TC

Microsoft-owned adtech Xandr accused of EU privacy breaches

Comment

Image Credits: David Paul Morris/Bloomberg / Getty Images

An adtech business owned by Microsoft is the target of a complaint backed by European privacy advocacy group, noyb — a nonprofit that punches far above its weight when it comes to chalking up strikes against data protection-infringing tech giants.

For its latest action, noyb is supporting an unnamed individual in Italy to lodge a complaint against Xandr with the country’s data protection authority. The complaint has been filed under the European Union’s General Data Protection Regulation (GDPR) — meaning, if it prevails, it could lead to fines of up to 4% of Xandr’s parent entity’s Microsoft’s global annual turnover.

Xandr stands accused of transparency failings and breaches of the data access rights to people in the bloc whose information is processed to create profiles that are used for microtargeted advertising sold through programmatic ad auctions. The complaint also contends the adtech company is using inaccurate information about people.

Specifically, noyb alleges Xandr is breaching Articles 5(1)(c) and (d); 12(2); 15 and 17 of the GDPR.

The complaint asks the data protection authority to investigate and, if breaches are confirmed, to order Xandr to come into compliance. noyb is also suggesting it should impose a fine of up to 4% of annual revenue on Xandr’s parent (NB: Microsoft’s full year revenue for 2023 was close to $212 billion).

Acquiring regulatory risk?

Microsoft picked up at the “data-enabled technology platform,” as it called Xandr, at the back end of 2021, to expand its digital advertising business, though Xandr retained its structural autonomy and operates as a separate entity. Microsoft’s press release at the time talked of the acquisition enhancing its “retail media solutions,” as well as touting “strengthened monetization for publishers through larger first-party data access and a full funnel marketing offering.” It did not mention the prospect of amped up regulatory risk flowing from the acquisition.

The problem, according to the noyb-backed complaint, is that Xandr is failing to respond to any data access requests from individuals wanting their personal information deleted or corrected. The complaint links to a “hidden” web page where it says Xandr publishes data access metrics. Per this page, between January 1, 2022, and December 31, 2022, the company received 1,294 access requests and 600 deletion requests — but denied every single one.

A explanatory note on the web page states: “Access and deletion requests are denied when we are unable to verify the identity and jurisdiction of the requestor. Due to the pseudonymous nature of the data Xandr collects on its Platform, we are unable to verify the identity of the consumers who made access and deletion requests when such requests are not tied to any other identifiers, and therefore we denied such requests.”

So Xandr appears to be claiming it doesn’t have to comply with GDPR data access rights because the information it holds on individuals is pseudonymous.

However, the complaint argues it is not credible for a company whose entire business hinges on profiling individuals for targeted advertising profit to claim it cannot identify the people whose information it holds.

Commenting in a statement, Massimiliano Gelmi, data protection lawyer at noyb, said: “Xandr’s business is obviously based on keeping data on millions of Europeans and targeting them. Still, the company admits that it has a 0% response rate to access and erasure requests. It is astonishing that Xandr even publicly illustrates how it breaches the GDPR.”

It’s worth noting that the GDPR takes an expansive view on what constitutes personal data and data that has undergone pseudonymization remains personal data — meaning those holding such info must abide by Pan-EU legal requirements such as providing data access rights.

Guidelines on data subject access rights adopted by the European Data Protection Board (EDPB) last year include an illustrative example from the realm of microtargeted advertising in which the Board points out an adtech company should be able to “precisely identify” an individual who is requesting access to their personal data from the same terminal equipment as is linked to their advertising profile (i.e., through cookies dropped on it) since “a link between the data processed and the data subject can be found.”

If an individual requests their data in another way, say by email, the EDPB guidance suggests the adtech company should request additional info from them in order to identify the relevant advertising profile and fulfill their data access request. Specifically the guidance says an individual would need to provide the cookie identifier stored in their terminal equipment.

It’s not clear what steps Xandr took to identify the ad profiles of the people requesting access to or deletion of their data.

Returning to the complaint, noyb’s research also unearthed what appears to be high levels of inaccuracy within the info Xandr holds on individuals — which may raise separate questions for its customers about the quality of its ad targeting services. But it also has legal significance given the GDPR furnishes individuals with the right to rectification of incorrect data held about them.

EU people can rely on the GDPR for other rights, too, including the ability to ask for a copy of their data. Again, noyb alleges this is another area where Xandr isn’t compliant. It wasn’t able to get a copy of the complainant’s data from Xandr itself but rather used a subject access request to one of its data broker suppliers.

