SFBX

Vector illustration of a little girl looking at a glossary with a magnifying glass

The little SFBX glossary

 

Essential words in our sector:

  • CMP stands for Consent Management Platform. The CMP is a technological platform specifically dedicated to the collection, recording, restitution and proof of consent given by Internet/mobile users in the field of personal data management on the various digital platforms (websites, applications, connected TV, etc.). It also ensures the transmission of end-user consent parameters to all partners wishing to use the data collected and for which the request for authorization has been submitted.
  • Consent : means any free, specific, informed and unambiguous expression of will by which the person concerned accepts, by a declaration or by a clear positive act, that personal data concerning him or her may be processed, as defined by the Personal Data Regulations. This consent must be obtained prior to the deposit and reading of cookies or tracers on the digital platform used by the Internet/mobile user. Consent is not a new concept, as it was already enshrined in the French Data Protection Act (Loi Informatique et Libertés) and the ePrivacy Directive. However, GDPR completes its definition and clarifies the notion in certain respects, to enable data subjects to exercise real and effective control over the processing of their data. Consent is one of the 6 legal bases provided for by GDPR authorizing the processing of personal data, along with legal obligation, contract, public interest mission, safeguarding vital interests and legitimate interest.


  • Personal data This is any information relating to a natural person who is likely to be identified or identifiable, directly (e.g. surname or first name) or indirectly (e.g. an identification number, biometric data, voice or image). The identification of a person can be made from a single piece of data (e.g. a name, a fingerprint, a postal address, an e-mail address, a telephone number, a social security number, etc.) or from a combination of data (e.g. a man with such and such an occupation, living at such and such an address and born on such and such a day).


  • Notice This is the name we give to the consent form that appears on all digital platforms (websites, applications, connected TV, etc.) that collect personal data. This window informs and requests consent to deposit cookies/trackers on users' computers/telephones/TVs (etc.). By means of this notice, users are able to make informed choices, knowing all the partners and purposes for which these cookies or tracers are deposited. This window must comply with the requirements of GDPR, the ePrivacy directive and the guidelines and recommendations of the CNIL. For example: the presence of the "Accept all", "Refuse all" and "Personalize my choices" buttons.
  • Publishers : (publishers in French). Publishers provide the capacity and inventory in their applications or websites that allow advertisers to serve ads. They are the ones who must collect consent directly from their visitors. In the IAB Framework, publishers are digital media that publish content on the Internet or mobile applications. Publishers represent the first party, i.e. the website or application that the user has sought to access.
  • Tracers The CNIL uses the term "tracer" to refer to what is more generally known as a cookie, i.e. the reading and/or writing of information on a user terminal, whether on a computer browser, a smartphone, a voice assistant, a connected TV or any other connected object.

            The tracers are for example : 

    • HTTP cookies,
    • flash" cookies,
    • the result of the calculation of a unique fingerprint of the terminal in the case of "fingerprinting" (calculation of a unique identifier of the terminal based on elements of its configuration for tracing purposes),
    • invisible pixels or "web bugs",
    • any other identifier generated by a software or operating system (serial number, MAC address, unique terminal identifier (UTI), or any set of data that is used to calculate a unique fingerprint of the terminal (e.g. via a "fingerprinting" method)

