Behavioral Advertising Restrictions .

Behavioral Advertising Restrictions — Detailed Explanation With Case Laws

1. Meaning of Behavioral Advertising

Behavioral advertising means showing advertisements based on information about a person's or group's past or predicted behavior.

Examples include advertising based on:

  • websites visited;
  • searches;
  • app activity;
  • purchases;
  • location information;
  • device identifiers;
  • viewing history;
  • inferred interests;
  • browsing patterns; or
  • interactions with advertisements.

A simple example is:

A person repeatedly searches for running shoes → an advertising platform records the activity → the platform predicts an interest in sports products → advertisements for running shoes are displayed on other websites or applications.

Behavioral advertising is therefore different from ordinary contextual advertising.

Contextual advertising

The advertisement is based primarily on the content currently being viewed.

Example:

User reads an article about cameras → camera advertisement appears.

Behavioral advertising

The advertisement is based on information about the user's broader activity.

Example:

User searched for cameras yesterday and visited several camera websites → camera advertisements appear today while the user reads unrelated news.

2. Why Governments Restrict Behavioral Advertising

Behavioral advertising can create several legal concerns:

privacy + consumer protection + discrimination + manipulation + children's protection + data security + transparency.

The central regulatory concern is not necessarily advertising itself.

Rather:

How was the personal information obtained, what was inferred from it, what consent or other legal basis exists, and how is the resulting profile used?

3. European Union — GDPR

The EU's General Data Protection Regulation (GDPR) provides one of the world's most important legal frameworks for behavioral advertising.

Relevant provisions include:

  • Article 5 — data-processing principles;
  • Article 6 — lawful bases;
  • Article 7 — consent;
  • Article 9 — special categories of personal data;
  • Article 12–14 — transparency;
  • Article 21 — right to object;
  • Article 22 — automated individual decision-making;
  • Article 25 — privacy by design/default;
  • Article 35 — data-protection impact assessments.

Behavioral advertising can therefore trigger multiple GDPR requirements simultaneously.

4. Lawful Basis for Behavioral Advertising

A company cannot simply say:

"We want to show personalized advertisements."

It must identify a lawful basis for processing personal data.

Possible GDPR bases include:

  • consent;
  • contractual necessity;
  • legal obligation;
  • vital interests;
  • public task; or
  • legitimate interests.

For many forms of cross-site behavioral advertising, the lawful-basis analysis is particularly difficult.

Consent is frequently used where tracking technologies require prior permission.

5. Consent Must Be Genuine

Valid consent generally needs to be:

  • freely given;
  • specific;
  • informed;
  • unambiguous;
  • capable of being withdrawn.

A company should not make the process deliberately confusing.

For example:

"Accept personalized advertising" — large obvious button
"Manage settings" — hidden link
"Reject all" — several screens away

may create questions concerning whether consent is genuinely freely given and informed.

6. Planet49 — CJEU

Bundesverband der Verbraucherzentralen und Verbraucherverbände v Planet49 GmbH

CJEU, Case C-673/17 (2019)

This is one of the most important European cases concerning online tracking.

The Court considered cookies used in connection with an online promotional service.

The CJEU held that consent for cookies could not validly be obtained through a pre-ticked checkbox.

The user had to actively consent.

Importance for behavioral advertising

Tracking technologies frequently form the technical foundation of behavioral advertising.

Therefore:

No valid tracking consent → potentially unlawful tracking → potentially unlawful behavioral advertising.

The case also reinforces the principle that consent must be an affirmative act rather than passive inaction.

7. Fashion ID — CJEU

Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW e.V.

Case C-40/17 (2019)

The CJEU considered a website operator embedding Facebook's "Like" button.

The embedded functionality could transmit visitors' personal data to Facebook.

The Court examined the respective responsibilities of the website operator and Facebook.

Significance

A company cannot necessarily avoid privacy obligations by saying:

"The tracking technology belongs to another advertising platform."

Where an organisation participates in the collection or transmission of personal data, it may have its own legal responsibilities.

This is highly relevant to:

  • social-media pixels;
  • advertising SDKs;
  • retargeting technologies;
  • analytics tools; and
  • embedded advertising technology.

8. Meta Platforms — CJEU

Meta Platforms Ireland Ltd v Bundeskartellamt

Case C-252/21 (2023)

This case concerned Meta's combination of data from different sources for its Facebook service.

