Privacy-enhancing technologies (PETs) in AdTech: examples and use cases

July 31, 2026 14 min read 268 views

An overview of PETs, their key examples, and how they enable privacy-focused advertising in the AdTech ecosystem.

AdTech has become increasingly advanced, offering advertisers the ability to reach their target audiences with unprecedented precision. However, this practice often involves the collection and utilization of personal information without users’ knowledge or consent, leading to serious privacy concerns.

As a result, governments worldwide are taking steps to protect users’ personal information online, recognizing the need to balance the benefits of ad targeting with the right to privacy. This has led to a shift in how AdTech works as companies seek to adapt to this new privacy-focused world.

The emergence of privacy-enhancing technologies (PETs) has been a key development in this space. PETs are designed to help companies protect user privacy while still enabling them to collect and use data for programmatic advertising.

In this blog post, we will explore the various types of PETs available and provide examples of how they are being used in AdTech today.

Key points

  • Privacy-enhancing technologies (PETs) are tools and techniques used to protect user privacy and minimize the amount of data processed by companies.
  • They are adopted in industries that process large amounts of personal and sensitive data.
  • PETs focus on minimizing the use of personal data, maximizing data security, and minimizing the amount of data processed.
  • Examples of PETs include encryption, anonymization, virtual private networks, privacy-preserving APIs, trusted execution environments, on-device learning, privacy-preserving data mining, differential privacy, homomorphic encryption, and multi-party computation.
  • The use of PETs has enabled the creation of many projects in the AdTech industry, including universal IDs, Google Privacy Sandbox, SKAdNetwork, PCM and PAIR.

What are privacy-enhancing technologies (PETs)?

Privacy-enhancing technologies (PETs) are tools and techniques designed to protect personal and sensitive data during collection, sharing, and analysis. PETs allow organizations to generate insights and use data while reducing exposure to identifiable information and maintaining user privacy.

Privacy-enhancing technologies are commonly used in industries that process large amounts of personal and sensitive data, such as banking, insurance, health, government, marketing, and advertising.

PETs help ensure data is secure by focusing on three key pillars:

  • Minimizing the collection and use of personal data.
  • Maximizing data security to protect consumer privacy.
  • Minimizing the amount of data processed.

Some examples of privacy-enhancing technologies include:

  • Minimization techniques
  • Encryption
  • Anonymization/pseudonymization
  • Virtual Private Networks (VPNs)
  • Privacy-preserving APIs
  • Trusted execution environment (TEE)
  • On-device learning/federated learning (FL)
  • Privacy-preserving data mining (PPDM)
    • Differential privacy (DP)
    • Homomorphic encryption (HE)
    • Multi-party computation (MPC)

In AdTech, these technologies can support secure data processing, privacy-preserving audience analysis, measurement, identity matching, and data collaboration without compromising privacy. 

How do privacy laws and technology changes affect AdTech?

For years, programmatic advertising relied on extensive data collection to support audience targeting, campaign measurement, and personalized advertising. As privacy expectations, regulations, and digital technologies have evolved, the AdTech industry has had to rethink how it collects, processes, and activates user data.

Governments and technology companies have introduced new privacy measures that affect how personal information can be collected, stored, and used. Privacy laws such as the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and Brazil’s Lei Geral de Proteção de Dados (LGPD) establish requirements for handling personal data and give individuals more control over how their information is used.

Tech companies have also introduced privacy-focused changes across browsers and platforms. For example, Safari uses Intelligent Tracking Prevention to limit cross-site tracking, while Firefox blocks cross-site tracking cookies by default through its Enhanced Tracking Protection features. These changes reduce reliance on traditional tracking methods such as third-party cookies and push the industry toward more privacy-conscious approaches to advertising and measurement.

As a result, publishers, advertisers, and AdTech companies are exploring solutions that allow them to use data effectively while preserving user privacy. Privacy-enhancing technologies have become an important part of this transition, enabling secure data processing, privacy-preserving measurement, and collaboration without exposing unnecessary personal information.

Examples of PETs

Common types of privacy-enhancing technologies used in AdTech include secure multi-party computation, trusted execution environments, on-device learning, differential privacy, aggregation, and federated learning.

These technologies help AdTech platforms protect data privacy while still enabling targeted advertising, measurement, and data collaboration. By applying PETs, organizations can reduce privacy risks when processing personally identifiable information (PII) and other sensitive data.

Most AdTech solutions that incorporate PETs combine one or more of the following techniques:

Secure multi-party computation (MPC)

Secure multi-party computation (MPC) is a technique that enables two or more entities to share encrypted data through multiple nodes/servers and gain insights without learning about each other’s data. Private Set Intersection (PSI), a cryptographic protocol that allows two parties to compute the intersection of their sets while keeping the contents of their sets private, is an MPC technique.

