Home Privacy Google Is Accused Of Leaking Data Through A GDPR Workaround – But What’s Really Going On Here?

Google Is Accused Of Leaking Data Through A GDPR Workaround – But What’s Really Going On Here?

SHARE:

By Allison Schiff and James Hercher

Are Google’s cookie syncing capabilities a violation of consumer privacy or are they common industry practice? The answer to both could be “yes.”

This new data debate, which fired up the ad tech industry, was sparked Wednesday when ad browser Brave’s chief policy officer, Johnny Ryan, asserted that Google’s consent data architecture could allow partners to sync cookies with unauthorized third-party companies.

The question is whether these claims are a big deal or a big nothing burger.

For one, OpenX was the only company that’s been documented actually using Cookie Match Assist – the Google Open Bidding feature that allows partners to match their cookies with Google’s advertising ID – to sync with other vendors, said MetaX Chief Data Officer Zach Edwards, who conducted the research on behalf of Brave.

Edwards claims that OpenX’s behavior is not standard operating procedure and is enabled by a loophole in Google’s Cookie Match Assist program. Specifically, that Google doesn’t audit how their partners build redirect URLs.

But, according to some industry pundits, the process being described is nothing more than run of the mill cookie matching.

So, what’s going on? 

Brave describes how Google is creating iframe pages – what it calls “Push Pages” – that fire within a web browser that isn’t visible to the user, so that partners can sync cookies with consent data.

After analyzing Chrome browsing data from more than 100 volunteers over a number of hours, Edwards identified 199 Google partners able to fire on the hidden iframe pages. These partners could then use data for advertising in Google’s GDPR compliance program.

But using iframes for cookie matching isn’t new. Google doesn’t hide the fact that its partners can cookie match or sync across sites based on a user’s browsing, and Google prohibits activities like data harvesting.

Ryan, however, argues that just because something is considered to be a standard practice, and just because Google has documented restrictions around it, “doesn’t mean it’s legitimate.”

So though the report, commissioned by Brave, doesn’t necessarily point to newly-discovered malfeasance, it does surface a pertinent question that hasn’t been answered yet, which is whether cookie matching, and real-time bidding for that matter, is compatible with GDPR or not.

But there’s one other important distinction. According to Google, cookie matching is a process that only happens between itself and one additional party. The accusation is that cookies matches actually facilitated between multiple companies which are then able to cross match between themselves.

What’s the actual problem?

In this way, Edwards’ research appears to show that Google’s system is vulnerable to abuse, because it allows partners to create their own URL redirects within the iframe – a box-within-a-box scenario worthy of an “Inception” sequel.

The iframe pages don’t pass a cookie, but rather the time and location of when the page loads. Since it fires at the same time as the normal site page, it can cross reference consent collected by a publisher with an ad partner’s data.

Although the URLs all start with the same parameter (cookie_push.html), they’re each appended with a string of around 2,000 additional characters which transforms them, in essence, into unique identifiers.

OpenX has been creating URL redirects within the iframe to call on its own data partners after it matched with Google, thus connecting the identity match with partners that otherwise wouldn’t sync with Google’s consent data, Edwards said. The impact is hard to quantify, but it would likely help OpenX win a higher percentage of bids on Google inventory.

Edwards published a series of videos on Wednesday that claim to demonstrate this leakage in action, using OpenX as the example.

Possible fallout

Under GDPR, companies are required to safeguard personal data, conduct audits of their data flow and ensure that their partners are also treating data in the proper way.

“But Google loses control over its pages when other parties like OpenX can create their own,” Ryan said. “These pages in themselves are vulnerable.”

And then there’s also the question of pseudonymous data, which is data that’s been hashed, encrypted or anonymized. Pseudonymous data is considered personal and therefore protected under GDPR if it can be re-identified with a reasonable amount of effort.

As part of the matching process, the cookie_push.html URLs associated with Google’s iframe syncing are distinguished by several thousand characters added to the end. The combination of cookies supplied by Google could allow companies to create pseudonymous identifiers that wouldn’t have existed otherwise, which would be a GDPR infraction.

Regardless, push pages aren’t the main attraction, Ryan said. In his view, they’re just one example of “a loss of control over personal data that happens in the RTB system in general.”

“There is a collective delusion among ad tech companies that the law can be read in other ways,” Ryan said. “That delusion is being gradually dispelled.”

Helping to clear the air is the ongoing statutory investigation being conducted by the Irish Data Protection Commission, Google’s lead regulatory authority in Europe, digging into Google’s ad exchange and data-processing practices. Google, a company spokesperson told AdExchanger, welcomes the scrutiny and is cooperating with it “in full.”

“We do not serve personalized ads or send bid requests to bidders without user consent,” the spokesperson said.

Must Read

TV Manufacturer Telly Touts Programmatic Home Screen Ads

Telly, the startup that gives away free smart TVs in exchange for data and ad exposure, is making its home screen ads available for brands to buy programmatically – and pushing for industry standards to help attract more spend. 

AI Is Helping L’Oréal Brainstorm Unique Ways To Reach Male Audiences

L’Oréal adopted creative AI platform Springboards to generate creative ideas that led to a collaborative, ongoing ideation process.

AdExchanger's Big Story podcast with journalistic insights on advertising, marketing and ad tech

Google Had Its Day In Court. Now, It’s Amazon’s Turn

Google won’t have to break up its ads business after being declared an online monopolist. Meanwhile, Amazon faces a lawsuit from the FTC alleging that it charged advertisers more than necessary for ecommerce ads.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

The FTC’s Amazon Lawsuit Is Ad Tech’s History Of Opacity Repeating Itself

Buy-side experts said it’s another example of a Big Tech platform taking advantage of the lack of transparency built into programmatic ad auctions. And they’re not optimistic change is coming.

How The Fin Tech Clearco Finances Ecommerce Startups (Without Losing Its Shirt)

This week, the Commerce Media Newsletter catches up with a startup from outside the world of data-driven advertising, but with an interesting position when it comes to ecommerce advertising. That’s Clearco, a Canadian fin tech company founded in 2015.

LOS ANGELES, CALIFORNIA - APRIL 26: Halo Collar CMO Seth Solomons attends a Celebration to Shine a Light On Dog Safety With Halo Collar on April 26, 2022 in Los Angeles, California. (Photo by Stefanie Keenan/Getty Images for Halo Collar)

How Halo Collar Uses Data And Incrementality To Raise Both Awareness And Sales

Halo Collar, a dog collar brand with direct-to-consumer origins, is preparing for its retail expansion by honing its first-party data strategy and incrementality measurement.