Google gave user data to Russian ad company RuTarget, including potentially sensitive info about users in Ukraine, four months after the US sanctioned RuTarget
This report extends a decade-long pattern of Google's ad machinery surfacing in Russia-related scrutiny: the company previously found Russian-bought ads on YouTube, Gmail, and DoubleClick tied to the 2016 election effort, and a later Wired investigation found US law left advertisers unable to name sanctioned countries as targets or exclusions, so ads served there anyway.
What changes here is direction and stakes: instead of ad money flowing toward Russia, user data — including potentially sensitive information on people in Ukraine — flowed out to RuTarget for four months after Washington sanctioned the firm. It compounds the picture from the Display & Video 360 sensitive-data investigation, which showed Google's own rules against exploiting personal data failing inside its ad stack.
First-order effects
RuTarget received Google user data for four months past its US sanctioning, putting the sanctions-exposure question on Google rather than only on the sanctioned party, with Ukrainian users' information among what was shared.
Advertisers and publishers running campaigns through Google's ad stack face new due-diligence pressure over where their audience data travels, extending the trust deficit the Display & Video 360 reporting created.
Sanctions enforcement is pushed beyond ad spending into data flows — the earlier finding that Google's tooling could not cleanly exclude sanctioned countries suggests the gap is architectural, not a one-off vendor lapse.
Third-order effects
If the pattern holds, cross-border user-data flows in programmatic advertising become a formal sanctions-compliance surface, forcing platforms to build auditable permission boundaries over which counterparties can receive personal data — the durable principle behind the public-data permission boundary.
The trend: Sanctions law and privacy controls are converging on programmatic ad infrastructure, turning the movement of user data itself into a compliance surface for platforms like Google.
NEW: Google was sharing user data with a sanctioned state-owned Russian ad company until we alerted Google last wk. The shared data may have included sensitive location info and mobile IDs of people in Ukraine. Based on research by @kfranasz. Story & 🧵 https://www.propublica.org/…
Excellent study that does not just examine how Google may have been sharing extensive personal data via RTB with Rutarget, an adtech/data firm owned by state-owned Sberbank, but more broadly, how Google shares data with hundreds of firms across the planet: https://adalytics.io/..…
Web and app publishers that use RTB systems from Google or other companies have no control over with whom personal data on their users is being shared. Google (and other adtech firms that e.g. rely on the TCF) claim to have control over who they share data with but that's a lie.
I went through a few privacy policy links and quickly found that several do not address GDPR requirements in any way or are just inaccessible (404s, invalid certificates). G wants publishers to trick users into consenting to personal data processing by these ‘certified’ vendors. …
I don't think that letting sanctioned data companies owned by the Russian state harvest data is the one and only problem here, even though e.g. letting a state-owned actor harvest Ukrainians' identity+behavioral data from the RTB bidstream could be certainly a very serious issue.
Anyway, the real+underlying problem is that most digital advertising is based on uncontrolled personal data sharing today. Google, other adtech firms and myriads of sites/apps are selling ads *and* user data billions of times a day. Many companies and state actors can access it.
Google may have provided Sberbank-owned RuTarget with unique mobile phone IDs, IP addresses, location information, and details about users' interests & online activity nearly 700 times *after* the U.S. Treasury sanctioned the Russian ad company on Feb 24. https://www.propublica.o…
This is why I get riled up about TikTok. Is TikTok's PRC ownership a liability? You betcha. But that same data is easily available from any number of American vendors. Drain the swamp of private data availability writ large. https://twitter.com/...
New: Alarming story by @CraigSilverman ... Google stopped sharing user data with a sanctioned Russian entity after we asked them about it for this story. https://twitter.com/...
We're in a serious non-kinetic war with Russia, but Google is STILL sharing unique mobile phone IDs, IP addresses, location information, and details about Americans' interests and online activity straight to OFAC-sanctioned Russian companies. Happy July 4! https://www.propublica.…
“Google may have turned over such critical information as unique mobile phone IDs, IP addresses, location information and details about users' interests and online activity, data that U.S. senators and experts say could be used by Russian military and intelligence services” https…
“Google's initial failure to fully enforce sanctions on RuTarget highlights how money and data can flow through its market-leading digital advertising systems with little oversight or accountability.” Must read reporting from @CraigSilverman @propublica & research from @kfranasz …
The way digital advertising works today, myriads of companies share personal data on everyone with shady actors the second we visit a website or use a mobile app. Google also facilitates data sharing via “real-time bidding” (RTB), see e.g. this lawsuit: https://www.documentcloud.…
JFC. Google was *still* sharing user data with Russia even after the sanctions. Senate Intel wrote them and asked them to cool it. They only stopped *last week* when this story was about to publish. https://www.propublica.org/...