Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: TCF and Vendors

Supply-Side Platform

Also known as: SSP, Sell-Side Platform
Simply put

A supply-side platform (SSP) is advertising technology that helps publishers, such as website owners, mobile app developers, and connected TV providers, automatically sell their available advertising space. It manages and optimizes the sale of ad impressions, generally connecting publishers to advertisers who buy that space through programmatic systems. SSPs sit on the publisher side of the digital advertising market, complementing demand-side platforms (DSPs) used by advertisers to buy ads.

Formal definition

A supply-side platform (SSP), also called a sell-side platform, is a programmatic advertising technology platform used by publishers (web, mobile app, and connected TV) to automate and optimize the sale of display, video, and other advertising inventory. SSPs manage available ad impressions, expose them to buyers and ad exchanges, and support monetization and yield optimization on the supply side of the programmatic ecosystem, functioning as the counterpart to demand-side platforms (DSPs) used by advertisers. Note that this definition describes the SSP's advertising function only; the specific tracking technologies (such as cookies, pixels, or device identifiers) an SSP may employ, and the associated consent and data-processing obligations under regimes such as the ePrivacy Directive and the GDPR in the EU or applicable US state privacy laws, are outside the scope of the evidence provided here and would require separate assessment.

Why it matters

Supply-side platforms sit at the point where a publisher's available advertising space is exposed to programmatic buyers, which makes them a significant node in the flow of data that can accompany digital advertising. While the evidence here describes the SSP's commercial function of automating and optimizing the sale of ad impressions, real-time programmatic advertising commonly involves the use of tracking technologies such as cookies, pixels, and device identifiers. Whether and how any particular SSP relies on such technologies is not established by the evidence provided and would require a separate, fact-specific assessment.

For compliance teams, the relevance of an SSP lies less in its advertising mechanics than in the data-processing questions that may arise around it. Where an SSP or the broader programmatic chain involves placing or accessing information on a user's device, the ePrivacy Directive and its national implementations generally require prior consent in most EU jurisdictions for non-essential purposes, and any processing of personal data that follows engages the GDPR. Requirements differ under other regimes, including the UK and individual US state privacy laws such as California's CCPA and CPRA, which often rely on an opt-out rather than an opt-in model. The precise obligations depend on facts not covered by this definition.

Because publishers typically integrate SSPs to monetize their inventory, publishers should not assume that using an SSP settles their consent or transparency responsibilities. Roles and responsibilities among publishers, SSPs, exchanges, and buyers can be complex and are frequently contested in regulatory and industry discussion, so allocation of controllership and consent obligations should be assessed case by case rather than presumed.

Who it's relevant to

Publishers and monetization teams
Website owners, mobile app developers, and connected TV providers use SSPs to automate and optimize the sale of their advertising inventory. Because publishers control the properties where impressions are generated, they may bear responsibilities relating to consent and transparency for any tracking technologies used in that context, though the precise allocation of those responsibilities depends on facts not covered by this definition.
Privacy and data protection officers
DPOs and privacy teams assessing programmatic advertising need to understand where an SSP sits in the supply chain in order to map potential data flows. Whether an SSP involves the placing of or access to information on a user's device, or the processing of personal data, cannot be determined from this definition alone and requires a separate assessment against the ePrivacy Directive, the GDPR, and any applicable non-EU regimes.
Legal and compliance counsel
Counsel advising on advertising technology contracts and data-sharing arrangements may need to consider how obligations are allocated between publishers, SSPs, exchanges, and buyers. Requirements differ across the EU, the UK, and individual US states, and the roles of parties in the programmatic chain can be contested, so conclusions should be reached on a case-by-case basis.
Marketing and adtech operations teams
Teams integrating or managing SSP relationships benefit from distinguishing the SSP's commercial function from the separate question of what tracking technologies and data processing an integration involves. Understanding this distinction supports coordination with privacy and legal colleagues when configuring consent management and monetization together.

Inside SSP

Definition and Function
A supply-side platform (SSP) is an advertising technology system used by publishers and website or app operators to offer their advertising inventory for sale, typically through automated real-time bidding and programmatic auctions. It sits on the sell side of the programmatic advertising ecosystem, in contrast to demand-side platforms used by advertisers to buy inventory.
Relationship to Tracking Technologies
SSPs commonly rely on cookies, pixels, device identifiers, local storage, and SDKs to identify users, build audience segments, and enable targeted or measurable advertising. Because these technologies involve the placing of or access to information on a user's device, they generally fall within the scope of the ePrivacy Directive and its national implementations in the EU, even where the technology is not literally a cookie.
Interaction with Consent Standards
The advertising-related processing facilitated by SSPs is typically treated as non-essential in most EU jurisdictions, meaning that prior consent is generally required under EU law before the associated cookies or similar technologies are used. Requirements differ under frameworks such as US state privacy laws, which often rely on an opt-out model rather than opt-in consent.
Role of Consent Signals and Frameworks
SSPs frequently integrate with consent management platforms (CMPs) and may consume or transmit consent signals, for example through the IAB Transparency and Consent Framework (TCF) or Global Privacy Control signals. These mechanisms are intended to communicate a user's choices downstream to participants in the programmatic chain, though the way they are implemented and honored can vary.
Legal Overlap: ePrivacy and GDPR
Two distinct regimes may apply. The ePrivacy Directive governs the placing of and access to information on the device, while the GDPR governs any subsequent processing of personal data, such as profiling or audience segmentation. Consent or a lawful basis under one regime does not automatically satisfy the other, and both must be considered separately where personal data is processed.

