INTEL

Real-Time Bidding: The Segments You Cannot Delete

From 1 August 2026, a Californian can make a single deletion request and have it routed to every registered data broker in the state. The brokers must check for new requests every 45 days and act on them. The Delete Request and Opt-Out Platform, California DROP, has been live since January. From August it has teeth.

It does not touch real-time bidding, and that is the subject of this piece.

This is the strongest deletion mechanism any individual has been given in the United States. We have covered how California DROP routes deletion requests to registered data brokers separately, and the short version is: use it.

Every time a page loads, an RTB bid request carrying identifiers, location and audience segments about the person loading it goes out to a large number of companies at once. None of them is a registered data broker. None of them holds a record you can ask to have deleted.

A deletion right operates on records. Someone holds a file about you, and the law compels them to destroy it. That model requires three things to be true: a holder, a record and a register of who the holders are. California DROP works because the state made data brokers register. The registry is the hinge the whole right hangs on.

Real-time bidding breaks all three conditions. There is no single holder. There is no stored record at the moment of transmission. And the recipients do not register with anyone, because receiving the data does not make you a broker. It makes you a bidder.

What happens when a page loads: inside the RTB bid request

Almost every time you open a website or an app, an auction runs for the advertising space on it. The auction finishes in under a second.

A supply-side platform packages information about the person loading the page into a structured message called a bid request. It sends that to one or more ad exchanges. Each exchange broadcasts the request to the demand-side platforms that buy on behalf of advertisers. Each of those decides whether to bid.

The bid request is a defined object in a published protocol, OpenRTB, maintained by the IAB Tech Lab. Its fields include device.ifa, the advertising identifier assigned to a phone. They include user.id and user.buyeruid, identifiers that let a buyer recognise the same person across auctions. They include device.geo, a latitude and longitude with an accuracy radius. And they include data and segment objects, key-value pairs describing the person, contributed by named data providers and mixed together from several providers in a single message.

The protocol is aware of the problem. Its own implementation guidance says device.ifa “should not be used as a user identifier or for audience targeting purposes” and may be used for narrower things such as capping how often someone sees an ad.

That is a norm written into a data format. The specification asks. It cannot enforce, and nothing downstream of the broadcast is in a position to.

Losing the auction still delivers the data

Here is the part that matters, and it is a design property rather than an abuse of one.

Every participant receives the bid request. The winner receives it. So does everyone who bids and loses, and so does everyone who receives it and never bids at all. The auction distributes the data first and selects a winner second. There is no version of the process in which only the buyer sees you.

The numbers come from the industry’s own documentation. Google’s documentation states that 2,051 entities may receive data from its auctions in the United States. Microsoft has said 1,647 firms may receive its RTB data. A single ad slot is often sold through an auction of auctions, with several exchanges running competing sales coordinated by one supply-side platform, which widens the distribution again.

Two protocols govern almost all of this. The IAB Tech Lab’s OpenRTB covers roughly 89.5 per cent of RTB broadcasts of US data. Google’s Authorized Buyers protocol covers the remaining 10.5 per cent.

The identity join happens through a separate step. A supply-side platform and a demand-side platform each hold their own identifier for the same person, so they synchronise them, through redirects or iframes calling endpoints built for the purpose. Cookie syncing is what turns a stream of individually pseudonymous auctions into a durable profile held by whoever was listening.

The industry’s own term for what is transmitted is bidstream data. The Irish Council for Civil Liberties, which has campaigned on this for years and whose framing should be read as advocacy, quotes industry documentation making the consequence explicit: there is “no technical way to limit the way data is used” once it has been broadcast.

That sentence is the whole problem in nine words. Not that the data is misused, but that after transmission there is no mechanism by which it could be controlled, audited or recalled.

What the industry says it is for, and what governs it

The legitimate use is narrow and real. A buyer needs enough information to decide what an impression is worth. Frequency capping needs to know whether it has already shown you this ad four times.

What stops a recipient keeping the data, building a profile and selling it on is a contract rather than a technical control. Publishers and exchanges forbid derivative use of bidstream data, and demand-side companies risk penalties from regulators and clients if they are caught.