On the regulator's side

  • CNIL The Commission Nationale de l'Informatique et des Libertés (CNIL) was created by the Data Protection Act of 6 January 1978. It is responsible for ensuring the protection of personal data contained in computer files and processing or paper, both public and private. Thus, it is responsible for ensuring that information technology is at the service of the citizen and that it does not infringe on human identity, human rights, privacy, or individual or public freedoms. The CNIL is an independent administrative authority (AAI), i.e. a public body that acts on behalf of the State, without being placed under the authority of the government or a minister. It is composed of 18 elected or appointed members and is supported by departments. It has a role of alert, advice and information to all publics but also has a power of control and sanction.
  • Data Protection Act : Created in 1978, amended in 2004 and again in 2019 to incorporate the ePrivacy directive and then GDPR. It regulates all personal data processing. It therefore applies to all sectors that use personal data as part of their activities. Several provisions are included in this law, namely:
    • The obligation to declare files containing personal data to the CNIL,
    • The prohibition of collecting sensitive data, i.e. data relating to religion, health, politics, etc. (with some exceptions),
    • The principle of fair data collection,
    • The obligation to ensure the security of all data collected,
    • The obligation to inform the individuals concerned of the collection of theirrs their data,
    • The right to access, modification and deletion of the data in question,
  • GDPR GDPR stands for Règlement Général sur la Protection des Données " (in English "General Data Protection Regulation" or GDPR). The GDPR frames the processing of personal data on the territory of the European Union, since May 2018. The legal context is adapting to keep pace with changes in technology and our societies (increased uses of digital technology, development of online commerce...). This new European regulation follows on from the French Data Protection Act of 1978 and strengthens European citizens' control over the use that may be made of data concerning them. It harmonizes rules across Europe, providing a single legal framework for professionals. It enables them to develop their digital activities within the EU on the basis of user confidence. Any organization, whatever its size, location or activity, can be affected. Indeed, GDPR applies to any organization, public or private, that processes personal data on its behalf or otherwise, provided that:
    • it is established in the territory of the European Union,
    • or that its activity directly targets European residents.
  • ePrivacy Directive Directive on Privacy and Electronic Communications (2002/58): European directive of July 12, 2002 on the protection of privacy in the electronic communications sector. This European directive aims to specifically protect privacy on Internet. It was transposed and integrated into the Data Protection Act in 2004.

 

On the market side

 

  • ALS : for Service Level Agreement, is a contract or part of a contract by which an IT provider undertakes to provide a set of services to one or more customers. In other words, it is a contractual clause that defines the precise objectives and the level of service that a client is entitled to expect from the signatory service provider.


  • KPI : For Key Performance Indicator, is a quantified element that must be determined before the launch of an action, in order to assess the impact and determine the ROI (return on investment). The analysis takes into account several KPI to estimate, for example, the number of visitors to calculate the rate of consent of a website in digital marketing or the rate of subscription to a product.

 

The IAB lexicon

 

  • IAB : The IAB (Interactive Advertising Bureau) is an international association created in 1998, bringing together the players in Internet advertising and whose mission is threefold: to structure the digital advertising market, to encourage its use and to optimize its effectiveness.
  • TCF : For Transparency & Consent Framework developed under the aegis of the IAB Europe, proposes common rules to be adopted when processing personal data or accessing and/or storing information on a user's terminal, such as cookies, advertising identifiers, device identifiers and other tracking technologies. The aim is therefore to provide users with greater transparency on the use of their personal data, as well as to collect their consent and transmit it to all advertising actors identified in the GVL. In practice, the IAB Framework functions as a system for communicating the status of user consent between first parties (i.e. publishers), third parties (i.e. advertisers) and the consent management provider (i.e. the CMP) used on the first party's website.
  • GVL : For Global Vendors List, is the registry of vendors that participate in the TCF. All vendors, including sell-side platforms (SSPs), demand-side platforms (DSPs), ad servers, and data management platforms used on a publisher's site, may apply to join the GVL.
  • Purpose : For "purpose" in French. The 12 collection purposes defined by the IAB are called IAB purposes.
    • Store and/or access information stored on a terminal
    • Select standard ads
    • Create a custom ad profile
    • Select custom ads
    • Create a profile to display personalized content
    • Select custom content
    • Measuring ad performance
    • Measuring content performance
    • Leverage market research to generate audience data
    •  Develop and improve products
    • Ensure security, prevent fraud and debug
    • To technically distribute the advertisements or content
  • Stack Stack is a defined group of IAB purposes. A stack is a defined group of IAB purposes. In total, the IAB has defined 42. This list can be found on the IAB website Europe website.
  • Vendors For vendors in French. In the IAB Framework, these are third-party advertisers with whom the publisher has chosen to partner. Vendors display third-party content on the publisher's website or application. They are the ones who place cookies or marketing trackers on the end user's browser or application in order to display relevant ads to potential customers.

 

Words related to our activities

 

  • Blockchain : Developed from 2008, blockchain is primarily a technology for storing and transmitting information. This technology offers high standards of transparency and security because it operates without a central control body. More concretely, the blockchain allows its users - connected in a network - to share data without intermediaries.
  • Environment Centric : understanding the environmental impact of products and technological infrastructures from the moment they are built.
  • Privacy by default the controller must provide the highest level of protection to data subjects by default, which implies that security and protection measures are taken systematically when processing personal data.


  • Privacy by design Privacy by design: a concept that requires companies to integrate the principles of GDPR right from the design stage of a project, a service or any other tool linked to the handling of personal data. The idea is to ensure that any new technology designed to process personal data must be designed to offer a high level of data protection.


