Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Mirantis reveals Lens Prism, an AI copilot for operating Kubernetes clusters

      July 3, 2025

      Avoid these common platform engineering mistakes

      July 3, 2025

      Full-Stack Techies vs Toptal: Which Is Better for React.js Outsourcing?

      July 3, 2025

      The AI productivity paradox in software engineering: Balancing efficiency and human skill retention

      July 2, 2025

      Microsoft Gaming studios head Matt Booty says “overall portfolio strategy is unchanged” — with more than 40 games in production

      July 3, 2025

      Capcom reports that its Steam game sales have risen massively — despite flagship titles like Monster Hunter Wilds receiving profuse backlash from PC players

      July 3, 2025

      Cloudflare is fighting to safeguard “the future of the web itself” — standing directly in the way of leading AI firms

      July 3, 2025

      Microsoft reportedly lacks the know-how to fully leverage OpenAI’s tech — despite holding IP rights

      July 3, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      PHP 8.5.0 Alpha 1 available for testing

      July 3, 2025
      Recent

      PHP 8.5.0 Alpha 1 available for testing

      July 3, 2025

      Recording cross browser compatible media

      July 3, 2025

      Celebrating Perficient’s Third Databricks Champion

      July 3, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft Gaming studios head Matt Booty says “overall portfolio strategy is unchanged” — with more than 40 games in production

      July 3, 2025
      Recent

      Microsoft Gaming studios head Matt Booty says “overall portfolio strategy is unchanged” — with more than 40 games in production

      July 3, 2025

      Capcom reports that its Steam game sales have risen massively — despite flagship titles like Monster Hunter Wilds receiving profuse backlash from PC players

      July 3, 2025

      Cloudflare is fighting to safeguard “the future of the web itself” — standing directly in the way of leading AI firms

      July 3, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Brussels Court Slams Tracking-Based Ads, Upholds GDPR Privacy Standards

    Brussels Court Slams Tracking-Based Ads, Upholds GDPR Privacy Standards

    May 19, 2025

    GDPR

    The Brussels Court of Appeal ruled on May 14, 2025, that the consent model used in tracking-based advertising by major tech companies such as Google, Microsoft, Amazon, and X (formerly Twitter) does not comply with EU privacy laws, including the General Data Protection Regulation (GDPR).  

    The ruling, which targets the Transparency and Consent Framework (TCF) utilized for real-time bidding (RTB) in online advertising, marks a crucial step in the European Union’s ongoing fight against surveillance-based advertising. 

    The Implications of Tracking-Based Ads 

    The case centered on the methods employed in tracking-based advertising, specifically those using Real-Time Bidding (RTB) systems. RTB allows advertisers to bid in real time to display ads to users based on personal data. Each time a user visits a website, information such as location, browsing habits, and even inferred personal attributes like beliefs or health conditions can be shared with thousands of companies.  

    Despite efforts by Big Tech companies to claim compliance with the GDPR by using the TCF, the court ruled that this framework falls short of the regulation’s requirements, particularly in terms of transparency and consent. The core issue lies in how user consent is obtained through pop-up notifications that, according to the court, do not adequately address the complexities of consent and data protection standards. 

    Background: The Legal Battle 

    The ruling stems from a case between the Interactive Advertising Bureau Europe (IAB Europe) and the Belgian Data Protection Authority (GBA). IAB Europe, a non-profit organization representing the digital advertising sector, developed the TCF, which aims to help businesses comply with privacy laws when processing personal data through RTB systems. The TCF collects user preferences and stores them in what are known as “TC Strings,” which are then shared with advertising platforms to manage consent. 

    In 2022, the GBA issued a ruling against IAB Europe, asserting that the TCF violated several provisions, especially regarding the transparency and legality of user consent. The GBA imposed a €250,000 fine on IAB Europe, arguing that the TC Strings, which can be linked to identifiable individuals, qualify as personal data.  

    IAB Europe appealed the decision, arguing that TC Strings alone do not constitute personal data, but the court upheld the GBA’s position, affirming that TC Strings, when combined with other identifiers like IP addresses, can indeed identify individuals, making them personal data under GDPR. 

    Key Legal Questions and the Court’s Findings 

    The case brought to light two critical legal questions: whether TC Strings should be classified as personal data and whether IAB Europe should be considered a data controller under GDPR. The Court of Justice of the European Union (CJEU) had already ruled that TC Strings qualify as personal data when linked with identifiers like an IP address, as they can be used to identify individuals either directly or indirectly. Furthermore, the CJEU clarified that organizations like IAB Europe, which influence how personal data is processed, are considered joint controllers under GDPR, even if they do not directly access the personal data. 

    The Brussels Court of Appeal dismissed IAB Europe’s objections, affirming that the TC Strings do indeed constitute personal data. The court also concluded that IAB Europe, as the architect of the TCF, plays a key role in determining how personal data is processed, thus making it a joint data controller along with other participants in the digital advertising ecosystem. 

    The Role of the GDPR in Protecting Privacy 

    The General Data Protection Regulation, which came into force in 2018, is a landmark piece of EU legislation designed to protect personal data and privacy. It sets strict requirements for obtaining user consent, ensuring transparency, and limiting the scope of data processing. The ruling against IAB Europe reinforces the idea that surveillance-based advertising, which relies heavily on the collection and monetization of personal data, is incompatible with data privacy principles. 

    Moreover, the court’s decision reinforces the EU’s commitment to enforcing privacy laws and holding companies accountable for violations of users’ privacy rights. The ruling also emphasizes the importance of informed consent and the need for advertisers to adopt more ethical, transparent practices in the collection and use of personal data. 

    Conclusion  

    This ruling signals a transformative shift in the digital advertising landscape. With the EU firmly stepping up against tracking-based ads and surveillance-based advertising, businesses will need to adapt to more privacy-conscious models to meet the rising demands for transparency and compliance.  

    This case stresses that protecting privacy is not just a legal obligation, but a fundamental responsibility in today’s data-driven world. As the legal journey continues, this decision paves the way for a future where ethical and transparent advertising practices take precedence, offering hope for stronger privacy protections not only in Europe but globally. 

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleAdobe’s brand refresh
    Next Article Why CTEM is the Winning Bet for CISOs in 2025

    Related Posts

    Security

    Critical Lucee Flaw (CVE-2025-34074, CVSS 9.4): Authenticated RCE Via Scheduled Task Abuse, Metasploit Module Out

    July 3, 2025
    Security

    Exposed JDWP Debug Ports Under Attack: Cryptominers Infiltrating Java Apps in Hours

    July 3, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    Ubuntu 25.04: Ripresi gli aggiornamenti dopo il blocco per bug su Kubuntu

    Linux

    GuardianGamer scales family-safe cloud gaming with AWS

    Machine Learning

    Designer Spotlight: Bimo Tri

    News & Updates

    This one Elden Ring Nightreign feature saved the day when I needed it most

    News & Updates

    Highlights

    CVE-2025-6432 – Mozilla Firefox DNS Proxy Bypass Vulnerability

    June 24, 2025

    CVE ID : CVE-2025-6432

    Published : June 24, 2025, 1:15 p.m. | 1 hour, 23 minutes ago

    Description : When Multi-Account Containers was enabled, DNS requests could have bypassed a SOCKS proxy when the domain name was invalid or the SOCKS proxy was not responding. This vulnerability affects Firefox
    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    New generative AI tools open the doors of music creation

    May 13, 2025

    5 Pocket replacements that might even be better than the original

    May 29, 2025

    CVE-2024-7562 – InstallShield Elevated Privilege Vulnerability

    June 12, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.