Lesson 2 of 5 · 8 min read · intermediate
First-party data and the new IDs: UID2, RampID, MAIDs and more
How logins, hashed emails and shared IDs like UID2, EUID, RampID and ID5 try to replace cookies, plus MAIDs, ATT and the 2024 ID bridging row.
When a cookie is missing, the ad ecosystem goes looking for another way to say this is the same person as before. The answers range from the very solid (you logged in with your email) to the very shaky (your phone model and IP address look familiar). Knowing which is which is the difference between a smart buyer and a gullible one.
A cookie is a stamp on your hand that washes off. A logged-in ID is more like a membership card with your name on it. A probabilistic ID is a bouncer saying you look like the guy who was here last Tuesday. All three get you recognised, but you would not bet the same money on each.
The data ladder: zero, first, second, third
| Type | Who collects it | Example |
|---|---|---|
| Zero-party data | The person tells you directly | A quiz answer: I prefer vegetarian recipes |
| First-party data | You collect it from your own customers | A Tokyo retailer's purchase history for its app users |
| Second-party data | Another company's first-party data, shared by agreement | An airline sharing traveller segments with a hotel chain |
| Third-party data | Aggregators who did not collect it from the person | A data broker selling in-market for SUVs segments |
First-party data became the prize because it is collected with a direct relationship, which usually makes consent clearer and the signal fresher. Publishers push readers to log in, and retailers build loyalty programmes, partly so they own an identity signal that does not depend on any browser's cookie policy.
Hashed emails and why they are not magic
The most common login-based signal is a hashed email. The email is normalised (lower-cased, spaces trimmed) and run through a one-way function like SHA-256, turning [email protected] into a long string of letters and numbers. Two companies that hashed the same email the same way get the same string and can match without swapping the raw address.
The shared ID landscape
Several companies turned hashed emails and other signals into shared identifiers that can travel through the bidstream. The most discussed are listed below. None of them is universal; buyers usually see a patchwork.
| ID | Run by | How it works in brief |
|---|---|---|
| Unified ID 2.0 | Created by The Trade Desk, open-source | Encrypted token built from a hashed email or phone number, with an opt-out portal; mainly used outside Europe |
| European Unified ID | The Trade Desk's European version | Similar approach adapted for GDPR-style consent in Europe |
| RampID | LiveRamp | A people-based ID resolved against LiveRamp's identity graph, often used for onboarding offline data |
| ID5 ID | ID5 | Combines deterministic signals with probabilistic ones, widely used by European publishers |
| Mobile advertising ID | Apple (IDFA) and Google (GAID) | A device-level advertising ID built into the phone's operating system |
The two big techniques behind any identity graph are deterministic matching (two records share an exact key, such as the same hashed email) and probabilistic matching (records are linked because signals like IP address, device type and time of day make it likely they are the same person). Deterministic is more accurate but covers fewer people; probabilistic covers more but is wrong more often.
Identity: cookies, IDs and clean rooms
You browse a shoe store, then read the news. Each site, and the ad tech on it, gives your browser its own ID in a cookie.
- You visit two sites: You browse a shoe store, then read the news. Each site, and the ad tech on it, gives your browser its own ID in a cookie.
- Different IDs for the same person: Cookie A and cookie B do not know they are the same browser. On their own, the shoe ad cannot follow you to the news site.
- Cookie syncing joins them: Third-party cookies and cookie syncing let ad platforms swap IDs in the background, so A and B are matched. That is how retargeting works across the web.
- Where cookies fail: Safari and Firefox restrict third-party cookies, and apps never had them. Chrome still allows them (Google dropped its plan to remove them), but many people still cannot be matched this way.
- Logged-in IDs: When you log in, your email can be turned into a one-way hashed ID such as UID2. It is stable across sites that use it, and you can opt out.
- Clean rooms: match without handing over data: In a data clean room, a retailer and a brand match their customer lists in a controlled space and only see aggregated results, never each other’s raw data.
Mobile: MAIDs and the ATT shock
Phones never relied on cookies. Apps used the Mobile advertising ID: IDFA on iOS and GAID on Android. In April 2021, with iOS 14.5, Apple introduced App Tracking Transparency (App Tracking Transparency), which requires apps to ask permission before accessing the IDFA for tracking. Many users say no, so on iOS the IDFA is now missing for a large share of traffic. Android still offers GAID, though users can delete it, and Google's own plans for Android privacy changed alongside the Chrome reversal.
ID bridging: the 2024 controversy
In 2024 trade press, researchers and buyers began scrutinising ID bridging. The practice attaches an ID observed in one environment (say, a Chrome cookie or a hashed email from a login elsewhere) to a request from an environment where that ID was not actually present (say, Safari with no cookie). Some sellers argued it was a legitimate way to restore addressability. Critics said bridged IDs were often not declared, so buyers could not tell whether an ID truly belonged to the person on the page.
- Frequency capping breaks if impressions are counted against the wrong person.
- Attribution gets polluted when conversions are credited to an ID that was guessed.
- Prices get inflated because addressable Safari inventory normally sells at a premium.
- Transparency suffered, which led to industry responses such as the IAB Tech Lab's guidance on declaring how an ID was generated and BidSwitch's ID Provenance Protocol in September 2024.
How to judge an ID
- Ask how it was createdDeterministic from a login, probabilistic from device signals, or bridged from somewhere else?
- Check consentWas the person asked, and does the ID carry their opt-out through the chain?
- Measure match and accuracyCoverage is easy to claim; accuracy against a known truth set is harder and more important.
- Watch for anomaliesOne ID on thousands of devices, or thousands of IDs on one IP address, is a red flag.
Key takeaways
- First-party data comes from your own relationship with a customer and does not depend on browser cookie rules.
- Hashed emails are pseudonymous personal data, not anonymous, and match rates are limited by people using different emails.
- UID2, EUID, RampID and ID5 are the best-known shared IDs; none covers everyone.
- Apple's ATT (iOS 14.5, April 2021) made the IDFA opt-in, removing it from much iOS traffic.
- ID bridging became controversial in 2024 because undeclared bridged IDs can mislead buyers.
Questions people ask
Is a hashed email anonymous?
No. Hashing turns an email into a fixed string, but anyone who has the same email can hash it and get the same string, so the person can be re-identified. European regulators generally treat hashed emails as personal data under GDPR. Hashing reduces exposure of the raw address during data sharing, which is useful, but it does not remove privacy obligations or the need for consent.
What is UID2 and who uses it?
Unified ID 2.0 is an open-source identifier created by The Trade Desk. It is built from a hashed and salted email or phone number, encrypted into tokens that travel through programmatic auctions. Publishers generate it when users log in, and many DSPs and SSPs accept it. Its European counterpart is EUID. Users can opt out through a central portal.
What did Apple's App Tracking Transparency change?
Since iOS 14.5 in April 2021, apps must show a prompt asking permission before they access the IDFA to track users across other companies' apps and websites. If a person declines, the IDFA returns zeros. This removed a reliable device ID from much iOS traffic and pushed advertisers toward Apple's SKAdNetwork, contextual signals and first-party data.