Home Reviews About
Twenty of Time

The GDPR Loophole That Lets Advertisers Still Shadow-Profile You

The General Data Protection Regulation was supposed to give people meaningful control over their personal information. It introduced stronger rights, clearer consent requirements, limits on data retention, and serious penalties for companies that misuse personal data. Yet years after the law came into force, advertisers can still build remarkably detailed pictures of people who never knowingly agreed to be tracked.

This does not usually happen because a company openly ignores the GDPR. The more persistent problem is that the advertising ecosystem has adapted. Tracking companies have changed their terminology, shifted responsibility between partners, relied on alternative legal grounds, and combined information from many supposedly separate sources. The result is a shadow profile: an inferred record of your interests, habits, location, income, relationships, and likely behaviour.

The loophole is less a single sentence in the regulation than a collection of legal ambiguities and technical workarounds. Understanding those mechanisms helps explain why clicking “reject all” often reduces surveillance without actually stopping it.

Consent Is Only One Legal Door

Many people associate the GDPR with cookie banners because consent is the most visible legal basis for online tracking. A website generally needs permission before placing non-essential cookies or accessing certain information on a device. This created the impression that refusing advertising cookies would prevent companies from learning much about a visitor.

In practice, consent is only one of six lawful bases under the GDPR. Companies may also refer to contractual necessity, legal obligations, vital interests, public tasks, or legitimate interests. Advertising firms most often invoke legitimate interests, arguing that measuring audiences, preventing fraud, personalising content, or marketing products serves a business purpose that does not seriously override an individual’s rights.

That argument is not automatically valid. A legitimate-interest assessment is supposed to weigh the company’s purpose against the person’s reasonable expectations and privacy rights. The difficulty is that these assessments are often internal documents, written by the organisations benefiting from the data processing. Individuals rarely see the reasoning, and regulators have limited capacity to examine every ad-tech transaction.

The GDPR’s broader impact is therefore easier to understand when the law is viewed as a framework of obligations rather than a universal prohibition on data collection. The regulation restricts certain practices, but it does not make commercial profiling unlawful by definition.

The Profile Can Survive Without Your Name

A common defence from advertisers is that they do not need to know your name. They may store a random identifier, a hashed email address, a device ID, or a probabilistic match between several browsers. From their perspective, an advertising ID is not the same thing as a civil identity. From the individual’s perspective, the distinction may offer little practical protection.

A profile attached to “user 8f42” can still record visits to fertility websites, searches for debt advice, repeated trips to a cancer clinic, or interest in a particular political movement. The identifier does not need to display your name to influence which adverts you see or to classify you as financially vulnerable, likely to move house, or interested in a sensitive health topic.

The GDPR does recognise pseudonymous information as personal data when it can be linked back to an individual. However, the chain of identification may be distributed across multiple companies. One firm collects an email address, another receives a hashed version, a publisher supplies browsing behaviour, and an auction platform assigns an advertising segment. Each participant may claim to hold only a fragment.

This fragmentation creates accountability problems. The person being profiled experiences one continuous system, while the legal responsibilities are divided among data controllers, processors, publishers, demand-side platforms, identity vendors, and data brokers. A privacy notice can name dozens of partners without making the flow of information understandable.

Legitimate Interest Keeps the Market Moving

The advertising industry has used legitimate interest as a way to preserve behavioural targeting where consent is refused, unavailable, or too difficult to obtain. A company might argue that it has a commercial interest in showing relevant adverts, reducing irrelevant marketing, or understanding how visitors use its service. It then claims that the processing is proportionate.

That reasoning becomes especially contentious in real-time bidding. When a webpage loads, information about a visitor can be broadcast to numerous advertising participants competing to show an advert. The signals may include approximate location, device characteristics, browsing context, language, and inferred audience categories. Even if no single bid wins, many parties may receive data about the opportunity.

Regulators have repeatedly questioned whether this system can satisfy transparency, purpose limitation, data minimisation, and security requirements. A person cannot realistically understand hundreds of downstream recipients, and a website may not know exactly how every vendor will use a data point after receiving it.

The system also benefits from ambiguity. “Measurement,” “personalisation,” “fraud prevention,” and “service improvement” sound less intrusive than surveillance or behavioural advertising. Yet the underlying operation can remain similar: observing a person across digital environments, assigning predictions, and using those predictions to decide what they are shown.

First-Party Data Became the New Tracking Infrastructure

Browser restrictions have weakened some third-party cookies, but they have increased the value of first-party data. Large platforms can collect information directly through accounts, apps, payment systems, loyalty programmes, connected televisions, cloud services, and operating systems. Because the relationship is presented as being between the user and the service, the data may appear less like external tracking.

A retailer, for example, can connect purchases with email engagement, mobile-app activity, customer support records, location signals, and website visits. It can then build audiences for its own campaigns or allow advertising partners to target those groups without revealing the underlying customer list. The process may be described as privacy-preserving because raw identifiers are not openly shared.

Data clean rooms and encrypted matching systems extend this model. Two companies can compare hashed identifiers to find overlapping customers, then measure advertising outcomes or create a target audience. Hashing makes direct exposure less obvious, but it does not erase the fact that the same person’s behaviour is being connected across commercial databases.

The shift from third-party cookies to first-party identity can therefore produce a more durable form of surveillance. Instead of a fragile tracker following a browser, a powerful company can maintain a persistent account-based record. Refusing cookies on one website does little if the same person is recognised through a logged-in service, a loyalty card, an app, or a retailer’s email database.

