Microsoft -owned adtech company Xandr is at the center of a complaint backed by European privacy advocacy group noyb — a nonprofit organization that has made a name for itself by taking action against tech giants that violate data protection regulations .

See also: Microsoft: Spell check and autocorrect are coming to Notepad
In its latest move, noyb is supporting an anonymous individual in Italy to file a complaint against Xandr with the country’s data protection authority. The complaint was filed under the European Union’s General Data Protection Regulation (GDPR), which means that if successful, it could lead to fines of up to 4% of the global annual turnover of Microsoft, Xandr’s parent company.
Xandr is accused of a lack of transparency and violation of individuals' rights to access data, whose information is processed to create profiles used for micro-targeted advertising through programmed auctions. The complaint also alleges that the adtech company uses inaccurate information about individuals.
The complaint asks the data protection authority to investigate and, if violations are confirmed, order Xandr to comply. Noyb also recommends a fine of up to 4% of Xandr's parent company's annual revenue (note: Microsoft's annual revenue for 2023 was about $212 billion).
Risk management
Microsoft launched its “data-enabled technology platform,” as it called Xandr, in late 2021, with the goal of expanding its digital advertising business. Despite the acquisition, Xandr has maintained its autonomy and operates as a separate entity. Microsoft’s press release at the time said the acquisition strengthened its “retail media solutions” and offered “enhanced monetization for publishers through greater access to first-party data and an integrated approach to marketing.” However, there was no mention of the potential increase in risk that could result from the acquisition.
The problem, according to the complaint, is that Xandr fails to respond to data access requests from individuals who want to delete or correct their personal information. The complaint refers to a “hidden” website where Xandr publishes access statistics. According to that page, from January 1, 2022 to December 31, 2022, the company received 1,294 access requests and 600 deletion requests, but denied all of them.
Read more: Detection and analysis of malicious scripts
A note on the website states: “We deny access and deletion requests when we cannot verify the identity and jurisdiction of the requester. Due to the nature of the data (which) Xandr collects on its platform, it is not possible for us to verify the identity of consumers who submit access and deletion requests unless these requests are linked to other identifiers. Therefore, we deny such requests.”
So Xand seems to be claiming that it does not need to comply with GDPR data access rights because the information it holds about individuals is pseudonymous.
However, the complaint argues that it is unreliable for a company that bases its entire business on profiling individuals for targeted advertising profits to claim that it cannot identify the individuals whose information it holds.
Commenting on a statement, Massimiliano Gelmi, data protection lawyer at noyb, said: “Xandr’s business is based on holding data on millions of Europeans and targeting them. Yet the company admits to having a 0% response rate to access and deletion requests. It is striking that Xandr is publicly showing how it violates the GDPR.”.
It is worth noting that the GDPR has a broad understanding of what is considered personal data. Even data that has been pseudonymized remains personal data. This means that those who hold such information must comply with EU-wide legal requirements, such as providing rights of access to the data.
The guidelines on data subjects’ access rights, adopted by the European Data Protection Board (EDPB) last year, include a typical example from the area of “micro-targeted advertising”. In this example, the Board points out that an adtech company should be able to “accurately identify” an individual requesting access to their personal data, using the same terminal equipment associated with their advertising profile (i.e. via the cookies rejected there). This is possible because “a link can be established between the data processed and the data subject”.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
If an individual requests their data in an alternative way, such as via email, the EDPB guidance suggests that the adtech company should request additional information to identify the relevant advertising profile and fulfill the data access request. Specifically, the guidance states that the individual should provide the cookie identifier stored on their terminal equipment.
It is unclear what actions Xandr took to identify the advertising profiles of individuals requesting access to or deletion of their data.
See more: Vinted: €2.3 million fine for GDPR violation
Returning to the complaint, noyb’s investigation also uncovered what appears to be high levels of inaccuracy in the information Xandr holds about individuals — a fact that may raise separate questions for its customers about the quality of its ad targeting services. But it also has legal implications, given that GDPR gives individuals the right to correct inaccurate data held about them.
EU individuals can rely on the GDPR for other rights, including the ability to request a copy of their data. Again, noyb claims this is another area where Xandr is not compliant. He was unable to obtain a copy of the complainant’s data from Xandr itself, but instead used an access request to one of the data broker providers.
“Thanks to a request for access with data broker — and Xandr vendor Microsoft — emetriq, we know that at least part of Xandr’s database consists of grossly inaccurate and inconsistent personal data about individuals,” it writes in a press release. “According to emetriq, the individual who made the complaint is male and female, has an estimated age between 16-19, 20-29, 30-39, 40-49, 50-59, and 60+. He also has an income between 500-1,500 euros, 1,500-2,500 euros, and 2,500-4,000 euros. In addition, the same individual is a job seeker, employed, a student, an apprentice, and works at a company. This company, in turn, employs 1-10, 1,000+, and 1,100-5,000 people at the same time.”
“It’s hard to imagine how these categories of data could be used for precise ad targeting,” noyb adds. “While emetriq is not the only data broker providing data to Xandr, it must be assumed that this information is used for ad targeting.”
Commenting further, Gelmi also wrote: “It seems that parts of the advertising industry are not really interested in providing advertisers with accurate information. Instead, the dataset contains a chaotic assortment of conflicting information. This can potentially benefit companies like Xand, as they can sell the same user with young and old to different business partners.”.
Microsoft responded to the complaint
A noyb spokesperson told us that it does not expect the complaint to be referred from Italy to Irish data protection authorities under the GDPR’s one-stop-shop process, as Xandr is based in the US. This corporate structure suggests that the adtech company could be the target of additional complaints in other EU member states where data from local residents has been processed, further increasing regulatory risk.

The complaint supported by noyb highlights previous research that showed that Xandr collects highly sensitive information about individuals for the purpose of creating advertising profiles. This information includes data about sex life or sexual orientation, religious beliefs and political opinions. The GDPR sets particularly high standards — explicit consent — for the lawful processing of sensitive categories of data.
Read also: EU: Fine on Microsoft for violating antitrust laws?
It is unclear how Microsoft’s Xandr would have obtained consent from the individuals whose data it holds. However, website visitors can be a source of information, as tracking for advertising purposes can be enabled by users accessing publishers’ content. In the EU, such websites are required to ask visitors for consent to tracking, but the industry’s standard mechanisms for obtaining that consent are often accused of violating the GDPR.
Source: techcrunch
