Let’s enter the worldwide conversation about FLoC, cookies, and targeted advertising. In March of this year, Google had announced that it intends to promote the privacy of its users by replacing third-party cookies with a new solution: ‘Federated Learning of Cohorts’ or FLoC for short.

I don’t know about you, but the full name sounds like a stuffy university meeting, while the acronym sounds like a collective noun for tweets (a FLoC of tweets). But, name policing aside, the worldwide response to FLoC has been bipolar. While some commentators welcomed the news of FLoC, privacy advocates emerged from their inner sanctums and admonished it.

If you’re confused about what the heck all of this means – rest assured – you’re not alone. The topic is dense and baffles the brightest minds in the Ad Tech and legal worlds. Fortunately, we’ve done our homework to explain the topic.

This post starts by describing cookies and then considers why Google wants to replace cookies with FLoC. Next, it looks at how FLoC works, and because we’re data protection lawyers, we give our take on whether FLoC actually promotes privacy.

Let’s start with some cookies

Before we get into the details of how FLoC works, we need to consider what it seeks to replace, i.e. cookies.

What are cookies?

We’re not referring to those yummy baked goods that pair perfectly with your favourite cuppa. Instead, we’re talking about ‘website cookies’, more formally known as ‘HTTP cookies’.

A cookie is a small piece of data that a specific website stores on your device when you browse it.

As a side note, contrary to popular belief, Britons don’t refer to cookies as ‘biscuits’ 🍪🤣.

What can cookies do?

Cookies can do many things. Below, we list some of the notable functions.

  • They can have simple functions, such as remembering your login details to a website. For example, if you log in to your Gmail account and accidentally close your browser tab, you’ll still be logged in to your account when you re-open Gmail.
  • Cookies help website owners track how many people visit their website. How? Each cookie has a unique ID that can identify the website visitor.
  • They also keep track of your browsing activity to serve you targetted information, such as ads for goods or services. For example, suppose you search on Takealot for rabbit food but never end up buying it. Later, when you log on to Facebook, you might see ads for rabbit food on your timeline.

How do cookies work?

When you visit a website for the first time, it will place a cookie on your hard drive – the data storage place on your device. If you recall, we mentioned that each cookie has a unique ID. Websites use this ID to keep track of your session (overall visit to the website from start to end).

To make this explanation real, let’s look at the example of the online store Amazon. They use cookies to keep items in your shopping cart, memorise the items you looked at to advertise similar products to you or save coupons on your device.

First-party versus third-party cookies

Cookies usually originate from the specific website you visit. These cookies are known as first-party cookies. But, there’s another type of cookie, i.e. third-party cookies.

If you’ve ever visited an online news website and were reading an article, you probably would have noticed the option to share the article to Facebook. In that scenario, you’d be interacting with third-party cookies. They give third parties, like Facebook, the ability to save cookies from Facebook onto your device. So, later, Facebook will serve news-related ads to you.

Why would Google want to replace third-party cookies with FLoC?

Google currently uses third-party cookies to track the behaviour of website visitors. Using the data it collects from these cookies and other sources, Google creates a behavioural profile of each website visitor. Then, it sells this behavioural profile to advertisers. This business model underpins the advertising surveillance industry.

For much time, people didn’t know that Google had been tracking their online behaviour. When they discovered this fact, it caused uproar amongst users and privacy advocates. Several awareness campaigns and policy shifts later, the EU introduced the GDPR.

The GDPR requires website owners to make their visitors aware that they use cookies to track online behaviour. The owners also need to allow the visitors to opt-out from inessential third-party cookies. However, privacy laws worldwide are fragmented, so this approach doesn’t hold for all countries.

Over time, with a global move to privacy by design, many internet browsers have opted to block third-party cookies: Apple’s Safari in 2017 and Mozilla’s Firefox in 2019. However, Google Chrome still uses them.

The fact that Google still uses third-party cookies has placed them under scrutiny for not valuing the privacy of its users. So, Google has proposed FLoC. It argues that FLoC offers stronger privacy controls than third-party cookies or alternative behavioural advertising techniques.

In short, Google believes that FLoC promotes privacy better than the other techniques for targeted advertising.

How does FLoC work?