Data Brokers Fill the Gaps

Advertisers also purchase information from data brokers that gather records from public sources, mobile applications, retailers, surveys, credit-related products, and other commercial relationships. These companies may infer household income, age range, occupation, purchasing interests, family status, property ownership, and likely future events. The information can then be licensed to marketers or used to enrich an existing customer record.

The GDPR gives individuals rights to access, correct, erase, and object to certain processing. Those rights are valuable, but exercising them across a broker ecosystem is difficult. A person may not know which companies possess a profile, which broker supplied it, or which advertising platform used it. Some data is generated through statistical inference rather than copied from a single source, making correction particularly complicated.

Accuracy is another concern. An inferred profile can be wrong while still affecting prices, offers, visibility, and reputation. A person may be categorised as a high-value customer, a likely borrower, a new parent, or a resident of a particular neighbourhood based on weak evidence. The decision can shape what they see without any clear explanation or opportunity to challenge it.

The privacy habits guide is useful in this context because reducing exposure is a continuing practice rather than a single browser setting. Limiting unnecessary accounts, separating email addresses, reviewing app permissions, and being selective about loyalty schemes can reduce the number of connections available to profiling systems.

Why the Opt-Out Often Feels Ineffective

A consent banner can give the appearance of control while leaving important processing untouched. Selecting “reject” may stop a website from placing some advertising cookies, yet essential analytics, fraud detection, logged-in account data, server logs, and information supplied by partners may continue to operate under different justifications.

Dark patterns make the choice harder. Some interfaces use bright buttons for acceptance, hide the rejection control behind several screens, or describe legitimate-interest purposes in broad categories. A person who wants to refuse targeted advertising may have to disable dozens of vendors individually. Even then, a new vendor or later visit can restore part of the tracking network.

Technical signals are also imperfect. A Global Privacy Control signal can communicate an opt-out preference in supported environments, but adoption varies. Browser privacy settings may block local storage while leaving account-based tracking untouched. Deleting cookies can remove a local identifier without deleting the profile stored on a company’s servers.

The result is a gap between formal choice and practical control. The law may give someone a right to object, but the person still has to identify the relevant organisation, find the correct form, prove ownership of an account, and repeat the process with other companies. The burden falls on the individual even though the system was designed by the businesses collecting the data.

What Advertisers Can Still Infer

Shadow profiling does not require a complete diary of someone’s life. A few repeated signals can be enough to make useful predictions. The pages visited, time spent reading, device type, approximate location, purchase categories, and response to previous adverts can reveal patterns that are commercially valuable.

Algorithms can also infer sensitive characteristics from non-sensitive details. A postcode may suggest income or ethnicity. A shopping basket may indicate health concerns. Night-time activity may imply shift work or insomnia. A cluster of searches can suggest pregnancy, financial distress, addiction, or political interest before a person has disclosed any of those facts directly.

These predictions are often used for audience selection rather than an explicit decision about an individual. That distinction can make the practice harder to challenge. The person may never be told that an advertising platform placed them in a category, and the platform may claim it does not make a legally significant decision about them.

Tracking method Typical data used Why refusal may not stop it Main privacy concern
Third-party cookies Pages visited, clicks, referral data Other identifiers or server-side signals remain Cross-site behavioural tracking
Account-based profiling Email, purchases, app activity Service access may require an account Persistent identity-linked records
Device fingerprinting Browser, screen, fonts, settings No cookie permission is required Recognition without local storage
Data broker enrichment Public and commercial records Person may not know the source Inaccurate or sensitive inferences
Ad-tech auctions Context, location, device, audience labels Data passes through many vendors Weak transparency and control
Clean-room matching Hashed emails or customer IDs Matching occurs behind business systems Databases become connected invisibly

This does not mean every advertiser has a complete or accurate dossier. It means the market is structured to make continual inference possible. The profile can be partial, probabilistic, and wrong while still influencing commercial decisions.

Practical Ways To Reduce The Trail

No individual can fully opt out of the modern data economy through settings alone. Privacy protection works better as a series of decisions that reduce the amount of information available, weaken the links between identities, and create pressure for companies to explain their practices.

Useful steps include:

It is also worth treating loyalty programmes and “free” digital services as data exchanges. The immediate discount or convenience may be reasonable, but the long-term cost can include persistent categorisation and commercial sharing. Read the parts of a privacy notice that explain recipients, retention periods, profiling, and legal bases rather than focusing only on the cookie pop-up.

For organisations, compliance should mean more than collecting consent records. Companies need to minimise the information they receive, prohibit secondary uses, audit vendors, honour opt-out signals, and provide genuine alternatives to personalised advertising. Regulators can strengthen this standard by examining the whole chain of data flows instead of assessing each company in isolation.

The GDPR has made surveillance more visible and has given people important tools, but its protections are weakened when identity fragments, inferred data, and vendor networks fall between clear lines of responsibility. The advertising industry does not need to know your name to follow your probable interests. It only needs enough signals to make you predictable.

Start with one account, one app, or one broker that holds more information than it needs. Request access, remove unnecessary permissions, reject personalised advertising where possible, and keep a record of the response. Individual actions will not dismantle shadow profiling by themselves, but they can reduce the data available today and make privacy a demand that companies can no longer treat as optional.