Request Demo

#newsletter

Newsletter - Match Rate, Issue #2

By Geetha Neelakantiah 9 min read
#newsletter #adtech
match_rate_issue2

Match Rate, Issue #2

Identity, data and measurement, from someone who runs it.

Wednesday, October 7, 2026 · By Geetha Neelakantiah


This week has two stories, and both are about rules. One is a rule nobody outside Apple can see. The other is a Connecticut law that took effect last Thursday.


The two that matter

1. Apple's Safari block runs on a list Apple can change at any time

What happened

Last week I wrote about Safari in iOS 27 blocking The Trade Desk's ad serving domain (adsrvr.org), along with several identity providers. Here is where that stands.

There may be a fix on the way, but it's in beta, not in live iPhones. On Oct 5, a WebKit engineer at Apple wrote on the public bug report The Trade Desk had filed that "a new iOS 27.2 beta went out today. Please test with it." A Trade Desk engineer replied that he could see "the changes" in that build and would report back. As of Wednesday morning, neither company has said whether the block is lifted in that build, Apple hasn't said publicly what changed, and the bug is still open. Until iOS 27.2 ships and people install it, Safari users on iOS 27 are still blocked. The bug report covers only adsrvr.org. Nothing public says whether anything changed for UID2 or the other identity providers.

On Oct 2, AdExchanger reported that the list is not fixed. According to two sources with knowledge of the WebKit changes, Safari checks a list that Apple can update remotely, without an iOS update or release notes. AdExchanger says the list could grow from the first five names (The Trade Desk, LiveRamp, ID5, Permutive, Audigent) to hundreds of customer data platforms, DSPs, DMPs, data sellers and identity graph operators. AdExchanger saw the list in a private repository but could not publish it. Apple has not confirmed any of this, so treat the scope as reported, not confirmed.

What it changes

Last week the question was whether Apple would fix the Trade Desk block. It looks like Apple may, in its own time and through a beta. That's good news for The Trade Desk's buyers, but it doesn't change the bigger point. A company got blocked, filed a bug, and is waiting on a beta to find out whether it can serve ads. That's the only appeal process there is. Now the question is whether any other vendor in your plan is on a list you can't see, and whether that list will change while your campaign is running.

You can plan around a rule you know. You can't plan around a rule that isn't published.

People in the industry see this very differently. ID5 CEO Mathieu Roche called it "an attack against the business model of the web" and said regulators should look at it. AdExchanger's Allison Schiff pointed out that App Tracking Transparency made tracking harder, while this stops some companies from working at all. On the other side, Safari users never agreed to be followed across sites, and Apple has been moving in this direction since 2017. Both of those things can be true.

One thing Apple hasn't explained: Google's ad.doubleclick.net, which also serves ads across sites, was reportedly still working in Safari as of last week. If the list is about blocking cross-site tracking, why is The Trade Desk's ad domain on it and Google's isn't? Without published criteria, nobody outside Apple can say.

What to do this week

  1. Pull your Safari and iOS impressions and conversions by vendor for the last 30 days and compare them with the 30 days before. If one vendor drops sharply, that's your signal.
  2. Ask each vendor in writing which domains their ad serving, identity and measurement depend on, and what happens if one of those domains is blocked.
  3. Don't rely on a vendor saying "we're not on the list." No one outside Apple can check that.
  4. If you buy through The Trade Desk, don't count on Safari reach coming back until iOS 27.2 is released and people have installed it. iOS updates take weeks to spread.
  5. Repeat the check every week. The list can change without notice.

My bias

Semcasting resolves identity on the server, so a browser blocklist doesn't change how we match records. That's part of why I follow this closely, so take my view with that in mind. But our clients' campaigns still run through DSPs, so a blocked DSP affects them too. A rule that isn't published and has no appeal process is a problem for every company in this business, including the ones that aren't on the list today.

Sources: WebKit bug 324771 · AdExchanger · AdExchanger opinion · PPC Land on ID5 · PPC Land on the iOS 27.2 beta


2. Connecticut bans the sale of precise location data

What happened

Amendments to the Connecticut Data Privacy Act took effect Oct 1. Three parts matter for advertisers:

  • Selling precise geolocation data is banned. Connecticut defines precise geolocation as technology-derived location accurate to within 1,750 feet. Companies can still collect it with consent, but they can't sell it, apart from a few narrow exceptions. Most states only require consent; Connecticut bans the sale outright.
  • "Publicly available" covers less than it used to. Profiles built by combining public records with other data now count as personal data. Consumers can ask for that data to be deleted. This part is already being challenged: Bloomberg Law reports that Spokeo, PeopleConnect and about six other people-search companies sued on Sep 17, arguing it violates the First Amendment, and asked the court to block enforcement. The court hasn't ruled. The suit does not target the location data ban.
  • Data brokers have to register. Registration with the Department of Consumer Protection starts Jan 1, 2027, making Connecticut the sixth state with a broker registry. A statewide deletion mechanism follows in July 2028.

What it changes

Many location audiences are built from phone GPS data: store visitors, competitor shoppers, people who attended an event. In Connecticut, selling that raw data is now off the table. Whether the ban also covers segments built from it is a question for lawyers, and vendors may not all read it the same way.

It also connects to the New Jersey law from Issue #1. New Jersey bans the sale of sensitive data, including precise location and health conditions, and starts broker registration in April 2027. New Jersey's enforcement is still unclear: the attorney general's office says it will handle cases "case by case." That makes two neighboring states acting within one quarter.

