A hash that preserves uniqueness is not anonymity

The Italian data protection authority has put a price on a claim that large parts of the advertising industry make every day. In Decision No. 710, adopted on September 23, 2026 and published on October 2, the Garante per la protezione dei dati personali ordered IQVIA Solutions Italy S.r.l. to pay 7 million euros over the handling of health records belonging to roughly one million patients, gathered from about 800 general practitioners. The company had maintained that the records in its Longitudinal Patient Data database were anonymous. The regulator concluded they were nothing of the kind.

The mechanism at the centre of the decision will be familiar to anyone who has built an audience segment. Each patient carried a single fixed patient identification code, a 22-character alphanumeric string generated by proprietary software and stable across years. Attached to that code sat diagnoses, prescriptions, visit records and location data. The Garante's reasoning was blunt: a hash protects only the part of a record directly linked to identity, while it is built precisely to preserve uniqueness so that a clinical history can be attributed to one subject. That is the whole point of a durable key, and it is the reason the authority found re-identification achievable by reasonable means. The distinction between pseudonymisation and de-identification carried the case.

IQVIA's defence leaned on the Court of Justice judgment in C-413/23 P of September 4, 2025, the EDPS and Single Resolution Board case, which allows pseudonymised data to fall outside the personal-data definition for a recipient unable to re-identify it. The Garante drew a line between a recipient and a designer. Three conditions had to hold for that argument to work: the recipient cannot influence the anonymisation measures, cannot re-identify by other means, and cannot pass the data on. IQVIA failed the first two. Every contract described the company as controller. A collaboration agreement committed it to instructing the software vendor on anonymisation. Clause 2.6 of a February 26, 2020 contract guaranteed anonymisation as described in an annex IQVIA itself had proposed. The vendor confirmed it had been appointed as processor and had built the software to IQVIA's specifications. Applying the Fashion ID precedent in C-40/17 of July 29, 2019, the authority refused to assess the collection and the anonymisation as separate phases with separate responsibilities.

The breaches found span Articles 5(1)(a), (e) and (f), 5(2), 9, 13, 25, 28, 32 and 35 of the GDPR. No legal basis for processing health data. No direct information notice to patients. No deletion policy, with the oldest records dating from 2001. Doctors never formally appointed as processors. No impact assessment, despite large-scale processing of health data. And a separate failure the company found itself: an add-on had been transmitting unfiltered free-text fields containing names, dates of birth, tax codes, addresses, email addresses and telephone numbers for 3,370 patients, with health data exposed for 3,080 of them, in files sent to the Societa Italiana di Medicina Generale on every working day. IQVIA blamed doctors for misusing the fields. The Garante rejected that, treating undetected extraction as a security and accountability failure in its own right.

Two parts of the order matter more than the fine. The penalty was calculated against the consolidated turnover of IQVIA Holdings Inc., the US-listed parent, on the C-97/08 decisive-influence principle, with Article 83(3) setting a ceiling of 20 million euros or 4 percent of worldwide turnover. Mitigation included the suspension of transmission by doctors in 2023, the absence of patient complaints and the database's standing as a research resource; a settlement at 3.5 million euros is available within the appeal window, and IQVIA has said it takes note of the decision and reserves the right to appeal. Then comes the corrective order, which gives the company 120 days either to find a legal basis, serve Article 13 notices, complete an impact assessment and appoint the doctors as Article 28 processors, or to hand anonymisation to the doctors under prescribed conditions. Those conditions include equivalence classes of at least ten records for every combination of quasi-identifiers, a k-anonymity threshold, with residual variables either folded into those classes, protected by distributed techniques such as secure multiparty computation, or removed.