The CJEU examined the relationship between competition law and GDPR.

A particularly important point was that a company's dominant market position does not automatically make consent invalid, but the circumstances surrounding consent must be carefully examined.

Behavioral advertising significance

Large platforms often combine:

first-party data + third-party data + platform activity + inferred interests

to create advertising profiles.

The case demonstrates that competition-law considerations can intersect with privacy law when a dominant platform makes data processing central to its business model.

9. Special-Category Data

Article 9 GDPR gives additional protection to information concerning matters such as:

  • health;
  • political opinions;
  • religion;
  • racial or ethnic origin;
  • biometric data for identification;
  • sexual orientation.

Behavioral advertising based on sensitive characteristics creates substantially greater legal risk.

For example, an advertising platform inferring:

"This user probably has a particular medical condition"

and then using that inference for advertising may create serious GDPR issues.

The fact that the platform inferred the characteristic rather than receiving an explicit statement does not automatically eliminate the privacy concern.

10. Right to Object

Article 21 GDPR contains a particularly important rule for direct marketing.

Where personal data are processed for direct marketing, the individual has a right to object to such processing.

Once the objection is validly exercised, the processing for that direct-marketing purpose generally must stop.

This is an important practical difference from a simple "unsubscribe from email" mechanism.

Behavioral advertising can involve continuous profiling, so companies must have systems capable of respecting objections across relevant advertising operations.

11. Automated Decision-Making

Article 22 GDPR concerns certain automated decisions producing legal or similarly significant effects.

Ordinary behavioral advertising will not automatically constitute an Article 22 decision.

However, the risk becomes greater where profiling affects:

  • credit;
  • employment;
  • insurance;
  • housing;
  • essential services; or
  • other significant opportunities.

For example:

An algorithm profiles a consumer and determines that the consumer should receive less favorable credit terms.

That is much more legally significant than merely showing the person an advertisement for shoes.

12. Digital Services Act

The EU's Digital Services Act (DSA) adds platform-specific restrictions.

Particularly important are restrictions concerning:

Sensitive characteristics

Platforms cannot use certain categories of sensitive personal data for targeted advertising.

Children

Platforms are subject to stronger protections regarding advertising directed at minors.

Transparency

Platforms must provide information concerning the main parameters used for advertising targeting.

The DSA therefore complements the GDPR rather than replacing it.

13. Behavioral Advertising to Children

Children receive heightened legal protection.

The concern is that children may:

  • have less understanding of advertising;
  • have greater difficulty distinguishing persuasion from information;
  • be more susceptible to manipulation;
  • lack mature understanding of data collection.

Consequently, advertising systems that profile children require particular caution.

The EU DSA contains important restrictions concerning targeted advertising based on personal data of minors.

14. U.S. Legal Framework

The United States does not have one comprehensive federal equivalent of the GDPR.

Instead, behavioral advertising is governed through a combination of:

  • Federal Trade Commission (FTC) enforcement;
  • Children's Online Privacy Protection Act (COPPA);
  • state privacy laws;
  • sector-specific legislation;
  • consumer-protection law;
  • state unfair/deceptive acts laws.

15. FTC Act

Section 5 of the Federal Trade Commission Act prohibits:

  • unfair methods of competition; and
  • unfair or deceptive acts or practices.

The FTC can therefore challenge advertising practices where companies misrepresent:

  • what data they collect;
  • how data are used;
  • whether users are tracked;
  • whether consumers can opt out; or
  • whether privacy protections actually exist.

16. FTC v. Wyndham Worldwide Corp.

FTC v. Wyndham Worldwide Corp., 799 F.3d 236 (3d Cir. 2015)

This important case concerned cybersecurity rather than behavioral advertising specifically.

The Third Circuit accepted that the FTC could bring an enforcement action under Section 5 concerning unreasonable cybersecurity practices.

Relevance

Behavioral advertising depends upon large-scale collection and processing of personal information.

A company that promises strong privacy/security protections but fails to implement them can therefore face regulatory exposure.

17. FTC v. Facebook

The FTC's enforcement actions against Facebook/Meta demonstrate the importance of truthful representations about privacy and data use.

A central regulatory concern has been whether the company's actual data practices match what consumers were told.

