Digiday Publishing Summit:

Hear from execs at The New York Times, Thomson Reuters, Trusted Media Brands and many others

SECURE YOUR SEAT

How an ad tech firm co-opted IAB Europe’s Transparency and Consent Framework to collect fingerprinting data

IAB Europe’s heavily scrutinized Transparency and Consent Framework was designed to help companies respect people’s privacy and comply with European privacy law, the General Data Protection Regulation. But earlier this year, ad security monitoring company Confiant detected an ad tech company exploiting the framework to collect information on potentially millions of people in the U.S.

“What makes this case especially odd is that it was taking place in the United States, which is not a GDPR jurisdiction. And TCF is a framework for GDPR compliance,” said Kaileigh McCrea, a privacy engineer at Confiant.

McCrae declined to name the company behind the exploit — which Confiant has dubbed “Voldrakus” — beyond describing it as a small ad tech company based in Eastern Europe. She did, however, detail the mechanics of the exploit and explained how the data collected by the company — including devices’ geolocations, battery levels and motions — could be used to target people working in corporate buildings and government offices with misinformation and malware.

However, the risks extend beyond this specific exploit. Voldrakus provides an example of how a privacy framework can be co-opted and, as a result, put other companies at risk of violating privacy laws. 

“The brand is responsible for any type of tracking technology that is on its site,” said Daniel Goldberg, partner and chair of the privacy and data security group at law firm Frankfurt Kurnit Klein & Selz. He added, “The brand is the gatekeeper. So Voldrakus somehow or another is able to get data from the site, and so under the law, very technically speaking, the brand could be held liable for the data that is collected and pass to Voldrakus.”

For more about the Voldrakus exploit, watch the video below.

More in Marketing

How brands like Staples, JanSport, Nuuly are targeting crucial Gen Z cohort in back-to-school period

With consumer spending confidence doubtful the pressure on marketers to make the most out of the back-to-schools season is even higher than usual.

Warby Parker joins brands that have killed home try-on in favor of virtual tests

This story was originally published on sister site, Modern Retail. The end may be near for at-home try-on programs. Warby Parker, the eyewear brand that helped pioneer online glasses sales in the 2010s, said last Thursday on its quarterly earnings call that it would end its home try-on program by the end of the year. […]

Forget about the tech, OpenAI and Perplexity are brands too

Both platforms reminded everyone that in 2025, AI isn’t just about tech. It’s about brand. And when companies forget that, the fallout is fast and public.