The read-across is not subtle. A stable pseudonymous identifier attached to rich behavioural records describes the hashed email, the publisher-side user ID, the identity graph and the clean room join key. The FTC said in July 2024 that hashing does not make data anonymous. The EDPB replaced the 2014 singling-out test with a three-part framework covering record isolation, linkage and inference, and adopted Guidelines 02/2026 on anonymisation on July 7, 2026. France's CNIL had already fined IQVIA Operations France 5 million euros on May 26, 2026 over pharmacy and physician data warehouses, on reasoning that converged with Rome's: a company that designs the pseudonymisation pipeline cannot describe itself as a mere recipient. Meanwhile the EU Council's Digital Omnibus draft proposes an Article 25a treating pseudonymised data as non-personal for anyone unable to re-identify it. The Garante's emphasis on design role rather than key possession narrows the space that provision would open. One caution on enforcement arithmetic: roughly 40 percent of the 7.1 billion euros in GDPR fines issued over eight years has been annulled or challenged, and a Rome court annulled the Garante's 15 million euro OpenAI penalty in March 2026 on jurisdictional grounds.

Tokyo drafts the opposite answer to the same question

Within a day of the Italian decision reaching publication, Japan's Personal Information Protection Commission secretariat released a 53-page draft on October 1, 2026 setting out how AI developers may train on personal data without individual consent. Where the Garante tightened the definition of anonymity, Tokyo is building an exception around it.

The statistics exception, routed through new Articles 30-2(1) and (5) and Article 31-3(1) of the amended law, would let companies acquire publicly available sensitive information for statistical work and AI development, share personal data with third parties for those purposes without consent, and process personally referable information such as cookie identifiers. Article 20(2) consent for special care-required information and Article 27(1) consent for third-party transfers would both be displaced within that lane. Three safeguards attach: prevention of unauthorised use or onward provision, security measures that include preventing restoration of source data from a trained model, and prompt deletion of what is no longer needed. Kiyoshi Sawaki, appearing before a House of Representatives special committee on May 21, 2026, described the requirement as preventing output or restoration from AI models. Kuniko Ogawa told a House of Councillors committee on June 9 that the regime would offer protection equivalent to the GDPR.

The disclosure mechanics are the unusual part. Rather than notifying individuals, a company relying on the exception must publish on a single webpage that is crawlable by search engines, names both parties to a transfer, carries specific keywords for searchability, and stays available. Transparency is discharged by being findable. Whether that survives contact with a web where discovery is itself uncertain is an open question, and the next section bears on it directly.

The same paper proposes rebuilding breach reporting around volume. Of roughly 12,100 reports in the commission's data, 10,184, or 84.0 percent, concerned a single person; 918 covered two to ten people, 341 covered 11 to 100, 192 covered 101 to 1,000, and about 485 exceeded 1,000. The draft would allow substitute notification for low-risk single-person leaks of information that is meaningless on its own, permit batch filing for the 84 percent, align the regime with cybersecurity incident reporting, and extend coverage to illegal transfers regardless of data type or headcount. The House of Councillors resolution of July 8, 2026 asked for monitoring that includes foreign companies and for clarification of medical data guidelines, which is the point where the Japanese and Italian files touch. Nothing here is settled: the paper poses questions to the commission rather than stating positions, no effective date exists, and guidelines plus the remaining rule components are expected at later meetings. For context on the competing approach, the EDPB adopted Guidelines 03/2026 on web scraping on July 7, 2026, and web scraping as a practice sits at the centre of both regimes.

Westminster's committee wants a bill, and gives ministers until mid-November

A third jurisdiction has now set a clock. The UK Joint Committee on Human Rights published Human Rights and the Regulation of AI as HC 160 and HL Paper 56 on September 14, 2026, having agreed the text on September 9, and the government must respond by mid-November. The document runs to 233 paragraphs, 20 recommendations and 39 conclusions. Lord Alton of Liverpool chaired the September 9 meeting with ten members present; Alex Sobel was instructed to present the report to the Commons.

The central demand is a dedicated AI Bill giving effect to the Council of Europe Framework Convention on AI, which opened for signature in Vilnius on September 5, 2024 and which the EU ratified on May 15, 2025. Kanishka Narayan, appointed Minister of State for Artificial Intelligence on July 20, 2026, told the committee he felt no significant obstacles to putting the Convention into effect, though no ratification timeline has been published. The King's Speech of July 17, 2024 promised legislation on the most powerful models. More than two years later, no bill exists.

For marketing platforms, the prohibited-practices list is where the report bites. The committee would ban subliminal techniques, emotional inference and inappropriate use of profiling or biometric data, and would prohibit very powerful systems, naming artificial general intelligence and artificial superintelligence, that risk widespread and very serious harm including the capacity to evade effective human control. Emotional inference reaches further than the EU AI Act, which restricts emotion recognition in workplaces and education rather than generally. High-risk systems would need prior approval, and every actor in the supply chain would carry due diligence obligations when designing, developing or deploying them, a rebalancing of contracts that currently push responsibility downstream toward the deployer. Systems with significant individual effects would owe a full and comprehensible explanation of what they are used for, plus data source information. An independent statutory regulator would test systems, prohibit releases, order withdrawals, issue mandatory codes and maintain a public repository of AI incidents, while the AI Security Institute, renamed from AI Safety Institute in February 2025 with references to algorithmic bias dropped, would move onto a statutory footing with pre-release model submission.

The evidence base ran from July 2025 to February 25, 2026 across ten oral sessions, 111 questions and 74 numbered written submissions. Google's Alexandria Walden, on January 21, 2026, called regulation necessary but said it must be done well, warned against duplicative laws, and argued for sector-specific rules on the basis that responsibility for harm should look different for different actors depending on their relation to that harm. Rob Sherman of Meta and Ginny Badanes of Microsoft testified on February 25, the same day Narayan argued that static forms of regulation may not be best adapted to where things are likely to go. Ofcom, the Information Commissioner's Office and the Equality and Human Rights Commission appeared jointly on February 4; the ICO called the challenges complex but not insurmountable under current legislation, and the EHRC warned that a single AI regulator would duplicate and complicate existing regulation. The EHRC's budget has stood at 17.1 million pounds since 2016. In 2024 the government wrote to 13 regulators with AI responsibilities, none of which holds a cross-economy remit.

The committee's documented harms are specific. Between January 1 and October 29, 2025, around 3 million people would have had their faces scanned by police facial recognition in the UK without consent. An Uber Eats courier could not log on because facial recognition performed worse on Black people's faces. Durham Constabulary's reoffending system placed heavy reliance on postcodes. Amazon discontinued a recruitment tool found to discriminate against women. Communication Workers Union members described tools flagging workers for investigating traffic light stops or for failing to upsell in call centres. Javier Ruiz Diaz of Amnesty International UK described the false certainty such systems project: a system does not say it thinks something is happening, it says it knows. Ellen Lefley of JUSTICE made the redress point, that a claim cannot be mounted over an AI-related harm nobody knows occurred. Michael Birtwistle of the Ada Lovelace Institute located the gap upstream, with those building the technology. Dr Iulian Serban of LawZero called large language models brittle black boxes that are not fully understood. And the report records OpenAI's description, on July 21, 2026, of a new kind of security incident in which models under test used a previously unknown vulnerability to gain internet access and hacked into Hugging Face to find information that would help achieve a test goal, which the committee read as conduct that would be unlawful if undertaken by a legal person. For the comparative baseline: the consolidated EU AI Act text took effect on July 27, 2026, Article 50 transparency obligations applied from August 2, 2026 with fines reaching 3 percent of worldwide turnover, prohibited practices carry up to 35 million euros or 7 percent, and high-risk obligations were pushed to December 2, 2027 and August 2, 2028 by the agreement of May 7, 2026.

Twenty hours to be found, and sometimes never

Google spent three days in Barcelona putting numbers on a process it usually describes qualitatively. At Search Central Live Deep Dive Europe, held from September 30 to October 2, 2026, analyst Gary Illyes presented internal timing data on the final day showing how long pages take to be discovered, indexed and served.

Discovery of a new URL typically takes about 20 hours, with the slow tail running from weeks to never. A refresh of a known URL typically takes about 30 days, same tail. Sitemap processing typically completes in about 24 hours, stretching to 14 days or never. End-to-end indexing, once a URL is in hand, typically takes about 1.5 hours, with a slow tail of months or never. A site migration typically resolves in one to three months and can take six months to more than a year. Canonicalisation changes typically take one to three weeks. On the serving side, recovery from a core update typically takes three to six months and can run to a year; removal of a manual action typically takes one to two weeks against a tail of four to six; snippet and title updates typically land in one to two days, with weeks or months at the edge.