So the regime runs like this. The data goes to everyone, everyone promises not to keep it, and the promise is checked by discovery after the fact.

An entire category of business sits in the gap between what gets transmitted and what is contractually permitted.

What it costs to use this against a person

In 2017, researchers at the University of Washington bought ads to find out. Their paper, presented at the ACM Workshop on Privacy in the Electronic Society, showed that roughly $1,000 of ad spend through a demand-side platform was enough to track a chosen individual’s physical movements and to work out which sensitive applications they were using, including apps that indicate religion and sexuality.

The target never has to click. The purchaser learns where the ad was served regardless of whether anyone interacts with it.

That research is nine years old and predates GDPR enforcement, Apple’s tracking-transparency changes and most of the cookie deprecation argument. We cite it for the mechanism, not for the price. The finding that survives is structural: an ad buyer is an ordinary customer of this system, and buying into it is the documented route to using it for surveillance.

Who is in the segments

In November 2023 the ICCL published two reports, on the United States and on Europe, written by Johnny Ryan and Wolfie Christl. Ryan previously held senior roles in the RTB industry. The reports carry 135 footnotes and, unusually, the underlying segment lists were published so the claims can be checked.

They examined marketplace listings. One Microsoft Xandr list ran to 651,463 segments across 19,956 pages. A Dun & Bradstreet list carried 38,786 segments.

The categories on offer included people who work at the Pentagon, people in the Department of Defense, people working in defense and space, active military personnel broken out by branch, recently recruited military personnel, and military spouses and families. There were segments for people working in the judiciary, for judges, for lawmakers, and for government decision makers described as working specifically on national security and international affairs.

There was a segment for people located within six miles of a military base. There were segments for people whose location placed them at security conferences, hotels, restaurants and venues.

The industry’s own classification codes carry the rest:

  • IAB Context 122 — defense industry
  • IAB Audience 885 — procurement intent, aerospace and defense
  • IAB Audience 1502 — recent family bereavement, inferred from intent to purchase funeral services
  • IAB Audience 1395 — payday and emergency loans
  • IAB Context 65 — bankruptcy
  • IAB Context 405 — personal debt
  • IAB Context 287 — mental health
  • IAB Context 311 — substance abuse

Commercially available segments in those lists identified people likely to be experiencing depression, chronic pain, anxiety or substance abuse, people likely to be insolvent, and people categorised as likely survivors of sexual abuse.

Money, ideology, compromise and ego is the framework intelligence services have long used to describe how a person becomes recruitable. Read the segment list against it. The categories map almost exactly, and they are purchasable.

The reports also documented US bid request data reaching companies in Russia and China, where national law gives security agencies access to data held domestically.

These findings are from November 2023. We have found no public announcement since of either governing protocol removing personal data fields, though the ICCL and EPIC have formally demanded it and filed a complaint with the FTC in January 2025. Absence of an announcement is not proof of inaction, and it is not evidence of change either.

The tool that productised it

The same investigation described a surveillance product called Patternz, sold by an Israeli company. Its marketing claimed profiles on five billion people, assembled from RTB data obtained from a large number of advertising companies. The described capability included a target’s current location, their movements over months, who they met frequently, their co-workers, their driving route and their children.

The strongest corroboration came from what happened next. Google suspended the associated adtech firm’s authorised-buyer account and Microsoft terminated its access to Xandr.

Two of the largest companies in the industry cut off a participant over how the data was being used. That is an admission by conduct that the concern was real, and it is the clearest available evidence that the distinction between bidding and collecting is not enforced by the system itself.

What enforcement has actually achieved

The record is real, and narrower than the headlines suggest.

In December 2024 the US Federal Trade Commission acted against Mobilewalla and Gravy Analytics over precise location data, finalising the Mobilewalla order the following January. That order matters as precedent because it was the first time the agency treated collecting consumer data from real-time bidding exchanges, for purposes outside the auction itself, as an unfair practice.

