Behavioral Advertising and the Consent Problem That Hasn't Gone Away

Behavioral advertising is the practice of targeting advertising to individuals based on their observed behavior — the websites they visit, the content they engage with, the searches they conduct, the purchases they make.

RCDr. Richard Chingombe · Founder, Verisq·4 min read·Practitioner perspective, not legal advice

It is also the practice that has produced the largest volume of data protection enforcement actions in Europe, the most significant cookie consent enforcement under GDPR, and the most active regulatory attention to online tracking practices globally. The practice has not gone away. The legal basis for it, under GDPR, has become significantly more contested. The gap between how behavioral advertising is currently conducted and what a compliant consent infrastructure requires is, in most organizations that rely on it, still significant.

What GDPR Actually Requires for Behavioral Advertising

Behavioral advertising that involves the processing of personal data — which includes most behavioral advertising using cookies, device fingerprints, or other tracking mechanisms that can be linked to individuals — requires a valid legal basis under GDPR. The legal basis that the behavioral advertising industry historically relied on — legitimate interests — has been significantly narrowed by EDPB guidance and enforcement decisions that have found that behavioral advertising does not meet the balancing test required for legitimate interests: the interests of the individual in not being tracked outweigh the commercial interests of the advertiser in tracking them.

The remaining legal basis for behavioral advertising under GDPR is consent: specific, informed, freely given, and unambiguous consent to the specific processing activities involved in behavioral advertising. This consent standard is meaningfully higher than what most consent management platforms were designed to collect when they were deployed in the years following GDPR's implementation. Banners that presented 'Accept All' and 'Learn More' options, pre-checked consent boxes, and designs where rejection required more clicks than acceptance do not meet the consent standard that enforcement action has established.

The consent that most behavioral advertising consent management platforms were collecting in 2019 and 2020 was not the consent that enforcement decisions in 2022 and 2023 established as required. The enforcement has not been retrospective in most cases. The forward compliance obligation is clear: the consent collected now must meet the standard enforcement has established.

The Gap Between Current Practice and Required Standard

Consent Banner Design That Violates the Standard

Enforcement decisions from the Irish DPC, the French CNIL, the Belgian APD, and the Italian Garante have established specific design requirements for consent banners: the option to reject must be as prominent and accessible as the option to accept, rejection must require no more clicks than acceptance, and the banner must clearly describe the specific processing activities for which consent is sought. Many consent management platform implementations deployed before these decisions do not meet these specific design requirements.

Consent Scope That Does Not Match Processing Reality

Consent collected through a consent management platform covers the vendors and processing activities listed in the CMP's consent layer. The actual processing that occurs when a user consents may involve more vendors, different processing activities, or different data uses than what the consent layer disclosed. Real-time bidding processes that share behavioral data with hundreds of bidders in milliseconds create a disclosure challenge: the full scope of processing and data sharing is difficult to describe accurately in a consent layer that must be comprehensible to a user making a consent decision in real time.

Consent Records That Cannot Demonstrate the Standard Was Met

Consent records in most CMPs capture that a user made a consent choice, when they made it, and what the consent state was. They do not always capture the specific consent banner version the user saw, the specific processing activities described in the banner at the time of consent, or the specific processing activities that occurred as a result of the consent. Demonstrating that a specific user's consent was freely given, specific, informed, and unambiguous requires this level of documentation.

See how your own vendors measure up.Security and privacy posture for any vendor, from the outside, free.
Check a vendor's scorecard

The Enforcement Trajectory

The regulatory enforcement trajectory for behavioral advertising consent has been consistently in one direction: toward stricter requirements for what constitutes valid consent and higher standards for how consent must be obtained and documented. The EDPB's guidelines on consent have been updated and clarified multiple times since GDPR's implementation, each iteration adding specificity to requirements that initial implementations did not meet.

The TCF — the Transparency and Consent Framework operated by IAB Europe that underlies most behavioral advertising consent infrastructure in Europe — has been found by the Belgian APD to have specific compliance deficiencies. IAB Europe is implementing changes. Organizations that rely on TCF-based consent infrastructure need to understand what the required changes are and whether their specific implementation satisfies the updated standard.

The broader regulatory attention to behavioral advertising extends beyond GDPR to include the Digital Markets Act's restrictions on combining personal data across services for advertising purposes, and increasing scrutiny from data protection authorities in the UK, Australia, and US states that have enacted privacy laws with opt-out requirements for targeted advertising.

Assess the consent infrastructure against the standard that enforcement has established, not the standard that was understood when the CMP was deployed.

The consent banner that was compliant in 2020 may not be compliant in 2025. Audit the implementation against current enforcement standards before the regulator does.

Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.