1---2name: marketing-analytics-dpia3description: Guides DPIA for marketing profiling, behavioural targeting, cross-device tracking, and advertising analytics. Covers ePrivacy Directive Art. 5(3) cookie consent, PECR regulations, legitimate interest balancing for direct marketing, and adtech processing chain assessment. Keywords: marketing analytics, DPIA, profiling, behavioural targeting, cross-device tracking, ePrivacy, PECR, adtech, legitimate interest.4license: Apache-2.05---67# Assessing Marketing Analytics Privacy89## Overview1011Marketing analytics processing — including customer profiling, behavioural targeting, cross-device tracking, programmatic advertising, and conversion attribution — triggers multiple DPIA criteria under WP248rev.01: evaluation/scoring (C1), systematic monitoring (C3), matching or combining datasets (C6), and potentially innovative technology (C8). This skill provides a DPIA methodology for marketing analytics processing, integrating GDPR obligations with ePrivacy Directive requirements for cookie-based tracking and PECR compliance for UK-based operations.1213## Legal Framework1415### GDPR Provisions for Marketing Analytics16- **Art. 5(1)(b) Purpose limitation**: Marketing data collected for one purpose cannot be repurposed for incompatible marketing without further lawful basis.17- **Art. 6(1)(a) Consent**: Required for most marketing profiling; must be freely given, specific, informed, and unambiguous.18- **Art. 6(1)(f) Legitimate interest**: May apply to direct marketing to existing customers (Recital 47) but requires balancing test for profiling.19- **Art. 21(2)-(3) Right to object**: Data subjects have an absolute right to object to processing for direct marketing purposes, including profiling related to direct marketing.20- **Art. 22 Automated decision-making**: Profiling that produces legal or similarly significant effects requires Art. 22(2) exception and Art. 22(3) safeguards.2122### ePrivacy Directive (2002/58/EC) Art. 5(3)23Storing or accessing information on a user's terminal equipment (cookies, device fingerprinting, local storage) requires:24- Clear and comprehensive information about the purposes25- Consent of the user (interpreted per GDPR standard: freely given, specific, informed, unambiguous)26- Exception: strictly necessary cookies for the service explicitly requested by the user2728### PECR (UK Privacy and Electronic Communications Regulations 2003)29- Regulation 6: Cookie consent requirements (mirrors ePrivacy Art. 5(3)).30- Regulation 22: Unsolicited marketing communications require prior consent (opt-in) with exception for existing customer soft opt-in.31- ICO enforcement powers under Regulation 31.3233## Marketing Processing Types and Risk Assessment3435### Customer Profiling3637| Aspect | Assessment |38|--------|-----------|39| Description | Aggregating customer data to create profiles for segmentation and targeting |40| WP248 criteria | C1 (evaluation/scoring), C6 (matching datasets) |41| Lawful basis | Consent (Art. 6(1)(a)) for new prospects; legitimate interest (Art. 6(1)(f)) for existing customers with LIA |42| Key risks | Discriminatory profiling, unexpected inferences, purpose creep |43| Mitigation | Transparency about profiling logic; opt-out mechanism; regular profiling accuracy review |4445### Behavioural Targeting4647| Aspect | Assessment |48|--------|-----------|49| Description | Tracking online behaviour to serve targeted advertisements |50| WP248 criteria | C1 (scoring), C3 (systematic monitoring), C6 (matching), C8 (innovative tech) |51| Lawful basis | Consent required (ePrivacy Art. 5(3) for cookies + GDPR Art. 6(1)(a) for processing) |52| Key risks | Pervasive tracking, opaque adtech supply chain, data leakage to multiple parties |53| Mitigation | Consent management platform; vendor due diligence; real-time bidding data minimisation |5455### Cross-Device Tracking5657| Aspect | Assessment |58|--------|-----------|59| Description | Linking user activity across multiple devices (desktop, mobile, tablet, smart TV) |60| WP248 criteria | C1, C3, C6, C8 |61| Lawful basis | Consent required — cross-device tracking exceeds reasonable expectations |62| Key risks | Comprehensive behavioural