TC

Microsoft-owned adtech Xandr accused of EU privacy breaches

Comment

Image Credits: David Paul Morris/Bloomberg / Getty Images

An adtech business owned by Microsoft is the target of a complaint backed by European privacy advocacy group, noyb — a nonprofit that punches far above its weight when it comes to chalking up strikes against data protection-infringing tech giants.

For its latest action, noyb is supporting an unnamed individual in Italy to lodge a complaint against Xandr with the country’s data protection authority. The complaint has been filed under the European Union’s General Data Protection Regulation (GDPR) — meaning, if it prevails, it could lead to fines of up to 4% of Xandr’s parent entity’s Microsoft’s global annual turnover.

Xandr stands accused of transparency failings and breaches of the data access rights to people in the bloc whose information is processed to create profiles that are used for microtargeted advertising sold through programmatic ad auctions. The complaint also contends the adtech company is using inaccurate information about people.

Specifically, noyb alleges Xandr is breaching Articles 5(1)(c) and (d); 12(2); 15 and 17 of the GDPR.

The complaint asks the data protection authority to investigate and, if breaches are confirmed, to order Xandr to come into compliance. noyb is also suggesting it should impose a fine of up to 4% of annual revenue on Xandr’s parent (NB: Microsoft’s full year revenue for 2023 was close to $212 billion).

Acquiring regulatory risk?

Microsoft picked up at the “data-enabled technology platform,” as it called Xandr, at the back end of 2021, to expand its digital advertising business, though Xandr retained its structural autonomy and operates as a separate entity. Microsoft’s press release at the time talked of the acquisition enhancing its “retail media solutions,” as well as touting “strengthened monetization for publishers through larger first-party data access and a full funnel marketing offering.” It did not mention the prospect of amped up regulatory risk flowing from the acquisition.

The problem, according to the noyb-backed complaint, is that Xandr is failing to respond to any data access requests from individuals wanting their personal information deleted or corrected. The complaint links to a “hidden” web page where it says Xandr publishes data access metrics. Per this page, between January 1, 2022, and December 31, 2022, the company received 1,294 access requests and 600 deletion requests — but denied every single one.

A explanatory note on the web page states: “Access and deletion requests are denied when we are unable to verify the identity and jurisdiction of the requestor. Due to the pseudonymous nature of the data Xandr collects on its Platform, we are unable to verify the identity of the consumers who made access and deletion requests when such requests are not tied to any other identifiers, and therefore we denied such requests.”

So Xandr appears to be claiming it doesn’t have to comply with GDPR data access rights because the information it holds on individuals is pseudonymous.

However, the complaint argues it is not credible for a company whose entire business hinges on profiling individuals for targeted advertising profit to claim it cannot identify the people whose information it holds.

Commenting in a statement, Massimiliano Gelmi, data protection lawyer at noyb, said: “Xandr’s business is obviously based on keeping data on millions of Europeans and targeting them. Still, the company admits that it has a 0% response rate to access and erasure requests. It is astonishing that Xandr even publicly illustrates how it breaches the GDPR.”

It’s worth noting that the GDPR takes an expansive view on what constitutes personal data and data that has undergone pseudonymization remains personal data — meaning those holding such info must abide by Pan-EU legal requirements such as providing data access rights.

Guidelines on data subject access rights adopted by the European Data Protection Board (EDPB) last year include an illustrative example from the realm of microtargeted advertising in which the Board points out an adtech company should be able to “precisely identify” an individual who is requesting access to their personal data from the same terminal equipment as is linked to their advertising profile (i.e., through cookies dropped on it) since “a link between the data processed and the data subject can be found.”

If an individual requests their data in another way, say by email, the EDPB guidance suggests the adtech company should request additional info from them in order to identify the relevant advertising profile and fulfill their data access request. Specifically the guidance says an individual would need to provide the cookie identifier stored in their terminal equipment.

It’s not clear what steps Xandr took to identify the ad profiles of the people requesting access to or deletion of their data.

Returning to the complaint, noyb’s research also unearthed what appears to be high levels of inaccuracy within the info Xandr holds on individuals — which may raise separate questions for its customers about the quality of its ad targeting services. But it also has legal significance given the GDPR furnishes individuals with the right to rectification of incorrect data held about them.

EU people can rely on the GDPR for other rights, too, including the ability to ask for a copy of their data. Again, noyb alleges this is another area where Xandr isn’t compliant. It wasn’t able to get a copy of the complainant’s data from Xandr itself but rather used a subject access request to one of its data broker suppliers.

