patcg / ppa-api

Privacy-Preserving Attribution
https://patcg.github.io/ppa-api/
4 stars 3 forks source link

Delegation #32

Open benjaminsavage opened 1 month ago

benjaminsavage commented 1 month ago

There are millions of businesses who buy advertising. The vast majority of them will prefer to delegate ad measurement to another party. The work of collecting and storing encrypted histogram contributions, and subsequently passing them to the aggregation service will likely be too complex for all but the most sophisticated advertisers.

The spec does not (yet) address delegation.

We have discussed this at TPAC and here's a summary:

  1. Advertisers can delegate the ability to call measureConversion to iframes on their website.
  2. They can use a permission policy to grant access to call the API, and to specify how much of their privacy budget the script is allowed to spend.
  3. Different browsers will make different decisions about 3 numbers: the max number of delegations, the max privacy budget per delegation, the max combined privacy budget across all delegations.

Related issues: