
What Your Shopping Data Knew Before You Did
Loyalty and purchase data can spot a pregnancy, an illness or a death months before the shopper says a word. In 2012 that was a clever trick.
The short version
- The data you trust most, your own record of what shoppers buy, now reveals their most private moments. A pregnancy, an illness, a divorce, a death in the family, often before the people close to them know.
- That guess is worth real money. A big life event is the rare moment when people tear up their habits and pick new brands, so spotting it early is like getting a key to a whole future basket. That is why shops sell it at a premium.
- The 2012 Target pregnancy story was one shop with one model. The same trick is now built into retail media, a business worth well over 180 billion dollars a year, sold to brands as a standard product, and run inside data only the shop can see.
- The catch sits in one place. The data you are betting your post-cookie future on is also your biggest unpriced liability, and for one plain reason. What makes it valuable, the fact that only the shop sees all of it, is the very thing that stops you checking how the guess was made or whether anyone ever agreed to it.
- The law moved under your feet, in the United States and faster in Europe. What looked like a clever edge in 2012 is now, in many markets, a legal risk that lands on the brand, not just the data broker. In Europe it is mostly off limits without the shopper's explicit consent, which a loyalty sign-up does not give.
- These systems are built to catch the profitable start of a life event and are blind to its end, so they keep selling cribs to a woman who has lost her baby. Designing for that ending is the decent thing to do, and it also makes commercial sense.
- What you now have to decide: how you will govern this data, what you will demand from your retail-media partners, how you will price a risk you are already carrying, and how much of your future to bet on data you truly own, with real consent, rather than data you rent.
The shop knew before you did
A woman in London started seeing baby adverts before she had told a soul she was pregnant. Not her friends, not her family. The first thing in her life to know was an advertising system. Tanya O'Carroll, who works on technology and human rights, found that Facebook had tagged her with hundreds of traits, and that the change came, in her words, "before I'd even told people in my private life, and yet Facebook had already determined that I was pregnant" [1].
Most of us file that under "social media is creepy" and move on. I want to make a different case, because the same thing runs through a channel that sits much closer to home for anyone in consumer goods. It runs through the loyalty card and the till. And it works on the data your business treats as its cleanest, most defensible asset, the record of what real people actually bought.
The story everyone reaches for is Target, back around 2012. A statistician there built a pregnancy score out of about 25 products. The unscented lotion bought early on, the calcium and magnesium tablets, the sudden bulk bags of cotton balls. The shop used it to reach expectant mothers at the one moment their shopping was about to change for years [2]. You may know the dramatic version, the father who storms into a store, furious about baby coupons sent to his teenage daughter. Treat that part as a story. It comes from a single unnamed employee in one reporter's account, and analysts who looked at it later called it too neat to take at face value [2]. The method underneath was real. The method is the part that has grown ever since.
It gets personal from here, because Target was one shop running one clever model, and that is no longer the world we are in.
So what has really changed since 2012?
Four things, and together they turn an old curiosity into a live problem on your desk.
First, the trick became infrastructure. As third-party tracking kept getting harder and less reliable, with Safari and Firefox blocking it by default and Google threatening for years to follow, a brand's own first-party data turned into the prize of digital advertising. Retailers built advertising businesses on top of their loyalty records, the retail media networks, now worth about 184 billion dollars a year worldwide and forecast to pass 300 billion by 2030 [3]. The life-event guess became a product you can buy off the shelf rather than a science project one shop runs.
Second, the guessing moved out of sight. In 2012 you could point at Target's score. Now the matching happens inside the shop's own systems, and you are handed a result rather than shown the working.
Third, the law changed what it cares about. It used to chase how the data was collected. Now it cares about what the data lets you guess, and in places it reaches the company that acts on the guess, not only the broker who sold it.
Fourth, the stakes rose. After the US Supreme Court overturned Roe v Wade in 2022, a guess about someone's pregnancy stopped being only awkward and started being dangerous, for the shopper and for whoever holds the data. And the machines themselves kept getting sharper.
Hold those four together and the Target anecdote reads less like a ghost story and more like a memo about this year's media plan.
Why is a pregnancy the most valuable thing a shop can guess?
Because almost nothing else resets a person's habits the way a big life event does, and habits are the whole game in consumer goods.
For most of our lives, our buying runs on autopilot. We reach for the same brands without thinking, which is lovely if you are the brand being reached for and miserable if you are the one trying to break in. A big life event switches the autopilot off. A new parent has to choose dozens of products they never bought before, in aisles they never thought about, all in a few exhausted weeks, and they are wide open to suggestion. Win them then and you may keep them for a decade. A pregnancy is valuable as a key to a long corridor of future shopping.
