Skip to content
RiverCore
BidSafe One and Screencore Bet on Privacy as Programmatic Infra
programmatic privacy infrastructureconsent signalsad tech partnershipmid-market SSP DSP consent signal fragmentationprivacy engineering programmatic data flows

BidSafe One and Screencore Bet on Privacy as Programmatic Infra

5 Sep 20266 min readSarah Chen

Two ad tech companies signed a partnership this week, and the framing matters more than the announcement itself. Screencore, a programmatic vendor running across CTV, video, display and mobile, is bringing in BidSafe One to sit inside its data flows rather than beside them. The pitch is that privacy engineering belongs in the product, not in a PDF binder.

That is one signal. The bigger one is what the deal implies about how mid-market SSPs and DSPs plan to survive the next 18 months of consent-signal fragmentation.

What Happened

BidSafe One and Screencore announced a strategic partnership focused on privacy readiness across Screencore's programmatic and publisher monetisation stack, as ExchangeWire reported. BidSafe One is a specialist consultancy in ad tech privacy, data protection, and regulatory implementation. Its scope, per the announcement, covers privacy audits, data mapping, transparency and consent mechanisms, TCF and GPP implementation, DPIAs and LIAs, cross-border data considerations, and reviews of complex DSP and SSP data flows. That is a long list, and each item is a distinct engineering surface.

Screencore describes itself as a global programmatic advertising technology company connecting brands, agencies, and publishers. Its publisher offering combines verified demand, real-time yield optimisation, and privacy-first monetisation. It is already a registered vendor in the IAB TCF and has documented policies covering how data is processed across its ad tech services.

Liz Tokareva, CEO and ad tech product expert at BidSafe One, said privacy in ad tech cannot sit separately from the product, and that the decisions that matter happen inside real data flows, integrations, and programmatic workflows. Jess Okan, CEO and co-founder of Screencore, framed the goal as making privacy part of how the infrastructure evolves rather than a separate compliance exercise.

The announcement does not disclose commercial terms, scope of engagement (advisory versus embedded engineering), or KPIs. Those omissions matter, and I will come back to them.

Technical Anatomy

Take the checklist BidSafe One is bringing in and map it against a real programmatic path. A single ad impression on Screencore's stack likely touches: a CMP producing a TCF consent string, a GPP string wrapping US state signals, an OpenRTB bid request with the regs.gpp and user.consent fields populated, one or more SSP-to-DSP hops, macro replacement in a VAST wrapper for video and CTV, and downstream measurement pixels. Every hop is a place where a consent signal can be stripped, misinterpreted, or contradicted by a downstream partner's policy.

DPIAs (Data Protection Impact Assessments) and LIAs (Legitimate Interest Assessments) sound like paperwork, but done properly they force an engineering team to inventory every field in every bid request, every enrichment call, and every log sink. Cross-border data considerations translate into concrete infrastructure questions: where is the RTB endpoint terminated, where are logs persisted, is there a Schrems II compliant transfer mechanism for the DSP side. TCF and GPP implementation is not a one-time integration. Vendor lists change, purposes are re-scoped, and the CMP payload has to stay in lockstep with what the SSP actually enforces on the wire.

Screencore's CTV footprint sharpens the challenge. CTV consent capture is genuinely hard: no cookies, limited CMP surfaces on device, and IFA-based identifiers that behave differently across Roku, Fire TV, and native smart TV apps. The Privacy Sandbox conversations barely apply here. If BidSafe One is genuinely reviewing complex DSP and SSP data flows, that review has to produce diffs against actual bid request samples, not policy diagrams.

What the source does not disclose, and what matters most, is whether BidSafe One's engagement includes code-level review, access to production bid stream samples, or authority to block feature releases that fail privacy gates. The bound is meaningful: an advisory retainer produces documents, an embedded model produces PRs. Those are different products with different cost curves.

Who Gets Burned

The exposed cohort here is not Screencore. It is every mid-tier SSP and DSP that has been treating TCF vendor registration as the ceiling of their privacy posture rather than the floor. Regulatory attention on programmatic data flows has been climbing in EU markets for three years, and the enforcement surface now extends to bid request contents, not just cookie banners. A vendor that cannot produce a data map of its own bid stream on demand is exposed, whether or not it is a TCF signatory.

