Prompt
How do I ensure my retargeting shoppers on retailer sites with a display ads platform is compliant?
Latest observation
To keep retargeting shoppers on retailer sites compliant, you’ll want to treat it as a data privacy + ad platform policy + retailer contract problem, not just a media-buying problem.
Here’s a practical checklist:
1) Confirm you have a lawful basis to retarget
Depending on where users are located, you may need:
- Consent for cookies/pixels/device IDs
- Or another lawful basis where permitted, but retargeting is often treated as tracking that requires consent in many jurisdictions
Make sure:
- Your site/app collects consent properly
- Your retargeting partner only fires tags after consent where required
- You can prove consent status and timestamp
2) Use only permitted identifiers
Make sure your platform and audience segments use identifiers that are allowed under the relevant laws and platform rules:
- Cookies
- Mobile ad IDs
- Hashed emails, if properly collected and disclosed
- Avoid using sensitive data or inferred sensitive categories unless explicitly allowed and consented
Do not build audiences from:
- Health, children’s data, precise location, or other sensitive attributes unless you have the specific legal basis and platform permission
3) Provide clear disclosures
Your privacy policy and consent notices should clearly explain:
- That you use cookies/pixels/retargeting
- What data is collected
- Who you share it with
- The purposes of use, including advertising and cross-site tracking
- How users can opt out or withdraw consent
For retailers/sites you’re retargeting from or on, make sure the data collection and ad use is disclosed in their privacy notices too.
4) Honor opt-outs and withdrawal of consent
Your system should support:
- Opt-out from targeted advertising
- Consent withdrawal
- Global privacy signals where applicable, such as:
- GPC (Global Privacy Control)
- “Do Not Sell or Share” requests under applicable state laws
Once a user opts out, stop:
- Tracking them for retargeting
- Including them in remarketing audiences
- Sending them personalized ads, where required
5) Have proper data processing agreements
If you’re working with:
- A display ads platform
- A retailer
- A data management platform
- A tag provider
Make sure you have:
- A DPA or equivalent terms
- Clear controller/processor roles
- Data use restrictions
- Security obligations
- Rules around retention and deletion
If data is transferred internationally, confirm the transfer mechanism is valid.
6) Follow retailer and publisher policies
Retailer sites often have strict rules about:
- Pixel placement
- Audience sharing
- Customer data use
- Frequency caps
- Brand/category restrictions
- Competitive exclusions
Some retailers also prohibit using their onsite data for offsite retargeting unless explicitly agreed.
7) Avoid dark patterns and misleading practices
Retargeting ads should not:
- Reveal sensitive inferences
- Mislead users about why they’re seeing the ad
- Use overly personal language that implies you know private behavior
- Target minors or exploit vulnerable groups
8) Keep data minimization and retention tight
Only collect what you need:
- Use short retention windows for audience lists
- Remove stale users
- Limit log retention
- Re-segment audiences periodically
9) Set age-gating and child-safety controls
If your audience may include minors:
- Exclude children where required
- Do not retarget based on child-directed content
- Apply child/privacy restrictions under applicable laws and platform policies
10) Audit your setup regularly
Run periodic checks on:
- Tag firing behavior
- Consent gating
- Audience source and eligibility
- Exclusion lists
- Region-specific compliance
- Vendor access and retention
11) Document everything
Keep records of:
- Consent language and versions
- Tag maps and event flows
- Audience definitions
- Vendor contracts
- Opt-out handling
- Internal approvals and risk assessments
12) Get legal review for the jurisdictions you operate in
Compliance depends heavily on geography:
- EU/UK: GDPR + ePrivacy/cookie rules
- US: state privacy laws like CCPA/CPRA and others
- Canada: PIPEDA/provincial rules
- Other regions may have their own ad-tech restrictions
Quick rule of thumb
If you are tracking a user across sites to show them ads later, assume you need:
- Clear disclosure
- Valid consent or lawful basis
- Opt-out/withdrawal handling
- Restricted vendor/data-sharing terms
- Region-specific compliance checks
If you want, I can turn this into a retargeting compliance checklist or a policy template for your display ads platform.
Observation history
See 1 earlier observation
Create a free Obsurfable account to unlock historical responses, model comparisons, and deeper brand intelligence.
How did Obsurfable measure this prompt?
Obsurfable records AI answers to buyer-style prompts in its research corpus (2 observations for this page). Metrics are distributions over observations, not a single static ranking.
Which AI systems does Obsurfable collect answers from?
OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, and Meta AI.