DPDP NavigatorAct 2023 · Rules 2025
All guides
Sector Deep Dives

DPDP Compliance for Ad-Tech and Programmatic Advertising Platforms

20 Jul 202611 min read

Real-time bidding shares a device profile with dozens of parties in milliseconds — a structure that sits uneasily with consent that is supposed to be specific and informed.

The consent chain behind a single ad impression

A programmatic ad impression typically starts with a publisher's consent-management pop-up, but the actual bidding process fans that single consent signal out to a real-time bidding exchange, dozens of demand-side platforms, and their own downstream data partners, all within the time it takes a page to load. Section 6's requirement that consent be specific, informed, and unambiguous sits uneasily with this structure, since a user clicking “accept” on a publisher's banner has no practical way to understand, in the moment, which of the dozens of parties in the bid stream will actually receive their device and behavioural profile.

Consent Managers registered under the framework the Rules describe are meant to give data principals a more legible, centralised way to grant and track consent across such multi-party ecosystems, and ad-tech platforms relying on programmatic consent signals should be building toward interoperability with that model rather than continuing to rely solely on a publisher-side pop-up as the entire consent record.

Device identifiers and cross-app tracking

Advertising IDs, hashed emails used for identity resolution, and cross-app tracking pixels together let ad-tech platforms stitch a single profile of a person's behaviour across many unrelated apps and sites, which is precisely the kind of profiling that needs its own clearly stated purpose in a notice, distinct from any single app's own functional data collection. Identity-resolution vendors that match hashed identifiers across data sets are, in effect, building a shared profile from data multiple fiduciaries each partially hold, and each contributing fiduciary needs its own lawful basis for feeding data into that resolution process.

Where any of this cross-app profiling reaches a user later identified as a child, Section 9's prohibition on behavioural monitoring and targeted advertising to minors applies regardless of how many intermediary parties sit between the ad platform and the fact that the underlying user is under 18 — which argues for age-signal checks earlier in the bid-stream pipeline, not just at the publisher's own app.

Algorithmic targeting and Significant Data Fiduciary exposure

Large ad-tech platforms running algorithmic audience segmentation and bidding models at scale are natural candidates for eventual Significant Data Fiduciary notification given the volume and sensitivity of behavioural data processed, which would bring mandatory algorithmic due-diligence expectations, periodic impact assessments, and independent audits under Section 10. Building explainability into targeting models now — being able to say, at a summary level, what inputs placed a user into a given segment — is considerably easier to do from the start than to retrofit once an audit is underway.

Contracts between publishers, exchanges, and demand-side platforms should allocate responsibility clearly for security safeguards and breach notification across the bid-stream chain, since a breach at any single node can expose data that originated from many different original fiduciaries at once.

Where to go next

The Consent Notice Builder can help publishers and ad-tech platforms draft consent language that is honest about the scale of the bid-stream sharing, rather than a generic cookie banner. A Vendor Assessment across exchanges, DSPs, and identity-resolution partners is worth running given how many parties typically sit in a single programmatic chain.