Documenting Advertising Data Requests: Record if request is for access, correction or deletion under APPs; Maintain a vendor register with purpose, data sent, contact and owner details; Assign privacy team to verify requester and sign off responses
Image: AdTech Market Guide

Vendor Due Diligence

Part of AdTech privacy and permission signals

Documenting responsibility for advertising data requests

An advertising data request may reach the advertiser, publisher, consent provider or technology vendor.

An advertising data request may reach the advertiser, publisher, consent provider or technology vendor. Without an owner map, it can sit between teams while each assumes someone else holds the relevant data.

For organisations covered by the Privacy Act 1988 (Cth), document requests in the context of the Australian Privacy Principles (APPs), including access and correction. Record whether a request seeks access, correction or deletion, and have the privacy team determine which rights and response process apply to the specific case.

Use a register for every material vendor, with one row per vendor. Record its purpose, data sent, contact, contract reference, access or deletion route, and internal owner; name the accountable person and their role rather than leaving the owner field generic.

Assign the privacy team accountability for determining the applicable rights and response process. In the register or case record, name who verifies the requester, who communicates with vendors and who signs off the response.

For a typical request, trace which systems hold identifiable records and which contain only aggregate reports. Record the relevant systems and the route for obtaining an answer from each vendor.

Do not promise access or deletion that a platform cannot actually perform. Document any limitation for privacy review.

IAB GPP and TCF may carry preference signals through advertising systems, but they are not a complete request-management workflow. OAIC guidance on tracking pixels asks Australian organisations to understand third-party data handling and their own obligations; the OAIC also lists guidance on requests for access and correction of personal information.

Test the handoff with a fictional request: can the team identify every relevant vendor and obtain an answer within its internal deadline? Set and record that internal deadline, then update the owner map after each integration change so responsibility stays attached to the real data path.

Handling Advertising Data Requests in Compliance with Australian Privacy Principles

  1. Identify Request TypeDetermine if request seeks access, correction or deletion of personal information under the Privacy Act 1988 (Cth)
  2. Map Data OwnershipAssign internal owner and role for each vendor; avoid generic 'owner' fields
  3. Record Vendor DetailsMaintain a register with purpose, data sent, contact, contract reference, access/deletion route, and accountable person
  4. Trace Data SystemsIdentify which systems hold identifiable records vs. aggregate reports; document retrieval routes
  5. Verify Requester & CommunicateConfirm identity of requester; assign team members to contact vendors and sign off responses
  6. Assess Platform LimitationsDocument any inability to deliver access or deletion; flag for privacy review
  7. Test Handoff ProcessUse fictional request to verify end-to-end traceability within internal deadline; update owner map after changes

More from Vendor Due Diligence

Vendor Due Diligence

AdTech vendor due diligence

Assess an AdTech vendor’s service, fees, integration, data access and exit terms against a defined Australian use case.