What to do this week

  1. List every audience in your current plans that uses location: visitation, footfall, geofencing.
  2. Ask each vendor three things: Does this segment use precise location? How are Connecticut and New Jersey consumers handled? Since when?
  3. If you buy for health, finance or political clients, involve legal now, before Q1 2027 planning.

My bias

Semcasting is an audience data company, and laws like this apply to us. I'd rather buyers ask these questions now, and we're working through them ourselves. None of this is legal advice.

Sources: Mintz · InfoLawGroup · Connecticut Attorney General · Kelley Drye on the 1,750-foot definition · Bloomberg Law on the lawsuit


Quick hits

Google's ad tech damages case goes to a jury. On Sep 30, Judge P. Kevin Castel rejected Google's bid to end the publishers' main claims about its ad server and AdX exchange before trial. Expert damage estimates are about $901M for Gannett, $600M for Daily Mail and $1.72B for a class of AdX publishers. These are estimates, not awards. Search Engine Land

ChatGPT ads are stuck at test budgets. Agencies told Digiday that OpenAI's conversion reporting lags 24 to 36 hours and doesn't match their own tracking. One agency counted about 20 clicks where ChatGPT reported about 100. Many advertisers won't turn on conversion tracking because their lawyers object to OpenAI's terms. It's a new channel with an old problem: the platform grades its own results. Digiday

AppLovin sues Unity over ad data. AppLovin says Unity's Ad Quality SDK collects clearing prices, auction IDs and creatives from ads AppLovin wins, and could use them to train competing models. Unity says publishers gave permission and calls the suit "a classic case of a dominant incumbent resorting to litigation and intimidation." Last week a San Francisco court turned down AppLovin's request for a temporary restraining order. That ruling only covered emergency relief, not the merits, and the dispute now moves to arbitration. The underlying question is who owns auction data that passes through a publisher's app. Digiday · Tradingpedia


The explainer: what counts as "precise" location

Connecticut's ban depends on one number: 1,750 feet. Data that pins a person down more closely than that, and comes from technology like GPS, counts as precise. Here is how common data types usually line up. Your lawyers have the final word.

match-rate-02-precise-location-table_1

How common location data lines up against Connecticut's 1,750-foot rule. Not legal advice.

Three questions to ask any location data vendor

  1. What is the raw input: GPS, Wi-Fi, IP, or address?
  2. Is the data sold as raw coordinates, or only as segments built from it?
  3. Which states are excluded or handled differently, and when did that start?

The Semcasting Angle: pharma data

This section reflects my company's view. Everything above it is vendor-neutral.

In Issue #1 the spotlight was the open enrollment audience briefs. This week it's pharma, and it ties straight into the Connecticut story. Pharma buyers work under the strictest rules on health and location data, so they need clear answers about where their data comes from.

We've published pharma condition briefs for 27 conditions, heart failure among them. Each brief shows four things: qualified reach, audience quality lift, prescriber counts by specialty, and the primary data sources behind the audience. That last item is the one I'd point you to after this week's lead story. Before you buy an audience, you should be able to see what it's made of.

What sits behind the briefs, all published on our website:

  • Healthcare professionals. 6.5 million Type 1 NPI records (individual healthcare providers, checked against the national NPI registry CMS runs), of which about 6.4 million are matched to digital identities. Targeting covers specialty, practice type, prescriber category, disease state and treatment.
  • Health systems. Targeting by system name, bed count, geography and department.
  • Measurement. Script lift and enrollment measurement.
  • Controls. No PHI used or stored, SOC 2 Type II, HITRUST CSF certified infrastructure, and Business Associate Agreements available.

What to ask any pharma data partner

  1. Are any condition audiences built from PHI? If they're modeled, what are the inputs?
  2. How do you measure script lift, and who checks the methodology?
  3. Where does the NPI verification come from, and how often is it refreshed?

Ask for these answers in writing.

The pharma condition briefs are at semcasting.com/briefs/pharma.


A question worth asking this week

"Is a household-level audience safer than a device-level one under these new state laws?"

Not automatically. Connecticut and New Jersey regulate the type of data, not how detailed the audience is. Selling precise location is banned in Connecticut. Selling health condition data is banned in New Jersey. Neither law has an exception for data rolled up to the household.

That cuts both ways. A household audience built from GPS store visits or health condition data can still involve the data these laws restrict. A device-level audience built from non-sensitive inputs, like content a device has viewed, may not.

So the question to ask your vendor isn't "household or device?" It's "what went into this segment?" A household-level audience gives you less exposure when its inputs don't involve sensitive data, and that's something to check, not assume.

My bias: Semcasting works at the household level. I'd still give you this answer, because the inputs are what count under these laws, including for us.


That's Issue #2. If you're seeing changes in Safari performance, or you have a question about Connecticut, hit reply. I read every one.

Geetha


 

Match Rate is written by Geetha Neelakantiah, SVP at Semcasting, a deterministic identity resolution and audience data company. The views are my own. Sections labeled "The Semcasting Angle" reflect my company's perspective. Nothing here is legal advice.   Semcasting builds audiences, resolves identity, and measures outcomes for brands and agencies in healthcare, pharma, financial services, political, and B2B. Talk to us →

Geetha Neelakantiah

Geetha Neelakantiah

20+ years in digital marketing, database marketing, measurement and data integration. Drives ADS, IDX, and innovative identity data products.

See Identity Resolution in Action

Upload a sample file. We'll deliver your match rate analysis in 24 hours — no commitment.