Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: TCF and Vendors

Demand-Side Platform

Also known as:
Simply put

A demand-side platform (DSP) is automated software that advertisers use to buy digital advertising space across many websites, apps, and channels in real time. Instead of negotiating placements manually, advertisers set their goals and the platform automatically bids on and purchases suitable ad inventory. Because DSPs typically rely on tracking technologies to target and measure ads, their use often triggers cookie consent and data protection obligations.

Formal definition

A demand-side platform (DSP) is an automated buying system that enables advertisers and advertising agencies to purchase, manage, and optimize digital ad inventory in real time across multiple ad exchanges and channels, matching advertiser demand with available placements. In the consent and compliance context, the targeting, bidding, and measurement functions of a DSP commonly depend on cookies, pixels, device identifiers, SDKs, or similar technologies. In most EU and UK jurisdictions, the placement of and access to such information on a user's device is governed by ePrivacy rules and generally requires prior consent for non-essential purposes, while any resulting processing of personal data is separately governed by the GDPR; requirements differ under US state frameworks such as the CCPA/CPRA, which typically rely on opt-out mechanisms. The evidence provided describes only the general advertising function of DSPs; it does not address the specific legal basis, consent flows, or record-keeping obligations that apply to any particular deployment, and those depend on facts outside the scope of this definition.

Why it matters

Demand-side platforms sit at the center of programmatic advertising, allowing advertisers to buy digital ad inventory automatically across many websites, apps, and channels in real time. Because the targeting, bidding, and measurement functions of a DSP commonly depend on cookies, pixels, device identifiers, SDKs, or similar technologies, their use frequently brings an advertiser's activity within the scope of both cookie consent rules and broader data protection law. For privacy and compliance teams, understanding how a DSP operates is a prerequisite to assessing whether the tracking it relies on has an appropriate legal footing.

In most EU and UK jurisdictions, the placement of and access to information on a user's device is governed by ePrivacy rules, which generally require prior consent for non-essential purposes such as advertising, while any resulting processing of personal data is separately governed by the GDPR. Consent obtained for storing or reading data on a device does not automatically satisfy the separate GDPR requirements that apply to the downstream processing, and both must be considered when a DSP is deployed. Under US state frameworks such as the CCPA/CPRA in California, the model differs and typically relies on opt-out mechanisms rather than opt-in consent.

The compliance exposure is heightened by the fact that DSP-driven advertising often involves data flowing to and among multiple parties, including ad exchanges and other vendors. This can make it harder to map data flows, identify legal bases, and maintain consent records. The general advertising function described here does not, on its own, establish which consent flows or record-keeping obligations apply to any particular deployment; those depend on facts specific to the implementation and on the jurisdictions involved.

Who it's relevant to

Marketing and advertising compliance teams
Teams running programmatic campaigns through a DSP need to confirm that the tracking technologies underpinning targeting and measurement have an appropriate legal footing. In most EU and UK jurisdictions this generally means obtaining prior consent for non-essential advertising cookies and similar technologies before they are placed, while in US states such as California an opt-out model may apply instead.
Privacy officers and data protection professionals
Because DSP activity typically involves both the placement of information on a device and the subsequent processing of personal data, privacy professionals must address ePrivacy consent requirements and GDPR obligations as distinct questions. They are also responsible for mapping data flows to the exchanges and vendors involved and assessing consent record-keeping obligations, which depend on the specific deployment.
Legal counsel
Counsel advising on programmatic advertising should assess the legal basis for both the tracking technologies used and the resulting data processing, and should account for differences between EU, UK, and US state frameworks. Enforcement positions and regulatory guidance in this area continue to evolve, so conclusions may need to be revisited over time.
Web and app developers
Developers who integrate DSP-related tags, pixels, or SDKs into websites or apps play a practical role in ensuring that non-essential tracking does not fire before valid consent is obtained where that is required. Their work in configuring consent gating and signal handling supports compliance but does not by itself determine whether a particular deployment is lawful.

Inside DSP

Programmatic Buying Engine
The core function of a demand-side platform (DSP) is to enable advertisers and agencies to purchase digital advertising inventory in an automated, real-time manner across multiple ad exchanges and supply sources, typically through real-time bidding.
Audience Targeting and Data Integration
A DSP typically ingests and processes data used to target audiences, which may include personal data collected via cookies, pixels, SDKs, device identifiers, or other tracking technologies. Where personal data is involved, its processing generally engages the GDPR in the EU, while the placing of or access to identifiers on a user's device separately engages the ePrivacy rules and their national implementations.
Bid Request Handling
DSPs receive and evaluate bid requests, which can carry user-related signals. In the EU, any personal data flowing through these requests must have a valid legal basis, and where consent is relied upon it must generally be freely given, specific, informed, and unambiguous.
Consent Signal Consumption
In advertising ecosystems that use frameworks such as the IAB Transparency and Consent Framework (TCF), a DSP may receive and act on consent or transparency signals passed downstream. The presence of such a signal supports, but does not by itself guarantee, lawful processing.
Integration with the Wider AdTech Chain
A DSP operates alongside supply-side platforms, ad exchanges, and data providers. Responsibility for obtaining valid consent typically arises at the point of collection on the publisher's property, meaning a DSP generally depends on upstream parties for the lawfulness of the signals it relies upon.

Common questions

Answers to the questions practitioners most commonly ask about DSP.

