I’m excited to share our latest working paper, “𝐓𝐨𝐰𝐚𝐫𝐝𝐬 𝐃𝐞𝐯𝐞𝐥𝐨𝐩𝐢𝐧𝐠 𝐚𝐧 𝐔𝐧𝐝𝐞𝐫𝐬𝐭𝐚𝐧𝐝𝐢𝐧𝐠 𝐨𝐟 𝐂𝐨𝐧𝐬𝐮𝐦𝐞𝐫𝐬’ 𝐏𝐞𝐫𝐜𝐞𝐢𝐯𝐞𝐝 𝐏𝐫𝐢𝐯𝐚𝐜𝐲 𝐕𝐢𝐨𝐥𝐚𝐭𝐢𝐨𝐧𝐬 𝐢𝐧 𝐎𝐧𝐥𝐢𝐧𝐞 𝐀𝐝𝐯𝐞𝐫𝐭𝐢𝐬𝐢𝐧𝐠”, co-authored with Kinshuk Jerath (Columbia Business School) and Daniel Sokol (University of Southern California). We conducted online experiments with U.S. and European consumers and compared how different ad-targeting strategies affect perceived privacy violations (PPV). Key take-aways - Behavioral targeting (high tracking + individual matching) generates the strongest PPV (Mean = 5.22). - Cutting-edge, on-device privacy-enhancing technologies (PETs) lower PPV only marginally (≈ 4.5), even when targeting is aggregated to groups. - Contextual targeting—ads chosen purely from page content, with no tracking—slashes PPV by ~50 % (Mean = 2.7). - Consumers show virtually the same comfort with untargeted ads (2.1) as with no ads / no tracking at all (1.86). These results echo dual-privacy theory: people value privacy both intrinsically (tracking feels wrong) and instrumentally (risk of personal harm). Technical fixes that focus only on data locality miss the bigger picture—perception matters. A consumer-centric lens is essential for regulators and ad-tech practitioners who want to rebuild trust in the data-driven web. The full paper is available (link in comments). I’d love to hear your thoughts! #Privacy #AdTech #MarketingResearch #PETs #ConsumerInsights #HECParis #ColumbiaBusinessSchool #USC (Figure 1 below: Perceived Privacy Violations across advertising strategies—lower scores are better)
Privacy Concerns in Retargeting Ads
Explore top LinkedIn content from expert professionals.
Summary
Privacy concerns in retargeting ads refer to worries about how advertisers track and use personal data to show targeted ads across websites and apps. With growing scrutiny and tougher privacy laws, people are becoming more aware of how their online behavior, location, and identifiers are collected for advertising purposes.
- Review data sharing: Take time to understand which apps and websites have access to your information and adjust settings to limit unnecessary tracking.
- Prioritize consent: Make sure you’re giving clear, informed permission before your data is used for ad targeting, especially with new privacy regulations emphasizing user control.
- Seek transparency: Choose platforms and brands that openly explain how they use your data and offer easy tools to manage privacy preferences.
