Consenter Documentation

Criteo Configuration

How to configure Criteo and properly map these configurations within the customer panel to ensure users are clearly informed about the use of this Third Party Provider (TPP). The tables below outline how different configurations of Criteo affect the privacy risks for users.

Additional Notes for Criteo Configuration

Important Compliance Considerations:

  1. Criteo Universal Match: If using email-based matching, this constitutes high-risk processing requiring selection of "Direct identifiers" category.
  2. TCF 2.2 Integration: If using IAB's Transparency & Consent Framework, ensure proper vendor registration and purpose mapping (typically Purposes 2, 3, 4, 7, 9, 10).
  3. Data Retention: Criteo's default retention periods:
    • Cookie data: 13 months
    • Transactional data: Up to 39 months
    • User profiles: Ongoing while user remains in active retargeting pool
  4. Sensitive Product Categories: Special attention needed for health, pharmaceutical, financial services, or other sensitive verticals.

Privacy relevant configurations (Parameters)

This table shows features which can be enabled or disabled within Criteo. Use this overview to ensure your Criteo setup and Consenter Manager settings stay consistent.

Each row represents a feature that can be disabled or enabled in various ways when configuring your TPP for your website. The left-hand column describes the feature, while the right-hand column provides guidance on where to find it in the Consenter Manager and how to configure it to accurately reflect your TPP setup.

Some functions or data categories may be named differently between TPPs or in our overview due to the lack of standardization. As the data controller, you are responsible for informing users in a clear and comprehensible manner. This guide supports you by offering uniform, established terminology that helps users understand how their personal data is processed, thereby fostering trust in your brand.

Parameters➡️ Criteo Config Mid Risk (Consent)➡️ Criteo Config High Risk (Consent)➡️ Consenter Manager Config How to map your Criteo configurations in Consenter Manager
ConsentYes (Opt-In)Yes (Opt-In)Select Criteo as data recipient.
Data sharingEnabled - Criteo partner networkEnabled - Full advertising ecosystem and third partiesIf data sharing with Criteo products & services is enabled, Criteo or other parties might act as Joint Controller or Controller, which must be indicated in Consenter Manager accordingly.
Data processing agreementYes - Criteo acts as Data Processor (for advertiser data) and Joint Controller (for retargeting data)Yes - Criteo acts as Data Processor (for advertiser data) and Joint Controller (for retargeting data)Select legal role: Joint Controller or Processor (depending on specific services)
Enter into: Data Processing Agreement
Tracking methodFirst party and third party cookies, cross-domainThird party cookies, cross-device, cross-platform with user matchingSelect respective tracking method.
IdentifierDevice identifier (cookies), advertising IDsDirect Identifiers, email hashes, Customer IDs, cross-device matching, advertising IDsSelect respective data categories:
- Device identifiers
- Direct identifiers
- Authentication-derived identifiers
Retargeting FeaturesDynamic retargeting across Criteo network with product recommendationsAdvanced retargeting with lookalike audiences, predictive bidding, cross-device orchestration1. Select data categories:
- eCommerce activity
- Browsing and interaction data
- Users' profiles
2. Select personalization model
Retention Period13-24 months> 24 months (up to 39 months per Criteo policy)Indicate maximum storage duration based on configuration. Default Criteo retention: 13 months for cookies, up to 39 months for transactional data.
Processing locationUSA/EU/GlobalUSA/EU/GlobalSelect respective processing location.

Data categories

This table details the categories of data collected by Criteo. Use this overview to ensure your Criteo setup and Consenter Manager settings stay consistent.

Each row represents a data category that can be disabled or enabled in various ways when configuring your TPP for your website. The left-hand column describes the data category, while the right-hand column provides guidance on where to find it in the Consenter Manager and how to configure it to accurately reflect your TPP setup.

Some functions or data categories may be named differently between TPPs or in our overview due to the lack of standardization. As the data controller, you are responsible for informing users in a clear and comprehensible manner. This guide supports you by offering uniform, established terminology that helps users understand how their personal data is processed, thereby fostering trust in your brand.

Collected Data Categories➡️ Criteo Config Mid-High Risk (Consent)➡️ Criteo Config High Risk (Consent)➡️ Consenter Manager Config How to map your Criteo configurations in Consenter Manager
IP AddressYes (anonymized or pseudonymized)Yes (plain)Select data category:
IP Address
Technical data
- Device characteristics
- Browser/OS data
YesYesSelect data category:
Device characteristics
Aggregated site statisticsYesYesSelect data category:
Aggregated site statistics
Behavioral dataShopping cart events, product searches, category browsing, time spent on product pages, scroll behaviorComprehensive cross-site behavioral tracking: purchase history, product affinities, shopping frequency, basket abandonment patterns, price sensitivitySelect respective data category:
- Browsing and interaction data
- eCommerce activity
- Users' profiles
eCommerce DataProduct details, prices, availability, cart additionsFull transaction history, order values, product categories, margins, stock keeping units (SKUs), purchase frequencySelect data category:
eCommerce activity
Geo-location infoCountry / region levelCity-level or more precise (derived from IP)Select data category:
- Non-precise location data
User Authentication DataNoYes - Hashed emails, Customer IDs, CRM identifiers for cross-device matchingSelect respective data category:
- Authentication-derived identifiers
- Direct identifiers (hashed)
Device identifiersYesYesSelect data category:
Device identifiers
Probabilistic identifiersNoYes - Cross-device matching via probabilistic and deterministic methodsSelect data category:
Probabilistic identifiers
Direct identifiersNo (Hashed only)Yes - Hashed emails, customer IDsSelect data category:
Direct identifiers
Special categories of personal dataNoPotential risk - Inferred from product browsing (e.g., health products, religious items)❗Assess content risk carefully. If selling sensitive product categories, select special categories and implement additional safeguards.
Privacy choicesNoNo-

For technical integration guides (code implementation), see Criteo Integration Guide →

Last updated on