How your data ends up shaping the ads you see

Every ad you see online is shown to you because something you did, somewhere, told a system you might respond to it. This guide explains what data advertisers actually collect, how it moves through programmatic auctions and demand-side platforms (DSPs), and what UK rules under the ICO and ASA's CAP Code say about consent and targeting.

Check a test's results with the A/B Test Significance Calculator Work out your monthly spend with the Ad Budget Calculator

When people talk about data in advertising, they usually mean two different things at once: the information a business collects about its own customers, and the much larger pool of behavioural signals that platforms like Google and Meta gather across the web and hand back to advertisers in aggregated, targetable form. Both matter if you're running ads in the UK, because both are covered by data protection law and both shape how much your advertising costs.

What counts as data in an advertising context

Data, in this setting, is anything that lets an advertiser or a platform identify a person or a group of similar people and show them something relevant. That includes obvious things like an email address collected at checkout, and less obvious things like the fact that a phone has visited three gardening websites this week and is therefore likely to see an advert for lawn feed. The second kind, inferred interest rather than declared fact, does most of the work in modern targeting.

A useful distinction is between data a business collects directly and data it buys or licenses through a third party. A retailer's own customer list, built from purchases and sign-ups, is first-party data. Data bought from a broker, or supplied by a platform based on browsing activity elsewhere on the internet, is third-party data. The two are treated differently under UK law, and increasingly differently by the platforms themselves.

How advertisers actually get hold of it

First-party data

This is the data a business already owns because a customer gave it to them: names and emails from a newsletter sign-up, purchase history from an online shop, phone numbers from a loyalty scheme. It's the most reliable targeting asset a small or medium-sized business has, because it doesn't depend on a platform's tracking and it was collected with the customer's knowledge. Uploading a customer list to Meta or Google to build a lookalike audience, a group of new people who resemble existing customers, is one of the most common uses of first-party data in UK small business advertising.

Third-party data and cookies

Third-party data is gathered by someone other than the business running the advert, most often through a cookie: a small file a website places in a visitor's browser to recognise them on a return visit or track them across other sites. Advertising networks use this to build a picture of a person's interests over time, which is what lets a shoe advert follow someone around the internet after they've looked at trainers once. This is the practice that data protection rules and browser makers have both been tightening, and it's worth understanding before you plan a campaign around it, because the targeting options available today may not all be there in twelve months.

Where programmatic advertising fits in

Most of this data is put to work through programmatic advertising: the automated buying and selling of ad space, where an algorithm decides in real time which advert a particular visitor sees, based on the data available about them. A demand-side platform (DSP), the software an advertiser or its agency uses to bid on ad space, matches an advertiser's target audience against the data attached to each available impression, and the highest relevant bid wins the placement, often within a fraction of a second. Our guide to how digital ad auctions work covers the mechanics of that bidding process in more detail.

The practical effect for an advertiser is that better data, more accurately describing the right audience, tends to produce a lower cost per outcome, whether that's measured in cost per thousand impressions (CPM) or cost per click (CPC). This is why platforms push businesses to install tracking pixels and connect their own customer data: it sharpens the targeting, and sharper targeting is generally cheaper to run.

The rules that govern data use

UK GDPR and PECR

Any UK business collecting or using personal data for advertising sits under UK GDPR (the UK's version of the General Data Protection Regulation) and PECR (the Privacy and Electronic Communications Regulations), which specifically covers cookies and direct electronic marketing. The core requirement is straightforward: a website must ask for consent before setting non-essential cookies, and a business must have a lawful basis before using someone's personal data to target them with adverts. The Information Commissioner's Office (ICO) enforces this, and it has taken action against businesses running cookie banners that make refusing consent harder than accepting it.

The ASA and the CAP Code

Separately, the Advertising Standards Authority (ASA) applies the CAP Code to the adverts themselves, including rules on how targeted advertising is disclosed and how data-driven claims are substantiated. The two systems overlap but aren't the same thing: the ICO deals with how data is collected and used, the ASA with what the resulting advert says and how it's presented. Readers wanting the fuller picture on advertising compliance can see what the ASA requires, and the UK advertising regulation map sets out which body is responsible for which part of the process. As with any regulatory summary, it's worth checking the current wording at asa.org.uk or ico.org.uk before relying on it, since both codes are updated periodically.

What this means if you're the one running the adverts

If you collect customer data (an email list, a CRM, order history) and plan to use it for advertising, you need a lawful basis for that use and a way to honour opt-outs, before you upload anything to an ad platform. If your website sets cookies to support ad targeting, your cookie banner needs to make refusal as easy as acceptance, not just technically possible. Neither of these is a formality: the ICO's enforcement record shows it does act on cookie consent design.

There's also a commercial reason to take this seriously beyond compliance. Platforms are increasingly restricting what third-party data they'll accept, which means a business with clean, well-organised first-party data has a growing advantage over one that has relied entirely on platform-supplied targeting. Building that list properly, with real consent and a clear record of where each contact came from, is becoming as much a part of media planning as choosing a channel or setting a budget.

The move away from third-party cookies

Browser makers have been reducing how much third-party cookies can do, and advertisers have been adapting by leaning harder on first-party data, on platform-run audience matching that doesn't expose individual identifiers, and on contextual targeting, showing an advert based on the content of the page. None of these fully replaces what third-party cookies used to offer, and the transition has been uneven across platforms and slower in places than originally expected. For a business building a campaign now, the practical takeaway is not to design a strategy that depends entirely on cookie-based retargeting, because the targeting options available at launch may narrow before the campaign ends.

For a wider grounding in the terms used here, including CPM, CPC and DSP, the advertising glossary defines each on its own page. Anyone weighing up whether a given platform's targeting is worth the spend is usually better placed to judge that after seeing how the auction and the data behind it actually work.

Knowing how your data is used is only half the job

The targeting explains why an ad reaches you. Whether it actually persuades anyone is a separate question, one that a proper test answers.