yf
Article

M13h Interview on Privacy: Data Protection in 2021

Privacy refers to the way brands and advertisers manage the collection and use of personal data relating to their customers and prospects. It refers both to legal and technological constraints and to issues of ethics and transparency. The term also encompasses issues related to protecting collected data against potential external attacks.

To discuss this current topic, we met with Mickaël Avoledo, Managing Director of M13h (a consulting firm within the Labelium Group), who agreed to answer our questions and explain how to approach Privacy challenges and define an action plan accordingly.

  1. Mickaël, can you introduce M13h? What does the company specialize in?

M13h is a data and marketing technology consulting firm that joined the Labelium Group in 2018. We have two areas of expertise:

  • On the one hand, the Data Marketing division: through which we offer our clients the management of initial scoping projects (audits, benchmarks, strategies, use cases, etc.), support for projects through to their operational implementation (adtech/martech tools, Privacy, etc.), and monitoring of marketing action optimization.
  • On the other hand, the Data Science division: where we offer data engineering (aggregation of data sources into data lakes, data flows between tools, advanced data activations, etc.), data modeling (customer segmentation, LTV, predictive purchase or churn analyses, etc.), and data visualization.

To put it simply, our guiding principle is to help our clients move through the different maturity gaps required to optimize their marketing activities through data.

  1. Can you tell us more about Privacy?
  • What are the challenges for GAFA?

The GAFA companies do not all face the same Privacy challenges. On the one hand, we have Apple, which has understood that this issue represents a real point of differentiation and wants to turn it into a competitive advantage. After strengthening anti-tracking measures in its Safari web browser, it is now turning its attention to the world of apps with consent for the use of its mobile ID (IDFA), which is expected to arrive in 2021. Apple has not hesitated to highlight Privacy in its advertising campaigns for several years now (the latest campaign actually took place in recent weeks).

On the other hand, we have Google and Facebook, whose main challenge is to limit the impact of regulatory and technological developments relating to Privacy on their advertising business, their main source of revenue. After a cat-and-mouse game aimed at circumventing browsers’ anti-tracking measures, these players (and Google in particular) are beginning to accept the need to change their approach. We are going to move from “one-to-one” targeting and deterministic conversion measurement to one-to-few” targeting and increasingly probabilistic measurement based on extrapolation.

  • What are the impacts and consequences for merchants?

Merchants can expect several types of impacts. The first is related to recent regulatory developments concerning consent collection. In France, on October 1, the CNIL issued new recommendations with which all companies will have to comply by March 31, 2021. For users, these recommendations notably make it easier to refuse the use of cookies by giving greater prominence to refusal options on cookie banners. The market is therefore preparing for a drop in the volume of data available for advertising targeting (the most pessimistic estimates suggest a decline of up to 80%).

The second impact is related to technological developments. Changes in browsers (for example, the rejection of third-party cookies) eliminate certain use cases such as retargeting or post-view performance measurement. This is already the case on Safari and Firefox, and it will soon be the case on Chrome. Apple is also continuing to move forward on the app side, with IDFA consent coming soon, which will significantly limit cross-app retargeting on iOS (around 70% less volume is being discussed) and app campaign attribution. In addition, the “Sign in with Apple” buttons, which Apple has required in apps that already had Facebook or Google Connect, deprive brands of a valuable piece of information: users’ email addresses, as an option is available to hide them. Ultimately, these developments make performance measurement less precise and limit the reach of possible targeting.

  • What should merchants prioritize implementing?

Currently, following the CNIL recommendations, all our clients are focused on updating their cookie banners. It is important to anticipate as much as possible in order to have time to test different versions and maximize consent rates, which are essential for tomorrow’s marketing management and targeting.

In the medium term comes the issue of adapting the marketing stack, with the aim of limiting regulatory and technological impacts. We can mention quick-win topics such as implementing consent mode on Google tools to respect users’ Privacy choices while preserving measurement capabilities through extrapolation within the tools. Other actions, such as server-side conversion and audience imports, should also be considered. They make it possible to achieve two things at once by limiting, on the one hand, the impact of Privacy on marketing management and, on the other hand, providing new indicators for measuring drive-to-store campaigns, for example. This is a major request from our clients at the moment.

In the longer term, server-side tracking can also be considered and will arrive one day, but it requires more implementation effort. Contextual targeting is also making a strong comeback. And if I had to add just one topic, it would be 1st-party data. Tomorrow’s targeting should be divided between “people-based” targeting and aggregated cohort targeting as described in Privacy Sandbox, Google’s solution for the end of third-party cookies. If merchants want to be able to activate people-based targeting at scale, they need to think about customer journeys and the value proposition in order to capture the data required to do so.

  1. For advertisers, what is the next important deadline? Why?

March 31, 2021, because this date marks the end of the CNIL tolerance period regarding cookie consent. Cookie banners and the associated data processing will then have to be compliant. Otherwise, the penalties merchants face are those provided for under the GDPR: 4% of global revenue or €20 million.

  1. What would be your best short-term advice for merchants?

With the ongoing health crisis and the accelerated digitalization associated with it, merchants already have plenty on their plates! My advice is to make sure not to forget about Privacy, while remaining very pragmatic in the way you approach it. It is a complex subject that can quickly become far-reaching. It is therefore important to take a step back and ask a few simple questions: what is my level of compliance and risk? What should my areas of focus be when addressing this issue? In this changing environment, which “stabilized” elements should I address now, and which topics does the market still need to develop before I pay more attention to them?

This is the perspective we try to provide to our clients in order to make the subject less anxiety-inducing and move step by step, but quickly, toward compliance without losing focus on the business.

To conclude

Given the current context, Privacy could take a back seat, yet it is a key issue that concerns us all and must be addressed in both the medium and long term. To do so, we recommend approaching the next steps as follows:

  1. Prepare for the new CNIL consent guidelines.
  2. Monitor the development of solutions and the various initiatives undertaken by industry players.
  3. Implement short-term solutions.

And if we had to make one general recommendation: do not hesitate to call on a specialist to provide you with the best possible support throughout these various processes.