Behavioral Advertising Restrictions .
Behavioral Advertising Restrictions — Detailed Explanation With Case Laws
1. Meaning of Behavioral Advertising
Behavioral advertising means showing advertisements based on information about a person's or group's past or predicted behavior.
Examples include advertising based on:
- websites visited;
- searches;
- app activity;
- purchases;
- location information;
- device identifiers;
- viewing history;
- inferred interests;
- browsing patterns; or
- interactions with advertisements.
A simple example is:
A person repeatedly searches for running shoes → an advertising platform records the activity → the platform predicts an interest in sports products → advertisements for running shoes are displayed on other websites or applications.
Behavioral advertising is therefore different from ordinary contextual advertising.
Contextual advertising
The advertisement is based primarily on the content currently being viewed.
Example:
User reads an article about cameras → camera advertisement appears.
Behavioral advertising
The advertisement is based on information about the user's broader activity.
Example:
User searched for cameras yesterday and visited several camera websites → camera advertisements appear today while the user reads unrelated news.
2. Why Governments Restrict Behavioral Advertising
Behavioral advertising can create several legal concerns:
privacy + consumer protection + discrimination + manipulation + children's protection + data security + transparency.
The central regulatory concern is not necessarily advertising itself.
Rather:
How was the personal information obtained, what was inferred from it, what consent or other legal basis exists, and how is the resulting profile used?
3. European Union — GDPR
The EU's General Data Protection Regulation (GDPR) provides one of the world's most important legal frameworks for behavioral advertising.
Relevant provisions include:
- Article 5 — data-processing principles;
- Article 6 — lawful bases;
- Article 7 — consent;
- Article 9 — special categories of personal data;
- Article 12–14 — transparency;
- Article 21 — right to object;
- Article 22 — automated individual decision-making;
- Article 25 — privacy by design/default;
- Article 35 — data-protection impact assessments.
Behavioral advertising can therefore trigger multiple GDPR requirements simultaneously.
4. Lawful Basis for Behavioral Advertising
A company cannot simply say:
"We want to show personalized advertisements."
It must identify a lawful basis for processing personal data.
Possible GDPR bases include:
- consent;
- contractual necessity;
- legal obligation;
- vital interests;
- public task; or
- legitimate interests.
For many forms of cross-site behavioral advertising, the lawful-basis analysis is particularly difficult.
Consent is frequently used where tracking technologies require prior permission.
5. Consent Must Be Genuine
Valid consent generally needs to be:
- freely given;
- specific;
- informed;
- unambiguous;
- capable of being withdrawn.
A company should not make the process deliberately confusing.
For example:
"Accept personalized advertising" — large obvious button
"Manage settings" — hidden link
"Reject all" — several screens away
may create questions concerning whether consent is genuinely freely given and informed.
6. Planet49 — CJEU
Bundesverband der Verbraucherzentralen und Verbraucherverbände v Planet49 GmbH
CJEU, Case C-673/17 (2019)
This is one of the most important European cases concerning online tracking.
The Court considered cookies used in connection with an online promotional service.
The CJEU held that consent for cookies could not validly be obtained through a pre-ticked checkbox.
The user had to actively consent.
Importance for behavioral advertising
Tracking technologies frequently form the technical foundation of behavioral advertising.
Therefore:
No valid tracking consent → potentially unlawful tracking → potentially unlawful behavioral advertising.
The case also reinforces the principle that consent must be an affirmative act rather than passive inaction.
7. Fashion ID — CJEU
Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW e.V.
Case C-40/17 (2019)
The CJEU considered a website operator embedding Facebook's "Like" button.
The embedded functionality could transmit visitors' personal data to Facebook.
The Court examined the respective responsibilities of the website operator and Facebook.
Significance
A company cannot necessarily avoid privacy obligations by saying:
"The tracking technology belongs to another advertising platform."
Where an organisation participates in the collection or transmission of personal data, it may have its own legal responsibilities.
This is highly relevant to:
- social-media pixels;
- advertising SDKs;
- retargeting technologies;
- analytics tools; and
- embedded advertising technology.
8. Meta Platforms — CJEU
Meta Platforms Ireland Ltd v Bundeskartellamt
Case C-252/21 (2023)
This case concerned Meta's combination of data from different sources for its Facebook service.