Trusted execution environment (TEE)

While they share some similarities with MPCs, trusted execution environments (TEEs) differ by enabling operations within a single server. TEEs use secure hardware with cryptographic protections to process data in a confidential computing environment, ensuring security and data privacy during data processing.

On-device learning

On-device learning uses machine learning models trained on historical data, such as user interests or conversion patterns, to make predictions directly on a device. The data is processed locally, reducing the need to send personal information back to a central server.

Differential privacy (DP)

Differential privacy is a technique used to analyze a dataset that provides a formal privacy guarantee by controlling the amount of privacy loss through mathematical methods. As DP is an algorithmic property, it can be applied uniformly to different data sets, thus protecting an individual’s identity from reconstruction or re-identification. DP can also be combined with other privacy-enhancing technologies (PETs) as part of a comprehensive approach.

Aggregation/K-anonymity

Aggregation combines data into groups to reduce the visibility of individual records, while k-anonymity ensures that each record cannot be distinguished from at least k−1 other records based on selected attributes. Together, these techniques can reduce the risk of identifying individuals in aggregated datasets.

Federated learning (FL)

Federated learning is a machine-learning technique that enables models to be trained on decentralized data across multiple parties without exchanging any information.

The purpose of using privacy-enhancing technologies in AdTech

Privacy-enhancing technologies (PETs) are used in AdTech to protect personal data, reduce privacy risks, and enable data-driven advertising processes without unnecessary exposure of user information. They help companies collect, share, process, and analyze data while maintaining user privacy and supporting secure data collaboration.

AdTech does not only process data but also collects it, shares it between parties, and uses it to power various programmatic advertising processes. PETs can support privacy and security across each stage of this data lifecycle:

Data collection

PETs can help organizations comply with data privacy regulations and avoid the potential legal and financial consequences of non-compliance when collecting data. Privacy-enhancing technologies also enable data minimization, which reduces the risk of data breaches, ensures that personal data is only collected for a specific and legitimate purpose, and decreases the space needed to keep data.

Identification

Without privacy-enhancing technologies, personally identifiable information and even sensitive data could be leaked. AdTech companies can protect this information from cyber attacks and data breaches by encrypting the data. There are many different techniques for encrypting data, but the three main ones are symmetric encryption, asymmetric encryption, and hashing.

Data sharing between parties

Running advertising campaigns demands collaboration, such as data sharing between different AdTech platforms. However, this can also increase privacy concerns if not handled transparently and responsibly.

To keep the data safe and secure, AdTech companies can use encryption, secure multi-party computation, and differential privacy to exchange data confidentiality. Also, by using PETs, they can state who can have access to the data, which will minimize the risk of unauthorized access to it.

Data processing

A set of procedures, such as computation, analysis, and measurement, are run on data every time an ad is served to a user.

Privacy-Enhancing Technologies (PETs) play a crucial role in ensuring that personal data remains secure and confidential during these procedures. For example, PETs like differential privacy enable the analysis of anonymized user data without revealing personal information, such as personal identifiers or browsing history.

Ad targeting

Advertisers want to show relevant ads to their audiences and provide personalized experiences to their users. PETs, such as federated learning, allow them to display ads by processing data on a user’s device, rather than sending it to an external server. This approach reduces the possibility of personal data being shared with multiple companies.

Use cases of privacy-enhancing technologies in AdTech

Privacy-enhancing technologies (PETs) are used in AdTech to support privacy-preserving targeting, measurement, attribution, and data collaboration. They allow advertisers, publishers, and platforms to work with data while reducing exposure to personal information and addressing privacy challenges across the advertising ecosystem.

Common use cases for PETs in AdTech include:

Universal IDs

PETs can be used to generate a universal ID in a privacy-preserving way. For example, companies can apply a hashing algorithm, such as SHA-256, to an email address or phone number to produce an ID. So instead of using a user’s actual email address as the universal ID, companies can use the hashing algorithm to produce a random string of numbers and letters and use that as the ID.

This not only prevents a user’s raw data (i.e., the email address) from being used, but it also protects their privacy, as the hashed ID can’t be unscrambled once it’s been hashed. This ensures that the universal ID cannot be traced back to an individual.

Google’s Privacy Sandbox

Privacy Sandbox aims to replace the processes carried out by third-party cookies by utilizing advanced privacy techniques such as differential privacy, k-anonymity, and on-device processing.

Additionally, it helps to minimize other forms of tracking, like fingerprinting, by limiting the amount of information websites can access, ensuring that your personal information remains confidential, protected, and secure.

Data clean rooms

There are many different use cases of data clean rooms in the context of advertising. Brands can utilize data clean rooms for ad targeting, audience targeting, and measurement.

Encryption and double blinding for data inputs, differential privacy in running queries, injecting data noise, maintaining k-anonymity thresholds, are some of the techniques used in DCRs.

SKAdNetwork

SKAdNetwork is a privacy-centric API operated by Apple. For marketers running ad campaigns on iOS-powered devices, this system provides insights into campaign attribution that are anonymous, aggregated, and delayed.

Private Click Measurement

Private Click Measurement (PCM) by Apple was created for measuring ad clicks across websites and from iOS apps to websites. PCM uses on-device processing, differential privacy, blinded signatures and data minimization to ensure that user data is protected.

Publisher Advertiser Identity Reconciliation

Google’s Publisher Advertiser Identity Reconciliation (PAIR) enables publishers and advertisers to privately and securely reconcile their first-party data for audiences who have visited both a publisher’s and an advertiser’s website.

The solution works by allowing advertisers and publishers to activate encrypted first-party data that is specific to their sites via aggregation. This ensures that no data related to individual users is shared between parties, and the aggregated data is only readable and relevant in the context of their direct relationship.

MPC in an SSP

Magnite, a leading AdTech company, utilizes a form of technology called MPC to support activation without accessing raw data. Advertisers and publishers encrypt their data, such as first-party publisher lists or advertiser customer lists, using MPC.

The encrypted data is then sent to Magnite, who can match and create synthetic stable IDs using the data. These IDs can then be used to activate the data without accessing the raw data itself.

Private computation

Meta uses multi-party computation to improve its ad targeting capabilities while preserving user privacy. The system allows Meta to analyze encrypted user data to identify trends and patterns without accessing the raw data itself. This enables Meta to provide more personalized ads without compromising user privacy.

FAQ

The main challenges of implementing privacy-enhancing technologies include technical complexity, integration with existing systems, and the need for industry standards. Organizations need to select PETs that match their specific use cases, data requirements, and privacy goals.rnThe deployment of PETs can also require changes to existing workflows, infrastructure, and data practices. As privacy technologies continue to evolve, companies must balance data usability with security and privacy while addressing potential privacy and security risks.

Privacy-enhancing technologies support data privacy by allowing organizations to collect, process, and analyze data while reducing exposure to personal and sensitive information. PETs provide technical methods for preserving data privacy, limiting unnecessary data access, and protecting individual privacy.rnTechnologies such as encryption, differential privacy, and secure multi-party computation enable organizations to gain insights from data while maintaining privacy and confidentiality. This makes PETs especially valuable in environments where privacy and data protection are critical.

Privacy-enhancing technologies can support compliance with privacy regulations by helping organizations apply principles such as data minimization, secure data processing, and responsible data handling. Regulations like GDPR, CCPA, and LGPD encourage companies to strengthen privacy and data protection practices.rnWhile PETs do not replace privacy policies or legal requirements, they provide technical safeguards that help organizations reduce privacy risks and demonstrate a stronger commitment to privacy and compliance.

Privacy-enhancing technologies enable organizations to collaborate on data without compromising privacy. In AdTech, advertisers, publishers, and platforms can use PETs to share insights, measure campaign performance, and activate audiences without exposing raw personal data.rnTechniques such as secure multi-party computation, encrypted data processing, and data clean rooms allow parties to work with encrypted data without directly accessing sensitive information. This supports privacy-preserving collaboration while maintaining data security.

The benefits of privacy-enhancing technologies include stronger data protection, reduced privacy risks, and greater control over how personal information is used. PETs help organizations use data responsibly while supporting security and privacy requirements.rnAs privacy preferences and regulations continue to change, PETs are becoming increasingly important for companies that need to balance data-driven innovation with individual privacy. By using PETs, organizations can protect sensitive data, build trust, and support more privacy-focused digital experiences.

The future of privacy-enhancing technologies in AdTech

To define the future of PETs, we need to take into consideration multiple factors, such as the growing awareness about privacy protection on the Internet, technological changes, new legal regulations, and the ongoing debate about privacy among publishers, advertisers, and organizations representing their interests.

Consumers and governments recognize the importance of privacy in the digital age. This consciousness will drive the wide adoption of PETs and the creation of new regulations around the topic, similar to how the GDPR, LGPD, CCPA, and the IAB Tech Lab’s TCF have been adopted. These, and other, legal frameworks will require companies to incorporate PETs into their AdTech technologies and processes to ensure they are compliant with various privacy laws.

Some advertisers and publishers have already recognized the benefits of PETs, such as an increase in consumer trust and reduced risk of data breaches.

As a result, more and more companies will dedicate budgets to new solutions such as data clean rooms to leverage PETs in their AdTech efforts.

Moreover, various technologies will go through different stages of development. The current priority lies in providing more granular control over the use of personal data, so in the nearest future, we can expect to see advancements and more sophistication in this field.

The last important aspect of the development of PETs is working on providing standardization.

The IAB Tech Lab has established a dedicated group to develop standards for PETs in AdTech. This group is made up of representatives from advertisers, publishers, technology providers, and privacy advocates.

Their goal is to develop a set of standardized protocols for PETs that can be adopted by the industry. This standardization will help to ensure that PETs are effective and consistent across the industry.

Do you want to learn which PETs would work best for your business? Get in touch with us and let’s find the right fit together.