MSME & Global Commerce · established evidence
The Data Economy: Surveillance as Media's New Business Model
Every dominant medium sells something to survive. The penny press sold circulation; broadcast television sold an aggregated demographic audience; the platforms that built the internet's advertising economy discovered a third, more valuable product: a prediction about one identified person, assembled from that person's own behavior. Google and Meta built their businesses on this insight so completely that advertising supplied 82 percent of Alphabet's revenue in 2021, financed by systems that infer habits, location, and intent rather than by anything the companies publish. That shift, from selling attention to selling prediction, concentrated ad-financed wealth in the platforms holding the most granular data, and it globalized a fight over who controls that data, because it crosses borders the platforms' American headquarters do not answer to on their own terms. When Ireland's regulator fined Meta a record 1.2 billion euros in 2023 for moving European users' data to the United States, the fine made a geopolitical point as much as a legal one: data has become a resource that sovereign governments now contest directly.
Selling attention, then selling prediction
Every advertising-financed medium has had to answer the same question: what, exactly, is being sold to the advertiser. The penny press of the 1830s sold circulation, a count of how many people held the paper in their hands. Broadcast television, a century later, sold audience share, an estimate of how many households a channel reached during a given hour, measured by ratings services and sold in aggregate blocks. Digital platforms started the same way. Early web advertising was priced by the impression, a single ad shown once to an anonymous visitor, an audience-count model translated onto a screen.
What the platforms found, through the 2000s and into the 2010s, was that this model radically undersold what they actually possessed. A search engine or a social network did not just know that a visitor existed; it could observe, page after page and click after click, what that specific person searched for, where they lived, what they bought, and what they had looked at the day before. An advertiser paying for that individual prediction, rather than a rough demographic slice, would pay more for it, because the prediction was more likely to convert into a sale. The product for sale changed, quietly, from a count of eyeballs to a forecast of one person's next decision.
The infrastructure built to sell that forecast is called real-time bidding. For most of the display advertising a person sees on the open web, a single webpage load triggers an auction that runs in the time it takes the page to render. A bid request goes out carrying a profile of the visitor: the device, the approximate location, and a set of behavioral signals drawn from that person's browsing history. Hundreds of advertising intermediaries can receive that same request for a single page view and bid against one another for the right to show an ad to that specific visitor. It is a market that transacts, many times a second, in individual predictions rather than aggregate audiences.
That auction, run at a scale of billions of impressions a day, is what turned personal behavioral data into the raw material of the media economy. The data broadcast in each bid request has itself become a subject of privacy complaints in Europe, precisely because the mechanism depends on distributing a profile of an identifiable person to a long chain of companies most of whom that person has never heard of. The commodity being traded is not the ad slot. It is the knowledge of who is looking at it.
The scale of the wager
The clearest evidence of how completely this model took over a company's economics is Alphabet, Google's parent. In 2021, advertising accounted for 82 percent of Alphabet's total revenue, a figure drawn from the company's own reporting. Search, Maps, Gmail, and YouTube are used by billions of people for free; the business that pays for all of it is the same behavioral-prediction engine described above, applied to a company whose products generate more individual signal than almost any other on the internet.
A ratio that high is not typical even for an advertising-supported company. It means a business built its entire economics around one activity: inferring what an identified person is likely to want next, and selling that inference. The company's public-facing products, the search bar, the map, the inbox, the video feed, function as the surface where that inference is collected, not as the source of the revenue that funds them.
Google did not hold that position alone. Together with Meta, the two companies controlled the largest concentration of ad-financed wealth in the history of media, and they held it specifically because their targeting data was the most granular available at scale. Industry estimates put their combined share of US digital advertising spending at 50.5 percent in 2022, easing to 48.7 percent in 2023 and 47.7 percent in 2024. The decline is real, and it marks the first sustained loss of ground the pairing had suffered since digital advertising became the dominant form of ad spending in the previous decade. It does not, on its own, mean the underlying model is fading. It means the model has new competitors.
A third power enters: retail data and a rival platform
Amazon is the clearest of the new competitors, and its advantage is a different kind of data from Google's or Meta's. Comparable estimates placed Amazon's share of US digital ad spending at roughly 12.9 percent against Meta's 19.5 percent, with the gap between the two projected to narrow to about 3.2 percentage points by 2025. Amazon is not selling a prediction assembled from browsing behavior; it is selling access to a record of what people have actually purchased, a resource Google and Meta do not hold at the same depth. TikTok, majority owned by the Chinese company ByteDance, has taken share on a third axis again, engagement data drawn from a recommendation feed rather than a search bar or a social graph. The duopoly, in other words, is not being replaced by an economy that trades less data. It is being joined by rivals who each hold a different slice of the same resource.
When the mechanism became visible: Cambridge Analytica
The public did not get a clear look at how the prediction engine worked until March 2018, when reporting revealed that Cambridge Analytica, a political consulting firm, had improperly obtained data from as many as 87 million Facebook users. The data had not been stolen in a conventional breach. It had been harvested starting in 2014 by a personality-quiz app built by the academic researcher Aleksandr Kogan, using access Facebook's developer platform granted at the time to any app a user installed.
The scale of the exposure came from a design choice in that platform, not from Kogan's app alone. A user who installed the quiz gave the app access to their own data. The app also reached data about that user's entire network of friends, most of whom had never heard of the app and had not consented to anything. A few hundred thousand installs turned into tens of millions of exposed profiles, because the platform's own architecture treated a friend's data as reachable through anyone in that friend's network.
The episode became famous for its political use, Cambridge Analytica had marketed itself as a firm that could build psychological profiles for campaign targeting, but its lasting significance for the media economy was narrower and plainer. It showed, in public and in detail, that the same behavioral-inference machinery built to sell an ad could be extracted wholesale and repurposed by a third party the platform never intended to supply.
The reckoning that followed was financial as much as reputational. The United States Federal Trade Commission fined Meta 5 billion dollars, at the time the largest privacy-related penalty the agency had ever imposed on any company. It was a domestic US response to a scandal that had, by its nature, touched users well outside American jurisdiction, since Facebook's audience and its data pipelines were never confined to one country.
Sovereignty over the second resource
The Cambridge Analytica fine was large, but it was also a single national regulator acting after the fact. European regulators took a different route, one aimed less at punishing a specific scandal and more at asserting standing control over a resource that was, by its nature, crossing their borders continuously. Under the General Data Protection Regulation, a European user's data can be moved outside the European Economic Area only under specific legal safeguards, and Meta's core business model, transferring EU user data to servers and systems in the United States for processing and ad targeting, put it in direct and repeated conflict with that requirement.
On 22 May 2023, Ireland's Data Protection Commission, the lead GDPR regulator for Meta because the company's European operations are headquartered in Dublin, fined the company 1.2 billion euros specifically for unlawfully transferring EU and EEA Facebook users' personal data to the United States. It was, and remains, the single largest fine ever issued under GDPR. The penalty targeted the transfer itself, not any one downstream use of the data, which is the clearest evidence that European regulators had come to see the data pipeline, not merely what was built on top of it, as the thing worth regulating.
That fine was not an isolated event. Meta and its affiliated entities accrued roughly 2.8 billion dollars in cumulative GDPR fines over the four years following the regulation's stricter enforcement phase, an order of magnitude beyond Google's own GDPR penalties, which escalated more gradually: 100 million euros in 2020, 150 million euros in 2021, and 325 million euros by 2025. Both companies were fined under the same law for the same underlying behavior, using European users' data at a scale and a specificity the regulation was written to constrain, but Meta's business model, more dependent on cross-platform behavioral tracking, drew the heavier and more repeated penalty.
The geopolitical logic underneath these fines is straightforward once stated plainly. The platforms that built the data economy are headquartered in the United States; the people whose behavior generates the data being sold live everywhere, including inside a European regulatory zone with its own law and its own enforcement apparatus. GDPR gave that zone a mechanism to reach into a foreign company's core business model and price the cost of moving a European resource across a border. It is the same contest that has recurred with every dominant medium: whoever sets the terms on which the medium's raw material moves, print runs, broadcast spectrum, or now, data, holds real power over the economy built on top of it.