Well, one of the key features of third-party cookies is that they track individual website visitors. However, FLoC works a bit differently.

To start, FLoC currently works only on the Google Chrome browser. So, to activate FLoC, Google would send you a Chrome software update. The update will contain code that makes FLoC work. Once updated, your browser will be able to track your web activity.

Essentially, Chrome will track every site you visit and your browsing habits, e.g. how long you spend on a site, what you click on, and during what time you browse most frequently. This process is what the ‘L’ for ‘Learning’ in FLoC represents.

Chrome will store all your web activity data on your device. However, according to Google, the browser will anonymise your data then send it to Google via an encrypted communication channel to store it on their servers. The result is that the data on Google’s servers shouldn’t be able to identify you. The word ‘Federated’ that starts the term FLoC describes the model where your data is spread across your browser and Google’s servers.

Once your data reaches Google,  they’ll group you with other Chrome users based on your shared behaviours. This group is called a ‘Cohort’ – the ‘C’ is FLoC. Each cohort has a unique ID, e.g. R2D2, and will apparently consist of a minimum of 1000 people. Plus, one user can be part of more than one cohort.

Google will assign your cohort ID to your browser. And, your browser will present your ID to every website you visit to indicate that you’re part of a cohort with specific browsing behaviours. For example, say you’re part of cohort R2D2. And this cohort contains people who love CSI, hate mothers in law, and recently searched for ‘isolated places to take your wife’s mom on holiday’. The website you’re visiting will be able to see your web behaviours and push related targeted ads to you.

Does FLoC really protect my privacy?

The short answer is that FLoC, in its current state, doesn’t meet its promise of protecting your privacy.

The future of privacy

For context, there are two possible futures for your online privacy:

  1. You have control over your behavioural data and the power to decide whether to share it with a website; or
  2. Without your choice, your data – a behavioural label – reveals you to every site you visit.

FLoC trials

In our view, FLoC seems to fall into the second future. Why? Well, in March 2021, Google started trials of FLoC on Chrome users without warning or consent. However, conveniently, it’s limited the trials to the USA and other countries with flexible privacy laws. If FLoC were really privacy-conscious, why not test it in jurisdictions with robust privacy laws?

Notably, some commentators believe that Google expressly avoided the EU because it was worried that FLoC would go against the GDPR. This point probably means that FLoC will also not pass POPIA’s scrutiny because the laws are similar.

If you want to know whether Google is FLoCing you, please visit the site “Am I FLoCed?”.

Cross-context exposure of behavioural data

FLoC still enables cross-context exposure of your behavioural data. Say you visit a medical site to make a doctor’s appointment and the site sees your cohort ID. Unnecessarily, your cohort ID reveals that you’ve searched for Range Rovers, you’re a right-wing politics supporter, and you enjoy buying Jamie Oliver’s cookbooks. How is any of this behavioural data relevant to the site? Likewise, if you visit an online store to buy goods, the site shouldn’t need to know that you’ve recently read up on treatment for chronic anxiety.

From a data protection perspective, FLoC appears to go against the principle of data minimisation. This principle says that organisations should not collect or process data that is not essential for the specific business activity.

In addition to your cohort ID, you may have login details for the site, e.g. to make appointments. Currently, there’s nothing to stop the site from combining your behavioural data with your full name and email address to reveal your identity.

Misuse and abuse of personal data

Crucial to note, nothing prevents people from using FLoC to target, harm, exploit, and discriminate against groups of people. The Electronic Frontier Foundation correctly points out that “[t]he ability to target people based on ethnicity, religion, gender, age, or ability allows discriminatory ads for jobs, housing, and credit. Targeting based on credit history—or characteristics systematically associated with it— enables predatory ads for high-interest loans. Targeting based on demographics, location, and political affiliation helps purveyors of politically motivated disinformation and voter suppression. All kinds of behavioral targeting increase the risk of convincing scams”.

Next steps

  • Stay on top of the latest FLoC and cookie news by subscribing to our newsletter.
  • Get consent from website visitors through pop-ups by asking for our advice.
  • Comply with Cookie law by asking us to draft you an up-to-date cookie notice and policy.
  • Use software to manage your cookies by asking us to recommend a consent management platform to you.