profiling; re-identification of pseudonymous profiles; tracking beyond user awareness |63| Mitigation | Explicit consent for cross-device linking; device-level opt-out mechanisms; limited retention |6465### Conversion Attribution6667| Aspect | Assessment |68|--------|-----------|69| Description | Tracking user journey from ad impression to purchase to attribute marketing ROI |70| Lawful basis | Consent for cookie-based attribution; legitimate interest may apply for first-party server-side attribution |71| Key risks | Extended tracking windows; cross-site tracking; data sharing with attribution platforms |7273## DPIA Methodology for Marketing Analytics7475### Phase 1: Marketing Data Flow Mapping (Week 1)761. Inventory all marketing data sources (website analytics, CRM, email platform, social media, advertising platforms, DMP/CDP).772. Map data flows from collection to activation (profiling, targeting, measurement).783. Identify all third-party recipients (ad exchanges, demand-side platforms, data management platforms, social platforms).794. Document all cookies, pixels, and tracking technologies deployed.805. Identify cross-site and cross-device tracking mechanisms.8182### Phase 2: Lawful Basis Assessment (Week 2)831. For each marketing processing activity, determine the lawful basis:84 - Cookie-based tracking: consent required (ePrivacy Art. 5(3))85 - Profiling for targeting: consent (Art. 6(1)(a)) or legitimate interest with LIA (Art. 6(1)(f))86 - Direct marketing emails: consent (PECR Reg. 22) or soft opt-in for existing customers872. Assess consent quality: is consent freely given, specific, informed, unambiguous, and withdrawable?883. For legitimate interest claims, conduct and document a legitimate interest assessment (LIA).8990### Phase 3: Risk Assessment (Week 3-4)91Assess marketing-specific risks:9293| Risk | Description | Typical Level |94|------|-------------|--------------|95| MK-R1 | Opaque adtech supply chain — personal data shared with multiple parties without transparency | High |96| MK-R2 | Cross-site tracking building comprehensive browsing profiles beyond user expectation | High |97| MK-R3 | Discriminatory targeting — excluding or disadvantaging groups based on inferred characteristics | High |98| MK-R4 | Consent fatigue leading to uninformed consent | Medium |99| MK-R5 | Data leakage through real-time bidding bid requests | High |100| MK-R6 | Dark patterns in consent interfaces undermining genuine choice | High |101| MK-R7 | Children encountering targeted advertising | High |102| MK-R8 | Re-identification of pseudonymous marketing profiles | Medium |103104### Phase 4: Mitigation and Approval (Week 4-5)1051. Implement technical measures: consent management platform, server-side analytics, data clean rooms, privacy sandbox APIs.1062. Implement organisational measures: marketing data governance policy, vendor due diligence, data subject rights processes.1073. DPO review and approval.1084. Schedule review: annually or upon new marketing technology deployment.109110## Enforcement Precedents111112- **CNIL vs Google LLC (2022)**: EUR 150 million fine for making cookie rejection more difficult than acceptance on google.fr and youtube.com — dark pattern in consent interface.113- **CNIL vs Amazon Europe (2020)**: EUR 35 million fine for placing advertising cookies without prior consent.114- **CNIL vs Criteo (2023)**: EUR 40 million fine for behavioural advertising without valid consent, insufficient transparency about profiling, and failure to demonstrate consent had been obtained.115- **Belgian DPA vs IAB Europe (2022)**: EUR 250,000 fine — Transparency and Consent Framework (TCF) consent string constitutes personal data; IAB Europe is a joint controller for TCF processing.116- **Norwegian DPA vs Grindr (2021)**: NOK 65 million fine for sharing location and sexual orientation data with advertising technology partners without valid consent.117- **AEPD vs CaixaBank (2020)**: EUR 6 million fine for commercial profiling without adequate consent management and insufficient transparency about profiling purposes.118- **ICO vs TikTok (2023)**: GBP 12.7 million fine for processing children's data for targeted advertising without appropriate age verification and parental consent.