
Azerion, one of Europe's leading digital advertising platforms, announces the integration of Global Data Resources (GDR) into its Hawk DSP. This strengthens the company's targeting capabilities with one of the most advanced geo-demographic datasets in the industry.
The partnership enables Azerion teams and external clients to directly access GDR's comprehensive audience taxonomy via the Hawk DSP and activate it during campaign creation. This allows for more precise, scalable and privacy-compliant targeting in key European markets.
GDR is a pioneer in the field of geo-demographic insights. The company works with data partners and national statistics offices to create target group segments based on lifestyles, life stages, household characteristics, income, savings and consumer interests.
Unlike traditional audience data providers, GDR focuses exclusively on geographic clusters and micro-geographic neighborhood patterns. This ensures that no personal data is collected or used, no cookies or user IDs are required and there is full compatibility with DSPs, SSPs, social platforms and omnichannel environments. The privacy-first approach is perfectly aligned with the changing regulatory environment and supports the industry-wide trend away from individual tracking.
As GDR's segments address geographical areas rather than individual people, the integration is particularly suitable for channels such as digital out-of-home (DOOH), connected TV (CTV), audio, mobile, display and gaming environments. In addition, GDR's ID-free activation approach enables marketers to reach the same target group across multiple ecosystems - while complying with data protection regulations. Cross-platform campaigns can thus be played out consistently across devices and formats.
With the launch, the GDR segments are available in the following countries within the Hawk DSP: Germany, Austria, Switzerland, Denmark, Finland, France, Italy, Netherlands, Norway, Poland, Spain, Sweden and the United Kingdom. The integration of this solution into the Azerion offering provides advertisers with extensive European reach, backed by deep consumer insights.
The cooperation between Azerion and GDR builds on an already successful history. Under the former name NDR (Nordic Data Resources), GDR provided Azerion with some of the most widely used and powerful data segments, particularly in the Nordic countries. Following the rebranding of the company to GDR (Global Data Resources) and the expansion beyond the Nordic markets, this new cooperation represents an important milestone that strengthens Azerion's data expertise in several European markets.
"The integration of GDR's advanced geo-demographic data into the Hawk DSP marks a significant step towards privacy-focused, precise audience targeting in Europe," explains Edouard Petitjean, DSP Sales Director Europe at Azerion. "This partnership allows us to offer clients rich, location-based insights without compromising user privacy. This is exactly in line with today's regulatory requirements and the industry's shift away from individual tracking. We look forward to supporting advertisers with scalable, cross-channel solutions that truly understand audiences at a local level."
"Our longstanding relationship with Azerion has demonstrated time and again what is possible when technology and privacy-focused data go hand in hand," adds Gunar Kihl, Chief Operating Officer, Global Data Resources. "The integration of our segments into the Hawk DSP allows advertisers to activate meaningful audience insights at scale - in a way that respects consumers and supports the industry's transition to ID-free solutions. We are proud to deepen this partnership in so many European markets."
]]>
This article is intended to help you understand in a simple manner that there is no universally valid standard answer to the consent question and that, as is so often the case, it "depends" on how the facts of the case present themselves. Questions such as the following are currently unsettling: Has Switzerland adopted the obligation to provide consent from European law with the new DPA? Can a Swiss website operator be subject to EU data protection law? Do cookie and data protection rules even apply to server-side tracking? Is the USA safe or not and can a data transfer there require consent?
In Switzerland, the following still applies: No consent is required for the setting of cookies and other client-side tracking technologies or for the processing of personal data. However, it is mandatory to inform the user transparently and to offer an opt-out option at any time. The legal basis for this is the Telecommunications Act and the Data Protection Act. The information can be provided in the data protection statement, which is always required, but also via an info banner.
Despite the Swiss "no consent" concept, there may be constellations that require consent. Specific individual cases should be clarified with a specialist.
A Swiss website operator without EU traffic uses cookie tracking. The tracking data is transferred directly to a server in the EU: No consent is required. Neither for cookie setting nor for the processing of any personal data, nor for the transfer to the secure EU countries.