  • Privacy by security Privacy by security: all data collected is anonymized, encrypted and hashed, which ensures security in the processing and integrity of the data.


  • UX design : for User Experience Design, is a set of methods whose objective is to place the human being at the heart of the design process by identifying his or her needs and obstacles in a given context.

 

Terminologies to be found in our products

 

  • Extra purposes purposes: the client can create his own, non-IAB purposes to be included in the consent notice or not, in the latter case, they will be called floating purposes.


  • Extra vendors The customer can add his non-IAB partners by linking them with IAB or non-IAB purposes.


  • Organic data : cThis is data collected on the user's device for which there is no need for system permission. This data is basic and non-intrusive. Examples: manufacturer, OS, version, etc...


  • AMP Accelerated Mobile Pages, is a publishing format created by Google to accelerate the display of pages on mobile devices.


  • MAU / UU : For Monthly Active Users / Unique users. This is the monthly number of active users.

 

Exclusive to certain offers

 

  • A/B testing Premium] A/B testing is a procedure to test the impact of a change in the version of a variable on the achievement of an objective (click, validation, etc.).


  • Cohorts [Premium] : This feature allows you to present a consent window to a specific group of people with the knowledge of their identifiers.


  • Consent guard Premium] This AppConsent feature allows you to do a first level scan of the cookies deposited on a website.


  • External ID's Premium] : With this feature, the client can choose the ID associated with a user consent.


  • Floating purposes Premium] This feature has the particularity of storing user consents in our blockchain, but the display of the question belongs to our clients' platforms. This feature can be useful to store the acceptance of the Terms of Use for example.


  • Rollback [Standard / Premium] This feature allows customers to rollback to previous versions of their records with one click.


  • ATT [Standard / Premium] : On iOS, user consent for ad tracking is managed by the AppTrackingTransparency (ATT) system. App developers will now be required to use the AppTrackingTransparency framework if their app collects user data and shares it with third parties for tracking purposes between apps and websites. If the user does not actively accept ATT, IDFA will not be available and tracking of apps across websites and apps will be prohibited.

What is Ad4good?

Ad4good is the first solidarity advertising network. If you accept personalised advertising on our site, you will be helping to finance some forty associations in need.

See the full list of associations on the Ad4good website

The Ad4good network is implementing 3 actions to ensure its mission:

  • Partnership between publishers and Ad4Good: part of the publisher's inventory is reserved for the distribution of solidarity ads. These ads are monetised by Ad4good, which then donates 50% of its margin to associations.
  • Partnership between advertisers and associations: each advertisement broadcast by the advertiser during an " Ad4Good" labelled campaign campaign generates a donation for the partner association of the campaign.
  • Partnership between publishers and associations: Ad4good offers publishers the opportunity to provide visibility to partner associations by reserving unused advertising space.

To allow the associations to continue their actions, you can accept in general or set the detail by allowing Store and/or access information on a terminal and Personalised advertising.

Ad4good, partner of the CMP AppConsent® for responsible and ethical advertising

We are partners with the Ad4good network, the first solidarity-based advertising network that brings together some forty associations.

See the full list of associations on the Ad4good website

The Ad4good network is implementing 3 actions to ensure its mission:

  • Partnership between publishers and Ad4Good: part of the publisher's inventory is reserved for the distribution of solidarity ads. These ads are monetised by Ad4good, which then donates 50% of its margin to associations.
  • Partnership between advertisers and associations: each advertisement broadcast by the advertiser during a campaign labelled "Ad4Good generates a donation for the partner association of the campaign.
  • Partnership between publishers and associations: Ad4good offers publishers the opportunity to provide visibility to partner associations by reserving unused advertising space.

What does this mean for your audience?

By opting in to the AppConsent® Xchange Solidaire offer, your participation will be mentioned on the first screen of your consent form.
If a user refuses collection for advertising purposes, a reminder screen will be displayed so that they can change their choices if they wish to be an actor of change towards more ethical advertising.

What are the eligibility criteria?

As a pre-requisite, your website must carry advertising. Once you have registered with AppConsent® Xchange Solidaire, you must have a significant amount of responsible advertising on your website (at least 20%).

The AppConsent® Xchange Solidaire offer allows you to take part in a more responsible advertising ecosystem focused on solidarity and environmental preservation.