Responsible Advertising & Data Governance
Maintain strong compliance and oversight processes to ensure transparency and responsible advertising on our platforms, while protecting core privacy principles in our collection and use of data.
Our Approach
Publishers rely on Magnite’s technology to sell advertising inventory across a variety of channels and formats, including desktop, mobile, and CTV. We help the world’s leading agencies and brands reach millions of consumers in a transparent, efficient, and brand safe manner, while respecting end user privacy.
Responsible Advertising
Magnite operates its platforms in a transparent and fair manner by actively working to identify and eliminate fraudulent transactions, non-human traffic, malware, abusive content, harmful disinformation, and brand unsafe inventory violations. We have developed a number of guidelines relating to inventory quality and advertising quality standards covering all of our platforms and across all formats.
Our inventory quality guidelines address inventory authorization, legal compliance (e.g. respecting laws and sanctions in originating countries), intellectual property infringements, transparency, viewability, performance characteristics and acceptable content standards. We also utilize a tapestry of industry, proprietary, and third-party technology to identify and eliminate machine, bot, and other non-human generated traffic in real-time. These guidelines ensure only high quality inventory is available for sale through Magnite platforms, while also ensuring that all parties are compensated fairly for any transaction over the Magnite platforms and protected from fraud. Magnite also maintains processes, and third-party technology for sellers with concerns about any undesired and/or malicious ad serving on their media.
Our advertisement quality guidelines provide direction and baseline requirements on the types of creatives permitted through our platforms. These guidelines cover legal compliance (including laws, and standards set by industry organizations such as the NAI), ad and landing page behaviors, acceptable content, and bid response requirements. Magnite works closely with buyers to address concerns about any ad serving against undesired and/or malicious content. We also reserve the right to reject, suspend, or remove from our platforms any ad in our sole discretion.
Magnite’s policies and guidelines relating to inventory quality, ad quality and privacy are available to the public and can be found here.
Privacy & Data Governance
Magnite is committed to responsible personal data processing that is compliant with applicable – and evolving – data protection legislation and best practices. As part of this commitment, Magnite does not process any raw or clear text personal information such as a user’s name, email address, phone number, or postal address to perform our services or for our services to work. The types of data we collect include IP addresses, cookie identifiers, device identifiers, and other device-related information such as web page URL, browser or app where a user is viewing content. Any information Magnite processes in delivery of its services is limited to a pseudonymized identifier.
Magnite has implemented a privacy program that is governed by a framework aligning with privacy principles outlined in the Fair Information Practice Principles and data protection laws around the world such as the General Data Protection Regulation, the California Consumer Privacy Act and other US consumer privacy laws. These principles focus on:
- Lawfulness and Transparency: Personal data is processed lawfully, fairly, and in a transparent manner;
- Purpose Limitation: Personal data is used only for the specific purposes disclosed;
- Data Minimization: Magnite collects only the data necessary for the task at hand;
- Data Integrity: Magnite ensures the accuracy, integrity, confidentiality, and security of personal data it processes;
- Accountability: Magnite maintains accountability over its processing activities and these principles.
Led by our Chief Privacy Officer and monitored by our Data Protection Officer, our privacy program documents the organizational approach and policy to how personal data is managed and processed across our business. This Program applies to all data processing whether for our clients and partners, or within our own internal employee management.
To ensure these standards are lived daily, all Magnite employees undergo annual training on data privacy and protection, keeping our team aligned with the latest regulatory shifts and best practices.
Privacy by Design
In addition to assessing risk and maintaining compliance with data protection regulations, the privacy program encourages a culture of privacy by design as a necessary component in developing business strategies and products for Magnite. Our commitment to Privacy by Design requires we consider privacy related features in new products and services that will process personal data. Privacy by Design enables Magnite to ensure compliance with data protection regulations, and to keep data privacy best practices at the focus of our offerings.
Memberships
Transparency and consumer choice are at the heart of our privacy framework. Magnite prides itself on membership in and compliance with self-regulatory groups within the advertising industry, including the Digital Advertising Alliance (DAA), the European Interactive Digital Advertising Alliance (EDAA), the Network Advertising Initiative (NAI), and the Interactive Advertising Bureau (IAB). Participation with these groups require that Magnite adheres to strict industry frameworks, principles, and regulations with respect to how personal data is used for behavioral, and other types of digital marketing. Beyond maintaining our own privacy controls, we collaborate with these self-regulatory bodies and industry groups to ensure consumers have clear, accessible ways to manage their digital preferences.
Find all of Magnite’s policies relating to data and privacy here.
Security Measures
Cybersecurity is a critical aspect of our business. As the world’s largest independent omni-channel sell-side advertising platform, we face a multitude of cybersecurity threats, and our customers rely on us to safeguard their data. These challenges make it imperative that we take information security seriously, and we expend considerable resources on cybersecurity.
Magnite has a range of technical and organizational security measures and controls to protect personal data and ensure the ongoing confidentiality, integrity and availability of Magnite’s solutions and services. These include:
- Framework and policies – security framework, and various data policies, all of which are regularly reviewed, reported on and, when necessary, improved upon.
- Processes and controls for configuration, monitoring, maintenance and disposal of technology and information systems according to prescribed internal and adopted industry standards. This also includes penetration testing and vulnerability scanning to evaluate and protect against threats to Magnite’s technology; transmission controls to protect information in transit; and access restrictions of key data, systems and facilities.
- Reviews of third-party software and service vendors, software development processes, as well as keeping an inventory of systems, applications and operating systems.
- Procedures such as incident response plans, business resiliency/continuity for key infrastructure.
- Regular training for employees around data security and privacy as well as employing a Data Protection Officer.
Please refer to our latest 10-K for additional information regarding our Cybersecurity practices.