Identical, but with transfer of personal data to a cloud in the U.S. that does not offer standard data protection clauses or other safeguards: From a Swiss perspective, the USA is currently considered an insecure third country. A transfer to the USA to a provider who does not provide standard data protection clauses or other guarantees is in principle a violation of data protection law. Obtaining explicit consent would be required. The new Data Privacy Framework (DPF) is expected to make things easier with regard to the USA in the near future.
A Swiss hotel chain offers special offers for customers from the European Economic Area (EEA) on its website with cookie tracking: Consent is required (only for EEA traffic), since the qualified reference to the EEA is the national implementations of the European ePrivacy Directive. This includes the German Telecommunications Telemedia Data Protection Act (TTDSG).
A Swiss bank with branches in the EU installs server-side "cookieless" tracking on its website: With this tracking, there is no access to the end device. It does not require consent, neither under CH nor under EU law.
To keep data protection risks under control, it is worth considering the services of local, established tracking providers who rely on European hosting solutions. These providers are also able to filter traffic according to content requirements. Because: Unnecessary content banners mean loss of valuable analytics data!

Author: Thomas Michel - Information Security Officer at Capture Media.
More information is available here.
]]>
In the event of encryption and extortion by cyber criminals, those who can fall back on a backup of their data are on the safe side, the Swiss Crime Prevention (SKP) announced on Thursday. The intercantonal SKP office launched the campaign together with the National Center for Cyber Security and the cantonal and municipal police corps.
Regular backups also help if the devices are lost or stolen, according to the statement. However, the backups should be separated from the network and stored securely so that they offer sufficient protection.
As part of the campaign, educational videos on data backup were posted on the campaign website S-u-p-e-r.ch on the Internet. In addition, the content of the campaign will be disseminated with posters, on public transport via traffic media screens and via social media. Municipalities can participate by actively disseminating the content within the administration.
The awareness campaign will last until the end of September 2023. (SDA/swi)
]]>
A functioning risk management is a control instrument for achieving the company's goals. For larger companies it is mandatory, for others it makes sense: to identify, analyze, treat and monitor risks. These risks are not limited to financial, strategic or information security risks. Data protection, i.e., the protection of the individual from infringing data processing, also harbors risks.
If "cookies" are placed on an end device during web tracking, the user is generally considered to be an identifiable person via IP address and, as a result, Swiss data protection law is applicable. A Swiss website operator is quickly also subject to EU data protection law if he tracks his EU traffic or selectively plays out offers in this area. The data protection law requirements are manifold: information obligations, data subject rights, data inventory, data security or the cookie consent question (EU yes, CH no) and much more. Data protection law requires regular risk analyses here, whereby assessing data protection risks is not easy even for specialists.
One bugbear is big-tech data transfers abroad and potential access by authorities. Although the probability is considered low, there would be a cluster risk associated with this: Requests for information, FDPIC notification, lawsuits, loss of reputation, very high threat of fines (EU) and newly personal fines in Switzerland. Even standard data protection clauses do not offer sacrosanct protection, as the record fine from Ireland shows. Another risk is the assurance of anonymization of IP addresses in data protection declarations, because this is relative, as it only takes place after transmission to the data center.
The seemingly cheapest and simplest treatment is to accept a risk, which must be formally documented with reasons (lack of resources). Risks are transferred classically via insurance. Cyber and D&O insurances, however, refuse to cover personal fine risks.
The right way is to reduce. This respects the risk-based approach of data protection law, according to which protective measures are taken in function of the probability of infringement and possible effects. The focus here is on the use of a European tracking solution. In addition to sharpened privacy awareness and on-site data centers, such solutions are equipped with first-class features. Data proximity and data sovereignty are particularly valued by companies from sensitive and regulated industries. Next, avoidance is an option by relying on tracking technology that does not require cookies and still provides useful marketing data. Companies that systematically address tracking risks often choose a mix: cookie tracking where consent is available or not necessary, and cookieless tracking where it is not.
Author: Thomas Michel, Information Security Officer at Capture Media.
More information is available here.
]]>
The Federal Data Protection Act (FADP) has been revised in recent years. The revised text of the law (revDSG) together with its revised ordinance (revDSV) will now, after lengthy discussions in Parliament and the public, be definitively published onSwiss companies that already comply with the provisions of the EU's General Data Protection Regulation (GDPR) will be able to implement the revDSG with manageable effort. However, if a company is now dealing with these provisions for the first time, it will mainly be the implementation of the new compliance obligations and the review of contracts with service providers, customers and other third parties that will take up some financial, time and human resources.
