TechReaderDaily.com
TechReaderDaily
Live
Privacy · Surveillance

Data Broker Economy Thrives as Post-Cookie Identity Tracking Refuses to Die

Google's Privacy Sandbox retreat and Apple's ATT legal battles reveal how the data broker economy fuels a quieter, costlier, and less accountable architecture for tracking people across the internet.

On October 17, 2025, the United Kingdom's Competition and Markets Authority released Google from its legally binding Privacy Sandbox commitments, a quiet administrative act that formally closed the book on six years of one of the most heavily scrutinised software projects in the history of digital advertising. The same week, Google announced it was retiring the Privacy Sandbox entirely, leaving third-party cookies in Chrome intact. The signal was unmistakable: the internet's largest advertising company had concluded that the post-cookie future was not, in fact, arriving on anyone's schedule.

The collapse of the Privacy Sandbox is the defining event of the ad-tech identity story over the past two years, and its implications are only beginning to be understood. Google had spent half a decade promising that its suite of APIs, Topics, Protected Audience, Attribution Reporting, would replace the tracking infrastructure that third-party cookies enabled, while purportedly being more private. But as MediaPost noted in January 2025, cookie deprecation had already ceased to be a meaningful industry narrative before Google formally abandoned it. The technology failed to gain advertiser adoption, its privacy properties were contested by civil-society groups, and regulators in both London and Brussels remained sceptical.

The upshot, as ExchangeWire summarised in its 2025 year-in-review, is a landscape defined by consolidation, chaos, and the enduring reign of cookies. But the collapse of the Sandbox does not mean that nothing has changed. It means that change has moved to the parts of the stack that consumers never see, and that regulators have barely begun to map.

To understand the identity architecture that actually exists in mid-2026, it helps to start not with Google but with Apple. In April 2021, Apple deployed App Tracking Transparency (ATT), a privacy feature that required apps to obtain user consent before accessing the Identifier for Advertisers (IDFA). The impact was immediate and measurable: opt-in rates settled somewhere below 30% in most markets, and mobile advertising, a market worth hundreds of billions of dollars, was forced to rebuild its targeting infrastructure around probabilistic signals, first-party data, and Apple's own ad network, which operated under different rules.

Five years later, ATT remains the single most consequential privacy intervention a platform has made against the ad-tech industry, and it is also the most contested. In March 2026, Reuters reported that German publishers and advertisers were calling for the country's competition authority to fine Apple over its app tracking rules, arguing that Apple's revised proposals did not go far enough. The German Association of the Branded Goods Industry and other trade bodies alleged that ATT unfairly advantages Apple's own advertising business, which is not subject to the same consent requirements. The underlying data flow is the one nobody is regulating: Apple collects behavioural signals across its own ecosystem, App Store, News, Stocks, Apple TV, and uses them to target ads, while third-party apps must beg for permission.

This asymmetry is not accidental. It is the business model. Every platform that has restricted third-party tracking, Apple with ATT, Google with its short-lived Sandbox, Meta with its conversion API push, has simultaneously deepened its own first-party data moat. The effect has been a radical concentration of advertising spend into the walled gardens. The post-IDFA world did not end tracking; it privatised it.

The scramble for first-party data has reshaped entire sectors. Retail media, the practice of retailers selling advertising space on their own digital properties, powered by their own customer data, has become the fastest-growing channel in digital advertising. Albertsons Media Collective integrated its first-party shopper data with Google and YouTube advertising in April 2026, launching with Keurig Dr. Pepper as its first partner. Walmart, Amazon, and Target have all built advertising businesses that rival mid-tier ad-tech platforms in revenue. The logic is straightforward: when you cannot track a user across the open web, you track them inside the store where they are already logged in, already identified, and already transacting.

AdExchanger argued in April 2026 that AI decision engines, optimised for outcomes such as sales and retention, require deterministic identity and clean first-party signals, not the probabilistic guessing that the open programmatic market relies on. This creates a feedback loop: the better the first-party data, the better the AI performs; the better the AI performs, the more budget shifts to channels with first-party data; and the more budget shifts, the harder it becomes for publishers and platforms without logged-in users to compete.

But the most consequential identity infrastructure of the post-cookie era is not a platform or a protocol. It is the data broker ecosystem, which has adapted to every privacy intervention with the patience of water finding a crack in concrete. In February 2026, the Federal Trade Commission sent letters to thirteen data brokers reminding them of their obligations under the Protecting Americans' Data from Foreign Adversaries Act (PADFAA). The letters were a procedural nudge, not a crackdown, but they signalled that the FTC is at least attempting to map a sector that has, for two decades, operated largely without federal oversight.