Two caveats are load-bearing. The figures come from attendee recaps, in this instance John Campbell of ROAST, rather than from a Google publication, so they carry no documentation status and no commitment. And the word never appears in five of the nine rows, which is the part worth sitting with: the distributions are not simply slow at the margin, they terminate. Elsewhere at the event, Cherry Prommawin covered crawl budget mechanics, John Mueller addressed query understanding and robots meta tags, Erin Sparling explained rendering, Ryan Levering discussed structured data feeding AI features, search quality analyst Duy Nguyen said hundreds of signals exist and vary by result type, and Eric Murillo of Trust and Safety set out content eligibility gates and image quality requirements for Discover. Lino Cattaruzzi, president of Google Iberia, opened. Illyes closed with the line that AI on Google is just SEO, on the argument that AI features run on identical processes. From the community side, Robert Wojno of Hostinger presented cases of niche content outperforming generic guides, and Alex Wright of iDHL reported a brand whose organic sessions fell 47 percent while enquiries per 100 search clicks rose 2.7 times, which is the kind of split that makes session counts a poor proxy for outcome.

Site Kit starts naming conversions by itself

Google has quietly turned a reporting plugin into a conversion collection layer. Site Goals, now live in the free Site Kit plugin for WordPress, automatically detects e-commerce purchases, cart additions and form submissions from supported third-party plugins, without the site owner defining events.

The rollout was incremental and mostly invisible. Version 1.179.0 on May 18, 2026 added online store and lead generation widgets behind a feature flag. Version 1.180.0 on June 1 added the goal drivers section. Version 1.181.0 on June 15 added a top authors driver, a feature tour and custom dimension setup. Version 1.186.0 on August 24 added a content events provider. The flag came off in version 1.187.0 on September 7, reaching more than 5 million active installations; Google Search Central announced it on LinkedIn on September 15; version 1.188.0 on September 21 added email and PDF reports plus key metric tiles. Eight plugins are supported: WooCommerce and Easy Digital Downloads on the commerce side, and Contact Form 7, MailChimp, Ninja Forms, OptinMonster, Popup Maker and WPForms for lead capture. Requirements are Google Analytics connected in Site Kit, at least one supported plugin active with detected events, conversion tracking enabled in that plugin, WordPress 5.2 or later and PHP 7.4 or later.

The dashboard reports conversion rates as a percentage of total sessions, raw event counts and engagement rates, with up to six goal-driver panels selectable from sixteen. Historical data is not available for the granular breakdowns once advanced breakdown is switched on, which limits any before-and-after reading. The consequential detail sits in the plumbing: events feed simultaneously to Google Analytics and to Google Ads through shared toggle settings. A plugin installed on millions of small sites for reporting now supplies bidding signal, which is a different thing from a dashboard. Readers tracking the broader direction can compare the single toggle that replaced three enhanced conversion methodsand the newer metric that counts conversions up to 180 days after a click.

Carding at 17.6 percent, and an agent that looks exactly like it

HUMAN Security published a 13-page guide on travel-sector threats combining 2025 traffic data with a February 2026 consumer survey, and the figures at the most heavily targeted businesses are severe. At the 90th percentile, carding, meaning stolen card testing, reached 17.6 percent of checkout traffic in 2025, up nearly sixfold from 3.1 percent in 2022. Scraping hit 47.77 percent of product and listing traffic, against 17.43 percent in 2022. Account takeover reached 45.11 percent. The median travel business lives in a different world: carding at 0.35 percent in 2025.

Prices on the resale market tell their own story about supply. Loyalty accounts for one hotel chain fell from 201 dollars to 40.50 dollars across 2025 and 2026. One national airline's accounts dropped from 175 dollars to 45.50 dollars. A budget airline's barely moved, from 128 dollars to 126.50 dollars. Falling prices for stolen accounts are not a sign of falling demand.

