Ad Server
An ad server is a technology system that manages online advertising and decides, often in real time, which ads to display to a given user on a website or app. Publishers, advertisers, and ad networks use it to store ad creatives, distribute them across web pages and apps, and control how campaigns run. Because ad serving frequently involves collecting or accessing information on a user's device and processing personal data, its use commonly raises cookie consent and data protection obligations that must be assessed separately.
An ad server is an ad tech platform that acts as a centralized system for ad management, storing ad campaigns and inventory and determining which advertisement to serve to a given placement, in many cases making that decision instantly at request time. It distributes creatives to websites, apps, and video environments and supports functions such as campaign management, inventory control, and delivery to publishers, ad networks, and advertisers. Ad serving may be delivered as a hosted or web-based application or self-hosted via open-source software. From a compliance standpoint, ad serving typically relies on cookies, pixels, SDKs, or similar technologies to identify devices and measure delivery; in most EU jurisdictions the placing of or access to such information generally requires prior consent under the ePrivacy Directive and its national implementations, while any resulting processing of personal data is separately governed by the GDPR. This entry describes the ad server as a technology component only; specific lawfulness depends on jurisdiction, the categories of data processed, and the consent mechanisms in place, and is out of scope here.
Why it matters
Ad servers sit at the center of online advertising delivery, and their operation commonly depends on cookies, pixels, SDKs, or similar device-side technologies to identify devices and measure ad delivery. Because of this, the use of an ad server routinely triggers cookie consent and data protection obligations. In most EU jurisdictions, the placing of or access to information on a user's device generally requires prior consent under the ePrivacy Directive and its national implementations, while any resulting processing of personal data is separately governed by the GDPR. These two regimes must be assessed independently: consent for placing a cookie does not automatically satisfy the GDPR's requirements for the downstream processing.
For privacy and compliance teams, the practical challenge is that ad serving is rarely limited to strictly necessary functionality. Serving targeted or measured advertising typically falls into categories that require prior consent in the EU, unlike essential cookies that may be exempt. Where consent is the basis relied on, it must generally be freely given, specific, informed, and unambiguous, expressed through a clear affirmative action. Requirements differ by jurisdiction, however: several US state frameworks such as the CCPA and CPRA in California often rely on an opt-out model rather than the opt-in approach common in the EU, so the same ad server configuration may carry different obligations depending on where users are located.
Because an ad server is a technology component rather than a compliance solution, deploying one does not by itself resolve any legal question. The lawfulness of a given ad serving setup depends on the jurisdiction, the categories of data processed, and the consent or opt-out mechanisms in place. Organizations should treat the ad server as one element of a broader compliance assessment rather than assuming that a vendor's platform guarantees a compliant outcome.
Who it's relevant to
Inside Ad Server
Common questions
Answers to the questions practitioners most commonly ask about Ad Server.

