Brave Privacy and GDPR Purpose Limitation in Practice

Brave Privacy and GDPR: Purpose Limitation in Practice

Brave browser has spent years pushing GDPR enforcement forward: filing a formal complaint against Google’s ad business, and separately accusing 27 EU member states of under-resourcing their own data protection regulators. 

That advocacy record, combined with how Brave built its own ad model, makes it a useful case study for any business trying to understand what purpose limitation and data minimisation actually look like in practice.

Key Takeaways

Brave filed a formal GDPR complaint against Google in 2020 alleging a breach of Article 5(1)(b)’s purpose limitation principle, which led Ireland’s Data Protection Commission to open a statutory inquiry into Google’s ad exchange business.

Brave separately complained to the European Commission that 27 EU member states under-resource their national data protection authorities, arguing that weak enforcement capacity undermines GDPR regardless of how the law reads on paper.

Brave’s own advertising model, Brave Rewards, matches ads to users entirely on-device, so the browsing signals used for targeting never reach Brave’s servers, a working example of data minimisation applied to advertising specifically.

Brave still appoints its own Article 27 representative for EU data subjects, showing that privacy advocacy doesn’t remove the same statutory obligations that apply to any other non-EU controller.

What Is Brave’s GDPR Complaint Against Google About?

In 2019, Brave’s then Chief Policy Officer Dr Johnny Ryan filed a complaint with Ireland’s Data Protection Commission targeting Google’s DoubleClick/Authorized Buyers advertising exchange. The complaint alleged that Google’s real-time bidding process broadcasts sensitive personal data, drawn from what a person is browsing, to potentially thousands of companies during a bid request, without a specified, documented purpose behind that broadcast. Article 5(1)(b) GDPR requires personal data to be collected for specified, explicit, and legitimate purposes, and not processed further in a way that’s incompatible with those purposes.

The complaint led Ireland’s DPC to open a statutory inquiry into Google’s ad exchange business. Brave went further in a follow-up complaint, arguing Google also breaches purpose limitation internally by reusing personal data collected in one part of its business, such as Gmail or YouTube, across other Google products and ad services without a clear, separate legal basis for each new purpose.

Why Did Brave Complain About EU Member States’ Enforcement of GDPR?

In April 2020, Brave took a different kind of complaint to the European Commission, this time targeting 27 EU member state governments rather than a single company. Brave’s research found that many national data protection authorities lacked the technical staff and budget to investigate large-scale adtech complaints at the pace GDPR’s enforcement mechanism assumes. Brave asked the Commission to open an infringement procedure against the governments responsible for funding those regulators.

For businesses, enforcement capacity varies significantly by country. Under GDPR’s one-stop-shop mechanism, the lead supervisory authority for a cross-border case is usually determined by where an organisation’s main EU establishment sits, regardless of where a complaint originates. A business shouldn’t assume that operating through a lightly resourced regulator lowers its actual compliance risk, since a well-resourced authority elsewhere in the EU can still act on a complaint that touches its residents.

How Does Brave’s Own Ad Model Apply Data Minimisation?

Brave built its own advertising system, Brave Rewards, around a structural constraint that its complaint against Google argues the adtech industry lacks: the browsing signals used to match an ad happen entirely on the device, and never reach Brave’s servers as raw data. Ads are matched locally using on-device signals, and Brave states it doesn’t build individual behavioural profiles from that matching process. Ad confirmations and payouts in BAT, the Basic Attention Token, are verified through an anonymous protocol and reported back only in aggregate.

This is data minimisation applied to a specific, hard problem: advertising normally depends on knowing enough about a person to target them, and Brave’s approach tries to keep that targeting local rather than centralising the underlying data at all. It’s also a direct contrast with the real-time bidding model Brave’s own Google complaint criticises, where browsing signals travel to a central exchange and are broadcast to a wide pool of bidders.

Does Brave Still Need to Appoint a GDPR Representative?

Yes. Like any organisation processing EU residents’ personal data from outside the EU’s structure of establishments, Brave has appointed an EU-nominated representative to handle GDPR-related enquiries and data subject rights requests on its behalf, with certain Brave properties using a separate representative for this purpose. Article 27 GDPR doesn’t carve out an exception for organisations whose business model happens to be privacy advocacy.

That consistency matters as a signal to other businesses: the Article 27 requirement is triggered by whether you offer goods or services to, or monitor, people in the EU or UK, independent of your product’s actual data-handling quality. Our guide to EU and UK representative requirements covers how the appointment works.

What Can Businesses Learn From Brave’s GDPR Activity?

Document a specified, legitimate purpose for every distinct use of personal data your organisation makes, including internal reuse across different products or teams. Purpose limitation applies just as much inside an organisation as it does to external sharing.

Review adtech vendors and ad exchanges in your supply chain specifically for real-time bidding practices. Brave’s complaint targets a mechanism used across much of the programmatic advertising industry, so the same bid-request data flows likely exist in your own vendor stack too.

Don’t assume a lightly resourced national regulator lowers your actual enforcement risk. The one-stop-shop mechanism means a well-resourced authority elsewhere in the EU can still take up a case that touches its residents.

Where possible, look at whether matching or personalisation logic can run locally rather than centralising the raw signal. Brave’s on-device model shows this is achievable for at least one hard use case, advertising, without abandoning monetisation entirely.

Conclusion

Brave’s GDPR activity runs in both directions: it has pushed regulators to act against adtech practices it argues breach purpose limitation, and it has built its own ad model around keeping targeting data on-device rather than centralised. Its own Article 27 representative appointment is a reminder that statutory obligations apply regardless of a company’s privacy positioning. For businesses reviewing their own compliance, the practical takeaway is to document purpose limitation internally as rigorously as any external promise, and to look hard at what your adtech vendors actually do with bid-request data.

Frequently Asked Questions

What did Brave accuse Google of under GDPR?

Brave’s complaint alleges Google breaches the purpose limitation principle in Article 5(1)(b) GDPR, both through its real-time bidding ad exchange broadcasting personal data to many companies without a specified purpose, and by reusing personal data across its own products and ad services without a clear, separate legal basis for each new use.

Did Brave’s complaint against Google lead to any regulatory action?

Ireland’s Data Protection Commission opened a statutory inquiry into Google’s DoubleClick/Authorized Buyers ad exchange business following Brave’s complaint. Regulatory inquiries of this scale typically take years to resolve.

How does Brave make money without collecting user browsing data?

Brave’s opt-in Brave Rewards programme matches ads to users through on-device processing, so the browsing signals used for targeting aren’t sent to Brave’s servers as raw data. Users who opt in earn Basic Attention Token for viewing privacy-preserving ads, verified through an anonymous confirmation protocol.

Does Brave have to comply with GDPR itself?

Yes. Brave appoints its own EU representative under Article 27 GDPR and states it doesn’t track cookies by default in its browser. Building a privacy-focused product doesn’t remove the same statutory obligations that apply to any other organisation processing EU residents’ personal data.

Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.

Zlatko Delev

About the Author

Zlatko Delev

Country Manager & Head of Commercial — GDPRLocal

Zlatko specialises in data protection compliance, ISMS strategy, and AI law. With a legal background and hands-on experience supporting organisations globally, he helps businesses navigate GDPR, the EU AI Act, and international privacy frameworks.