← Policies & standards

Data Processing in Digital Platforms

Updated controller, platform, agency and AI-assisted workflow

Version: 2.0 Updated: 06 August 2026

1. Operating principle

The client remains responsible for determining the purpose and lawful basis for use of first-party customer data. TFG acts only on documented instructions and does not require raw identifiable customer data for campaign activation where approved platform audience functionality can be used.

2. Client-controlled upload

The client or its authorised representative uploads or connects selected customer segments to approved advertising platforms such as Meta, Google/DV360, Microsoft Advertising or The Trade Desk. Uploads should use platform-approved hashing, pseudonymisation or direct integration. TFG must not receive raw personal data unless a separately approved processing arrangement, DPA, security review and operational need exist.

3. Platform processing

The advertising platform matches pseudonymised identifiers within its environment and provides named, non-identifiable segments for approved targeting, exclusion or modelling. The platform role must be confirmed through the relevant terms and DPA; it must not be assumed to be identical across providers or services.

4. TFG processing

Select approved audience segment names after media-plan approval.

Configure, optimise and report campaigns within approved platforms.

Use aggregated campaign and audience performance outputs.

Do not export or download underlying personal data.

Record purpose, owner and campaign approval for each first-party segment use.

5. AI-assisted analysis

Aggregated or anonymised campaign outputs may be used in an approved AI-assisted workflow only where the tool, purpose, source, retention and access have been approved. Personal data, raw audience lists, credentials and restricted client information must not be copied into unapproved tools. AI output is advisory and requires human review before client use or campaign action.

6. Access and account security

Named user accounts, least privilege and multi-factor authentication.

Client-approved access, periodic review and prompt removal when no longer required.

No credential sharing; privileged changes and critical actions logged where supported.

Third-party access governed by client instruction, platform controls and supplier terms.

7. Retention and deletion

The client controls first-party segment retention in the advertising platform. TFG retains campaign metadata and aggregated performance information according to the approved retention schedule. Staging copies of audience lists, where exceptionally authorised, must be deleted after upload and no later than 90 days unless a shorter client or contractual period applies.

8. Roles

Party

Role

Responsibilities

Client

Controller

Lawful basis, purpose, audience selection, upload/link, platform approval and revocation.

Advertising platform

Role determined by terms/DPA

Matching, platform security, delivery, retention and data-subject support as contractually defined.

TFG / Republic of Media

Processor or service provider as agreed

Act on instructions; activate named segments; optimise and report; protect access; avoid raw-data access.

AI/model provider

Processor/sub-processor only where approved

Process approved inputs under contract, security assessment, retention and training restrictions.

9. Required pre-use checks

Signed contract/DPA and confirmed party roles.

Lawful basis and transparent client notices.

Approved platform, audience purpose and suppression requirements.

Security review, account ownership and access list.

Retention/deletion route and evidence requirement.

AI use-case approval if AI-assisted analysis is proposed.