Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Confiant is an ad security and ad quality verification platform that inspects programmatic ads in the browser to block malvertising and enforce ad policies.
Confiant is an advertising security and quality platform used by publishers, ad exchanges and demand side platforms to detect malvertising, blocked content and policy violations. It runs partly as client side JavaScript that wraps and inspects programmatic ad creatives directly in the visitor browser, and partly as server side scanning across billions of ad impressions.
Confiant verifies advertising in real time to stop bad ads before they reach the visitor. It identifies forced redirects, fake download prompts, malware bearing creatives and ads that breach a publisher policy, and it can reauction the slot when an ad is blocked. To do this it observes how an ad behaves in the browser, which means it sits close to the user and the rendered page.
To analyse advertising context Confiant typically processes technical signals such as the IP address, user agent, device and browser characteristics, page context and ad interaction events. Because it inspects creatives in the browser it can also set or read identifiers and may combine device and browser signals in ways that resemble fingerprinting. These signals can relate to an identifiable person and therefore count as personal data under the GDPR.
Under the ePrivacy Directive any storage of or access to information on the visitor device that is not strictly necessary requires prior consent. Because Confiant operates within the advertising stack and can set identifiers, the safest position is that it falls outside the strictly necessary exemption. Some controllers argue legitimate interest for the pure security and fraud prevention function, but in an advertising context a regulator is likely to expect consent. A balancing test should be documented if legitimate interest is relied on for any part of the processing.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Where consent is the basis it must be freely given, specific, informed and collected before the tag loads, and visitors must be able to withdraw it as easily as they gave it. Confiant is a United States company and its scanning telemetry is generally processed on US cloud infrastructure, so personal data may leave the EEA. Such transfers need a valid mechanism such as the EU US Data Privacy Framework or Standard Contractual Clauses with a transfer risk assessment.
Gate the Confiant tag behind your consent management platform so it only runs after advertising consent is given, disclose it in the advertising section of your cookie policy, record it in your processing activities and put a data processing agreement in place. Verify the transfer safeguard, run a data protection impact assessment given the scale and the device level signals, and test that declining consent fully prevents the script from loading.
Websites using Confiant must obtain user consent under GDPR regulations.
DPIA considerations
Because Confiant runs client side code that inspects ad creatives and can read device and browser signals to fingerprint malicious ads, it may involve large scale processing and behavioural signals that warrant a data protection impact assessment. Assess the categories of data observed (IP address, user agent, device and ad interaction signals), the high volume of impressions analysed, transfers to the United States and the interaction with programmatic advertising partners. Document the legitimate interest balancing test for the security function and the consent basis for the advertising context.
Sample consent text
We use Confiant to check the advertising shown on this site for security threats and quality. This may process device and browser information and set identifiers. Do you consent to advertising and ad verification technologies?
Third-party domains contacted
confiant.comconfiant-integrations.netclarium.globalCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| Confiant ad session identifier | third party | session to short lived | Generic identifier that Confiant may set or read in the browser to correlate the analysis of an ad impression across the verification process. Exact names vary by integration. |
| Confiant device and ad signal store | third party | session or local storage | Browser storage that Confiant may use to hold device and ad interaction signals used for malvertising detection and ad quality scoring. Treated as advertising related and requiring consent. |
Confiant is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Confiant works mainly as client side JavaScript that inspects ad creatives, so rather than a fixed set of named cookies it may set or read short lived identifiers and use browser storage to correlate the analysis of an ad impression. The exact identifiers depend on the integration and the ad partners involved, and they should be treated as advertising related.
In most cases yes. Because Confiant operates inside the advertising stack and can set or read identifiers on the device, it generally falls outside the strictly necessary exemption of the ePrivacy Directive, so prior consent should be collected before the tag loads. A pure security only deployment might be argued on legitimate interest, but the advertising context makes consent the safer basis.
The advertising verification function should rely on consent under the ePrivacy Directive and Article 6(1)(a) of the GDPR. Where a controller treats the malvertising and fraud detection function as a security measure, it may rely on legitimate interest under Article 6(1)(f), but it must document a balancing test and remember that consent is still needed for any non essential device access.
Yes, this is likely. Confiant is a United States company and its scanning telemetry is generally processed on US cloud infrastructure, so personal data such as IP address and device signals may be transferred outside the EEA. You need a valid transfer mechanism such as the EU US Data Privacy Framework or Standard Contractual Clauses together with a transfer risk assessment.
A data protection impact assessment is advisable. Confiant runs client side, can read device and browser signals that resemble fingerprinting and analyses very large volumes of ad impressions, which points toward high risk processing. Assess the data observed, the scale, the US transfers and the advertising partners involved, and record your conclusions.
Load the Confiant tag only after advertising consent is given through your consent management platform, disclose it in the advertising section of your cookie policy, sign a data processing agreement, confirm the transfer safeguard and add it to your records of processing. Test that declining consent fully blocks the script and provide an easy way to withdraw consent.
Other ad security and verification providers include solutions such as those from Human Security, GeoEdge, Integral Ad Science and DoubleVerify. Each carries similar privacy considerations because ad verification runs close to the user, so compare their data processing, server locations and transfer safeguards before switching.
Add Confiant to the advertising or marketing category of your cookie and privacy policy, explain that it inspects ads in the browser and may set identifiers and process device signals, name it as a recipient, state that data may be transferred to the United States under an appropriate safeguard and link to its privacy notice. Keep the consent records and the policy in step.