News
The majority of global privacy regulations require publishers to implement robust data protection measures and effective consent mechanisms, ensuring that personal information is handled securely and that users have clear, unequivocal control over their data. These laws demand that publishers not only secure their user data against breaches but also transparently communicate what data is being collected, why, and how it will be used. As a result, publishers are having to rebuild their ID strategies to include robust consent processes that empower users and build a trust-based relationship centred on compliance.
The worldwide revolution in privacy laws got underway in 2018 with the General Data Protection Regulation in Europe. However, it is only now that the full impact of this and other similar rules is being felt. This is largely because ad tech companies are only now starting to embed privacy into their systems. Invasive technologies like tracking cookies and mobile device IDs are in decline, and although they will likely not disappear altogether, their scale and utility will be so reduced as to make them effectively redundant.
Publishers are therefore on the lookout for new IDs that can deliver the rich audience insights they need to monetise their data and meet the needs of advertisers, but which are also privacy-compliant and delivered with a clear consent mechanism. What makes this task even more challenging is that they must do so without impacting the user experience.
The potential negative impact of inappropriate ID technologies or processes on the user experience cannot be overstated. Research by HubSpot suggests that 88% of consumers are less likely to return to a site after a poor user experience. So, any friction in the experience, slow page loads, unnecessary pop-ups, or confusing processes potentially means a lost user. This is as true of apps as of webpages, with 90% of users reporting they stopped using an app due to poor performance.
As publishers reset their ID strategies they must, therefore, ensure that the user experience is prioritised even as privacy protection is enhanced.
In an ideal world, consumers would enjoy fast-loading, responsive websites with relevant and personalised ads that respect their privacy. These ads would feel like helpful, non-intrusive content rather than disruptive interruptions, enhancing the overall browsing experience. The entire experience would be frictionless and user centric.
One way to enable this vision is to create a simple consent mechanism, ideally avoiding any additional friction to the user journey. For example, while ensuring transparency and consent is vital to any new ID, this requirement should ideally be integrated with the existing consent mechanism, delivered via the publisher CMP, to ensure the simplest approach possible for consumers, as long as it is fully transparent.
Next, publishers should consider how the ID interacts with their sites. If it uses an iframe wraparound (whereby the ID is embedded into a website without integrating it into the main page’s code) the ID could impair site performance. Each iframe embedded in a web page acts like a separate webpage, loading its own HTML, CSS, JavaScript, and other resources. This means that the more iframes you have on a page, the more resources must be loaded, which can significantly increase the total load time of the page.
Iframes can be resource-intensive because they not only load their own content but may also execute scripts, load media, and perform other tasks independently of the parent page. This can strain the user’s device by consuming more CPU and memory resources. The effect of embedding an iframe on a web page has been likened to loading two or more pages simultaneously, leading to painfully slow load times.
Iframes are also a cybersecurity risk as they are vulnerable to common attacks such as cross-site scripting attacks (which combines malicious JavaScript with an iframe that loads a legitimate page to steal data from a user) and clickjacking (where an attacker tricks a user into clicking on a link by using hidden page layers).
Given these considerations, it is therefore worthwhile to find an ID that integrates directly with the website’s code. One approach is for the ID functional code to be embedded into the publisher’s site, either via code provided by the ID vendor or by the publisher creating the functional code. IDs can also be generated through the deployment of prebid or Secure Signals ID modules where the code is already integrated into the publisher environment.
Another issue to be wary of is the overuse of tags and cumbersome code. Excessive tags can increase page load times, negatively impacting the user experience and potentially drive visitors away from the website. Cumbersome or poorly optimised code can create inefficiencies, such as script conflicts or errors, which may degrade site performance or cause functional issues.
Publishers should therefore look for a streamlined solution that minimises the need for multiple tags. Telco-verified IDs, for example, operate within secure telecom environments, where IDs are generated and matched in real time. This approach eliminates the need for publishers to load and manage cumbersome third-party scripts, reducing the impact on page load times and simplifying site management.
Of course, publishers will need to consider many other factors when implementing new IDs, such as whether they are interoperable with their broader ad tech stacks, whether they are true first-party IDs and that the publisher controls the ID throughout the process, whether it can provide significant reach, and much else besides.
However, while these and other factors are all highly important, the ID will succeed or fail based on the user experience. Ensuring that consent mechanisms are simple and friction-free, and that the ID does not impact page performance are therefore two of the most significant factors for consideration as publishers rebuild their ID strategies.