A nonprofit founded by privacy advocate Max Schrems has filed a complaint against Google on behalf of an Austrian citizen, claiming Android Ad ID violates GDPR
Claims consent was neither informed, nor specific, nor free - but Google says it cannot identify a user from the ID
Context & Ripple Effects
This complaint extends a strategy Schrems kicked off in 2018 with forced-consent GDPR complaints against Google, Facebook, WhatsApp, and Instagram — this time targeting not a consent dialog but a device identifier, filed on behalf of a single Austrian citizen to create a test case. The core legal theory is that the Android Ad ID persists across apps without consent that is informed, specific, or free.
The playbook repeats from there: noyb later took the same identifier argument to Apple's IDFA before German and Spanish regulators in November 2020, and separately pressed the Android Ad ID as an ePrivacy violation before France's watchdog in April 2021. Google's defense here — that the ID alone cannot identify a user — sets up the factual question all these filings turn on.
First-order effects
- Google must answer a GDPR complaint in Austria while contesting whether an advertising identifier is personal data at all — its stated position that the Ad ID cannot identify a user is the crux of its defense.
Second-order effects
- Apple's IDFA now faces parallel complaints in Germany and Spain on the same tracking-identifier theory, meaning both dominant mobile platforms are defending their ad identifiers before European regulators at once rather than one being singled out.
Third-order effects
- If regulators accept that per-device advertising IDs require explicit, freely given consent, mobile ad targeting in Europe would need a new consent layer at the OS level — shifting compliance cost onto platform owners and shrinking the addressable inventory for ad-tech intermediaries.
The trend: Schrems' noyb is running a coordinated, regulator-by-regulator campaign against mobile tracking identifiers, testing whether Europe's consent rules reach past cookies into the operating system itself.