Back to glossary

GDPR / CCPA Compliance

EU and California privacy regulations governing personal-data processing in advertising. Foundational for any global ad-tech operation.

GDPR (the EU's General Data Protection Regulation, in force since 2018) and CCPA / CPRA (California's Consumer Privacy Act and its 2020 amendment) are the two foundational privacy regulations governing personal-data processing in advertising. GDPR applies to any processing of EU residents' data regardless of where the processor is located; CCPA applies to processing of California residents' data above a revenue threshold.

Key concepts: GDPR classifies biometric data (face features, gait, voice) as "special category" requiring explicit affirmative consent for processing. CCPA classifies the same data as "sensitive personal information" with opt-out rights. Both define a "data controller" (decides what to do with data) and "data processor" (acts on the controller's behalf) relationship with different liability profiles.

For DOOH with on-screen cameras, the Trillboards sensing SDK sends a record for each detected person and, on the Full profile, a face-identity template that Trillboards keeps for 400 days. The Trillboards Data Processing Addendum sets out every category, how long each is kept and who receives it.

Other adjacent regulations include the EU's AI Act (in force 2024, applies to high-risk AI systems, DOOH attention-measurement is borderline), the EU ePrivacy Directive (cookie-consent rules), and emerging US state-level laws (Colorado, Virginia, Texas) that broadly mirror GDPR's structure.

Authoritative reference

GDPR, Official Reference

See also

Reference docs

Building against Trillboards?

Our developer reference covers the DSP API, partner SDK, proof-of-play verification, and the sensing pipeline that powers buyer-grade audience signals.

View developer docs