Data, identity & privacy quiz
Cookies, first-party data, UID2, clean rooms, contextual targeting and consent. Ten questions to check you know where the industry actually stands in 2026. intermediate · 10 questions
Question 1 of 10Score 0
What makes a cookie a third-party cookie?
All questions with answers
- What makes a cookie a third-party cookie?
Answer: It is set by a domain other than the site you are visiting. A third-party cookie belongs to a different domain than the page in your address bar, typically an ad tech vendor's, which lets it recognise you across sites. The 'third' refers to who set it, not how many companies see it. - Which statement about third-party cookies is true in 2026?
Answer: Chrome still supports them, Google retired most Privacy Sandbox APIs in October 2025, and Safari and Firefox restrict them by default. Google abandoned its plan to phase out cookies in Chrome and in October 2025 retired most Privacy Sandbox APIs, including the Topics API. Safari and Firefox have long restricted them, so signal loss is real but not universal. - What is cookie syncing?
Answer: Two ad platforms matching their own user IDs for the same browser so they can trade data about it. Each vendor has its own ID for you; cookie syncing builds a lookup table between them so a DSP can recognise an SSP's user. It is plumbing for targeting, not storage or deletion. - A retailer uses purchase history from its own loyalty programme to target ads. What kind of data is that?
Answer: First-party data. Data a company collects directly from its own customers is first-party data. It is tempting to call it zero-party, but zero-party data is what customers deliberately tell you, such as stated preferences, not behaviour you observe. - Unified ID 2.0 (UID2) is built from what?
Answer: A hashed and salted email address or phone number, with user opt-out. Unified ID 2.0, started by The Trade Desk and now administered by Prebid.org, turns a login email or phone into an encrypted identifier. It is deterministic and login-based, unlike device fingerprinting or IP-based guesses. - What is the difference between deterministic and probabilistic matching?
Answer: Deterministic uses a known shared key such as a login; probabilistic infers a match from signals like IP, device and behaviour. Deterministic matching links records on a certain key like a hashed email, while probabilistic matching scores likely matches from signals. Probabilistic gives more scale but less accuracy. - What is a data clean room for?
Answer: Letting two companies match and analyse their data together without either seeing the other's raw user-level records. A data clean room enforces rules so partners, say a retailer and a brand, get aggregate answers such as overlap or sales lift. Neither side gets to walk away with the other's customer list. - What does contextual targeting use to decide which ad to show?
Answer: The content of the page, video or app the ad appears in. Contextual targeting matches ads to the content, such as a running shoe ad on a marathon article, without tracking the person. Using past browsing is behavioral targeting, which needs identifiers and consent. - What does an IAB TCF consent string carry through the ad supply chain?
Answer: The user's recorded choices about which vendors and purposes they consent to. Under the IAB TCF, a CMP encodes the user's choices into a consent string that travels with the bid request so vendors know what they may do. It holds preferences, not the user's identity or the bid price. - What does Apple's App Tracking Transparency (ATT) require?
Answer: Apps must ask users for permission before tracking them across other companies' apps and sites using the IDFA. Since iOS 14.5 in 2021, App Tracking Transparency makes tracking opt-in, and most users decline, so the IDFA is usually unavailable. Ads still run; measurement shifted toward SKAdNetwork / AdAttributionKit and modelled data.