In April 2025 the Department of Justice’s Data Security Program took effect. It restricts bulk transfers of six categories of sensitive personal data to six countries of concern, and it works more like export control than like privacy law. Two of those categories are covered personal identifiers and precise geolocation, which the rule defines as locating a device to within 1,000 metres. Bid requests routinely carry both. We have not confirmed that the rule names advertising data specifically, and we are not going to claim it does. What is verifiable is that the content of a bid request falls inside categories the US government now treats as a national security matter.

In Europe the Belgian proceedings over the advertising industry’s consent framework produced a €250,000 fine upheld by the Brussels Market Court in May 2025, after litigation measured in years.

And in March 2026 a federal judge granted final approval to the settlement in In re Google RTB Consumer Privacy Litigation. It is worth being precise about what that produced, because the coverage was not.

The settlement is injunctive relief only. No class member other than the named plaintiffs receives money. The figure of $21,856,239.22 that circulated as a headline settlement amount is the attorneys’ fee award. The much larger range quoted in some coverage was a claimed valuation of the injunctive relief in a filing, not a payment. What users actually got was a new control, launched on 24 April 2026, which limits what is transmitted about them in these auctions and which they have to switch on themselves.

The judge described the settlement as adequate but by no means excellent, and questioned how much would change given that people have to activate the control.

Five years of litigation over the largest routine personal-data transmission system in existence produced an opt-in toggle. Read that as a measure of how hard the flow is to reach with the levers currently available, rather than as a criticism of the plaintiffs, who won what there was to win.

Europe has a stronger right and the same wall

A European reader might reasonably assume none of this applies to them, because the GDPR erasure right is wider than anything in the DROP model. It is. Article 17 is not limited to companies that have registered themselves as data brokers. It applies to any controller holding personal data about you, which in principle includes every recipient of every bid request.

In principle. Exercising a right requires knowing who to serve it on.

The Californian mechanism is narrow and it works, because the state built a register and made the brokers join it. You do not have to know who holds your data, only that they are on the list. The European right is broad and hits the same wall from the opposite direction: it would cover the bidders, if you could name them. Nobody publishes the list of who received a bid request about you, and no part of the protocol requires anyone to.

A right you cannot aim is not the same as a right you do not have, but the practical distance between them is small.

The scale in Europe is lower than in the United States and not by much. The ICCL’s 2022 measurement put a European person’s data on the wire 376 times a day, against 747 in the US. Its companion 2023 report found the same categories of European defence personnel and political figures available in the same marketplaces.

Europe’s enforcement record on this is long rather than fast. Belgian proceedings against the advertising industry’s consent framework ran for years before the Brussels Market Court upheld a €250,000 fine in May 2025, and the underlying questions remain contested. The Irish regulator’s action on RTB took six years to produce a finding and is still being litigated.

Six years is longer than the useful life of most of the data in dispute.

The operational conclusion for a European reader arrives by a different route and lands in the same place. Erasure requests remain the right tool against brokers, people-search platforms and any controller you can identify. They do not reach the auction. An auction does not produce a defendant.

Why California DROP and the bid request never meet

Set the tools against the exposures they were built for.

MechanismWhat it isReachable by a deletion right?
Data broker recordA stored record held by a registered companyYes. This is exactly what California DROP and GDPR erasure are for
People-search profileA published, publicly viewable listingYes. Opt-outs work and the effect is visible, though slower than it should be, for the reasons set out in why data broker opt-outs are built around friction
Search resultA page ranking for your nameYes, and a separate problem: search result removal is not data removal
RTB bid requestA transient broadcast of bidstream data to a large number of recipients, none of whom is registered as a broker, none of whom has a retention duty to you, most of whom you cannot nameNo. There is no holder to serve, and no record to delete
Data clean roomA profile rebuilt on demand without being retainedPartly, and a different mechanism: data clean rooms rebuild profiles without storing them
Browser and device fingerprintDerived fresh from signals your device emitsNo. Nothing is stored, so there is nothing to delete

The first three categories are where deletion rights work, and they are where most of the public conversation sits. They are also where we do most of our removal work, because it is the part that responds to being worked on.