Does a demand-side platform obtain cookie consent on behalf of the websites where it serves ads?
No. A DSP is an advertiser-side tool used to buy programmatic ad inventory; it does not generally collect consent from the users who visit publisher websites. In most EU jurisdictions, the placing of and access to information on a user's device is governed by the ePrivacy rules, and the obligation to obtain prior consent for non-essential cookies and similar technologies typically falls on the party operating the website or app where those technologies are set. Any personal data processing that follows is separately governed by the GDPR. A DSP may rely on consent signals passed to it (for example through a framework such as the IAB TCF), but the DSP itself is not usually the entity that presents a consent interface to the user. The precise allocation of responsibility depends on the roles the parties play and the facts of the arrangement.
If a DSP participates in the IAB Transparency and Consent Framework, does that make its use of cookies compliant?
Not on its own. Participating in the TCF is a mechanism for signalling and receiving consent and related transparency information across the programmatic supply chain; it supports compliance efforts but does not by itself guarantee that any given cookie or data-processing activity is lawful. Valid consent under the GDPR must still be freely given, specific, informed, and unambiguous, and the underlying processing must have a lawful basis and meet transparency and other requirements. Enforcement positions on programmatic advertising frameworks have been contested and continue to evolve, and obligations differ across the EU, the UK, and individual US states. Framework participation is one input into a compliance assessment, not a substitute for legal judgment.
How should consent or opt-out signals reach a DSP in practice?
Signals typically flow to a DSP through the programmatic supply chain rather than being collected by the DSP directly. In EU and UK contexts this often relies on consent strings passed via a framework such as the IAB TCF, where a consent management platform on the publisher side captures the user's choices and communicates them downstream. In certain US state contexts, opt-out signals such as Global Privacy Control may be relevant instead, reflecting the opt-out orientation of frameworks like the CCPA and CPRA in California. The specific technical integration depends on the exchanges, supply-side platforms, and CMPs involved, and organizations should verify how signals are transmitted and honored across their particular stack.
What should a DSP or advertiser do when no valid consent signal is present for a user?
The appropriate handling depends on the applicable legal regime and the signal received. In most EU jurisdictions, where prior opt-in consent is generally required for non-essential cookies and associated advertising processing, the absence of a valid consent signal typically means that consent-dependent targeting and related data processing should not proceed for that user. In US state contexts that rely on opt-out mechanisms, the analysis differs and may permit certain activity unless an opt-out is indicated. Because the correct response turns on jurisdiction, the parties' roles, and the reliability of the signalling, organizations should document their decision logic and confirm it with legal advice rather than applying a single default everywhere.
What record-keeping is relevant when a DSP relies on consent gathered elsewhere in the supply chain?
Even where a DSP does not collect consent directly, it is generally advisable to retain evidence of the consent or preference signals it received and acted upon, alongside documentation of the contractual arrangements and technical integrations that govern signal exchange. Consent logging and record-keeping obligations can arise under the GDPR's accountability principle and may be reflected in guidance from data protection authorities, though the exact expectations vary by jurisdiction and role. What a DSP can demonstrate may be limited by what the upstream supply chain transmits, so organizations should assess whether the signals they receive are sufficient to evidence a lawful basis and adjust their arrangements accordingly.
How does a DSP fit within roles and responsibilities under data protection law?
The characterization of a DSP as a controller, joint controller, or processor depends on the specific facts, including who determines the purposes and means of the processing. In programmatic advertising these roles can be complex and have been the subject of contested regulatory interpretation, particularly around real-time bidding. Organizations working with DSPs should map the data flows, identify each party's role for each processing activity, and put appropriate agreements in place. Because the analysis is fact-specific and interpretations continue to evolve, this determination should be made with legal input rather than assumed.

Common misconceptions

A DSP obtains cookie consent directly from users, so advertisers using it do not need to worry about consent.
A DSP generally does not collect consent from end users itself; consent is typically gathered at the point of collection, often on the publisher's website via a consent management platform. Advertisers and other parties in the chain may still carry their own obligations under the GDPR and the ePrivacy rules in EU jurisdictions, and reliance on a DSP does not transfer or discharge those responsibilities.
Because a DSP works with cookies, only the ePrivacy Directive applies to it.
The ePrivacy Directive and its national implementations govern the placing of and access to information on a user's device, while the GDPR separately governs the processing of any personal data that follows. Both regimes can apply to DSP activity in the EU, and satisfying one does not automatically satisfy the other.
Receiving a TCF or similar consent signal means the DSP's processing is definitively compliant.
A consent framework signal supports compliance but does not replace legal judgment. The validity of the underlying consent, the accuracy of the transmitted signal, and the DSP's own processing purposes all matter. Consent standards and enforcement positions also differ across the EU, the UK, and individual US states, so no single signal guarantees lawfulness everywhere.

Best practices

Map where personal data enters the DSP and identify the legal basis for each processing activity, distinguishing the ePrivacy obligations around device access from the GDPR obligations around subsequent data processing in EU jurisdictions.
Do not assume the DSP collects consent; verify that valid consent (where required in the EU) is obtained upstream at the point of collection, and confirm how consent and transparency signals are passed down the chain.
Where a consent framework such as the IAB TCF is used, validate that received signals are honored in bidding and targeting decisions, while treating such signals as support for, not a substitute for, legal review.
Account for differing requirements across jurisdictions, recognizing that EU and UK regimes generally rely on prior opt-in consent while several US state laws, such as the CCPA and CPRA in California, often operate on an opt-out model, including recognition of signals like Global Privacy Control where applicable.
Maintain records that document the consent status relied upon and how it flows through the AdTech chain, to support accountability and record-keeping expectations.
Treat similar technologies handled by the DSP, such as pixels, device identifiers, SDKs, and fingerprinting, as falling within the same consent and processing rules as cookies, rather than assuming they are out of scope because they are not literally cookies.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.