-
-
As if Google’s shifting plans with #cookiedeprecation weren’t enough of a headache, the FTC has now re-cast serious doubt on hashed emails #HEMs, backbone for ID solutions—once considered a cornerstone for post-cookie identity solutions. The latest FTC warning reveals: hashed emails and similar data are not as anonymous as many thought. #Hashing transforms personal information into random-looking strings, but it doesn’t guarantee true anonymity. This recent guidance challenges the effectiveness of many privacy strategies and exposes the risk of relying on hashed IDs for user tracking. Notable enforcement cases like Nomi, BetterHelp, PreMom, InMarket, highlight the dangers of assuming that hashed data ensures user privacy. ❗Though BetterHelp sent hashes to Facebook, rather than email addresses, the outcome was the same: Facebook allegedly learned who was seeking counselling for mental health and used that sensitive information to target ads to them. 🗣 Word to the wise: pay close attention to the identifiers used to recognize users online: email addresses, phone numbers, MAC addresses, hashed email addresses, device identifiers, advertising identifiers, to recap a few. Regardless of what they look like, all user identifiers have the powerful capability to identify and track people over time, therefore the opacity of an identifier cannot be an excuse for improper use or disclosure. With Google moving towards an opt-out mechanism and increasing scrutiny on data privacy, it’s likely that hashed IDs might not be the ultimate solution we once believed. #Advertisers and #publishers need to reassess their strategies and likely "dont put all your eggs in one basket". The FTC has said this since 2012. But is monitoring closely, and so should you. Links in comments below #privacy #IDs #FTC #adtech #advertisers #digitaladvertising #b2c #hashedIDs #publishers
-
Your iPhone probably isn’t secretly eavesdropping on your conversations 🎧📱 The uncomfortable truth: it doesn’t need to. A recent article from CNET explains why the classic “I just talked about this and now I see an ad” feeling isn’t proof your phone is listening. Independent research hasn’t found evidence of hidden, always-on microphones being used for ad targeting. The real story is more systemic and more worrying 👇 🔍 The real issue: surveillance by design Instead of raw audio, the ad ecosystem feeds on: 📌 Cross-app and cross-site tracking building detailed behavioural profiles 📌 Location history, purchase records, loyalty card data and social graphs 📌 Data brokers aggregating and reselling this information at scale 📌 Real-time bidding systems trading user profiles in milliseconds, billions of times per day In short: adtech doesn’t need to listen to you – it predicts you, with high confidence. 🛡️ From a security & privacy perspective, the questions to ask are: ✅ Which apps have more permissions than they need (microphone, location, contacts, tracking)? ✅ How is my data being shared, enriched, and recombined across platforms and data brokers? ✅ Which controls am I actually using (App Tracking Transparency, privacy settings, DNS / tracker blocking, consent management)? The real risk isn’t a rogue microphone 🎙️ It’s an opaque, hyper-optimised data supply chain we’ve normalised. This is where users, regulators, and security / risk teams need to raise the bar in the next phase of privacy engineering, digital governance and platform accountability. 🔐🌍 https://lnkd.in/dbPp75xj #privacy #security #cybersecurity #adtech #infosec #dataprotection #ios #tracking
-
How India’s DPDP Act Will Change Social Media Advertising 📱🔐 The Digital Personal Data Protection Act, 2023 is not just a privacy law. It is a major shift for digital marketing. For years, social media ads relied on deep user tracking to deliver personalized promotions. With DPDP implementation, consent and user control become central to advertising. Here is the practical business impact 👇 📌 Smaller Targetable Audiences Users can now refuse or withdraw tracking consent easily. Result 📉 Reduced behavioral targeting 📉 Weaker retargeting campaigns 📉 Lower ad personalization 💰 Higher Customer Acquisition Costs Platforms like Instagram, Facebook, and YouTube may offer limited precision targeting. Result 💸 More ad spend 💸 Broader audiences 💸 Higher cost per conversion 🧾 First Party Data Becomes Critical Third party data becomes risky. Brands must collect data directly via apps, websites, and loyalty programs. Result 🏆 Stronger customer relationships 📊 CRM and consent tools become essential 🔐 Trust becomes a business asset 👶 Restrictions on Children’s Advertising Targeted ads to minors face strict limits. Result ⚠ Generic ads increase 🤝 Influencer marketing rises 📺 Context based promotions grow ⚖ Marketing Meets Privacy Compliance Campaigns now need clear purpose, disclosures, and opt out mechanisms. Result ⏳ Slower launches 👩⚖ Legal involvement 💼 Higher compliance costs 🧠 Rise of Contextual Advertising Ads based on content, not personal tracking. Example Travel video → hotel ads Cooking content → kitchen products Result 🙂 Less intrusive 🔐 More privacy friendly 🎯 Less personalized 🎯 The Big Shift Digital ads move from tracking driven marketing to consent driven marketing. Businesses that build trust, use ethical data practices, and strengthen first party data will win. Privacy is becoming a competitive advantage. 🌟Grateful to my privacy network for the constant inspiration and knowledge sharing that keeps me growing every day. Would love to hear your feedback. #DataPrivacy #DPDPAct #PrivacyProfessionals #DigitalTrust #InfoSec