“Thanks to an access request with the data broker — and Xandr supplier — emetriq, we know that at least part of Xandr’s database consists of wildly inaccurate and contradictory personal data about people,” it writes in a press release. “According to emetriq, the complainant is both male and female, has an estimated age between 16-19, 20-29, 30-39, 40-49, 50-59 and 60+. The complainant also has an income between €500-€1,500, €1,500-€2,500 and €2,500-€4,000. Furthermore, the same person is looking for a job, is employed, a student, a pupil and works in a company. That company, in turn, employs 1-10, 1,000+ and 1,100-5,000 people at the same time.”

“It is hard to imagine how these data categories can be used for accurate ad targeting,” noyb adds. “Although emetriq isn’t the only data broker supplying data to Xandr, it has to be assumed that this information is used for ad targeting.”

Commenting further, Gelmi also wrote: “It seems that parts of the advertising industry don’t really care about providing advertisers with accurate information. Instead, the data set contains a chaotic variety of conflicting information. This can potentially benefit companies like Xandr as they can sell the same user as young and old to different business partners.”

Microsoft has been contacted for a response to the complaint.

A spokesperson for noyb told us it does not expect the complaint to be referred from Italy to Irish data protection authorities, under the GDPR’s one-stop-shop process, because Xandr is established in the U.S. This corporate structure suggests the adtech firm could be targeted with further complaints in other EU member states where it has processed locals’ data — further dialing up regulatory risk.

The noyb-backed complaint highlights previous research it said has shown Xandr collects highly sensitive information about individuals for ad profiling purposes, such as data about their sex life or sexual orientation, religious beliefs and political opinions. The GDPR sets a particularly high bar — of explicit consent — for legally processing sensitive categories of data.

It’s not clear how such consents would have been obtained from individuals whose data Xandr holds. But visitors to websites may be one source of information as tracking for ads can be triggered by people accessing publishers’ content. In the EU such sites should ask visitors for their permission to tracking; however, industry standard mechanisms for obtaining people’s consent are themselves accused of breaching the GDPR.

More TechCrunch

With President Joe Biden dropping out of the race, Vice President Kamala Harris may become the Democrats’ new nominee. In announcing his plans, Biden offered his “full support and endorsement…

What Kamala Harris has said about AI, tech regulation, and more

U.S. President Joe Biden has announced he no longer plans to seek reelection, a decision that follows weeks of growing pressure from some Democratic Party supporters, including high-profile tech investors…

Joe Biden drops out of presidential race

Google is expected to announce four Pixel devices: the Pixel 9, Pixel 9 Pro, Pixel 9 Pro XL and Pixel 9 Pro Premium, running Android 15.

Made by Google 2024: Pixel 9, Gemini, a new foldable and other things to expect from the event

WazirX, one of India’s largest cryptocurrency exchanges, has “temporarily” suspended all trading activities on its platform days after losing about $230 million, nearly half of its reserves, in a security…

WazirX halts trading after $230 million ‘force majeure’ loss

Featured Article

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Subject to shareholder approval, Yandex N.V. is adopting the name of one of its few remaining assets, an AI cloud platform called Nebius AI which it birthed last year.

From Yandex’s ashes comes Nebius, a ‘startup’ with plans to be a European AI compute leader

Employees at Bethesda Game Studios — the Microsoft-owned game developer that produces the Elder Scrolls and Fallout franchises — are joining the Communication Workers of America. Quality assurance testers at…

Bethesda Game Studios employees form a ‘wall-to-wall’ union

This week saw one of the most widespread IT disruptions in recent years linked to a faulty software update from popular cybersecurity firm CrowdStrike. Businesses across the world reported IT…

CrowdStrike’s update fail causes global outages and travel chaos

Alphabet, the parent company of Google, is in advanced talks to acquire cybersecurity startup Wiz for $23 billion, the Wall Street Journal reported on Sunday. TechCrunch’s sources heard similar and…

Unpacking how Alphabet’s rumored Wiz acquisition could affect VC

Around 8.5 million devices — less than 1 percent Windows machines globally — were affected by the recent CrowdStrike outage, according to a Microsoft blog post by David Weston, the…

Microsoft says 8.5M Windows devices were affected by CrowdStrike outage

Featured Article

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Trump is an advocate for a number of policies that could be harmful to people of color.