The CJEU examined the relationship between competition law and GDPR.
A particularly important point was that a company's dominant market position does not automatically make consent invalid, but the circumstances surrounding consent must be carefully examined.
Behavioral advertising significance
Large platforms often combine:
first-party data + third-party data + platform activity + inferred interests
to create advertising profiles.
The case demonstrates that competition-law considerations can intersect with privacy law when a dominant platform makes data processing central to its business model.
9. Special-Category Data
Article 9 GDPR gives additional protection to information concerning matters such as:
- health;
- political opinions;
- religion;
- racial or ethnic origin;
- biometric data for identification;
- sexual orientation.
Behavioral advertising based on sensitive characteristics creates substantially greater legal risk.
For example, an advertising platform inferring:
"This user probably has a particular medical condition"
and then using that inference for advertising may create serious GDPR issues.
The fact that the platform inferred the characteristic rather than receiving an explicit statement does not automatically eliminate the privacy concern.
10. Right to Object
Article 21 GDPR contains a particularly important rule for direct marketing.
Where personal data are processed for direct marketing, the individual has a right to object to such processing.
Once the objection is validly exercised, the processing for that direct-marketing purpose generally must stop.
This is an important practical difference from a simple "unsubscribe from email" mechanism.
Behavioral advertising can involve continuous profiling, so companies must have systems capable of respecting objections across relevant advertising operations.
11. Automated Decision-Making
Article 22 GDPR concerns certain automated decisions producing legal or similarly significant effects.
Ordinary behavioral advertising will not automatically constitute an Article 22 decision.
However, the risk becomes greater where profiling affects:
- credit;
- employment;
- insurance;
- housing;
- essential services; or
- other significant opportunities.
For example:
An algorithm profiles a consumer and determines that the consumer should receive less favorable credit terms.
That is much more legally significant than merely showing the person an advertisement for shoes.
12. Digital Services Act
The EU's Digital Services Act (DSA) adds platform-specific restrictions.
Particularly important are restrictions concerning:
Sensitive characteristics
Platforms cannot use certain categories of sensitive personal data for targeted advertising.
Children
Platforms are subject to stronger protections regarding advertising directed at minors.
Transparency
Platforms must provide information concerning the main parameters used for advertising targeting.
The DSA therefore complements the GDPR rather than replacing it.
13. Behavioral Advertising to Children
Children receive heightened legal protection.
The concern is that children may:
- have less understanding of advertising;
- have greater difficulty distinguishing persuasion from information;
- be more susceptible to manipulation;
- lack mature understanding of data collection.
Consequently, advertising systems that profile children require particular caution.
The EU DSA contains important restrictions concerning targeted advertising based on personal data of minors.
14. U.S. Legal Framework
The United States does not have one comprehensive federal equivalent of the GDPR.
Instead, behavioral advertising is governed through a combination of:
- Federal Trade Commission (FTC) enforcement;
- Children's Online Privacy Protection Act (COPPA);
- state privacy laws;
- sector-specific legislation;
- consumer-protection law;
- state unfair/deceptive acts laws.
15. FTC Act
Section 5 of the Federal Trade Commission Act prohibits:
- unfair methods of competition; and
- unfair or deceptive acts or practices.
The FTC can therefore challenge advertising practices where companies misrepresent:
- what data they collect;
- how data are used;
- whether users are tracked;
- whether consumers can opt out; or
- whether privacy protections actually exist.
16. FTC v. Wyndham Worldwide Corp.
FTC v. Wyndham Worldwide Corp., 799 F.3d 236 (3d Cir. 2015)
This important case concerned cybersecurity rather than behavioral advertising specifically.
The Third Circuit accepted that the FTC could bring an enforcement action under Section 5 concerning unreasonable cybersecurity practices.
Relevance
Behavioral advertising depends upon large-scale collection and processing of personal information.
A company that promises strong privacy/security protections but fails to implement them can therefore face regulatory exposure.
17. FTC v. Facebook
The FTC's enforcement actions against Facebook/Meta demonstrate the importance of truthful representations about privacy and data use.
A central regulatory concern has been whether the company's actual data practices match what consumers were told.
The general principle is:
Privacy representations made to consumers can themselves become legally enforceable consumer-protection commitments.
