

On July 24, 2024, the U.S. Federal Trade Commission (FTC) released a statement that hit home for many in the digital advertising and marketing industry. The FTC categorically stated that hashing — commonly used by companies to obscure personal data — is not a foolproof method to ensure anonymity or privacy compliance.
This isn’t new information; the limitations and potential pitfalls of hashing as a privacy measure are well known. However, the FTC’s explicit stance is a strong signal to the industry. One that could have far-reaching implications, especially with the growing reliance on data clean rooms, identity solutions, identity resolution, identity bridging technologies and retail media networks.
The FTC’s statement can be found here.
Understanding the FTC’s position
Hashing converts personal data like email addresses, phone numbers or user IDs into seemingly random strings of characters. It is used to protect user privacy because people believe hashed strings are not easily reversible, making it difficult for anyone to trace the hash back to the original data.
The FTC says this is a flawed assumption. Hashes still serve as unique identifiers that track individuals across platforms and over time. However, users can be re-identified or their data reversed without significant cost or effort. This is a significant privacy risk with the potential for serious harm. The agency stressed that its “staff will remain vigilant to ensure companies are following the law and take action when the privacy claims they make are deceptive.”
If the government doesn’t see hashing as sufficient, companies must follow suit.
Implications for privacy technologies
This raises essential questions about the current and future use of privacy-preserving systems like data clean rooms, identity solutions, identity resolution and identity bridging.
These often combine multiple data points, sometimes from disparate sources, to establish or verify user identity and target consumers with precision. Although they are designed to reduce the risk of re-identification and protect data, overstating their privacy benefits and expecting them to serve as a silver bullet for all privacy compliance may not be enough.
Even adding comprehensive strategies combining encryption, differential privacy and robust access controls, might not be enough for regulators.
9 actions for advertisers and marketers
Advertisers and marketers must pivot toward more sustainable and privacy-compliant practices, here’s how:
1. Educate teams on the limits of hashing
Ensure teams understand hashing is not enough to comply with privacy obligations. Hashed identifiers should be treated as personal data and protected as such. Hopefully, this will help prevent over-reliance on hashing and using more comprehensive privacy measures.
2. Prepare for regulatory compliance
Expect increased scrutiny on claims about data de-identification and stricter compliance requirements. A comprehensive privacy strategy is essential to deal with this. It will also put your organization in a better position to handle stricter laws or guidelines.
3. Enhance transparency and prioritize user consent
Transparency is key to building and maintaining user trust and obtaining informed consent. You must tell users how their data is collected, used and shared. This has to be an ongoing effort, not a one-time disclosure.
It’s more important than ever to obtain informed consent from users before using their data for advertising and measurement purposes. Affirmative consent is necessary for handling certain highly sensitive personal data. This goes beyond ticking a box; it’s about educating users on how their data will be used and ensuring they can control it.
4. Perform third-party due diligence
Thoroughly investigate any vendor of a technology claiming it can de-identify personal data. Understand the methods used to determine if the output identifier is a unique value that can potentially identify and track an individual.
5. Conduct regular privacy audits
Regular privacy compliance reviews will tell you whether any data set considered unidentified can be used to trace or re-identify someone.
6. Support IAB Tech Lab’s Seller Defined Audiences
The IAB Tech Lab’s Seller Defined Audiences lets publishers use their first-party data within their own properties — provided user consent is obtained. This respects user privacy while allowing publishers to unlock the value of their data.
7. Move beyond first-party data and rethink consumer experience
Avoid direct response tactics that heavily depend on first-party data and hashed identifier. Instead, focus on enhancing consumer experiences with rich media, innovative ad formats, branded entertainment, advertorials and sponsorships.
8. Optimize audience reach on O&O platforms using data clean rooms for insights
Stricter government oversight increases the importance of using owned and operated (O&O) properties to reach audiences. Consider leveraging data clean rooms for insights, but think carefully about audience activation through these platforms.
9. Advocate for privacy-first data handling
Engage in industry discussions and advocate for a privacy-first approach to data handling that goes beyond hashing. Support efforts to create standards and best practices that recognize the limitations of hashing and promote stronger data protection methods.
What this means for the industry
The FTC’s announcement is the latest of many warnings about this. Reassess your data practices and privacy claims. It’s time to evolve strategies and adopt more holistic approaches that genuinely protect consumer privacy.
Responsible data handling practices aligning with regulatory expectations and consumer trust are crucial. The FTC’s latest statement reinforces the need for continuous innovation in how data is managed and protected. Moving forward, methods must be technically sound and legally and ethically robust.