Concept box: Why one guess is worth so much (surrogate prediction) Marketers rarely care about a life event for its own sake. They care because it stands in for a whole set of future needs. A pregnancy points to nappies, formula, wipes, bigger pack sizes, a different shopping trip, a changed budget. So the model does not really try to sell you "being pregnant". It treats the guess as a stand-in for the basket you are about to start buying. That is why a single hidden fact is worth so much. It forecasts dozens of decisions at once.
The same logic runs across every life event with a shopping signature. A house move changes where you shop and what you stock up on. A new diagnosis tilts the basket toward the pharmacy aisle. Even money worries leave a clear mark. When budgets tighten, people trade down well before any official figure catches it. One survey in late 2022 found 64 percent of shoppers had switched to cheaper brands and 58 percent to supermarket own label inside a single squeeze [4]. Your sales mix is a fast read on the financial health of a country, weeks ahead of the statistics office.
Who is buying the guess, and why does it cost so much?
This is where it stops being a privacy story and becomes a profit-and-loss one.
The guess belongs to the shop, not the brand, because the shop owns the one thing nobody else has in full: a complete, named record of what each household buys, week after week. In the United States, Kroger's data arm holds data on around 60 to 62 million households, with more than 95 percent of sales tied to a loyalty card and roughly two billion shopping trips a year linked back to the same household [5]. With coverage that complete, it is closer to a head count of how a nation shops for groceries than a sample.
The shop turns that into an advertising business and sells brands the chance to reach precise groups built from real purchases. The price tells you how much that precision is worth. Tesco's media arm reports that multichannel campaigns return 6.60 pounds in sales for every pound spent, against 3.80 pounds on other channels, across more than 450 brands [6]. Boots saw a 22 percent lift in that return once it joined a shopper's online and in-store buying into one view [7]. Walmart's advertising business alone brought in 6.4 billion US dollars in 2025 [8]. This is one of the fastest-growing, highest-margin lines in modern retail, and it runs on the guess.
Concept box: Your own data, and the closed loop First-party data is what a company collects straight from its own customers: the loyalty card, the till, the app. After third-party cookies faded, it became the prize of digital advertising, because the company owns it and, in principle, the customer agreed to it. A retail media network is the advertising business a shop builds on top of that data. The "closed loop" is what makes it powerful and awkward at the same time. The shop can connect an advert it showed you to a purchase you later made, all inside its own systems, and report the result back to the brand. The brand sees a number. It does not see the wiring behind it.
For a brand, the appeal is obvious. You stop spraying messages at rough age-and-postcode groups and start reaching the actual household about to enter your aisle. For a senior commercial leader, retail media has gone from a curiosity to a real chunk of the plan in about five years. The question almost nobody asks in the planning meeting is the one this piece is about. What exactly are you buying when you buy a life event, and what comes attached to it?
What are you actually buying when you buy a life event?
You are buying a precise result you are not allowed to check, built from a guess you are not allowed to see, on a "yes" you cannot confirm anyone ever gave. And you are paying extra for exactly that.
So stay with me here. The closed loop is sold to you as a benefit, and in pure advertising terms it is one. The shop sees every till, so the shop can prove the campaign worked with a precision a sample-based panel cannot match. Other ways to measure exist, but none of them can see what the shop sees. Now look at what that leaves you with. The very thing that makes the data so valuable, the fact that only the shop sees all of it, is what leaves you in the dark. Much of the matching now runs inside what the trade calls data clean rooms, which sound reassuring until you read what they are. The United States trade regulator looked at them in 2024 and said plainly that they "are not rooms, do not clean data" [9]. You cannot independently check the result. You cannot see how the "new parent" group was built, which purchases triggered it, or whether it swept in data the law now treats as off limits. Advertisers say as much themselves. In one 2026 survey, only about 15 percent of brands said they strongly trust how retail media measures its own results [10]. And the sensitive groups are not hypothetical. Reporters once obtained an advertising file holding hundreds of thousands of ready-made audiences, including people it tagged as heavy purchasers of pregnancy tests, and others it marked as prone to depression [11].
So you pay extra for precision, and that extra carries a risk you never put a number on. I call it the opacity premium. The measurement worry that keeps the finance chief up at night and the consent worry that keeps the lawyer up are the same worry, looked at from two sides. Both readings are correct, because it is one closed door. And the door now has your name on it, which is the part that has genuinely changed.