Thus, saying:
"We don't use your data for X"
while actually using the information for X can create substantial regulatory risk.
18. COPPA and Children's Behavioral Advertising
The Children's Online Privacy Protection Act (COPPA) is particularly important for services directed to children under 13 or that have actual knowledge they are collecting personal information from children under 13.
The law imposes requirements concerning:
- parental consent;
- notice;
- collection;
- disclosure;
- retention; and
- deletion of children's personal information.
Behavioral advertising based on children's personal information is therefore subject to particularly strong scrutiny.
19. FTC v. Musical.ly / TikTok
The FTC has taken enforcement action involving children's data collection by online video platforms, including Musical.ly/TikTok.
The broader lesson is that platforms cannot simply treat children's personal information like ordinary advertising data.
Where a service knows that children use the platform, COPPA compliance can become central to its advertising and data practices.
20. California CCPA/CPRA
California has one of the strongest state privacy regimes in the United States.
The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), addresses concepts particularly relevant to behavioral advertising.
California distinguishes between certain forms of:
- selling personal information; and
- sharing personal information for cross-context behavioral advertising.
Consumers have rights concerning such processing, including mechanisms to opt out.
This is important because a business can face legal obligations even where it does not literally "sell" a database for money.
21. Opt-Out of Sale/Sharing
California's framework gives consumers mechanisms to limit certain uses of personal information for cross-context behavioral advertising.
Businesses therefore need systems capable of recognizing:
- opt-out signals;
- consumer requests;
- browser-based privacy signals where applicable; and
- downstream restrictions on advertising partners.
A simple statement such as:
"We respect your privacy"
is insufficient if the technical advertising ecosystem continues to share information contrary to the consumer's valid choices.
22. EU vs U.S. Approach
| Issue | EU | U.S. |
|---|---|---|
| General privacy law | GDPR | Fragmented federal/state system |
| Tracking consent | Often central | Depends on law/context |
| Behavioral advertising | Highly regulated | Combination of FTC + state laws |
| Children's data | Strong restrictions | COPPA + state laws |
| Sensitive data | Special protection | Varies by jurisdiction |
| Profiling | GDPR rules | Sector/state-specific |
| Opt-out | Important | Increasingly important |
| Transparency | Extensive | FTC/state requirements |
23. Dark Patterns
Behavioral advertising restrictions increasingly overlap with dark-pattern regulation.
A dark pattern is a user-interface design that manipulates people into making choices they might not otherwise make.
Examples include:
- preselected tracking;
- misleading buttons;
- confusing privacy menus;
- repeated prompts;
- hiding the rejection option;
- making withdrawal substantially harder than acceptance.
The problem is especially significant where the design is used to obtain consent for advertising tracking.
24. FTC v. Amazon — Dark Patterns
FTC enforcement against major digital platforms has increasingly focused on interface design and consumer choice.
The underlying legal principle is:
A formally available opt-out may not be meaningful if the interface is deliberately designed to frustrate or manipulate consumers.
This is particularly relevant to cookie consent and personalized advertising.
25. Data Brokerage
Behavioral advertising can involve data brokers collecting information from multiple sources.
A consumer may never directly interact with the data broker.
For example:
Retail purchase → data broker → inferred interest → advertising exchange → targeted advertisement.
This raises questions about:
- notice;
- lawful basis;
- consumer rights;
- accuracy;
- sensitive-data inference;
- security; and
- downstream sharing.
26. Discriminatory Advertising
Behavioral advertising can also create algorithmic discrimination.
Suppose an advertising system learns that certain users are less likely to respond to particular housing advertisements.
The platform might unintentionally exclude certain demographic groups.
This can create issues under anti-discrimination law even if the advertiser never explicitly instructs the algorithm to discriminate.
Housing, employment and financial-services advertising are especially sensitive.
27. Case Law: Facebook and Discrimination
U.S. regulators and civil-rights authorities have examined targeted advertising systems where algorithmic targeting can restrict who sees advertisements for:
- housing;
- employment; or
- credit.
The legal lesson is significant:
Algorithmic neutrality does not necessarily eliminate discrimination risk.
An advertising system can create discriminatory outcomes through proxies or optimization even without explicitly targeting protected characteristics.
28. Financial Advertising
Behavioral advertising is especially sensitive in financial services.