“Thanks to an access request with the data broker — and Xandr supplier — emetriq, we know that at least part of Xandr’s database consists of wildly inaccurate and contradictory personal data about people,” it writes in a press release. “According to emetriq, the complainant is both male and female, has an estimated age between 16-19, 20-29, 30-39, 40-49, 50-59 and 60+. The complainant also has an income between €500-€1,500, €1,500-€2,500 and €2,500-€4,000. Furthermore, the same person is looking for a job, is employed, a student, a pupil and works in a company. That company, in turn, employs 1-10, 1,000+ and 1,100-5,000 people at the same time.”

“It is hard to imagine how these data categories can be used for accurate ad targeting,” noyb adds. “Although emetriq isn’t the only data broker supplying data to Xandr, it has to be assumed that this information is used for ad targeting.”

Commenting further, Gelmi also wrote: “It seems that parts of the advertising industry don’t really care about providing advertisers with accurate information. Instead, the data set contains a chaotic variety of conflicting information. This can potentially benefit companies like Xandr as they can sell the same user as young and old to different business partners.”

Microsoft has been contacted for a response to the complaint.

A spokesperson for noyb told us it does not expect the complaint to be referred from Italy to Irish data protection authorities, under the GDPR’s one-stop-shop process, because Xandr is established in the U.S. This corporate structure suggests the adtech firm could be targeted with further complaints in other EU member states where it has processed locals’ data — further dialing up regulatory risk.

The noyb-backed complaint highlights previous research it said has shown Xandr collects highly sensitive information about individuals for ad profiling purposes, such as data about their sex life or sexual orientation, religious beliefs and political opinions. The GDPR sets a particularly high bar — of explicit consent — for legally processing sensitive categories of data.

It’s not clear how such consents would have been obtained from individuals whose data Xandr holds. But visitors to websites may be one source of information as tracking for ads can be triggered by people accessing publishers’ content. In the EU such sites should ask visitors for their permission to tracking; however, industry standard mechanisms for obtaining people’s consent are themselves accused of breaching the GDPR.

More TechCrunch

Google will spend an additional $5 billion on its self-driving subsidiary, Waymo, over the next few years, according to Ruth Porat, Google’s chief financial officer. Porat announced the commitment to…

Google to invest another $5B into Waymo

There is no fool proof way to prevent a buggy update like CrowdStrike’s, but there are best practices that could mitigate the fallout.

How to prevent your software update from being the next CrowdStrike

Spotify CEO Daniel Ek says the streaming service is still in the “early days” of its plans to bring hi-fi support to the platform. During the company’s earnings call on…

Spotify CEO says company is in ‘early days’ of hi-fi audio plans

Featured Article

A comprehensive list of 2024 tech layoffs

The tech layoff wave is still going strong in 2024. Following significant workforce reductions in 2022 and 2023, this year has already seen 60,000 job cuts across 254 companies, according to independent layoffs tracker Layoffs.fyi. Companies like Tesla, Amazon, Google, TikTok, Snap and Microsoft have conducted sizable layoffs in the…

A comprehensive list of 2024 tech layoffs

Tesla was not the first company to begin working on a humanoid form factor, but while being the first to market does carry weight in this high-tech space, we’re at…

Elon Musk sets 2026 Optimus sale date. Here’s where other humanoid robots stand.

Harvey, a startup building what it describes as an AI-powered “copilot” for lawyers, has raised $100 million in a Series C round led by GV, Google’s corporate venture arm. The…

OpenAI-backed legaltech startup Harvey raises $100M

Digital banking startup Mercury informed some founders that it is no longer serving customers in certain countries, including Ukraine.

Digital banking startup Mercury abruptly shuttered service for startups in Ukraine, Nigeria, other countries

Welcome to TechCrunch Fintech! This week, we’re looking at Human Interest’s path toward an IPO, fintech’s newest unicorn, a slew of new fundraises, and more. To get a roundup of…

The next fintech to go public may not be the one you expected

Waymo has started testing a new robotaxi built by Chinese electric automaker Zeekr on public roads in San Francisco.  Waymo has “less than a handful” of the Zeekr vehicles in…

The Waymo-Zeekr robotaxi has come to San Francisco

The transaction values Cyabra at $70 million, and the company expects the merger to close by the end of the year.

