Overview

Following the definitions of the General Data Protection Regulation (GDPR), Commerce Grid is considered a separate and independent data controller for the personal data it receives and processes in connection with the Commerce Grid services. Commerce Grid processes such personal data as required for the performance of its agreements to carry out its services, and as further described in the Criteo Privacy Policy.

As Commerce Grid does not directly provide any services to end users/data subjects, it does not gather GDPR consent itself. Instead, it relies on publishers to obtain and document user consent for its stated purposes, and to include Criteo as a declared data controller where required.

IAB Europe released TCF v2.3 on June 19, 2025. This version introduces a new requirement that directly affects how Commerce Grid processes bid requests: vendors must now be disclosed in your Consent Management Platform (CMP), not only consented to.

In line with the IAB TechLab policy effective February 28, 2026, Commerce Grid applies the following policy for all traffic where GDPR applies:

  • The TCF consent string must be TCF v2.3-compliant, meaning the DisclosedVendors segment must be present and non-empty.

  • The DisclosedVendors segment must include Criteo (GVL ID: 91).

If either condition is not met, Commerce Grid will drop the bid request and cannot fire user syncs for that traffic.