Common questions

Answers to the questions practitioners most commonly ask about SSP.

Is a supply-side platform the same thing as a demand-side platform?
No. A supply-side platform (SSP) is technology used by publishers and other website or app operators to offer their advertising inventory for sale in programmatic auctions, whereas a demand-side platform (DSP) is used by advertisers and buyers to bid on that inventory. They sit on opposite sides of the same programmatic transaction. Because SSPs typically operate on the publisher's own properties, the publisher is generally the party responsible for obtaining any consent required before an SSP places or accesses information on a user's device or processes personal data through it, but the precise allocation of controller and processor roles depends on the specific facts and contractual arrangements.
Does deploying an SSP mean I have automatically met my cookie consent obligations?
No. An SSP is technology that facilitates the sale of advertising inventory; it does not by itself satisfy legal obligations. In most EU and UK contexts, where an SSP relies on cookies, pixels, local storage, or similar technologies for purposes such as advertising or measurement, prior consent is generally required under the ePrivacy rules before those technologies are used, and any resulting processing of personal data must also have a lawful basis under the GDPR. The SSP is one component in a broader compliance picture that also depends on the publisher's consent management, disclosures, and legal judgment. No tool guarantees compliance.
When should an SSP be allowed to fire relative to the consent banner?
In most EU and UK jurisdictions, an SSP that relies on non-essential cookies or similar technologies for advertising should generally not be triggered until the user has given a clear affirmative consent for the relevant purposes. In practice this typically means the SSP's tags or SDKs are held back until a consent management platform confirms the appropriate consent signal. Where a US state opt-out framework applies instead, the SSP may be permitted to operate unless and until the user exercises an opt-out. The correct sequencing depends on which regime governs the user and how you have categorised the purposes involved, so this should be confirmed against your own legal analysis.
How does an SSP interact with a consent management platform and the IAB Transparency and Consent Framework?
Many SSPs are designed to read consent signals produced by a consent management platform, and a number participate in the IAB Transparency and Consent Framework (TCF), which provides a standardised way to communicate users' consent and objection choices to downstream vendors. In a TCF-based setup, the CMP typically generates a signal that the SSP and connected buyers consume to determine which purposes and vendors have been consented to. Participation in a framework such as the TCF supports interoperability but does not by itself establish that consent was validly obtained or that the framework's implementation matches all applicable legal requirements, which remains a matter for your own assessment.
What should be recorded when an SSP relies on user consent?
Where consent is the basis for an SSP's use of cookies or similar technologies, publishers generally need to be able to demonstrate that valid consent was obtained, which typically involves consent logging or record-keeping handled through the consent management layer rather than the SSP itself. Records may cover what the user was shown, the purposes and vendors consented to, and the time of the choice. The specific record-keeping expectations vary by jurisdiction and by regulatory guidance, so the details of what to retain and for how long should be determined with reference to the frameworks that apply to your users.
How should an SSP handle a Global Privacy Control signal or a user opt-out?
Under certain US state privacy laws, a Global Privacy Control (GPC) signal or other opt-out preference may need to be treated as a request to stop selling or sharing data for targeted advertising, which can affect whether an SSP should continue to receive or act on that user's data. This generally requires that the opt-out or GPC signal be communicated to the SSP and downstream vendors so they can suppress the relevant processing. The recognition and effect of such signals differ between US states and other regimes, and how a given SSP responds depends on its configuration and contractual terms, so the handling should be validated against the requirements applicable to the users in question.

Common misconceptions

Using an SSP that integrates with a CMP or the IAB TCF automatically makes a publisher's cookie practices compliant.
CMPs, the TCF, and similar frameworks are tools that can support compliance, but they do not guarantee it and do not replace legal judgment. Whether the resulting practices are lawful depends on how consent is collected, whether it meets the applicable standard, and how signals are respected throughout the chain.
Because the SSP operates on the publisher's inventory, only the ePrivacy rules on cookies are relevant.
The placing of cookies or similar technologies is governed by the ePrivacy Directive, but any downstream processing of personal data through the SSP, such as profiling or audience building, is separately governed by the GDPR in the EU. Both regimes may need to be addressed, and satisfying one does not satisfy the other.
The same consent approach used for an SSP works identically across all jurisdictions.
Obligations vary. In most EU jurisdictions, non-essential advertising technologies generally require prior opt-in consent, whereas frameworks such as the CCPA and CPRA in California often rely on an opt-out model. Practice and enforcement positions differ by geography and continue to evolve.

Best practices

Map which cookies, pixels, device identifiers, local storage, and SDKs are set by the SSP and any downstream partners, and classify them by purpose so that non-essential advertising technologies can be gated behind prior consent where required.
Where EU law applies, ensure advertising-related tags served through the SSP do not fire before valid consent is obtained, applying a standard that is freely given, specific, informed, and unambiguous and based on a clear affirmative action.
Assess both the ePrivacy obligations for placing or accessing information on the device and the separate GDPR obligations for any personal data processed downstream, rather than treating one as covering the other.
Use a CMP and, where relevant, consent frameworks such as the IAB TCF or Global Privacy Control signals to communicate user choices to the SSP and downstream participants, while recognizing that these tools support but do not guarantee compliance.
Tailor consent mechanisms to the applicable jurisdiction, for example applying opt-in in most EU jurisdictions and honoring opt-out mechanisms under US state privacy laws such as the CCPA and CPRA, and document the geographic scope of each approach.
Maintain records of consent and configuration decisions to support consent logging and record-keeping obligations, and seek legal review for contested or evolving areas rather than relying solely on vendor assurances.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide