Data & Privacy
Your page view is auctioned in the time it takes the page to load
An advertising slot triggers a real-time auction among many bidders, and the bid request is where the personal data goes.

What follows is the working version of programmatic advertising: the decisions in the order you actually meet them, with the reasoning attached.
Before you start
- The bid request broadcasts information about you to many companies at once.
- Losing bidders receive the data regardless of whether they win.
- The auction completes in a fraction of a second, which shapes the whole design.
The auction runs while the page draws
When a page with advertising loads, the slot is offered to an exchange that solicits bids from many buyers simultaneously. The whole process must complete in roughly the time it takes the rest of the page to render, which is a hard latency budget. The highest bid wins, the advert is delivered, and the page finishes loading.
This is why advertising slots are the last thing to appear and why they delay pages when the auction is slow.
The bid request is the privacy event
To bid meaningfully, buyers need to know something about the opportunity, so the request carries page context, device details, approximate location and identifiers. That request is sent to every invited bidder, which can be dozens or hundreds of companies.
Under load, every recipient sees the data whether or not they bid, and whether or not they win. Regulators and researchers have described this broadcast as the largest ongoing data disclosure in the industry, and enforcement cases have followed.
Identifiers are what make it valuable
A stable identifier lets a buyer recognise the same person across sites and combine what they know from elsewhere. Cookies performed this role historically, and their retirement in some browsers pushed the industry towards alternatives. Hashed email addresses, first-party identifiers and probabilistic device matching are the main replacements, and none of them are visible to a browser blocker.
In the datasheet, logging in anywhere with an email address is what most reliably feeds this.
Where the data comes from originally
Publishers contribute the context of what you are reading and whatever they know about their own users. Data brokers contribute segments built from purchase records, loyalty schemes, app data, public records and location trails. Sources vary enormously in accuracy, which is why the inferred categories about any individual are frequently wrong.
Being wrongly categorised is not reassuring, since decisions are made on the category regardless.
Consent interfaces and their gaps
Consent frameworks were built to record and transmit user choices through the chain of participants. Enforcement actions have found that consent obtained through some of these interfaces did not meet legal standards, particularly where refusing was harder than accepting.
Because the bid request is broadcast, a downstream participant ignoring the signal is difficult for anyone to detect. The rules and their enforcement differ substantially between jurisdictions, and the same site behaves differently depending on where you appear to be.
What reduces the exposure
Blocking the advertising scripts prevents the auction being triggered from your browser at all, which is the most complete defence available. Resetting advertising identifiers and disabling app tracking permissions breaks the joins between separate collections. Avoiding logging in where it is not needed prevents the most durable identifier being attached.
Mechanically, none of this affects data collected by services you do use and have agreed terms with, which is a separate question.
The takeaway
Every advert slot broadcasts a description of you to everyone invited to bid. The losers keep it too.
Once you know what it is trading away, the design stops looking arbitrary.
Questions readers ask
Why do adverts follow me around the internet?
A buyer recognised the same identifier on another site and bid to reach you specifically. It is the same auction each time, with a bidder that already knows something about you.
Does clearing cookies stop this?
Partly and temporarily. Identifiers based on hashed email addresses, logins and server-side matching survive cookie clearing entirely.