Some Black startup founders feel betrayed by Ben Horowitz’s support for Trump

Featured Article

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

TechCrunch sat down with Strava’s new CEO in London for a wide-ranging interview, delving into what the company is prioritizing, and what we can expect in the future as the company embarks on its “next chapter.”

Strava’s next chapter: New CEO talks AI, inclusivity, and why ‘dark mode’ took so long

Featured Article

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

All week at the RNC, I saw an event defined by Silicon Valley. But I also saw the tech elite experience flashes of discordance.

Lavish parties and moral dilemmas: 4 days with Silicon Valley’s MAGA elite at the RNC

Featured Article

Tracking the EV battery factory construction boom across North America

A wave of automakers and battery makers — foreign and domestic — have pledged to produce North American–made batteries before 2030.

Tracking the EV battery factory construction boom across North America

Featured Article

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

Security giant CrowdStrike said the outage was not caused by a cyberattack, as businesses anticipate widespread disruption.

Faulty CrowdStrike update causes major global IT outage, taking out banks, airlines and businesses globally

CISA confirmed the CrowdStrike outage was not caused by a cyberattack, but urged caution as malicious hackers exploit the situation.

US cyber agency CISA says malicious hackers are ‘taking advantage’ of CrowdStrike outage

The global outage is a perfect reminder how much of the world relies on technological infrastructure.

These startups are trying to prevent another CrowdStrike-like outage, according to VCs

The CrowdStrike outage that hit early Friday morning and knocked out computers running Microsoft Windows has grounded flights globally. Major U.S. airlines including United Airlines, American Airlines and Delta Air…

CrowdStrike outage: How your plane, train and automobile travel may be affected

Prior to the ban, Trump’s team used his channel to broadcast some of his campaigns. With the ban now lifted, his channel can resume doing so.

Twitch reinstates Trump’s account ahead of the 2024 presidential election

This week, Google is in discussions to pay $23 billion for cloud security startup Wiz, SoftBank acquires Graphcore, and more.

M&A activity heats up with Wiz, Graphcore, etc.

CrowdStrike competes with a number of vendors, including SentinelOne and Palo Alto Networks but also Microsoft, Trellix, Trend Micro and Sophos, in the endpoint security market.

CrowdStrike’s rivals stand to benefit from its update fail debacle

The IT outage may have an unexpected effect on the climate: clearer skies and maybe lower temperatures this evening

CrowdStrike chaos leads to grounded aircraft — and maybe an unusual weather effect

There’s a man in Florida right now who wants to propose to his girlfriend while they’re on a beach vacation. He couldn’t get the engagement ring before he flew down…

The CrowdStrike outage is a plot point in a rom-com 

Here’s everything you need to know so far about the global outages caused by CrowdStrike’s buggy software update.

What we know about CrowdStrike’s update fail that’s causing global outages and travel chaos

This serves as an example for how easy it is to spread inaccurate information online during a time of immense global confusion and panic.

From the Sphere to false cyberattack claims, misinformation runs rampant amid CrowdStrike outage

Today is the final chance to save up to $800 on TechCrunch Disrupt 2024 tickets. Disrupt Deal Days event will end tonight at 11:59 p.m. PT. Don’t miss out on…

Last chance today: Secure major savings for TechCrunch Disrupt 2024!

Indian fintech Paytm’s struggles won’t seem to end. The company on Friday reported that its revenue declined by 36% and its loss more than doubled in the first quarter as…

Paytm loss widens and revenue shrinks as it grapples with regulatory clampdown

J. Michael Cline, the co-founder of Fandango and multiple other startups over his multi-decade career, died after falling from a Manhattan hotel, New York’s Deputy Commissioner of Public Information tells…

Fandango founder dies in fall from Manhattan skyscraper

Venture capital giant a16z fixed a security vulnerability in one of the firm’s websites after being warned by a security researcher.

Researcher finds flaw in a16z website that exposed some company data

Apple on Thursday announced its upcoming lineup of immersive video content for the Vision Pro. The list includes behind-the-scenes footage of the 2024 NBA All-Star Weekend, an immersive performance by…

Apple Vision Pro debuts immersive content featuring NBA players, The Weeknd and more

Biden centering Musk in his campaign is a notable escalation, considering he spent most of his presidency seemingly pretending the billionaire didn’t exist.

Elon Musk is now a villain in Joe Biden’s presidential campaign