR is likely to shift advertising away from the algorithmic models of communicating, back toward a simpler form of advertising, relying on less volume and better-quality data.

I predict programmatic technology will be used in a far more limited way and largely in a retention and customer management environment, and there will be a return to a more personal touch in advertising facilitated by human beings rather than machines.

GDPR will herald a new era of greater trust between organizations and customers still willing to share personal data to access tailored services. Organizations need to clearly explain to customers how their data will be used and how they can expect to benefit from it.

Follow REaD Group (@REaD Group) and AdExchanger (@adexchanger) on Twitter.

Must Read

The Big Story: Live From CES 2026

Agents, streamers and robots, oh my! Live from the C-Space campus at the Aria Casino in Las Vegas, our team breaks down the most interesting ad tech trends we saw at CES this year.

Monopoly Man looks on at the DOJ vs. Google ad tech antitrust trial (comic).

2025: The Year Google Lost In Court And Won Anyway

From afar, it looks like Google had a rough year in antitrust court. But zoom in a bit and it becomes clear that the past year went about as well as Google could have hoped for.

Why 2025 Marked The End Of The Data Clean Room Era

A few years ago, “data clean rooms” were all the ad tech trades could talk about. Fast-forward to 2026, and maybe advertisers don’t need to know what a data clean room is after all.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

The AI Search Reckoning Is Dismantling Open Web Traffic – And Publishers May Never Recover

Publishers have been losing 20%, 30% and in some cases even as much as 90% of their traffic and revenue over the past year due to the rise of zero-click AI search.

No Waiting for May – CES Is Where The TV Upfront Season Starts 

If any single event can be considered the jumping-off point for TV upfronts, it’s the Consumer Electronics Showcase (CES), which kicks off this week in Las Vegas, Nevada.

Comic: This Is Our Year

Comic: This Is Our Year

It’s been 15 years since this comic first ran in January 2011, and there’s something both quaint and timeless about it. Here’s to more (and more) transparency in 2026, and happy New Year!