Listed players
SST2.44▼ -7.58%TIG40.00▲ +3.90%TEAD0.56▲ +3.77%PERI8.50▼ -2.97%TBLA3.23▼ -2.71%INUV0.57▼ -1.74%AV10.06▼ -1.59%GOOGL343.50▲ +1.56%SNAP5.58▼ -1.24%PINS19.26▼ -1.03%MSFT517.53▲ +0.92%PPLI41.28▲ +0.81%IOS32.24▲ +0.44%META728.08▲ +0.30%GDDY97.21▲ +0.24%DV13.49▲ 0.00%MCHX1.29▲ 0.00%
Ticker byClearTrust

Does GDPR apply to search arbitrage?

Yes, if you have visitors from the EU or UK, wherever your company is based. Click IDs, cookies and device data are personal data. You need a lawful basis, normally consent collected through a consent banner, before setting most tracking and advertising cookies, and Google requires certified consent tools for ads served to those visitors.

Short answer · The Arbitrage Desk

GDPR and the related cookie rules affect both sides of the trade. On the buying side, passing visit data to a traffic source through a Conversions API is sharing personal data and needs a basis. On the selling side, Google requires publishers serving ads in the European Economic Area, UK and Switzerland to use a certified consent management platform.

Consent lowers measurable performance: visitors who decline cannot be tracked in the same way, and ads may be limited. That is one reason European RPV can lag. Other regions have their own laws, including US state privacy acts. A privacy policy, a working banner and a record of what data goes where are basic hygiene. Take advice for your own case.

Related questions