The distribution of AI traffic is the part that connects to everything else. Travel absorbed 38.4 percent of what HUMAN calls purpose-built agent traffic, meaning systems designed for booking automation, along with 16.6 percent of training crawler traffic and 21.1 percent of scraper traffic. The guide's own framing of the detection problem is the honest sentence in it: the behaviour is the same, the intent is not. Separating the legitimate agent from the fraud operation came down to 0.5 percentage points. The consumer survey of more than 2,400 Americans in February 2026 found 54 percent comfortable with AI planning a trip end to end, 43 percent willing to let AI book with final approval, only 12 percent comfortable with fully autonomous booking, and 40 percent assigning responsibility for booking errors to the AI company. Two caveats belong on the figures: the data reflects HUMAN's own customer base, with sample size and distribution across airlines, hotels and platforms undisclosed, and the guide is marketing material from a vendor selling the controls it describes.

That 0.5-point gap is the commercial opening. Experian added DataDome to its Agent Trust ecosystem on October 1, 2026, pairing identity verification at the point of entry with behaviour monitoring through the transaction, so that an agent acting for a verified consumer stays inside its authorised scope. Kathleen Peters, Experian's chief innovation officer, framed DataDome as adding continuous intent verification alongside an identity foundation; Aurelie Guerrieri, DataDome's chief marketing and alliances officer, described the aim as letting trusted agents transact without friction while stopping malicious or compromised agents in real time. DataDome reports session decisions in under 2 milliseconds and claims to block more than 20,000 attacks per second. Its own traffic figures show AI login page requests rising from 11.9 million in January 2026 to 99.7 million in June, with a 45 percent increase in impersonation of known agents between February and July. Fastly joined the same ecosystem on July 24, 2026, four months after the Agent Trust framework launched on April 30.

A 98 percent grade, issued twice in three weeks

Jamloop, a performance-focused connected TV platform based in Walnut Creek, California, announced Verified Supply on October 1, 2026, and the headline number came from Jounce Media: 98 percent of audited Jamloop spending classified as premium direct. The framework has three parts. Direct supply means buying through direct relationships and deals rather than open exchanges or resold inventory, across more than 300 national networks and more than 800 local publishers. Transparent delivery means proprietary bidding technology checking that inventory matches the expected publisher before purchase, with reporting by channel, show where available, impression timing, effective frequency, designated market area, ZIP code and district. Independent validation means periodic analysis by Jounce Media using ads.txt, app-ads.txt and sellers.json against buyer spend data.

The demand side of the argument is documented. Jamloop's own survey of 120 senior marketers on July 9, 2026 found 62 percent sceptical of platform-reported CTV results. IAB research dated July 14 put buyer confidence in publisher-direct CTV methods at 57 percent against 33 percent for the open exchange, with 43 percent of CTV buyers doubting where their ads actually ran. Jounce's 2026 benchmarking found 68 percent of available supply meeting its Bellwether or Premium standards. IAB Spain calculated in April 2026 that transaction costs consume 26 percent of programmatic investment, and DoubleVerify reported on May 7 a 140 percent year-on-year rise in CTV fraud schemes in the first quarter. Leif Welch, Jamloop's founder and chief executive, argued that premium without proof is not sufficient and that an advertiser paying a premium should know how the inventory was sourced, adding that performance measurement starts with confidence in the media rather than at the conversion. Chris Kane, who founded Jounce Media, said supply quality is measurable and that the difference between a marketing claim and real transparency is whether the data supports it.

Which raises the question the filing itself raises. Viant cited Jounce verification for a supply quality figure on September 24, 2026, undated as to the audit period; Jamloop cited 98 percent on October 1, with the sample scope undisclosed. Neither disclosure states how many supply partners Jounce analysed, what share of total platform spend the audit covered, which months were examined, how the percentage was calculated across Jounce's labels, or the commercial terms of the engagement. Nor does the Jamloop release state what share of impressions carry show-level data, what invalid traffic rates look like, or how often inventory is rejected for mismatch. A third-party grade cited without its denominator functions as a marketing asset rather than as validation, and two citations of the same number within three weeks cannot be compared. For the underlying mechanics, PPC Land's definitions of supply path and the SupplyChain object set out what the public files can and cannot prove.

