Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Prebid is an open source header bidding library managed by Prebid.org that runs in the visitor browser. It sends bid requests to many advertising demand partners and stores advertising identifiers in cookies and local storage. Because Prebid is only a wrapper, the actual data recipients are the bidders each publisher configures, so they must be documented case by case.
Prebid is an open source header bidding framework managed by Prebid.org that publishers add to their pages to run a real time auction for ad space. It executes client side in the visitor browser and is essentially a wrapper that orchestrates requests to many demand partners. Prebid itself does not decide who receives data; the publisher configures which bidders participate, so the recipient list varies from site to site.
Prebid stores advertising user identifiers in cookies and in browser local storage, including a shared first party identifier and user id modules. During each auction it sends bid requests that can include identifiers, page context, device data, and approximate location to the configured demand partners. These partners, such as supply side platforms and exchanges, may also run their own cookie syncing.
Header bidding involves storing identifiers in the browser and sharing personal data for advertising, which engages both the ePrivacy storage rule and the GDPR. The lawful basis is consent, and the configured bidders frequently act as independent or joint controllers for their own purposes. Because many partners are involved, transparency and a clear vendor list are essential.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Prebid supports the IAB Europe Transparency and Consent Framework, reading the consent string and passing it to bidders so they can honour the user choice. No advertising identifiers or bid requests should fire before valid consent is captured. Publishers should ensure their consent platform and vendor list match the bidders actually configured in Prebid.
Bid requests and identifiers are shared with numerous demand partners, many located outside the EEA including the United States. Each such transfer needs its own safeguard, typically Standard Contractual Clauses with supplementary measures. Because the partner set is publisher specific, the transfer mapping has to be maintained per configuration rather than assumed.
Document the exact bidders configured, gate all auctions behind consent, and integrate a TCF compliant consent platform. Maintain a vendor and transfer list that matches your Prebid setup and review it whenever bidders change. Disclose header bidding clearly in your privacy and cookie notices and provide an easy way to withdraw consent.
Websites using Prebid must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is strongly recommended because header bidding involves large scale sharing of advertising identifiers with many third parties. Key points to assess are (1) the full list of demand partners configured for the site, since Prebid is only a wrapper and recipients vary per publisher; (2) the categories of data in bid requests, including identifiers, device data, and approximate location; (3) the lawful basis, which is consent, and how the IAB TCF string is captured and passed to bidders; (4) international transfers to the United States and other third countries and the safeguards used for each partner; and (5) the controller relationships, as many bidders act for their own purposes, requiring clear allocation of responsibility.
Sample consent text
We work with advertising partners who use cookies and identifiers to show relevant ads and measure performance. These load only if you accept. You can change or withdraw your choice at any time.
Third-party domains contacted
cdn.jsdelivr.netib.adnxs.comprebid.orgCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _pubcid | Marketing | 1 year | Shared first party advertising identifier used to coordinate bidding across demand partners. |
| pbjs_userid | Marketing | Persistent (local storage) | Local storage entries holding user id module values passed to bidders during the auction. |
| uids | Marketing | 1 year | Bidder cookie sync cookie that matches identifiers between the page and a demand partner. |
| euconsent-v2 | Functional | 1 year | Stores the IAB TCF consent string so that the user choice can be read and passed to bidders. |
Prebid places tracking cookies for advertising — comply with GDPR using FlowConsent.
Prebid stores advertising identifiers in cookies and browser local storage, including a shared first party identifier and user id module values, plus a consent state entry. Configured bidders typically set their own cookie sync cookies as well. The exact set depends on which user id modules and bidders the publisher enables.
Yes, consent is required because Prebid stores advertising identifiers and shares personal data with partners for targeted advertising. No identifiers or bid requests should fire before the user opts in. Prebid reads the consent string and passes it to bidders so they can honour the choice.
The legal basis is consent under GDPR Art. 6(1)(a) and ePrivacy Art. 5(3), signalled to bidders through the IAB Europe TCF. Legitimate interests is generally not appropriate for this kind of cross site advertising. The configured bidders often act as independent or joint controllers for their own processing.
Yes, because bid requests and identifiers are shared with many demand partners, a number of which are based in the United States and other third countries. Each transfer requires its own safeguard, typically Standard Contractual Clauses with supplementary measures. Since the partner set is publisher specific, you must map transfers against your own configured bidders.
A DPIA is strongly recommended because header bidding involves large scale sharing of advertising identifiers with many third parties. The assessment should list every configured bidder, since Prebid is only a wrapper and recipients vary per site. It should also cover the data in bid requests, consent capture, transfers, and controller roles.
Integrate a TCF compliant consent platform and ensure no auction runs until consent is captured and passed to bidders. Document the exact bidders and user id modules you enable and keep a matching vendor and transfer list. Disclose header bidding in your privacy and cookie notices and review the configuration whenever partners change.
Alternatives include Google Open Bidding, Amazon Transparent Ad Marketplace, and other server side or managed header bidding solutions. Server side setups can reduce browser storage but still share data with partners. Whichever you choose, the same consent, transparency, and transfer duties apply because the underlying advertising data flows are similar.
Disclose that header bidding runs on your site and list the cookies and local storage Prebid uses, along with the configured bidders and their roles. Because the partner list varies, document it specifically for your setup rather than relying on a generic statement. State that advertising identifiers load only after consent and link to your vendor list.