“Put Privacy First” is the theme of this year’s Data Privacy Day, which falls today (28 January).
This year’s rallying call-to-action comes as the double-edged sword of artificial intelligence means companies are dealing with more data than ever before and therefore potentially exposed to more risk, be it on the consumer or via tighter data regulation across the world.
Here, our industry experts share their latest insights on what all businesses should be doing to put strong data privacy policies and systems at the heart of their operations…
Alexander Igelsböck, CEO & co-Founder, Adverity
“After a few turbulent years, it’s clear that all elements of data management – including quality control measures, privacy safeguards and secure democratisation – must work better together to create a responsible and effective advertising ecosystem.
“Privacy cannot be left to regulators or tech giants alone; it’s a shared responsibility at every touchpoint.
“Companies are realising that achieving a data-driven future requires better data-sharing processes. To guide employee decisions with data, information must be accessible while also ensuring proper governance.
“To avoid serious data privacy and security risks, all businesses need to establish strong management controls before expanding data access.
“This includes aligning practices with regulations and setting strict permissions so that only authorised individuals use data for approved purposes.”

Ben Ennis, Chief Operating Officer, Medialab
“If Information Security is to provide real value to your business, it can’t just be a tick box exercise and a certificate to bring out at pitches.
“It must be built into the core of your company’s culture and embedded within best practices across teams so it becomes a sub-conscious consideration daily.
“Training plays a key role in this, with a “little and often” approach ensuring teams are continually educated on security protocols and potential issues, while helping to create practicalities for companies to function around.
“It’s also important to educate your partners and clients on what to look out for and the challenges that arise should processes not be followed.
“This creates a culture of transparency and means businesses can operate more effectively, while maintaining the trust and safety clients expect.
“With the rise of AI-powered technologies, its vital privacy and security measures remain a top priority – not to mention that, with more clients seeking partners with recognised certifications (like ISO27001), you’ll be missing out on essential revenue if you’re not compliant with key standards and policies.”
Jason Warner, Managing Director, UK & EMEA, SBS
“Data Privacy continues to be under scrutiny and quite rightly so. The last few decades have seen the data collection of consumers proliferate and in most instances, policy playing catch-up.
“New advances that protect consumers and force business to find a better way to collect and use data has to be the right way forward.
“The Adtech industry needs frameworks to operate within, which will provide the guidance on how best to farm and use data for the purposes of digital marketing.
“These changes will force innovation and we should see a glut of new methodologies, giving competitive advantage to those willing to invest and find a better way. Embracing and acting upon change in industry is progression.”
Marko Johns, UK MD, Head of Agency Intl, Seedtag
“One of the biggest challenges advertisers face in 2025 is finding the balance between leveraging their own consented consumer data and ensuring levels of trust and transparency to those consumers, while being able to work with the shifting sands of regulation change.
“At the same time, we need to be conscious that privacy regulations do not hamper innovation, but are taken into account at the stage of product development.
“There are other strategies advertisers can apply, rather than a relentless need to use user data. Growth of brands in the marketplace has shown that maintaining individual-level targeting is not the be-all and end-all.
“After being shunted into the background when cookie-driven hyper-personalisation stole the show, contextual approaches are now set for an enduring role in the future of advertising. In their revitalised modern iteration, tools can offer scale and precision in audience targeting without needing individual data.”
Niklas Mortensen, Chief Design Officer, Designit
“Collecting people’s data isn’t just about being compliant – it’s core to earning trust in the long run.
“In an age where brands are in an intense battle to deliver personalised customer experiences, data privacy must be woven into every touchpoint.
“When consumers know their data is safe with you, they’ll also give you their loyalty.
“Data privacy shouldn’t just be about avoiding fines; it’s a democratic issue. As designers, we have a responsibility to turn what’s often seen as a limitation into an opportunity to build more authentic connections with people.
“Ultimately, people aren’t anti-technology, they’re anti-exploitation. Empowering them with real agency over their data means moving beyond intrusive cookie pop-ups and opt-ins.
“Instead, privacy should feel intuitive, accessible, and central to a better customer experience.”
