Demand-Side Platform
A demand-side platform (DSP) is automated software that advertisers use to buy digital advertising space across many websites, apps, and channels in real time. Instead of negotiating placements manually, advertisers set their goals and the platform automatically bids on and purchases suitable ad inventory. Because DSPs typically rely on tracking technologies to target and measure ads, their use often triggers cookie consent and data protection obligations.
A demand-side platform (DSP) is an automated buying system that enables advertisers and advertising agencies to purchase, manage, and optimize digital ad inventory in real time across multiple ad exchanges and channels, matching advertiser demand with available placements. In the consent and compliance context, the targeting, bidding, and measurement functions of a DSP commonly depend on cookies, pixels, device identifiers, SDKs, or similar technologies. In most EU and UK jurisdictions, the placement of and access to such information on a user's device is governed by ePrivacy rules and generally requires prior consent for non-essential purposes, while any resulting processing of personal data is separately governed by the GDPR; requirements differ under US state frameworks such as the CCPA/CPRA, which typically rely on opt-out mechanisms. The evidence provided describes only the general advertising function of DSPs; it does not address the specific legal basis, consent flows, or record-keeping obligations that apply to any particular deployment, and those depend on facts outside the scope of this definition.
Why it matters
Demand-side platforms sit at the center of programmatic advertising, allowing advertisers to buy digital ad inventory automatically across many websites, apps, and channels in real time. Because the targeting, bidding, and measurement functions of a DSP commonly depend on cookies, pixels, device identifiers, SDKs, or similar technologies, their use frequently brings an advertiser's activity within the scope of both cookie consent rules and broader data protection law. For privacy and compliance teams, understanding how a DSP operates is a prerequisite to assessing whether the tracking it relies on has an appropriate legal footing.
In most EU and UK jurisdictions, the placement of and access to information on a user's device is governed by ePrivacy rules, which generally require prior consent for non-essential purposes such as advertising, while any resulting processing of personal data is separately governed by the GDPR. Consent obtained for storing or reading data on a device does not automatically satisfy the separate GDPR requirements that apply to the downstream processing, and both must be considered when a DSP is deployed. Under US state frameworks such as the CCPA/CPRA in California, the model differs and typically relies on opt-out mechanisms rather than opt-in consent.
The compliance exposure is heightened by the fact that DSP-driven advertising often involves data flowing to and among multiple parties, including ad exchanges and other vendors. This can make it harder to map data flows, identify legal bases, and maintain consent records. The general advertising function described here does not, on its own, establish which consent flows or record-keeping obligations apply to any particular deployment; those depend on facts specific to the implementation and on the jurisdictions involved.
Who it's relevant to
Inside DSP
Common questions
Answers to the questions practitioners most commonly ask about DSP.