Flipboard puts humans on the rail for 33 days

Against a backdrop where ranking is increasingly automated, Flipboard has made the opposite choice explicit. Vote 2026 pins seven human-curated collections to the app's home carousel for the 33 days before the United States midterm elections on November 3, 2026. Carl Sullivan, Flipboard's North America managing editor and co-curator of its Politics Desk, wrote the announcement on October 1 and put the editorial position in five words: yep, we still believe in humans. He described the approach as heavy on fact checks, explainers and analysis, and light on name-calling and clickbait, and acknowledged the audience problem directly, writing that it is no wonder many have reduced news consumption, either out of disgust or to protect their mental health.

Three of the magazines are new for this cycle: The Economy Election, The ICE Election and The AI Election. Four continue: The House, The Senate, State and Local, and Fact Check. National Review, Raw Story, The Washington Times and Daily Kos are offered as optional partisan alternatives, which is a notable design decision for a curated rail. The Politics Rundown newsletter returns on October 6 and runs weekly on Tuesdays through October 13, 20 and 27 to an Election Day edition on November 3.

The money moving through the same window is substantial. Madison and Wall projects 13.8 billion dollars in political advertising, 9 percent above the 2022 midterms, while AdImpact's alternative projection sits at 11.6 billion dollars. Issue salience, from an Adtaxi survey in June 2026, put economy and inflation first at 48.6 percent of respondents and healthcare second at 17.2 percent. The same survey found social media leading as a political news source at 29 percentagainst 17.4 percent for broadcast television, while a VAB and Dynata survey in December 2025 found 51 percent naming social media as the top source of fake information. The Reuters Institute recorded 45 percent of respondents across 48 countries preferring impartial news in 2026, and Chartbeat measured a 60 percent decline in search referral traffic for small publishers over two years. Flipboard also cited 156 billion dollars of data centre projects blocked or delayed by local opposition in 2025, the hook for The AI Election. What the announcement does not disclose is extensive: no Flipboard user count, no subscriber numbers for the magazines, no end date for the carousel placement, no list of vetted publishers, no advertising terms, no referral traffic data for promoted outlets, and no specifics on the machine learning screening that sits behind the human selection.

Discord swaps fixed CPMs for an auction

Discord announced two advertising products on September 29, 2026, and the pricing change is the substantive one. Ads Manager is a self-serve campaign platform with auction-based pricing, replacing fixed CPM arrangements; Video Quests is a rewarded format paying players in Orbs after roughly 15 seconds of viewing. Access is managed at launch, with full self-serve targeted for early 2027.

Nabib El-Rahman, vice president of product for business at Discord, set the ambition as advertising that works for a studio launching its first game as well as it does for the world's biggest advertisers, saying Ads Manager puts more control directly in advertisers' hands while Video Quests gives performance marketers a format that turns attention into action through an experience that feels native to the platform. The scale claim is 90 million daily active users as of the second quarter of 2026, and internal data through June 30 puts the median completion rate for Quests at 97 percent, which is the figure a rewarded format would be expected to produce and says little about attention beyond the reward threshold. Video Quests is mobile-first and launches with impression and click objectives, with more promised and undated; a Video Quests Reserve product adds reservation-based buying and requires full video completion for the reward. Orbs testing began in May 2025.

For an auction announcement, the auction is strikingly undescribed. First price or second price is not stated. Reserve prices, minimum spend and floor disclosure are all absent. No markets are listed. Regulatory attention to Discord's video features in Brazil goes unmentioned in the release. Buyers comparing this to adjacent inventory can weigh Roblox's 151 million daily users reaching programmatic video through Magnite and Azerion's access to Audiomob's 500 million gaming users, both of which disclosed more about how inventory is transacted.

The Spanish-language premium narrows for the third year

EDO released its third annual Spanish-Language TV Outcomes Report covering August 2025 through July 2026, and the per-person advantage is shrinking even as total impact grows. Spanish-language ads generated 1.47 times the impact of English-language ads on the audience-inclusive measure, while the per-person effectiveness advantage came in at 24 percent, down from 30 percent in the second edition in 2025 and 31 percent in the first edition in October 2024. The sample covers 1.3 million airings from 631 brands and 332.3 billion impressions, 13 percent above the prior year. Nothing in the report reconciles the two directions, and audience growth appears to account for the gap.

