The GDPR mandates explicit consent for processing sensitive data categories, raising questions about how Xandr obtained such consents
A Microsoft-owned adtech business, Xandr, is the target of a complaint supported by the European privacy advocacy group, noyb. Known for its impactful actions against data protection-infringing tech giants, noyb is backing an unnamed individual in Italy to lodge the complaint with the country’s data protection authority.
Filed under the European Union’s General Data Protection Regulation (GDPR), the complaint could potentially lead to fines of up to 4% of Microsoft’s global annual turnover if it prevails. In 2023, Microsoft's revenue was nearly $212 billion, indicating the severe financial implications of such a fine. Xandr is accused of transparency failings and breaches of data access rights, particularly concerning the creation of profiles used for microtargeted advertising sold through programmatic ad auctions. The complaint also alleges that Xandr is using inaccurate information about individuals. Specifically, noyb asserts that Xandr is violating Articles 5(1) (c) and (d); 12(2); 15; and 17 of the GDPR. The complaint urges the data protection authority to investigate these claims and, if confirmed, to enforce compliance and consider imposing a substantial fine.
Microsoft acquired Xandr in late 2021 to expand its digital advertising business, although Xandr continues to operate as a separate entity. The GDPR mandates explicit consent for processing sensitive data categories, raising questions about how Xandr obtained such consents. One potential source could be website visitors, as ad tracking can be triggered by accessing publisher content. However, industry standard mechanisms for obtaining consent have also faced criticism for GDPR breaches.




























.webp)