Cyabra, a startup helping companies and governments detect disinformation, plans to go public via SPAC

Featured Article

There’s a lot more to the Kamala Harris memes than you think

“You think you just fell out of a coconut tree?” says Vice President Kamala Harris in a now infamous clip. An overlay of the lime green album art for Charli XCX’s “Brat” flashes on the screen, while a remix of “Von Dutch” scores increasingly frenetic clips of Harris hysterically laughing…

There’s a lot more to the Kamala Harris memes than you think

GM’s self-driving car subsidiary Cruise is scrapping plans to build the Origin — a purpose-built robotaxi with no steering wheel or pedals — and will instead use the next-generation Chevrolet Bolt…

GM’s Cruise abandons Origin robotaxi, takes $583 million charge

The Federal Trade Commission announced on Tuesday that it’s ordering eight companies that offer AI-powered “surveillance service pricing” to turn over information about the potential impact these products have on…

FTC is investigating how companies are using AI to base pricing on consumer behavior

Meta AI, Meta’s AI-powered assistant across Facebook, Instagram, Messenger and the web, can now speak in more languages and create stylized selfies. And, starting today, Meta AI users can route…

Meta AI gets new ‘Imagine me’ selfie feature

Mesa, Arizona-based Rosotics has kept a low profile. From the startup’s website, one would think they are solely focused on selling large metal 3D printers to aerospace and defense customers.…

Rosotics wants to manufacture massive orbital shipyards using 3D printing

Meta’s latest open source AI model is its biggest yet. Today, Meta said it is releasing Llama 3.1 405B, a model containing 405 billion parameters. Parameters roughly correspond to a…

Meta releases its biggest ‘open’ AI model yet

Hustle culture is embedded into the Silicon Valley startup ethos, but the expectation to grind all the time can be detrimental to a founder’s mental health. We’re pleased to welcome…

Andy Dunn talks the importance of founder mental health at TechCrunch Disrupt 2024

Meta has been given until September 1 to respond to consumer protection concerns in the European Union. The Consumer Protection Cooperation (CPC) Network, a network of authorities responsible for the…

Meta given weeks to tell EU consumer protection authorities how it’ll fix ‘pay or consent’

Google is no longer proposing to deprecate third-party tracking cookies in Chrome, instead suggesting that users be given an option to deny tracking.

Google’s latest Privacy Sandbox gambit could pit user choice against tracking

Let’s start with the premise that many people take notes as they work with customers as part of their jobs. As they take notes, they may need to access a…

Noded AI wants to make your notes the center of your work world

Nathan Rosenberg, the founder of farm automation platform Farmblox, said if there is one thing to know about trying to sell technology to farmers, it’s that you can’t tell them…

Farmblox puts the control into farmers’ hands with its AI-powered sensor-reading platform

Platforms like TikTok and Spotify have experimented with events on their platforms. But rather than concentrating on concerts and large gatherings, event startup Posh is focusing on intimate gatherings of…

Posh raises $22M to become TikTok for small events

Adobe released new Firefly tools for Photoshop and Illustrator on Tuesday, offering graphic designers more ways to use the company’s in-house AI models. Adobe’s new features let creative workers describe…

Adobe releases new Firefly AI tools for Illustrator and Photoshop

Grocery app Flashfood’s new offering is designed for independently owned grocery stores that want to reduce food waste and consumers who want to save money. 

Flashfood users can now save money on groceries at their local grocery store in addition to bigger chains

Quality assurance in the app development world is a necessary, but often resource-draining, undertaking. According to Statista, 23% of companies’ annual IT budgets are allocated to in-house or third-party contracted…

QA Wolf secures $36M to grow its app QA-testing suite

Level AI offers a suite of AI-powered tools to automate various customer service tasks.

Level AI applies algorithms to contact center pain points

In spite of maintaining stealth until now, Mytra has already drummed up interest with big names. The startup has a pilot with grocery giant Albertsons, among others.

Former Tesla humanoid head launches a robotics startup

An English school has been reprimanded by U.K. regulators after it used facial recognition technology without getting opt-in consent from students.

UK school reprimanded for unlawful use of facial-recognition technology

McGowan said she founded the company due to the rapid rise in cyber attacks these past years and the increased fears people have about cybersecurity.

After a 30-year career in IT, Protexxa founder raises $7.2M for cybersecurity employee hygiene

Featured Article

Legal tech Clio raises $900M at a $3B valuation, plans to double down on AI and fintech

Clio, a Canadian software company that aims to help law practices run more efficiently with its cloud-based technology, has raised $900 million in a Series F round that values the company at $3 billion. The valuation is nearly double the $1.6 billion valuation the Vancouver, British Columbia company achieved in…

Legal tech Clio raises $900M at a $3B valuation, plans to double down on AI and fintech