Posted on

Real-time advertising auctions and the spread of user information

An online ad can be sold in less time than it takes you to notice the empty rectangle where it will appear.

Before the winning ad arrives, information about the opportunity may already have traveled through an advertising auction.

That is the basic structure of real-time bidding, or RTB.

A bid request describes more than a rectangle

The IAB Tech Lab’s OpenRTB specification defines a standard way for an exchange or supply platform to ask bidders what they will pay for an advertising impression.

A bid request can contain information describing the site or app, device, user, advertising slot, auction rules, and optional audience or segment data. See the current OpenRTB specification and IAB Tech Lab’s OpenRTB overview.

Not every exchange sends every field.

Not every request contains personal information.

The important architectural point is that the auction request itself is a data-distribution event.

Multiple potential buyers may need enough information to decide whether the impression is valuable to them.

Only one may ultimately win.

Losing the auction does not mean never seeing the request

This distinction became unusually concrete in the Federal Trade Commission’s 2024 action against data broker Mobilewalla.

The FTC alleged that Mobilewalla collected and retained information from real-time bidding exchanges while participating in ad auctions, including information from bid requests even when the company did not win the advertisement. The agency alleged that the company accumulated hundreds of millions of advertising identifiers paired with precise location data and later used data for audience segmentation and other purposes. See the FTC’s Mobilewalla enforcement announcement.

Those are allegations in an enforcement action, not proof that every RTB bidder behaves that way.

But they demonstrate the structural issue clearly.

The information needed to evaluate an auction can be valuable even without the ad.

The actual payload matters

It is easy to describe RTB too dramatically.

A researcher should not assume that every auction contains a name, exact location, browsing history, or sensitive category.

The proper question is narrower:

What fields were actually sent, to which recipients, under which identifiers?

OpenRTB supports device and user context, but optional fields can be omitted, generalized, restricted, or transformed. Privacy rules, exchange policies, consent signals, browser restrictions, and seller configuration can all change the payload.

A packet capture, exchange documentation, contract, regulatory record, or bid-request sample is stronger evidence than merely observing that programmatic advertising exists on the page.

The auction creates a distribution problem

Traditional advertising sounds simple: a publisher shows an ad from an advertiser.

Programmatic advertising can involve publishers, supply-side platforms, exchanges, demand-side platforms, data providers, measurement companies, and other intermediaries.

The advertisement is the visible result.

The data path that produced it can be much wider.

That is what makes RTB important to the Surveillance Economy.

The auction is not just deciding which ad you will see.

It can also determine which companies get a chance to evaluate information about the person or device about to see it.