The scale of the problem is enormous. A Senate report released in early 2026, led by Senator Maggie Hassan, found that data brokers were fuelling billions of dollars in consumer losses by selling personal information that scammers use to target vulnerable populations. The report documented how brokers aggregate data from public records, loyalty cards, app SDKs, and data-sharing agreements between apps and analytics firms, then resell it in bulk to anyone with a credit card. The architecture is circular: a person downloads a weather app, which embeds an SDK from a location data broker, which sells the resulting location stream to a marketing platform, which cross-references it with purchase data from a retailer, which uses the enhanced profile to serve an ad inside another app that also embeds the SDK.

Every step of this chain operates under a different privacy regime, a different consent framework, and a different theory of what constitutes personal data. The SDK vendor claims it collects only anonymised device IDs. The data broker claims the IDs are not personally identifiable because they are hashed. The marketing platform claims it does not need consent because it never directly collects data from the user. The retailer claims its privacy policy covers third-party sharing. The weather app claims the user consented when they clicked 'Accept' on a 9,000-word terms-of-service document. The user, at no point, knows that their morning run in the park generated a data point that was sold, resold, enriched, and activated before they finished their coffee.

The regulatory response has been fragmented. In the United States, the FTC has pursued individual enforcement actions against data brokers under Section 5 of the FTC Act, but there is no comprehensive federal privacy law. California's attorney general has escalated scrutiny of surveillance pricing, the practice of using consumer data to personalise prices at the individual level, but enforcement remains case-by-case. In Europe, the GDPR theoretically prohibits much of this behaviour, but the enforcement gap is wide. The Irish Data Protection Commission, which oversees most large US tech firms operating in the EU, has been repeatedly criticised by civil-liberties groups for slow and under-resourced investigations.

Meanwhile, the identity resolution market has consolidated around a small number of authenticated-ID solutions. The Trade Desk's Unified ID 2.0 (UID2), built on hashed email addresses, has become the default identity framework for the open programmatic ecosystem. But its adoption, while broad among publishers and ad-tech platforms, has not solved the fundamental consent problem: most consumers do not know they have a UID2 identifier, have never consented to its creation, and cannot meaningfully exercise control over it. The identifier is generated when a user provides an email address to a participating publisher or advertiser; it then propagates across the bidstream without additional consent checks.

The IAB Europe's AdEx Benchmark 2025 report, released in July 2026, showed continued growth in digital advertising spend across Europe, driven in significant part by the same programmatic infrastructure that privacy advocates have spent a decade trying to reform. The numbers confirm what the policy stalemate suggests: the advertising economy has absorbed every privacy intervention and grown around it. ATT did not kill mobile advertising. GDPR did not kill programmatic. The Privacy Sandbox did not replace cookies. Each intervention forced the industry to build new pipes, and the new pipes are harder for regulators to see and harder for consumers to understand.

The biggest unanswered question of mid-2026 is whether the EU's Digital Omnibus proposals, under debate as privacy watchdogs convened in Brussels in June, will reshape the definition of personal data in ways that disrupt the hashed-email identity stack. If pseudonymous identifiers are explicitly brought within the GDPR's consent requirements, the UID2 architecture would need to be rebuilt from the ground up. But the debate has been captured by industry lobbying, and the outcome is uncertain.

Another fault line is the growing use of data broker-sourced information by US immigration enforcement. Oregon lawmakers attempted in early 2026 to bar data brokers from selling personal information to Immigration and Customs Enforcement, only to discover that the data flows are so deeply embedded in the commercial data market that targeted bans are nearly impossible to enforce without restructuring the entire broker licensing system. The same location data that powers retail footfall analytics and ad targeting can, with no technical modification, be used to track a person's movements for deportation purposes. The data does not know the difference, and the brokers are not required to ask.

The post-IDFA, post-cookie identity stack is not a stack at all. It is a patchwork of platform-controlled gardens, first-party data moats, probabilistic fingerprinting pipelines, and a thriving secondary market in personal data that has not been meaningfully regulated in any jurisdiction. The privacy interventions of the past five years have changed the surface, the consent pop-ups, the toggle switches, the platform marketing, without altering the fundamental dynamics underneath. Google's retreat from cookie deprecation confirmed what the market already knew: the industry will not voluntarily dismantle the tracking infrastructure on which it depends. The question for the next five years is whether anyone outside the industry will do it for them.

Watch for three checkpoints in the second half of 2026: the EU Digital Omnibus negotiations, which will determine whether hashed identifiers are personal data; the German competition authority's final decision on Apple's ATT rules, which could force a redesign of the mobile consent framework across the entire App Store ecosystem; and the FTC's follow-through on the PADFAA letters, which will reveal whether the Commission is building enforcement cases or merely sending reminders. The architecture that tracks you across the internet is not static. It is being rebuilt every quarter. The only question is whether anyone is drawing the blueprints.

Read next

Progress 0% ≈ 11 min left
Subscribe Daily Brief

Get the Daily Brief
before your first meeting.

Five stories. Four minutes. Zero hot takes. Sent at 7:00 a.m. local time, every weekday.

No spam. Unsubscribe anytime · Privacy.