Blog · Privacy

UK consumers block fewer ads than the global average, but two-thirds opt out of cookie tracking. That split is a bidstream problem.

ExchangeWire published survey findings on September 2 from a study of 22,000 consumers across 22 markets. In the UK, 40% say they use an ad blocker, below the 47% global figure. Meanwhile, 68% say they have opted out of cookie tracking, matching the global average. The headline reads like a tolerance story. For anyone sending UK bid requests, it is a reach classification story.

Ad tolerance and tracking tolerance are different metrics

Treating ad blocking and cookie opt-out as one privacy signal is how inventory gets mispriced. An ad blocker removes the impression entirely. A cookie opt-out removes the cross-site profile while the slot may still render, still fire server-side measurement, and still clear on contextual or first-party terms.

The UK numbers make that split visible. Fewer users block ads than the global norm, which suggests more viewable inventory on paper. Two-thirds have opted out of the tracking cookies that third-party identity, retargeting, and much frequency logic depend on. A buyer who reads lower ad-block rates as higher addressable reach is importing the wrong conclusion from the right survey.

The same release extends the distinction to AI chat placements. UK consumers responded negatively to ads alongside "highly personal" AI conversations (32% negative vs. 22% positive). Ads alongside "highly relevant" AI conversations were the only scenario tested where positive sentiment beat negative (32% positive vs. 18% negative). Relevance to the session mattered. Personal profiling did not. That is the same axis as cookie opt-out versus ad acceptance, just measured in a newer surface.

What the survey actually measured

The underlying study is a commissioned consumer survey, not a log-level measurement of programmatic traffic. Respondents self-report ad-blocker usage and whether they have opted out of cookie tracking. Tracking cookies are defined in the release as small files placed by sites or third parties to monitor activity, remember preferences, and build browsing profiles.

That population is UK consumers broadly, not a defended campaign cohort or a single publisher's logged-in base. You cannot map 68% directly onto match rates in your SSP dashboard. You can use it as a sanity check on how UK inventory should be labeled in the bidstream: most of the audience the survey describes has already rejected the mechanism your identity extensions assume.

The release is part of a broader Global Insights report on media quality and AI. The UK slice is one market in a 22-market design. The figures quoted here are the UK-specific bullets from the ExchangeWire summary, not invented extrapolations.

Where the split shows up in OpenRTB

None of this is visible in a CPM column. It shows up in whether the request tells buyers which parts of identity and measurement are still in bounds.

regs.gdpr          1 when the impression is in scope for GDPR.
                   Omission means unknown, not exempt.

user.consent       TCF consent string when GDPR applies.
                   Absent on a GDPR-scoped request tells buyers
                   they cannot rely on vendor-level consent for
                   the IDs and sync pixels in user.eids.

device.lmt         1 when the user has limited ad tracking.
                   Pairs with absent or zeroed device.ifa on CTV
                   and mobile. Different from cookie opt-out in
                   mechanism, same buyer question: what reach is
                   actually for sale?

user.eids          Identity extensions only matter when consent
                   and regulation allow them. Shipping eids on a
                   request with gdpr:1 and no user.consent is not
                   neutral; it is a claim buyers must discount or
                   drop.

A UK app or site with high viewability and thin privacy metadata looks like premium inventory right up until a buyer's GDPR filter runs. That filter is not measuring whether the user would have blocked the ad. It is measuring whether the request documents permission to use the identifiers attached to it. Our privacy signals reference and GDPR personal-data answer walk the field paths.

Why sellers misread this as a demand problem

Unfilled UK inventory often gets explained as weak CPMs or missing buyers. Some of that is true. Some of it is buyers passing on requests they cannot legally or operationally use for identity-heavy line items, while the seller still counts the opportunity as addressable in a direct report.

The ad-block half of the survey is the number sales teams like. The cookie opt-out half is the number that should change how requests are constructed. If your UK path still defaults to sending full user.eids arrays with regs.gdpr: 1 and an empty or stale user.consent, you are not failing because UK users hate ads. You are failing because the request describes a user who has already said no to cross-site tracking, without encoding that refusal where buyers read it.

Contextual and content-level signals become the honest reach story: content.genre, content.title, site.cat, app.bundle, and the page or app URL the impression actually runs in. Those fields describe what the user is watching, not who they were on another site yesterday. That aligns with the survey's emphasis on contextual relevance over personal targeting, including in AI chat environments.

What to check on a UK request this week

  • Pair regs.gdpr with user.consent on every UK EEA path. A GDPR-scoped request without a consent string is a filter trigger, not a bargain.
  • Stop treating missing consent as "unknown but probably fine." Unknown is how buyers classify requests they will not price with identity extensions.
  • Audit user.eids against consent scope. If you cannot map each extension to a permitted purpose in the TCF string, drop it before the auction, not after the pass.
  • Separate viewable reach from addressable reach in reporting. Lower ad-block rates do not convert into higher match rates when cookie opt-out is twice as common as blocking.
  • Validate a production UK sample in the tester. Paste a real request and read privacy paths before you trust a dashboard average. The bid request tester flags moved fields and missing consent pairs.

The honest limit

A consumer survey is not a measurement of your bid stream. It does not tell you what fraction of your impressions carry valid TCF strings or how many UK users in your app have limited ad tracking enabled. It does tell you the direction UK users say they prefer: ads yes, cross-site tracking no, contextual relevance over personal profiling.

RTBlint validates payload shape and consistency. It does not detect fraud, bots, or consent compliance in law. It will tell you when a UK request claims GDPR scope while omitting the fields buyers use to decide whether identity belongs in the bid at all. That is a cheap check against an expensive misread of what 68% opt-out means for addressable reach.

Sources

Survey figures are quoted from the ExchangeWire summary of the Global Insights consumer research. OpenRTB field names are from IAB Tech Lab specifications. RTBlint is independent and not affiliated with DoubleVerify, ExchangeWire, or IAB Tech Lab.