Skip to main content

Why Lunio Does Not Require User Consent

An explanation of the legal basis under which Lunio processes data for fraud detection, how controller and processor responsibilities are defined, and how to contact Lunio with data protection queries.

Updated today

Lunio typically operates under the legitimate interest legal basis (Article 6(1)(f) GDPR) for the purpose of fraud detection and prevention. As fraud prevention is considered a necessary security function, this processing generally does not require prior user consent. However, customers should assess this within the context of their own legal and regulatory obligations.

GDPR and Legitimate Interest

Processing under legitimate interest means Lunio can run essential fraud prevention activity without requiring a user to provide consent first. In practice, this means:

  • Data collected is limited strictly to what is necessary for fraud detection

  • No cookies are used unless they are strictly necessary under applicable laws

  • The data is not used for marketing, profiling, retargeting, or other secondary uses

Controller and Processor Responsibilities

Understanding how responsibilities are divided between Lunio and the customer is important for ensuring your use of the platform aligns with your compliance obligations.

  • Lunio acts as a data processor, processing data on behalf of the customer

  • The advertiser (customer) acts as the data controller, determining the purpose and means of processing

What Advertisers Need to Do

As a data controller, your only requirement is to mention Lunio's fraud prevention tool in your privacy policy, along with a brief explanation that it is based on legitimate interest. There are two ways to approach this:

  • If you remove Lunio as a vendor from your CMP or consent prompt, update your privacy policy to mention Lunio's fraud prevention tool and note that it operates under legitimate interest

  • Alternatively, ensure that Lunio is listed under the legitimate interest category within your CMP or consent prompt

This information is provided for guidance only and does not constitute legal advice. Please consult your legal team if you have specific compliance requirements.

Data Protection Contact

For any data protection queries, please contact [email protected].

If you run into any issues, please reach out to your account manager or email [email protected] and we will be happy to help.

Did this answer your question?