Posted on

The supply chain behind a company a user never knowingly contacted

You do not need to visit a company’s website for that company to have data about you.

That sounds mysterious until the supply chain is drawn.

A person visits a familiar app or website.

The service participates in an advertising system.

An exchange sends a bid request.

A company observing that auction receives data.

That company may then combine, retain, sell, or analyze the information.

At no point did the user intentionally knock on its door.

Mobilewalla provides a documented route

In 2024, the Federal Trade Commission alleged that data broker Mobilewalla collected consumer data from real-time advertising bidding exchanges and third-party aggregators. The FTC said consumers often had no knowledge that Mobilewalla had obtained their information. See the FTC’s Mobilewalla enforcement announcement.

According to the FTC complaint, Mobilewalla collected and retained information contained in bid requests even when it did not win the auction. The agency alleged that, between January 2018 and June 2020, the company collected more than 500 million unique advertising identifiers paired with precise location data.

The FTC finalized the order in January 2025. See the final order announcement.

That gives us a supply chain with real documentation rather than speculation.

Each intermediary sees a different slice

The route can look roughly like this:

  1. A person uses a website or app.
  2. Advertising inventory becomes available.
  3. A real-time bidding exchange distributes a bid request.
  4. The request contains information useful for evaluating the ad opportunity.
  5. A bidder or data company receives that information.
  6. The recipient may combine it with other records or sell derived products downstream.

Not every advertising auction contains the same fields.

Not every participant retains the data.

Not every recipient uses it for profiling.

Those details have to be verified case by case.

The important architectural fact is that direct contact is not required.

The visible service is only the first hop

Consumers naturally think in terms of brands they recognize.

I gave this app my location.

I visited this website.

I used this store.

But modern data systems often operate through chains of processors, SDK vendors, ad exchanges, analytics companies, identity providers, brokers, and clients.

One company can therefore know about a person because another company generated the event and a third company passed it along.

That is why privacy policies full of phrases such as partners, service providers, and advertising companies can be difficult to evaluate without actual recipient names and technical evidence.

The Surveillance Economy becomes hardest to see at the point where the person and the data holder have never met.

The person knows the app.

The broker knows the identifier.

The supply chain introduces them without an introduction.

Posted on

Opt-out signals and the challenge of honoring them across intermediaries

A privacy signal can be one bit.

The supply chain behind it can contain dozens of companies.

That mismatch is the central problem with global opt-out mechanisms.

A browser can send a simple instruction such as:

Do not sell or share my personal information.

The difficult part is making sure that preference survives every handoff that follows.

The browser can express the choice once

Global Privacy Control, or GPC, is a browser-based signal designed to communicate an opt-out preference automatically to websites.

California regulators currently describe GPC as an opt-out preference signal that covered businesses must honor for applicable sale or sharing rights. In September 2025, California, Colorado, and Connecticut privacy regulators announced a coordinated sweep focused on businesses that may have failed to process GPC requests. See CalPrivacy’s enforcement announcement.

California also enacted the Opt Me Out Act in 2025, requiring browsers operating in California to provide built-in opt-out preference signals beginning in 2027. See CalPrivacy’s announcement.

That solves one usability problem.

The user does not need to hunt for a privacy link on every site.

One preference must cross many systems

Now imagine the website uses:

  • an analytics provider,
  • an ad exchange,
  • a demand-side platform,
  • a measurement vendor,
  • a data broker,
  • a server-side tag gateway,
  • and several downstream processors.

The original site receives the signal.

What happens next?

Does it suppress the relevant outbound event?

Does it attach an opt-out flag to downstream requests?

Do intermediaries understand the flag the same way?

Does a broker already holding a profile update its state?

Does the choice apply only to future sharing, or does it also affect retained data?

Those are implementation questions, not interface questions.

The ad industry itself recognizes the propagation problem

IAB Tech Lab’s current privacy standards portfolio explicitly focuses on communicating privacy preference signals through the digital advertising supply chain. Its Global Privacy Platform and related standards exist because a preference that stops at the visible website is not enough for a multi-party ecosystem. See IAB Tech Lab’s Privacy Standards.

That does not prove every intermediary honors every signal correctly.

It proves the industry understands that the signal needs a transport mechanism.

Compliance has to be tested in the data flow

A website can display Your privacy choices were saved while still sending data to outside services.

That does not automatically mean the transfer violates a law; some processing may remain permitted or necessary.

But the message cannot be evaluated from the button alone.

A real audit compares network behavior, server-side processing, vendor configuration, and downstream contracts before and after the preference is expressed.

The Surveillance Economy is full of settings that look local but govern distributed systems.

An opt-out is only as strong as the farthest system that is supposed to remember it.

Posted on

Real-time advertising auctions and the spread of user information

An online ad can be sold in less time than it takes you to notice the empty rectangle where it will appear.

Before the winning ad arrives, information about the opportunity may already have traveled through an advertising auction.

That is the basic structure of real-time bidding, or RTB.

A bid request describes more than a rectangle

The IAB Tech Lab’s OpenRTB specification defines a standard way for an exchange or supply platform to ask bidders what they will pay for an advertising impression.

A bid request can contain information describing the site or app, device, user, advertising slot, auction rules, and optional audience or segment data. See the current OpenRTB specification and IAB Tech Lab’s OpenRTB overview.

Not every exchange sends every field.

Not every request contains personal information.

The important architectural point is that the auction request itself is a data-distribution event.

Multiple potential buyers may need enough information to decide whether the impression is valuable to them.

Only one may ultimately win.

Losing the auction does not mean never seeing the request

This distinction became unusually concrete in the Federal Trade Commission’s 2024 action against data broker Mobilewalla.

The FTC alleged that Mobilewalla collected and retained information from real-time bidding exchanges while participating in ad auctions, including information from bid requests even when the company did not win the advertisement. The agency alleged that the company accumulated hundreds of millions of advertising identifiers paired with precise location data and later used data for audience segmentation and other purposes. See the FTC’s Mobilewalla enforcement announcement.

Those are allegations in an enforcement action, not proof that every RTB bidder behaves that way.

But they demonstrate the structural issue clearly.

The information needed to evaluate an auction can be valuable even without the ad.

The actual payload matters

It is easy to describe RTB too dramatically.

A researcher should not assume that every auction contains a name, exact location, browsing history, or sensitive category.

The proper question is narrower:

What fields were actually sent, to which recipients, under which identifiers?

OpenRTB supports device and user context, but optional fields can be omitted, generalized, restricted, or transformed. Privacy rules, exchange policies, consent signals, browser restrictions, and seller configuration can all change the payload.

A packet capture, exchange documentation, contract, regulatory record, or bid-request sample is stronger evidence than merely observing that programmatic advertising exists on the page.

The auction creates a distribution problem

Traditional advertising sounds simple: a publisher shows an ad from an advertiser.

Programmatic advertising can involve publishers, supply-side platforms, exchanges, demand-side platforms, data providers, measurement companies, and other intermediaries.

The advertisement is the visible result.

The data path that produced it can be much wider.

That is what makes RTB important to the Surveillance Economy.

The auction is not just deciding which ad you will see.

It can also determine which companies get a chance to evaluate information about the person or device about to see it.