The general principle is:

Privacy representations made to consumers can themselves become legally enforceable consumer-protection commitments.

Thus, saying:

"We don't use your data for X"

while actually using the information for X can create substantial regulatory risk.

18. COPPA and Children's Behavioral Advertising

The Children's Online Privacy Protection Act (COPPA) is particularly important for services directed to children under 13 or that have actual knowledge they are collecting personal information from children under 13.

The law imposes requirements concerning:

  • parental consent;
  • notice;
  • collection;
  • disclosure;
  • retention; and
  • deletion of children's personal information.

Behavioral advertising based on children's personal information is therefore subject to particularly strong scrutiny.

19. FTC v. Musical.ly / TikTok

The FTC has taken enforcement action involving children's data collection by online video platforms, including Musical.ly/TikTok.

The broader lesson is that platforms cannot simply treat children's personal information like ordinary advertising data.

Where a service knows that children use the platform, COPPA compliance can become central to its advertising and data practices.

20. California CCPA/CPRA

California has one of the strongest state privacy regimes in the United States.

The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), addresses concepts particularly relevant to behavioral advertising.

California distinguishes between certain forms of:

  • selling personal information; and
  • sharing personal information for cross-context behavioral advertising.

Consumers have rights concerning such processing, including mechanisms to opt out.

This is important because a business can face legal obligations even where it does not literally "sell" a database for money.

21. Opt-Out of Sale/Sharing

California's framework gives consumers mechanisms to limit certain uses of personal information for cross-context behavioral advertising.

Businesses therefore need systems capable of recognizing:

  • opt-out signals;
  • consumer requests;
  • browser-based privacy signals where applicable; and
  • downstream restrictions on advertising partners.

A simple statement such as:

"We respect your privacy"

is insufficient if the technical advertising ecosystem continues to share information contrary to the consumer's valid choices.

22. EU vs U.S. Approach

IssueEUU.S.
General privacy lawGDPRFragmented federal/state system
Tracking consentOften centralDepends on law/context
Behavioral advertisingHighly regulatedCombination of FTC + state laws
Children's dataStrong restrictionsCOPPA + state laws
Sensitive dataSpecial protectionVaries by jurisdiction
ProfilingGDPR rulesSector/state-specific
Opt-outImportantIncreasingly important
TransparencyExtensiveFTC/state requirements

23. Dark Patterns

Behavioral advertising restrictions increasingly overlap with dark-pattern regulation.

A dark pattern is a user-interface design that manipulates people into making choices they might not otherwise make.

Examples include:

  • preselected tracking;
  • misleading buttons;
  • confusing privacy menus;
  • repeated prompts;
  • hiding the rejection option;
  • making withdrawal substantially harder than acceptance.

The problem is especially significant where the design is used to obtain consent for advertising tracking.

24. FTC v. Amazon — Dark Patterns

FTC enforcement against major digital platforms has increasingly focused on interface design and consumer choice.

The underlying legal principle is:

A formally available opt-out may not be meaningful if the interface is deliberately designed to frustrate or manipulate consumers.

This is particularly relevant to cookie consent and personalized advertising.

25. Data Brokerage

Behavioral advertising can involve data brokers collecting information from multiple sources.

A consumer may never directly interact with the data broker.

For example:

Retail purchase → data broker → inferred interest → advertising exchange → targeted advertisement.

This raises questions about:

  • notice;
  • lawful basis;
  • consumer rights;
  • accuracy;
  • sensitive-data inference;
  • security; and
  • downstream sharing.

26. Discriminatory Advertising

Behavioral advertising can also create algorithmic discrimination.

Suppose an advertising system learns that certain users are less likely to respond to particular housing advertisements.

The platform might unintentionally exclude certain demographic groups.

This can create issues under anti-discrimination law even if the advertiser never explicitly instructs the algorithm to discriminate.

Housing, employment and financial-services advertising are especially sensitive.

27. Case Law: Facebook and Discrimination

U.S. regulators and civil-rights authorities have examined targeted advertising systems where algorithmic targeting can restrict who sees advertisements for:

  • housing;
  • employment; or
  • credit.

The legal lesson is significant:

Algorithmic neutrality does not necessarily eliminate discrimination risk.

An advertising system can create discriminatory outcomes through proxies or optimization even without explicitly targeting protected characteristics.