Julie Rooney, Chief Privacy Officer, OpenX
“This year’s theme of “ensuring privacy and safeguarding personal data in the digital age” could not have come at a more poignant time in the advertising industry, with 2025 shaping up to be the year when the rubber meets the road in terms of privacy regulations in the US.
“Many states have now had comprehensive privacy laws in place for some time, and enforcement for those laws is expected to increase in the coming year.
“As that happens, regulators are likely to move beyond the low-hanging fruit and start addressing more substantive issues that could significantly shape how the digital advertising ecosystem is able to interact with consumers.
“For example, with more states providing consumers an explicit right to opt out of targeted advertising, we’re likely to see publishers offering more transparent and accessible opt-out mechanisms.
“Whether that will ultimately translate into higher consumer opt-out rates remains to be seen, but it is clear that publishers and brands alike will need to work hard to build and maintain consumer trust to thrive in a more privacy-focused online landscape.
“The fact that these laws are being enacted state-by-state rather than federally will further complicate how both publishers and brands adapt their strategies, sometimes requiring tailored approaches for compliance in each jurisdiction.
“In this environment, finding partners who understand the practical implications of these regulations is imperative. If someone is talking to you about data and identity but not privacy, I’d have concerns.”
Anoop Ramachandran, Chief Technology Officer, Preciso
“As a CTO, I understand that data security and privacy aren’t just internal concerns; they are fundamental to our relationships with our partners and clients.
“At Preciso, we see data protection not as a burden, but as a shared responsibility and a key differentiator in a competitive market.
“Our approach is designed to build trust, ensure compliance, and foster a culture of security, which we encourage our partners to embrace.
“A good data privacy strategy should be based around four key pillars:
“Transparency and Open Communication: so that partners understand your security framework and align their own security measures with your stringent standards.
“Adherence to Industry Standards and Regulations such as GDPR and other regional requirements.
“Vendor Validation: You should only interact with certified vendors. In our case, we allow traffic solely through vendors certified by the IAB Vendor List.
“Publishers also have the ability to specify approved vendors for European users. This process involves thorough cross-checking throughout the bidding process to ensure compliance.
“Data Encryption and Security Protocols at all levels: This ensures that data is secure and unreadable without proper authorisation. You should also encourage your partners to adopt similar practices.”
Fiona Salmon, Managing Director, Mantis
“At a time when we’re starting to see some shocking u-turns from social platforms on issues that directly impact users, such as fact-checking, quality publishers on the open web must lead the way to ensure that their readers’ preferences and rights are properly respected.
“A year ago we were on the cusp of Google rolling out its depreciation of the third-party cookie, with privacy challenges an immediate issue for the advertising industry to tackle.
“Although this never came to fruition, we shouldn’t be in denial about our ongoing trajectory towards a cookieless future, and privacy efforts can’t take a back seat in 2025.
“We should still be prioritising effective privacy measures, such as first-party data strategies — including signed-in users and established IDs — and contextual tools for successful, and respectful audience targeting.”
Alex Stil, Chief Commercial Officer, Verve
“The biggest issues around data privacy in 2025 centre on balancing personalisation with privacy. Consumers expect relevant, tailored experiences, but they also demand transparency and control over how their data is used.
“Emerging technologies like AI and advanced analytics bring even bigger challenges, as they require vast amounts of data to function effectively.
“Additionally, navigating the global, regional and local privacy regulations remains complex for businesses, making compliance a significant challenge.
“In order to ensure AI systems do not misuse our personal data, companies must clearly communicate how AI systems use data and adopt AI ethics guidelines that prioritise fairness, accountability, and privacy.
“By using methods like anonymisation and encryption, companies can protect data during AI training and deployment.
“Looking ahead, I anticipate an increase in more robust AI governance frameworks and standards to ensure ethical data use, as well as continued innovation in ID-less and contextual advertising solutions that prioritise privacy while maintaining relevance.”
Dom Selvon, Chief Technology Officer, Apply Digital
“The EU Digital Identity Framework – or EUDI to its friends – mandates all member states must provide a ‘Digital Identity Wallet’ to citizens and residents by 2026. This marks a major shift in how people across the bloc will manage and share their digital identities.
