Identificatiemerken uitwisselen
Twee partijen wisselen elkaars identifier uit, zodat hun aparte dossiers over dezelfde persoon te koppelen zijn.
- Familie
- Keten
- Status
- actief
- Geldt voor
- web, mobile-app
Wat er gebeurt
One party calls the other and passes its own identifier for the visitor in the request; the other answers, sets or reads its own identifier, and returns the pairing. Usually this runs as a short chain of redirects or invisible image requests at page load. Afterwards each party can translate its own identifier into the other's.
Waarom het ertoe doet
Two separate records become one. Data collected in one place, under one story about what it is for, can from that moment be matched with data collected somewhere else entirely. The person cannot see this happen, and deleting a cookie at one party does not undo the mapping already stored at the other.
Veelvoorkomende oorzaken
- a match or sync endpoint invoked automatically when a tag loads
- a chain of redirects in which each hop appends its own identifier to the query string
- an audience or measurement partner integrated by activating a template that includes the exchange
- a match performed between servers, so no cookie is set in the browser at all and a cookie-based audit reports the parties as absent
Dit is het níet
Passing an identifier to one recipient for that recipient's own use is ordinary tracking. What distinguishes this entry is the exchange: the value of party A appears in a request to party B, and the purpose of that request is the pairing rather than any content. One view reaching many bidders at once is Bid request broadcast. That entry is about the number of recipients of a single view; this one is about two parties pairing their values. An auction capture usually shows both, and then both are cited: capping the bidder list does not stop the exchange, and stopping the exchange does not cap the list.
Hoe je het vaststelt
Indicator
A request to a host under one registrable domain whose URL, body or redirect location contains, verbatim or trivially encoded, an identifier value that another registrable domain set as a cookie or returned in the same capture. The match of the two values is the finding, and it holds equally where no cookie is set anywhere and the value only travels in the requests.
Methode
network-with-identifier
Kwaliteit van de detectie
92 van 100
De grenzen van deze bevinding
Wat dit patroon zou weerleggen
- The matching value is a page identifier, campaign code or cache buster rather than a per-visitor identifier.met de hand te toetsende bevinding vervaltCompare across two clean profiles: a value that differs per profile is per-visitor, a value that is identical is not.
- Both hosts belong to the same registrable domain or the same declared processor.met de hand te toetsende bevinding krijgt een ander patroon
- The exchange only occurs after consent was registered.machinaal te toetsende bevinding wordt zwakkerIt changes the consent question, not the joining itself.
- The value passed is a per-recipient pseudonym that the receiving party cannot map back.niet uit de meting af te leidende bevinding wordt zwakkerCannot be settled from the capture. It is a question for the operator, and it belongs in the request for comment.
- The identifier field in the exchange contains an unresolved template placeholder rather than a value.machinaal te toetsende bevinding vervaltAn attempted exchange and a completed one are different findings. Report the completed one only where the field carries an actual value.
Wat dit patroon níet vaststelt
- harm; the catalogue standardises a finding so it can be referred to, it does not weigh it
- severity; there is no score here, by design. Weighing belongs to whoever applies the entry to a concrete case
- unlawfulness; that is for a supervisory authority or a court
- intent; a fault is usually a build decision, not a plan
- absence: not finding it in one capture is not evidence that it is not there
Reproduceren
- manual
METHOD.mdno dedicated reproduction exists yet; follow the general method and the indicator above
Juridisch kader
Bepalingen
Rechtspraak
Veelgehoorde tegenwerpingen
This is purely technical plumbing between suppliers.
Deciding to make two datasets joinable is a decision about the purpose and the means. That the mechanism is a redirect does not make it a technicality.
The identifiers are pseudonymous.
Pseudonymous data is personal data under the regulation, and the entire purpose of the exchange is to keep recognising the same person across contexts.
Users can delete their cookies.
Deleting a cookie at one party does not remove the mapping already stored at the other. The exchange survives the deletion.
Geldt wanneer
to-processing
Aangetroffen in
De onderzoeken waarin dit patroon gemeten is.