DPE-2026-0015

Bid request broadcast

One page view is offered to many bidding parties at once, each receiving the context and an identifier.

In het NederlandsBiedverzoek naar veel partijen tegelijkWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Chain webapp status active
Not a vulnerabilityNothing is exploited and nothing is broken. Broadcasting the request is how the auction is designed to work; the objection is to the design. There is no defect to patch, which is why no vulnerability register has a place for it.

What it is

An advertising slot is auctioned in the moment the page or screen loads. To collect bids, the request is sent out in parallel to a set of bidding parties, each copy carrying the same material: what is being viewed, an identifier for the device or the person, and usually coarse location and device characteristics. Losing bidders receive the same copy as the winner and keep it.

Why it is a separate entry

The person sees one advertisement and does not see that the occasion for it was distributed to dozens of companies, most of which they will never encounter. What is being viewed can itself be sensitive: a page about a diagnosis, a debt, a lawyer. Once broadcast, the copy cannot be recalled, and the number of holders makes any later exercise of rights impractical.

How it arises

Not to be confused with

A single third-party resource loaded from one party is Third-party resource loading. What distinguishes this entry is multiplicity: the same view, with the same identifier, delivered to many parties in one load. It is also not Undisclosed recipient, which is about a gap in a document; here the fault stands even if every bidder is named.

How to establish it

Within one page or screen load, requests to two or more hosts under different registrable domains that each carry the same identifier value together with the address or title of what is being viewed. In an application the same finding takes the form of one auction request whose body carries the device advertising identifier, coarse location and network operator in a single payload. The count of distinct receiving domains is the finding.

method network-with-identifierQoD 90

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itHow many companies receive a copy when one visitor opens one page, and who decides that list?
In a DPIA, verify this

Verify how many parties receive a copy of one page view and whether that list is fixed, rather than accepting that 'an advertising partner' is engaged.

As a procurement clause

The supplier states the complete list of parties receiving a bid request, the list is capped, and it is verifiable from a capture on delivery.

With a complaint, hand over

A HAR per consent mode, the list of distinct receiving domains, and the shared identifier value that connects the copies.

Reproduction

Legal framing

Objections, and the answer

“The bid request is anonymous.”

It carries an identifier that is stable enough to bid against, which is the entire point of sending it. A value that lets a party recognise the same device tomorrow is not anonymous.

“Consent was collected in the consent framework.”

Test what the person was actually told: how many recipients, named or as a list behind a link, and whether refusing removes them. A framework signal travelling alongside the request says nothing about whether the choice was informed or effective.

“Losing bidders discard the data.”

That is a statement about their internal handling, not something the sender can demonstrate. The sending is measurable, the discarding is not.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0015 (Bid request broadcast)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0015
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0015/index.json
Full
DPE Catalogue. DPE-2026-0015: Bid request broadcast. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0015
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0015, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.