The lower half describes a different shape of problem rather than a gap in anyone’s diligence. You cannot delete your way out of a broadcast, because deletion assumes a custodian and a broadcast has none.

This is also why an exposure assessment that consists of checking your name against a list of brokers will always read cleaner than reality. The list is finite and knowable. The set of entities that received a bid request about you last Tuesday is neither.

This distinction runs through how we scope work. Broker records and people-search listings are observable from outside. They can be found, documented and pursued, and the result checked afterwards. What a bid request carried about you is not observable from outside at all. We can describe the mechanism and reduce what feeds it. We cannot enumerate the recipients, and neither can anyone else selling you a report that implies otherwise.

The broker layer is the half of this that still answers to a removal request, and it is the half that rebuilds fastest if nobody is working on it.

Reduce the broker records that can still be removed

What this actually means for you

Use California DROP if you are a Californian. It is genuinely the strongest mechanism available and it addresses the largest reachable part of the problem. Use GDPR erasure and opt-outs if you are in Europe. None of what follows is a reason to skip any of that.

Then be accurate about the residue.

The reducible part is mostly at the collection end, before anything is broadcast. Reset the advertising identifier on your phone and do it on a schedule rather than once. Audit which applications hold location permission, and reduce “always” to “while using” or to nothing. Ad-supported mobile apps are the highest-volume contributors here, and removing one you do not use is worth more than any request you can file afterwards. This sits inside the wider location ad-tracking layer, which is where the identifiers in a bid request come from in the first place. Where a platform offers a control over what is transmitted in these auctions, including the one Google launched in April, switching it on is a small and worthwhile action.

The irreducible part is what has already gone out. It is not recallable, there is no register of who holds it and no request will retrieve it. Anyone who tells you otherwise is selling something.

For most people that residue is a diffuse commercial nuisance. For a smaller group it is not. If your role places you in one of the segments described above, or your household is adjacent to someone whose role does, the exposure is not an advertising problem. It is a targeting problem, and it is the reason we treat protective work and removal work as separate exercises rather than as one service with two names.

From 1 August 2026 a deletion request reaches further into the broker layer than it did before. It still stops where records end and broadcasts begin. Nothing in the current regulatory record suggests that boundary is about to move.

Sources

  1. California Privacy Protection Agency. Delete Act regulations and the Delete Request and Opt-Out Platform. cppa.ca.gov; regulations approved, 13 November 2025.
  2. California Senate Bill 362 (Delete Act), 2023. Statute text.
  3. IAB Tech Lab. “OpenRTB” specification and implementation guidance. iabtechlab.com.
  4. Ryan, J., Christl, W. “America’s hidden security crisis.” Irish Council for Civil Liberties, November 2023. PDF.
  5. Ryan, J., Christl, W. “Europe’s hidden security crisis.” Irish Council for Civil Liberties, November 2023. PDF.
  6. ICCL Enforce. Real-Time Bidding research and the 2022 scale measurement. enforce.ie/rtb.
  7. Vines, P., Roesner, F., Kohno, T. “Exploring ADINT: Using Ad Targeting for Surveillance on a Budget.” ACM Workshop on Privacy in the Electronic Society, 2017. DOI 10.1145/3139550.3139567. PDF.
  8. US Federal Trade Commission. Action against Mobilewalla for collecting and selling sensitive location data, December 2024. Press release.
  9. US Department of Justice, National Security Division. Data Security Program, 28 CFR Part 202. justice.gov/nsd/data-security.
  10. In re Google RTB Consumer Privacy Litigation, N.D. Cal., No. 4:21-cv-02155-YGR. Docket.
  11. EPIC and ICCL Enforce. Complaint to the Federal Trade Commission In re Google’s RTB Practices, January 2025. epic.org.

If this is your situation

If you want long-term removal across the broker ecosystem, the Eraser runs the multi-week purge.

Reduce broker exposure Request a free Snapshot Scan

Share this briefing

If this was useful, sharing it helps others protect themselves. It also helps keep the intelligence briefings free.

Or get the quarterly intelligence brief — significant breaches, OSINT technique shifts, and executive privacy risks, once a quarter. Read the briefing →