“While it should empower users with greater control, it will also present considerable challenges to businesses. Consent management will inevitably grow more complex and fragmented, with granular user control potentially leading to a ‘Cookie Consent 2.0’ scenario.
“Much like the frustrations of dealing with GDPR cookie banners, there is a risk of decision fatigue if users face repeated prompts to manage permissions.
“Furthermore, the shift from opt-in data sharing to user-managed preferences will likely restrict the amount of data people volunteer.
“Ultimately, this will make it harder for businesses to introduce digital services that consumers really value, such as personalisation.
“To navigate this new reality, brands must focus on developing intuitive, user-friendly consent tools that reduce friction while upholding transparency and compliance.
“The key question will be: are marketers prepared to invest in the privacy-first innovations necessary to meet these expectations?”
Greg Endean, Commercial Director EMEA, FreeWheel
“In the last few years, the industry has rapidly evolved to accommodate privacy considerations in the digital landscape, and despite the ongoing challenges, there are still opportunities for advertisers to provide relevant advertising while keeping data privacy at the forefront.
“Opting for quality environments that provide good user experience while upholding strict privacy regulations for both content and advertising – such as CTV and premium video – offers a safe and effective way of connecting with consumers.
“With growing adoption and engagement, these channels reflect the calibre of the environment on and behind the screen, while offering marketers audience insight built on meaningful and authenticated interactions rather than outdated tracking mechanisms.
“All these factors influence the industry’s ability to build trust with consumers and therefore contribute to building a better digital world for all parties.”
Alistair Bastian, CTO, InfoSum
“The theme of this year’s Data Privacy Day – you have the power to take charge of your data – should resonate equally strongly with consumers and businesses.
“Consumer awareness of privacy matters is growing, and is largely the driving force behind the positive regulatory changes we are seeing around the world. But in a fast-changing digital ecosystem, there’s a risk that their knowledge could quickly become outdated.
“It’s incumbent on all organisations that manage consumer data to not only be responsible custodians of that data, but to help to drive awareness of the changes in the data privacy landscape.
“Moreover, they should be helping to shape privacy regulation in a way that gives consumers more power over their data, and doing everything they can to ensure their own customers have full control of how their data is collected and used.”
Victoria Usher, CEO and Founder, GingerMay
“This Data Privacy Day has arrived at an uncertain time just days into a radically anti-regulation US presidency.
“Big tech leaders have been busy cosying up to Trump since his election victory, so it’s easy to imagine data privacy regulations being relaxed when they stand in the way of profit.
“Should this happen, we may end up with a very different internet ecosystem in the US compared to the rest of the world, especially given the EU’s continued firm regulatory stance on the topic.
“However, with almost three quarters (72%) of US adults — including 68% of Republicans — supporting privacy regulations, Trump’s populist tendencies could see him rein in tech companies instead, or at least not interfere with the state-level laws that currently make up the entirety of the US’ regulatory environment.
“We simply don’t know how the next four years will unfold, which is an alien feeling after a decade of what felt like unstoppable momentum towards stricter privacy controls.”
Joakim Antonsson, Chief Technology Officer, Brand Metrics
“One question everyone in adtech is starting to ask themselves is: how much data is it reasonable to collect, store and process?
“But the reason for the question isn’t all related to privacy. It also stems from the realisation that collecting, storing, and processing data has a massive carbon footprint, in the same ballpark as the airline industry.
“Our hope is that in 2025 we are leaving the current paradigm, which has long been to collect and store as much as we can get our hands on, in case one day we crack how to monetise it, and move into one in which we do what we have to do, and no more.
“This moral debate is focused primarily on sustainability and decreased carbon emissions, but if it can play a part in solving privacy issues along the way, it will benefit all of us.
“Brand Metrics is a no Personal Identifiable Information (PII) company with a Minimum Data Strategy.
“We hope that this is the path everyone starts to follow in 2025 – both for privacy reasons and for the love and protection of our one shared planet.”



