Five regimes decide how your ad stack must behave. This is the working map, not legal advice; your counsel owns the interpretation.
The five regimes
GDPR (EU/UK) sets the baseline: lawful basis for processing, consent standards, data subject rights. In the ad stack it shows up as consent signals that must travel with every event.
ePrivacy adds the cookie and device-access layer, which is why consent banners exist at all.
DMA regulates the gatekeepers themselves (Meta, Google, and peers), and its practical effect on advertisers is consent enforcement: Consent Mode v2 became mandatory for EEA/UK ad personalization because of this pressure.
DSA governs platform transparency and ad repositories, mostly the platforms’ problem, occasionally yours in ad-disclosure requirements.
CCPA/CPRA (California) runs on opt-out rather than opt-in, adds “sharing” for advertising to the definition of sale, and drives the contractual terms your US data flows run under.
The pattern across all five
Regulators stopped accepting tracking as a default and started requiring provable permission. The technical consequence is uniform: consent must be captured once, recorded properly, and enforced everywhere an event travels, including server-side.
Stacks that treat consent as a banner problem fail audits; stacks that carry consent with every event pass them and keep their measurement. Legal and marketing now share this roadmap, because the same consent record has to satisfy an auditor and feed a bidding algorithm.
How Datahash handles consent, hashing, and data controls is documented in the Security Centre.