Concept box: The price of a guess, both ways (illustrative) Say a nappy brand buys a "new parent" group: 200,000 households, ten views each, so two million views. A precise, inferred group costs more than a plain one. At 25 pounds per thousand views against 10 pounds, that is 50,000 pounds versus 20,000 pounds, so you pay 30,000 pounds extra for the precision. Why pay it? If even 2 percent of those households (4,000) become buyers and spend 600 pounds on the category over the next year at a 30 percent margin, that is 180 pounds of profit each, or 720,000 pounds. Set against that, 30,000 pounds looks cheap. Now the side nobody books. The guess is never perfect. Say 3 percent (6,000 households) are in the group by mistake, a loss, a miscarriage, a wrong call, and get the one advert that should never reach them. Under a law that reaches the brand, put even 100 pounds per person for complaints, fixes and legal time. That is 600,000 pounds of exposure, twenty times the premium you booked, sitting on the same campaign and on none of the paperwork you signed. The numbers are illustrative, but the gap is the point: the premium goes on the plan, the risk does not.

When did the guess become a liability?
Around the point regulators stopped asking how the data was collected and started asking what it lets you work out.
For years the rules chased the obvious villains, the brokers who sold raw location trails and named lists. That enforcement is real and it is sharp. In December 2024 the United States Federal Trade Commission (FTC) acted against the data broker Mobilewalla, which had built groups of pregnant women, among other sensitive groups, from location data gathered at scale, including, the FTC alleged, straight from the automated auctions that decide which advert you see. The FTC's chair said the ease with which real-time bidding technology "can be exploited to surveil" people "should raise serious alarm" [12]. The same wave has hit health and fertility apps hard. GoodRx paid a 1.5 million US dollar penalty in a first-of-its-kind case for sharing medication and condition data with advertising platforms [13]. The period-tracking app Flo was found to have shared the fact of a user's pregnancy despite its privacy promises [14]. In the United Kingdom the pregnancy club Bounty was fined 400,000 pounds for sharing data on more than 14 million people with around 39 organisations [15].
Those are brokers and apps. The shift that should move this from your legal team's inbox to yours is simple. The newest rules reach the guess itself, and they reach whoever acts on it. Washington State's My Health My Data Act, in force from 2024, protects any data that lets a company work out something about your health, even when it started life as ordinary shopping, and it applies to brands and retailers, not only to brokers. Washington's Attorney General has said plainly that a shop's pregnancy-prediction score counts as protected health data, even though it was worked out from non-health buys [16]. Read that twice. The clever trick that built this industry is the exact example the authorities now use to describe what is off limits. The lawsuits have started, though none has yet reached an answer. In February 2025 the first class action under that law named Amazon's advertising business, over the way an advertising tool gathered data that could touch on health. The plaintiffs withdrew it a few months later without any ruling on the merits, so the question at the centre of it, whether using this kind of data for advertising is enough to trigger the new rules, has still not been tested in court [17]. The statute is on the books either way, the Attorney General has already named the pregnancy score as the example, and whoever brings the next claim gets to choose their moment.
This is not only an American story, and in Europe the ground moved earlier and harder. In 2023 Europe's top court ruled on this directly. If an advert is built on profiling that can reveal something sensitive, say a health condition or someone's sexuality, it needs the shopper's clear consent. And a guess at that fact counts the same as the fact itself, so inferring it is no way around the rule [18]. Health is a special category that, across the European Union, you cannot target without explicit permission, and a loyalty-card sign-up does not give it. The largest online platforms must go further still: since 2024 the Digital Services Act bars them from serving an advert targeted using this kind of data at all [19]. So the move this piece describes is, in Europe, mostly unlawful without a clear yes you almost never have.
And regulators have already used these rules on shops, not only on data brokers. A British retailer, Easylife, was fined for working out a likely health condition from the everyday products people bought, then advertising remedies back to them [20]. That is almost exactly the mechanism in this piece (a catalogue seller rather than a supermarket, but the same data logic). The grocer REWE's Austrian arm was fined eight million euros over the way its loyalty scheme profiled its members [21]. The advertising machinery behind all this has been hit too: France fined the ad-tech firm Criteo forty million euros over consent [22], and the consent system that runs Europe's ad auctions was itself ruled unlawful [23]. None of that is the exact move in this piece. It is the same regulators, circling closer. The one thing nobody has been fined for yet is the precise move this piece is about, a retailer selling brands access to audiences built from its loyalty data. That is the frontier, and being first across it is not the prize it sounds like.