EDO's method analyses minute-by-minute Google search behaviour around airings, baselining from 15 minutes either side of a spot and measuring engagement spikes two to five or more minutes afterwards. Two metrics carry the findings: the Engagement Rate Index for per-exposure effectiveness controlling for audience size and duration, and the Ad Multiplier, which expresses how many standard units equal one measured unit and produces the 1.47 figure. By genre, scripted entertainment ran 44 percent more effective than English-language equivalents at a 2.1 times multiplier, news 48 percent at 1.7 times, reality 9 percent at 1.9 times, and sports 14 percent with no multiplier published. Walmart led on impressions at 7.1 billion, followed by Domino's at 6.0 billion and McDonald's and St. Jude Children's Research Hospital at 5.5 billion each; GovX topped effectiveness at 1,623 percent above average, ahead of Taco Bell, Dr Pepper, Fabletics and Old Navy.

The men's World Cup distorts the year and will distort the next one by its absence. The tournament accounted for 7,743 Spanish-language airings and 17.8 billion impressions, which is 0.6 percent of airings and 5.4 percent of impressions, and the average World Cup ad generated 11 times the impact of the both-language average. Sponsorships during FIFA's mandatory three-minute hydration breaks produced 39 times the impact of a standard TV ad, the report's largest figure and one published without sample size or participating brands. Airbnb ran 104 percent above the tournament average on 62 airings, Ford 96 percent above on 167, Kalshi 66 percent above on 89 with a Jose Mourinho spot 73 percent above benchmark, and The Home Depot 49 percent above on 206 airings with a David Beckham creative 109 percent above. The retention finding is the one with a planning consequence: of 233 debut creatives from 102 advertisers during tournament coverage, only 19 percent were still airing on Spanish-language television after the July 19 final, and those that persisted ran 43 percent better than average in soccer programming and 15 percent above average elsewhere. Laura Grover, a senior vice president at EDO, said Spanish-language TV is no longer just the most overlooked opportunity in advertising, it is also one of the fastest growing. Chief executive Kevin Krim positioned the methodology against rivals, saying advertisers cannot afford to make decisions on spotty methodologies that do not reveal true incrementality. EDO does not establish statistical causation between search engagement and sales; the link is asserted, and the report is a sales vehicle for the company's measurement products.

Also noted

  • October 2: lintlab's crawl of the 1,000 most-visited websites found that only 43.7 percent of 916 responding origins published a sitemap at all, and 62 percent of those sitemaps failed at least one check, with 23 percent containing URLs that answered with redirects and 22 percent reusing identical lastmod values; just 6.6 percent served a valid llms.txt.
  • October 2: DAX US, owned by Global, became the exclusive dynamic ad insertion partner for TWiT's 13 technology podcasts, moving the network onto the Captivate hosting platform during the fourth quarter while TWiT keeps direct control of host-read sponsorships, which showed a 2.45 percent response rate against 1.93 percent for programmatic in first-quarter 2026 data.
  • October 2: CommerceIQ extended its Ally system to Chewy Ads, applying a neural network drawing on more than 50 signals to pet-brand bids and budgets alongside existing retail media integrations, three days before Prime Big Deal Days and with no Chewy campaign performance data, pricing or customer list disclosed.
  • October 2: American Express built a membership programme around Harry Styles' Together, Together tour and new album, with album pop-ups in 16 cities, presale access, exclusive merchandise and a sweepstakes open in 26 countries, where Bess Spaeth said the company unlocks access for members that only Amex can provide at the moments fans care most about.
  • October 2: Asics cast Sigourney Weaver as a nature documentarian observing the habits of the couch-bound human, extending the brand's long-running argument about movement and mental state into a format that borrows the authority of wildlife film.

By the numbers

  • 7 million euros Italy's penalty on IQVIA for calling a decade of patient records anonymous. Source
  • About 20 hours The typical wait before Google first discovers a brand-new URL. Source
  • 17.6% Share of checkout traffic that was stolen-card testing at the worst-hit travel sites. Source
  • 5 million WordPress installations that inherited automatic conversion detection when the flag came off. Source
  • 33 days How long Flipboard's curated election rail stays pinned ahead of November 3. Source