In addition to the revision, however, there have been other developments in data protection in recent years that present companies with quite a few thorny legal issues and practical problems. The IAB Switzerland Association IAB, the Swiss Media Publishers Association VSM, Leading Swiss Agencies LSA and the Swiss Advertisers Association SWA have jointly developed an industry recommendation to help their members answer questions that frequently arise in the implementation of the revised data protection law.
The guide was written by the Vischer data protection team under the leadership of David Rosenthal and Rolf Auf der Maur, Head of the Legal Working Group at IAB Switzerland.
"For the associations involved and their members, data protection is a constant, complex core issue. Accordingly, there was a great need for a recommendation for the industry that not only illuminates the extensive implications, but also highlights typical problems and provides practical solutions to them," says Urs Flückiger , Managing Director of IAB Switzerland. "With the new guide, developed by proven experts, a profound assistance with concrete recommendations for action has been created."
]]>
The new Data Protection Act DSG (nDSG) comes into force on September 1, 2023, more than five years after its European counterpart, the General Data Protection Regulation DSGVO. This new regulation brings challenges and opportunities for Swiss companies: While marketing and sales come first and juggle the largest amounts of personal data of prospects and customers, HR departments with their employee data are also affected.
Aside from compliance, data is both a big challenge and an opportunity for companies to differentiate themselves from the competition. It enables them to develop new use cases and be more agile in managing activities and performance. If companies master the entire chain from collection to use of data, they have the opportunity to create value here.
If you don't address the issue of data privacy properly, you risk your reputation. This is because the likelihood of complaints and sanctions going public is high and can seriously damage the company's image. The five-year history of the GDPR has shown a significant increase in complaints and sanctions as consumers have become aware of the challenges associated with the use of their personal data.
The most important points that Swiss companies need to consider in order to turn data into a competitive advantage rather than a risk have been summarized by Colombus Consulting in collaboration with Brandit in a new whitepaper.
]]>
According to the 2021 activity report of the city of Berne's ombudsman and data protection office published this week, the data protection commissioner had been asked whether a teacher in the city of Berne was allowed to use WhatsApp as a class chat.
The person seeking advice from the data protection office raised the issue in connection with the adjusted terms and conditions of the application.
The data protection officer subsequently carried out clarifications. She also came to the conclusion that the consent of all persons in a chat group was not sufficient for the use of WhatsApp to comply with data protection requirements. This is because all data of the persons listed in the telephone directory would be transmitted to the Whatsapp operator.
Following the intervention of the data protection commissioners, all head teachers in the city of Berne received instructions that WhatsApp should no longer be used for class chats or parent communications at their schools. Better, they said, was the more data-protection-friendly app "Mattermost".
As the secretary general of the City of Berne's Education, Social Affairs and Sports Directorate, Sven Baumann, said on Thursday in response to a question, this intervention by the city's data protection officers is being implemented. "This is generally lived practice," Baumann said. Whatsapp chats would no longer be used.
The cantonal Department of Education and Culture (BKD) stated in response to an inquiry that it does not prescribe to schools which messenger services they should use. No personal data may be exchanged via the messenger services. "We recommend that messenger services be used exclusively for organizational information," the BKD wrote.
The ombudsman's office of the City of Bern defines itself as an independent and neutral point of contact for citizens, but also for employees of the city and its companies. In the year under review, it handled a total of 647 cases and inquiries (previous year 610). The number of whistleblowing cases almost doubled from six to eleven.
The number of personnel cases remained at a high level, according to the activity report. There were 46, compared to 42 in the previous year. The reason for the increase is probably the city's cost-cutting measures and the pandemic situation, it says.
The Data Supervisory Authority is committed to the responsible handling of information. Last year, it handled 157 cases and inquiries (previous year: 133). In the activity report, both offices use several examples to show why they are called upon and how they proceed.
The ombudsman's office became active, for example, when a resident of the city of Bern did not want to participate in the counting of votes on an election weekend because of fear of corona infection. She had been asked to do so by the city administration and turned to the ombudsman's office. (SDA)
]]>