What is GDPR and How Does It Impact Digital Advertising?
GDPR is the EU's data protection law, and it sets the legal basis, consent standard, and cross-border transfer rules that govern how advertisers can collect, use, and target with personal data in Europe.
The General Data Protection Regulation (GDPR) is the European Union's data protection law, and it directly governs how advertisers can collect, use, and target with personal data. Any processing needs a valid legal basis, and for cookie-based or profiling-based ad targeting, that basis is almost always freely given, specific consent, not a pre-ticked box or a condition bundled into using a site.
What GDPR Actually Requires for Advertising
GDPR gives controllers six possible legal bases for processing personal data, but for most ad targeting only two hold up in practice: consent and legitimate interest. Consent has to be freely given, specific, informed, and as easy to withdraw as it was to give. Legitimate interest can cover some first-party analytics or fraud prevention, but it does not cover cross-site profiling for ad targeting once a genuine alternative exists. Special category data (health, religion, sexual orientation, and similar) needs explicit consent, full stop, with no legitimate-interest workaround. GDPR also restricts moving personal data outside the EU/EEA to countries without an adequacy decision or contractual safeguards; a fuller breakdown of how that compares to other markets is in our cross-border marketing FAQ.
Consent Standards Are Tightening, Not Loosening
The UK's Information Commissioner's Office issued guidance in January 2025 on "consent or pay" advertising models, and its framing applies just as directly under the EU regime: consent is not freely given if a data subject has no genuine choice or can't refuse without real detriment. The ICO's assessment runs on four factors: whether there's a real power imbalance, whether any paid alternative is priced fairly rather than punitively, whether the ad-supported and paid options are genuinely equivalent, and whether the choice is presented with real transparency rather than a dark pattern. The direction of travel across both UK and EU enforcement is the same: default-on tracking and forced consent bundles are the pattern regulators are actively unwinding, not tightening. First-party approaches built around tracking cookies and first-party data hold up far better against this scrutiny than third-party profiling does.
Enforcement Is a Real Line-Item Risk
GDPR fines are not theoretical. As of March 2026, the CMS Enforcement Tracker records 2,685 fines totaling roughly €6.11 billion since the regulation took effect in 2018, including the €1.2 billion fine Ireland's Data Protection Commission imposed on Meta in 2023, the largest single GDPR fine issued to date. That scale changes the math on data strategy: the cost of a compliant targeting approach is consistently smaller than the cost of an enforcement action plus the campaign disruption that follows one.
2026's New Enforcement Focus: Transparency
The European Data Protection Board launched its 2026 Coordinated Enforcement Framework on 19 March 2026, with 25 data protection authorities across Europe assessing compliance with GDPR's transparency and information obligations (Articles 12 through 14): whether organizations tell people, clearly and up front, what data is collected and why. For advertisers, that means privacy notices and consent-flow copy are now as much an audit target as the cookie banner itself, and disclosures tied to privacy-preserving ad measurement or data clean rooms need to hold up to the same scrutiny.
How Criterion Global Builds Toward GDPR-Compliant Targeting
For PURE Insurance, a people-based, first-party-data strategy was the whole point, not a compliance afterthought: suppression of irrelevant impressions, lookalike modeling built on owned data, and personalized, privacy-compliant targeting across platforms, a model that held up as the account expanded into Canada as cleanly as it did domestically. That is the same sequencing the Criterion Global Budget Blueprint℠ applies to any brand entering a GDPR-regulated market: read compliance friction and audience response with a bounded Minimum Viable Market Investment℠ (MVMI℠) before committing spend at scale, rather than porting a US targeting stack into Europe unchanged and finding out what breaks after launch.