28. Financial Advertising

Behavioral advertising is especially sensitive in financial services.

Banks and fintech companies can use behavioral data to market:

  • loans;
  • credit cards;
  • insurance;
  • investment products;
  • overdraft services.

If advertising algorithms use personal data to steer consumers toward financial products, additional consumer-finance and fair-lending rules can become relevant.

Potential legal frameworks include:

  • Equal Credit Opportunity Act;
  • Fair Housing Act;
  • Fair Credit Reporting Act;
  • FTC Act;
  • state privacy laws.

29. Credit Advertising vs Credit Decision

A critical legal distinction is:

advertising a credit product

versus

deciding whether someone qualifies for credit.

The first may primarily involve advertising and privacy law.

The second can involve:

  • credit discrimination;
  • adverse-action requirements;
  • automated decision-making;
  • credit-reporting law;
  • model governance.

Therefore, an advertising algorithm should not quietly become an underwriting algorithm without appropriate legal controls.

30. Compliance Framework

A company using behavioral advertising should establish:

Data inventory

Identify what information is collected.

Purpose limitation

Define why each category of information is needed.

Consent management

Record valid consent where required.

Opt-out mechanism

Allow consumers to withdraw or object where legally required.

Vendor management

Review advertising networks, analytics providers and data brokers.

Sensitive-data controls

Prevent prohibited targeting based on protected information.

Children's controls

Identify child-directed services and apply heightened protections.

Retention controls

Delete or anonymize information when it is no longer necessary.

Security

Protect behavioral profiles against unauthorized access.

Algorithmic testing

Test advertising systems for discriminatory outcomes.

Documentation

Maintain records demonstrating compliance.

31. Risk Matrix

RiskExampleLegal concern
No valid consentTracking before consentGDPR/ePrivacy
Misleading privacy noticeClaiming data isn't shared when it isConsumer protection
Sensitive-data targetingHealth-based advertisingGDPR/state privacy
Children's profilingPersonalized ads to childrenDSA/COPPA
Dark patternsHidden rejection buttonConsumer/privacy law
Excessive retentionKeeping profiles indefinitelyData-minimization principles
Data-broker sharingUnseen third-party profilingPrivacy/consumer law
Discriminatory targetingExcluding groups from housing adsCivil-rights law
Security failureAdvertising database breachPrivacy/security law
Invalid opt-outContinuing targeted advertisingState/EU privacy rules

32. Key Case Laws

CasePrinciple
Planet49, C-673/17 (CJEU, 2019)Pre-ticked boxes do not establish valid cookie consent
Fashion ID, C-40/17 (CJEU, 2019)Website operators can have responsibilities for data transmission through embedded tracking
Meta Platforms v Bundeskartellamt, C-252/21 (CJEU, 2023)Data combination, consent and competition-law issues can intersect
FTC v Wyndham, 799 F.3d 236 (3d Cir. 2015)FTC authority concerning unfair/deceptive data-security practices
Greenman v. Yuba Power Products (1963)General product-liability principle; not directly an advertising case
FTC privacy enforcement actions against major platformsMisrepresentations concerning collection/use of personal data can create consumer-protection liability

33. Core Legal Principle

The modern legal approach can be summarized as:

Behavioral advertising is not inherently unlawful. The legality depends on the data involved, the method of collection, the legal basis, transparency, consumer choice, targeting criteria, age of the user, platform context, and applicable sector-specific restrictions.

A company should therefore ask five questions before launching a behavioral-advertising campaign:

  1. What data are we using?
  2. Where did the data come from?
  3. What legal basis permits the processing?
  4. Can the consumer meaningfully refuse or withdraw?
  5. Could the targeting produce prohibited or discriminatory outcomes?

If any of those questions cannot be answered clearly, the advertising campaign presents significant legal risk.

Bottom line

Behavioral advertising regulation is moving away from the simple question "Did the company collect the data?" toward a broader question:

"Was the consumer fairly informed, did the company have a lawful basis to use the data, was the targeting appropriate, and did the system respect meaningful consumer choice?"

For multinational businesses, the safest compliance model is to treat privacy, advertising, consumer protection, children's protection, discrimination and cybersecurity as interconnected controls rather than separate legal departments.

LEAVE A COMMENT