Concept box: When a guess becomes protected (inferred health data) Older privacy law mostly protected data you handed over, like a medical record or a stated condition. The newer wave protects data a company works out about you, even from everyday purchases. In Europe, health is a special category that needs explicit consent, and the courts have said an inference of it counts the same as the real thing [24]. If a pattern of buys lets a firm guess a pregnancy or an illness, that guess can be protected, and using it can need clear, opt-in permission. People in Europe and the UK also have an outright right to say no to direct marketing [25], and a "yes" merely assumed from someone's behaviour is not the clear permission these sensitive uses require. In plain terms: handing over a loyalty card is not permission to guess that someone is pregnant and sell the guess.
If you buy and switch on a group built from a sensitive guess, you are inside that chain, not standing safely outside it. The extra you paid for precision did not come with cover for the exposure.
Can the same trick that sells nappies also catch a cancer?
Before this tips into pure alarm, I want to be fair to the capability, because the same power cuts both ways.
Start with the case that should give you pause for a better reason. Researchers at Imperial College London used the loyalty-card records of two large high-street chains and compared what women later diagnosed with ovarian cancer had bought against women who were not. Ovarian cancer is vague in its early signs and usually caught late, which is why it kills so often. Five-year survival drops from about 93 percent when it is caught earliest to about 20 percent when it is caught latest. The loyalty data carried a signal. Purchases of pain and indigestion remedies were already pulling apart in the women who had cancer up to eight months before their diagnosis, about three times the odds of the women who did not [26]. And the sensing keeps getting sharper. A smart ring can now flag a pregnancy about nine days before a home test does [27]. The same machinery that feels invasive when it sells you nappies could, pointed the other way, flag a deadly disease months before a doctor does. That is a public-health gift hidden inside a marketing tool, and it raises a genuinely hard question about whether a shop that can see this owes anyone a duty to act.
Now the other face, and it is the one that should stay with you. The most revealing thing about these systems is what they cannot see. They are built to spot the profitable start of a life event, the beginning of a pregnancy, the move to a new home, because that is where the money is. They carry almost no signal for the end. So when a pregnancy ends in loss, the model does not know. It carries on. Parents who have been through a stillbirth or a miscarriage describe the particular cruelty of adverts for cribs and formula that keep arriving for months, because the system logged the start and was built blind to the ending.
Concept box: The data sees the start, not the end (asymmetric data) Sales data is eager to record an event and almost blind to its reversal. A purchase fires a clear signal. A non-purchase, a cancellation, a loss, a quiet return to how things were, usually fires nothing at all. So a model trained on this data learns the start of a life stage in high resolution and the end barely or not at all. The result is a system acting with confidence on a fact that may no longer be true. This same blind spot, the data sees what happened and not what stopped happening, is the thread that ties this issue to the next one in this series.
That blind spot is baked into the shape of the data. You cannot patch it with a cleverer model. The fix is a decision more than a piece of engineering, and it belongs to you.
So what do you actually do about it?
You treat the guess as the asset and the liability it is, and you do it before your next retail-media commitment, not after the first complaint.
Four moves.
First, ask how the group was built before you switch it on. For any life-stage or life-event group a retail-media partner offers you, ask which purchases built it and whether anything touching health, pregnancy or other sensitive areas sits inside the model. If the partner will not or cannot tell you, that is your answer about the risk you would be taking on.
Second, build in an ending. Most retail media is bought on a self-serve screen against standard terms, so unless your spend is big enough to negotiate, you will not get bespoke clauses. If you have that weight, put time limits and refresh rules in the contract so a "new parent" group expires and re-confirms rather than chasing a household for the year and a half a remarketing window can run. If you do not have that weight, set the limit yourself as policy and treat breaking it as a breach, not a media choice. Either way, this is the practical cure for the start-without-an-ending problem, and it is the difference between marketing to people and following them around long after you should have stopped.
Third, put a price on the exposure and set clear lines. The premium you pay for precision does not include the legal and reputational risk, so add it yourself and let it shape policy. A workable line: targeting on a category a shopper has openly stepped into is fair game; targeting on an obvious, non-sensitive life stage is fine with disclosure; targeting on a guessed pregnancy or health condition is off the table as a matter of policy, whatever a given country currently allows. In much of Europe that last line is not really a choice you get to make: targeting a guessed pregnancy or health condition needs an explicit yes you will almost never have. The worked example above is the kind of sum worth doing for real: a clear internal rule is far cheaper than a class action, and far cheaper still than the trust you lose when one goes public.