As long as an identifier can be used to identify and track people over time, companies must be sure they are complying with all privacy obligations, including transparency, consent, user choice, accountability, etc. As an industry, we must take this to heart and strive for transparency, compliance and, above all, trustworthiness in all data practices.
The post Why the FTC’s stand on hashing is a wake-up call for digital advertisers appeared first on MarTech.
**The FTC’s Position on Hashing: A Crucial Alert for Digital Advertisers**
In the rapidly evolving digital landscape, advertisers continuously seek innovative ways to target consumers with precision. One such method that has gained traction is the use of hashing, a technique that allows advertisers to anonymize personal data while still enabling effective targeting. However, recent developments have highlighted the Federal Trade Commission’s (FTC) growing scrutiny of this practice. The FTC’s position on hashing is a crucial alert for digital advertisers, signaling the need for a more cautious and transparent approach to data handling.
### Understanding Hashing in Digital Advertising
Hashing is a cryptographic process that converts data, such as email addresses or phone numbers, into a fixed-length string of characters, known as a hash. This hash is typically unique to the original data, but it is not reversible, meaning that the original data cannot be easily retrieved from the hash. In digital advertising, hashing is often used to anonymize personal information before it is shared with third parties, such as ad networks or data brokers, for the purpose of targeting ads.
For example, an advertiser might hash a list of customer email addresses and share the hashed data with an ad network. The ad network can then match these hashes with its own hashed data to identify users who should be targeted with specific ads, all without directly exposing the underlying personal information.
### The FTC’s Concerns with Hashing
While hashing is often touted as a privacy-preserving technique, the FTC has raised concerns about its effectiveness and the potential for misuse. The FTC’s position is grounded in the belief that hashing, while a step toward anonymization, does not fully eliminate the risks associated with the use of personal data.
1. **Re-identification Risks**: One of the FTC’s primary concerns is the possibility of re-identification. Although hashing is designed to anonymize data, it is not foolproof. With enough computational power and access to additional data sets, it is possible to reverse-engineer hashes or match them with other data to re-identify individuals. This risk is particularly pronounced when common hashing algorithms are used without additional security measures, such as salting (adding random data to the input before hashing).
2. **Transparency and Consumer Awareness**: The FTC is also concerned about the lack of transparency in how hashed data is used. Consumers are often unaware that their data is being hashed and shared with third parties, and they may not fully understand the implications of this practice. The FTC has emphasized the importance of clear and conspicuous disclosures to consumers about how their data is being used, even when it is hashed.
3. **Data Minimization**: The FTC advocates for the principle of data minimization, which suggests that companies should only collect and use the minimum amount of data necessary for a specific purpose. The use of hashing does not absolve companies of their responsibility to minimize data collection. The FTC has warned that companies should not use hashing as a way to justify the collection of excessive amounts of personal data.
4. **Legal and Ethical Considerations**: The FTC has also highlighted the legal and ethical implications of hashing. Even though hashed data may be considered “anonymized” under certain legal frameworks, it may still be subject to privacy regulations if there is a reasonable likelihood of re-identification. The FTC has cautioned companies against assuming that hashed data is exempt from privacy laws and has urged them to consider the broader ethical implications of their data practices.
### Implications for Digital Advertisers
The FTC’s position on hashing has significant implications for digital advertisers. Companies that rely on hashing as part of their data-driven advertising strategies should take the following steps to align with the FTC’s guidance:
1. **Enhance Security Measures**: Advertisers should use strong, industry-standard hashing algorithms and consider additional security measures, such as salting, to reduce the risk of re-identification. It is also important to regularly review and update these measures to keep pace with advancements in computational power and re-identification techniques.
2. **Increase Transparency**: Companies should provide clear and accessible information to consumers about how their data is being used, even when it is hashed. This includes updating privacy policies and offering consumers meaningful choices about data collection and sharing.
3. **Practice Data Minimization**: Advertisers should critically evaluate the data they collect and use, ensuring that they only gather the minimum amount necessary for their advertising objectives. This may involve rethinking data collection practices and exploring alternative targeting methods that do not rely on personal data.
4. **Stay Informed on Legal Developments**: The regulatory landscape surrounding data privacy is constantly evolving. Advertisers should stay informed about changes in privacy laws and regulations, both in the United States and globally, to ensure compliance. This includes understanding how different jurisdictions may interpret the use of hashed data.
5. **Ethical Considerations**: Beyond legal compliance, advertisers should consider the ethical implications of their data practices. This includes reflecting on the potential impact
Recent Comments