-
You know why first-party data matters so much in Meta Ads right now? Here’s the honest reality behind what’s happening on Meta today: People see your ad → video, static, carousel, DPA, whatever. They click → they visit your site → maybe they buy, maybe they don’t. Your website tries to communicate that activity back to Meta through Pixel or CAPI. But between privacy settings, ATT opt-outs, cookie blocking, VPNs, cross-device behavior, and session jumps… that connection is no longer a clean “signal in, signal out.” A huge chunk of people who engaged with your ads never show up in your website retargeting audiences. This is why first-party engagement audiences have become a quiet superpower. → Create a 30-day engagement audience (ad + organic) → Create a 30-day video-views audience → Treat them as your “warm layer,” even if Pixel-based traffic is missing You’ll reach people who did visit your site, did engage with your ads, and did show intent, Meta just couldn’t stitch it together because of privacy conditions and attribution gaps. Marketers who rely only on website retargeting will keep shrinking their reach without knowing why. Marketers who build retargeting pools from first-party engagement will keep winning the warm audience game. Bigger reach. Less saturation. More robust performance. This is the adaptation phase we’re in. And those who understand this shift will outperform the ones still chasing the old retargeting logic. #MetaAds #PaidSocial #PerformanceMarketing #CAPI #Tracking #PrivacyEra #DigitalMarketing #GrowthStrategy
-
Here is a little talked about ads fact: people have more control over their ad experience than they might think. As advertising professionals, we’re confronted by two seemingly contradictory facts: 8 in 10 people are concerned about companies using data collected about them, while about three-quarters of people also say they only want to see ads that are relevant and useful to them. How do you solve this? About a year and a half ago, Google launched My Ad Center, a tool embedded directly in the ads people see on YouTube, Search and Discover. From there, people can control what information is used for ads, limit ads in sensitive categories, and opt out of personalized ads altogether. We built this product - unique in the industry - following user research that showed that privacy concerns are influenced by two factors we could act upon: 1️⃣ People don’t understand how data is used: privacy tools are hard to find and written in legalese. 2️⃣ People don’t have control over their data: to make changes to their data settings, people often need to go through arduous and often confusing processes. This is why we launched My Ad Center. And data shows that people find it helpful. People globally have adjusted their preferences over 330 million times! Watch the video ⬇️ for more #AdsFacts
Customize the ads you see with My Ad Center #HowTo #Google #AdsFacts
https://www.youtube.com/
-
California just hardwired consent into the browser. Gov. Gavin Newsom signed three privacy laws on 8 Oct. The headline for adtech: AB 566 — the California Opt Me Out Act — amends the CCPA to require browser developers to build a native opt-out preference signal. One click in-browser. No more site-by-site opt-outs. AB 656 forces social platforms to offer simple account cancellation that auto-deletes personal data. SB 361 tightens the data broker regime with more transparency on what brokers collect. The AB 566 mechanics matter: - Browser makers must explain how the signal works. - Liability shield for browsers if a site ignores the signal. - California Privacy Protection Agency can regulate for implementation. - Effective 1 Jan. 2027. Expect volume. Darren Abernethy notes a likely surge in opt-out of sell/share signals. Retargeting and web marketing take a hit, depending on default settings and control prominence. The big unknown: will native OOPS be on by default? Jessica B. Lee flags the implementation gap. No specified mechanism in AB 566. Colorado lists approved universal opt-outs and currently recognizes Global Privacy Control. California leaves room for choice. Multiple signals mean confusion for operators. Alignment on one standard would reduce friction. Consumers will still need education across devices and contexts. Scope and jurisdiction: - If you are a CCPA “business,” you are in scope. Collection from California residents is the trigger, not headquarters. - Many leading browsers are California-based, easing enforcement reach. Mobile is a gray zone. The statute doesn’t mention mobile explicitly, but the definition of browser doesn’t exclude mobile or embedded app browsers. This could spill beyond California if browsers ship the feature broadly, unless they geo-fence or deactivate outside the state. What this means for teams today: - Audit sell/share flows tied to retargeting and lookalike models. - Map signal intake. Decide how you will detect and honor a native OOPS and any concurrent signals. - Plan for defaults. Scenario-test opt-out rates based on different browser UI choices. - Prepare clear consumer communications across devices. - Track CPPA rulemaking through 2026. Privacy by default is moving into the UI layer. Advertising strategies will need first-party strength, consented audiences, and measurement that survives a wave of universal opt-outs.
Explore categories
- Hospitality & Tourism
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Healthcare
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Career
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development