Banks and fintech companies can use behavioral data to market:
- loans;
- credit cards;
- insurance;
- investment products;
- overdraft services.
If advertising algorithms use personal data to steer consumers toward financial products, additional consumer-finance and fair-lending rules can become relevant.
Potential legal frameworks include:
- Equal Credit Opportunity Act;
- Fair Housing Act;
- Fair Credit Reporting Act;
- FTC Act;
- state privacy laws.
29. Credit Advertising vs Credit Decision
A critical legal distinction is:
advertising a credit product
versus
deciding whether someone qualifies for credit.
The first may primarily involve advertising and privacy law.
The second can involve:
- credit discrimination;
- adverse-action requirements;
- automated decision-making;
- credit-reporting law;
- model governance.
Therefore, an advertising algorithm should not quietly become an underwriting algorithm without appropriate legal controls.
30. Compliance Framework
A company using behavioral advertising should establish:
Data inventory
Identify what information is collected.
Purpose limitation
Define why each category of information is needed.
Consent management
Record valid consent where required.
Opt-out mechanism
Allow consumers to withdraw or object where legally required.
Vendor management
Review advertising networks, analytics providers and data brokers.
Sensitive-data controls
Prevent prohibited targeting based on protected information.
Children's controls
Identify child-directed services and apply heightened protections.
Retention controls
Delete or anonymize information when it is no longer necessary.
Security
Protect behavioral profiles against unauthorized access.
Algorithmic testing
Test advertising systems for discriminatory outcomes.
Documentation
Maintain records demonstrating compliance.
31. Risk Matrix
| Risk | Example | Legal concern |
|---|---|---|
| No valid consent | Tracking before consent | GDPR/ePrivacy |
| Misleading privacy notice | Claiming data isn't shared when it is | Consumer protection |
| Sensitive-data targeting | Health-based advertising | GDPR/state privacy |
| Children's profiling | Personalized ads to children | DSA/COPPA |
| Dark patterns | Hidden rejection button | Consumer/privacy law |
| Excessive retention | Keeping profiles indefinitely | Data-minimization principles |
| Data-broker sharing | Unseen third-party profiling | Privacy/consumer law |
| Discriminatory targeting | Excluding groups from housing ads | Civil-rights law |
| Security failure | Advertising database breach | Privacy/security law |
| Invalid opt-out | Continuing targeted advertising | State/EU privacy rules |
32. Key Case Laws
| Case | Principle |
|---|---|
| Planet49, C-673/17 (CJEU, 2019) | Pre-ticked boxes do not establish valid cookie consent |
| Fashion ID, C-40/17 (CJEU, 2019) | Website operators can have responsibilities for data transmission through embedded tracking |
| Meta Platforms v Bundeskartellamt, C-252/21 (CJEU, 2023) | Data combination, consent and competition-law issues can intersect |
| FTC v Wyndham, 799 F.3d 236 (3d Cir. 2015) | FTC authority concerning unfair/deceptive data-security practices |
| Greenman v. Yuba Power Products (1963) | General product-liability principle; not directly an advertising case |
| FTC privacy enforcement actions against major platforms | Misrepresentations concerning collection/use of personal data can create consumer-protection liability |
33. Core Legal Principle
The modern legal approach can be summarized as:
Behavioral advertising is not inherently unlawful. The legality depends on the data involved, the method of collection, the legal basis, transparency, consumer choice, targeting criteria, age of the user, platform context, and applicable sector-specific restrictions.
A company should therefore ask five questions before launching a behavioral-advertising campaign:
- What data are we using?
- Where did the data come from?
- What legal basis permits the processing?
- Can the consumer meaningfully refuse or withdraw?
- Could the targeting produce prohibited or discriminatory outcomes?
If any of those questions cannot be answered clearly, the advertising campaign presents significant legal risk.
Bottom line
Behavioral advertising regulation is moving away from the simple question "Did the company collect the data?" toward a broader question:
"Was the consumer fairly informed, did the company have a lawful basis to use the data, was the targeting appropriate, and did the system respect meaningful consumer choice?"
For multinational businesses, the safest compliance model is to treat privacy, advertising, consumer protection, children's protection, discrimination and cybersecurity as interconnected controls rather than separate legal departments.

comments