Fourth, own more of the relationship. The brands lowering their exposure are the ones building a direct, permission-based relationship with their shoppers, so the data and the "yes" live with them rather than inside a partner's black box. This is a multi-year build, not a quarter's work, and for a stretch your own consented base will be smaller than the rented guess. It is still the version of this asset that does not arrive with someone else's liability attached.
Pushback I expect, and it is fair. The first objection: this is a privacy and legal problem, so why is it in a commercial briefing? Because the value and the risk are the same asset, and pretending otherwise is how you get caught out. The precision is real money on the top line. The exposure is real money too, sitting unbooked, and it lands where it is hardest to rebuild, on trust and on the brand. The second objection I hear more often: "I do not buy guessed segments. I buy standard audiences and let the retailer do the targeting, so none of this is mine." I understand the instinct, but the newer laws do not. If the group you switched on was built from a sensitive guess, buying it at arm's length through a screen still puts you in the chain. The law reaches the act of targeting, not only the act of building the model.

What would have to be true for me to be wrong?
I would be wrong if the rules stall and trust never breaks. If enforcement under the new guess-based laws fizzles, if no big brand gets caught buying a sensitive group, and if shoppers turn out not to care once the novelty fades, then the opacity premium is just a premium, and the smart move is to buy all the precision you can while it is cheap. That is a real possibility and I would not bet the business against it lightly.
But I would not bet on it either. The direction is clear. In Europe the rulings are already on the books, the laws that reach the guess are spreading in the United States, and the one thing this industry keeps relearning about trust is that it goes slowly and then all at once.
Which brings me back to where we started. The data you treat as your safest asset, the clean, owned, agreed-to record of what people bought, is the very thing that exposes you most. That record was always more than a list of purchases. It was a read on who people are as well, and you never had permission for that second part. The asset and the liability were the same line in the ledger the whole time. The only question left is whether you put a price on it before someone else does it for you.
Signals
- The UK Information Commissioner backed Tanya O'Carroll's claim that targeted advertising is direct marketing she can refuse, and Meta settled days before trial in March 2025. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/03/statement-on-ocarroll-vs-meta/
- A UK retailer, Easylife, was fined for working out customers' likely health conditions from the products they bought, then advertising remedies back to them. https://ico.org.uk/media2/migrated/4021801/easylife-limited-mpn-article-5-1-a-20221004.pdf
- The first class action under Washington's My Health My Data Act named Amazon's advertising business, filed February 2025. https://natlawreview.com/article/first-class-action-filed-under-washingtons-my-health-my-data-act-draws-parallels
- Since 2024 the European Union's Digital Services Act bars the largest platforms from serving adverts targeted using special-category data such as health. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2065
- An Imperial College London study found loyalty-card purchases of pain and indigestion remedies pulled apart up to eight months before an ovarian-cancer diagnosis. https://pmc.ncbi.nlm.nih.gov/articles/PMC9912145/
References
- Tanya O'Carroll v Meta, settlement and quote. Silicon UK and BBC coverage, March 2025; ICO statement, 22 March 2025. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2025/03/statement-on-ocarroll-vs-meta/
- Charles Duhigg, "How Companies Learn Your Secrets," The New York Times Magazine, February 2012; Kashmir Hill, Forbes, February 2012; Eric Siegel, Predictive Analytics World, on the anecdote being "so good it sounds made up". https://www.nytimes.com/2012/02/19/magazine/shopping-habits.html
- Forrester, Global Retail Media Forecast 2025 to 2030 (retail media about 184 billion US dollars in 2025, forecast above 300 billion by 2030). https://www.forrester.com/blogs/global-retail-media-forecast-2030/
- Shopmium survey on trading down, November 2022, Grocery Gazette. https://www.grocerygazette.co.uk/2022/11/29/consumers-cheaper-brands/
- Kroger and 84.51 scale; Consumer Reports income-predictor finding, May 2025. https://www.consumerreports.org/money/questionable-business-practices/kroger-secret-grocery-shopper-loyalty-profiles-unfair-a1011215563/