Publishers are the second exposed group, and their next 90 days look uncomfortable. Yield optimisation and privacy-first monetisation are in tension whenever a publisher's mediation stack calls partners with divergent consent interpretations. If Screencore's approach becomes a differentiator on the sell side, publishers will start asking their other SSPs the same questions: show me your data map, show me your GPP implementation notes, show me the DPIA on your identity partner. Vendors without answers lose share, quietly, in RFP cycles rather than in press releases.

Demand-side platforms in the US market face a specific pressure. GPP adoption has been uneven, and DSPs that read the string but do not act on all applicable state signals are one enforcement action away from a bad quarter. The engineering cost of doing GPP properly (per-state purpose gating, opt-out signal honouring, sensitive data class handling) is non-trivial and has been under-invested.

The counter-scenario worth flagging: privacy-as-infrastructure narratives have been announced before and quietly downgraded into quarterly audits. We do not know yet which version this is. The testable signal will be whether Screencore ships observable product changes (updated TCF vendor scope, published data maps, GPP purpose expansion) in the next two quarters.

Playbook for Performance Marketing

For buy-side teams routing spend through Screencore or comparable SSPs, this week is a good time to run a concrete audit rather than wait for a vendor deck. Pull a sample of your last 10,000 winning bids on CTV and video inventory and check three things: what percentage carry a valid TCF consent string, what percentage carry a GPP string with the correct section IDs for the geo, and what percentage of your measurement partners are actually on the vendor list your CMP declares.

For publishers, the practical move is to ask every monetisation partner for their data map and DPIA summary in the next RFP round. Vendors that can produce these quickly are lower-risk counterparties. Vendors that need six weeks are telling you something.

For ad tech engineering leads, treat the BidSafe One scope list as a checklist for internal readiness: data mapping, TCF and GPP implementation, DPIA and LIA coverage, cross-border transfer posture, and end-to-end review of DSP and SSP flows. If any of those five buckets does not have a named owner on your team, that is the gap to close first. Privacy work that lives only in legal will not survive the next regulatory cycle. Work that lives in the product roadmap probably will.

Key Takeaways

  • Screencore is treating privacy as an infrastructure concern across its CTV, video, display, and mobile stack, not as a legal-department deliverable.
  • BidSafe One's scope covers audits, data mapping, TCF and GPP, DPIAs, LIAs, cross-border transfers, and DSP/SSP flow review, which is broad enough to imply embedded work, though the announcement does not confirm depth of engagement.
  • The unanswered question with a testable bound: does Screencore ship observable product changes (vendor list updates, published data maps, expanded GPP purposes) within two quarters, or does the partnership stay at the advisory tier.
  • Mid-tier SSPs and DSPs without their own data map on demand are the exposed cohort, particularly on CTV where consent capture is structurally harder.
  • If this framing plays out, expect privacy readiness to appear as a scored line item in publisher RFPs within the next 12 months, and expect at least one enforcement action against a TCF-registered vendor whose bid stream contradicts its declared purposes.

Frequently Asked Questions

Q: What does the BidSafe One and Screencore partnership actually cover?

BidSafe One will work with Screencore on practical implementation of privacy requirements across its ad tech operations, including audits, data mapping, TCF and GPP implementation, DPIAs and LIAs, cross-border data handling, and reviews of DSP and SSP data flows. The announcement does not disclose commercial terms or whether the engagement is advisory or embedded at the engineering level.

Q: Why does GPP implementation matter for programmatic vendors right now?

The Global Privacy Platform wraps a growing set of US state signals into a single string that SSPs and DSPs are expected to read and act on. Vendors that parse the string but do not honour all applicable opt-outs or sensitive data class rules are carrying regulatory exposure, and enforcement attention is shifting from consent banners to what actually happens inside the bid request.

Q: How should publishers evaluate whether their SSP is privacy-ready?

Ask for a current data map, a DPIA summary, the vendor's TCF vendor scope and GPP section coverage, and evidence that consent signals are enforced on the wire rather than only collected at the CMP. Vendors that can produce these documents quickly are meaningfully lower-risk than vendors that treat the request as unusual.

SC
Sarah Chen
RiverCore Analyst · Dublin, Ireland
SHARE
// RELATED ARTICLES
HomeSolutionsWorkAboutContact
News06
Dublin, Ireland · EUGMT+1
LinkedIn
🇬🇧EN▾