- Tesco Media and Insight Platform, return on ad spend, dunnhumby. https://www.grocerydoppio.com/articles/what-makes-tescos-retail-media-strategy-a-game-changer-and-differentiator
- Boots retail media closed-loop attribution, Criteo and LiveRamp, InternetRetailing. https://internetretailing.net/boots-boosts-retail-media-offering-with-closed-loop-attribution-in-data-partnership-with-criteo-and-liveramp/
- Walmart advertising revenue 2025, AdExchanger. https://www.adexchanger.com/commerce/walmarts-ad-revenue-totaled-6-4-billion-in-2025-as-the-ecom-flywheel-started-to-spin/
- US Federal Trade Commission, Office of Technology, "Data Clean Rooms: Separating Fact from Fiction," November 2024. https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/11/data-clean-rooms-separating-fact-fiction
- Skai (Stratably), The State of Retail Media 2026 (only about 15 percent of brands strongly trust measurement). https://skai.io/reports-and-whitepapers/2026-state-of-retail-media-report/
- Jon Keegan and Joel Eastwood, "From 'Heavy Purchasers' of Pregnancy Tests to the Depression-Prone," The Markup, 8 June 2023. https://themarkup.org/privacy/2023/06/08/from-heavy-purchasers-of-pregnancy-tests-to-the-depression-prone-we-found-650000-ways-advertisers-label-you
- FTC statement and chair's quote on Mobilewalla, December 2024. https://www.ftc.gov/news-events/news/press-releases/2024/12/ftc-takes-action-against-mobilewalla-collecting-selling-sensitive-location-data
- FTC enforcement action against GoodRx, February 2023. https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising
- FTC settlement with Flo Health, 2021. https://www.ftc.gov/news-events/news/press-releases/2021/01/ftc-finalizes-order-flo-health-fertility-tracking-app-shared-sensitive-health-data-facebook-google
- ICO fine of Bounty UK, April 2019. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2019/04/bounty-uk-fined-400-000-for-sharing-personal-data-unlawfully/
- Washington My Health My Data Act; Washington Attorney General guidance that an inferred pregnancy-prediction score is protected consumer health data. https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy
- Maxwell v Amazon.com, Inc. and Amazon Advertising LLC, No. 2:25-cv-00261 (W.D. Wash., filed 10 February 2025), the first class action under Washington's My Health My Data Act. Consolidated into In re Amazon Ads SDK Litigation, No. 2:25-cv-00252-BJR, then voluntarily dismissed without prejudice under Rule 41(a)(1)(A)(i) and the case closed in mid-2025, with no ruling on the merits. Docket checked 12 August 2026. https://www.courtlistener.com/docket/69623838/in-re-amazon-ads-sdk-litigation/
- Court of Justice of the European Union, Meta Platforms v Bundeskartellamt, Case C-252/21, judgment 4 July 2023 (inferred special-category data is protected; personalised advertising generally needs consent). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62021CJ0252
- Digital Services Act (Regulation (EU) 2022/2065), Article 26(3), barring online platforms from advertising based on profiling that uses special-category data; applied to all platforms from 17 February 2024. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32022R2065
- UK Information Commissioner's Office, monetary penalty notice against Easylife Ltd, 4 October 2022 (inferring health conditions from purchase history for targeted marketing). https://ico.org.uk/media2/migrated/4021801/easylife-limited-mpn-article-5-1-a-20221004.pdf
- Austrian Data Protection Authority fine against REWE International AG over the jo Bonus Club loyalty programme, 14 January 2022. https://www.dsgvo-portal.de/gdpr-fines/gdpr-fine-against-rewe-international-ag-2022-01-14-AT-1721.php
- CNIL (France), fine against Criteo of 40 million euros, Decision SAN-2023-009, 15 June 2023. https://www.edpb.europa.eu/news/national-news/2023/personalised-advertising-french-sa-fined-criteo-eur-40000000_en
- Belgian Data Protection Authority decision on the IAB Europe Transparency and Consent Framework (2022) and Court of Justice of the European Union, Case C-604/22, 7 March 2024 (the consent string is personal data). https://gdprhub.eu/index.php?title=CJEU_-_C-604/22_-_IAB_Europe
- General Data Protection Regulation (EU) 2016/679, Article 9 (special categories, including health; explicit consent required for sensitive data, including inferred). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:02016R0679-20160504
- ICO guidance, the right to object to direct marketing. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/individual-rights/right-to-object/
- Cancer Loyalty Card Study (CLOCS), Imperial College London, JMIR Public Health and Surveillance, January 2023. https://pmc.ncbi.nlm.nih.gov/articles/PMC9912145/
- Oura pregnancy-detection research: Grant and Smarr, PLOS Digital Health, 2022 (about nine days before a positive home test); UC San Diego, npj Digital Medicine, 2024. https://journals.plos.org/digitalhealth/article?id=10.1371/journal.pdig.0000034