A duopoly loosening its grip, not surrendering it
The erosion described above, from a combined 50.5 percent share to 47.7 percent over two years, is genuine competition, not collapse. Two readings of that fact sit uneasily next to each other, and both belong here. The data-advertising model has, in one sense, funded a great deal of content and commerce that would otherwise have needed a subscription or a storefront: it paid for nearly two decades of free search, free social platforms, and free video, and it let a small retailer or a local business reach a precisely defined customer at a price no comparable print or broadcast placement ever offered.
In another and equally true sense, the same model concentrated decision-making power in an unusually small number of companies. A newspaper's circulation was a public number anyone could check. The behavioral profile a platform builds on an individual user is proprietary, opaque to the person it describes, and the auction that trades it runs entirely inside infrastructure a handful of companies control. Amazon and TikTok entering that market did not decentralize the resource; they added two more large, similarly opaque holders of it. A market with two dominant buyers of behavioral prediction now has four, which is more competition, but it is not the same as an open one.
Both readings belong in the account of what happened. The data economy expanded who could afford to advertise and who could be reached precisely, while narrowing, to a handful of companies, who got to hold the data that made that precision possible. Neither fact cancels the other.
From ad auctions to answer engines
The mechanism described in this history, individual behavioral data traded to determine who sees what, was built for one purpose: deciding which ad a person sees. It is worth naming, carefully, where a version of that same underlying resource is heading next. Systems that answer a question directly, rather than returning a list of links, are trained and tuned on enormous stores of data about how people ask, search, and respond, some of it adjacent to the same behavioral signal that built the ad economy.
The businesses an AI system names in its answer are not chosen through the real-time bidding auction described above; that is a different mechanism, built for a different purpose, and collapsing the two would misstate history. What carries over is the pattern this account keeps repeating: control of the infrastructure that reads, ranks, and surfaces information shapes both who profits from it and which government gets to set its terms. The fight over data crossing the Atlantic inside an ad auction is an early instance of a question regulators are now asking again about the data feeding the systems that decide who gets named.
That question does not yet have a settled answer, and this account does not attempt to supply one. What the history of the data economy does establish is the pattern itself: every time a medium's dominant infrastructure became the place where the most valuable resource changed hands, control over that infrastructure, not the content riding on top of it, became the real site of economic and political contest. Advertising's shift from selling attention to selling prediction was one instance of that pattern. It will not be the last.
The evidence
Key findings, with their sources
-
Advertising accounted for 82 percent of Alphabet's (Google's) total revenue in 2021, illustrating how completely the company's economics depend on ad targeting built from user data rather than on any product it sells or content it produces.
established Wikipedia, "Big Tech" (2026).
-
Google and Meta's combined share of US digital advertising spending fell from 50.5 percent in 2022 to 48.7 percent in 2023 and 47.7 percent in 2024, as Amazon and TikTok captured a growing share, the first sustained erosion of the ad duopoly's dominance since digital advertising became the dominant ad medium.
established eMarketer, US digital advertising spending share estimates.
-
Amazon's share of US digital ad spending was estimated at roughly 12.9 percent against Meta's 19.5 percent, with the gap between the two projected to narrow to about 3.2 percentage points by 2025, evidence of a third major holder of behavioral and purchase data entering the market.
emerging eMarketer, US digital advertising spending share estimates.
-
Cambridge Analytica improperly obtained data from as many as 87 million Facebook users, harvested from 2014 onward by a personality-quiz app built by researcher Aleksandr Kogan that exploited Facebook's developer platform to pull data on users' entire friend networks, not just the people who installed the app.
established CNBC, "Facebook says the number of users affected by Cambridge Analytica data leak is 87 million" (2018).
-
The Cambridge Analytica scandal led the US Federal Trade Commission to fine Meta 5 billion dollars, at the time the largest privacy-related penalty the agency had ever imposed on a company.
established Huntress, "Cambridge Facebook Scandal Data Breach," threat-library summary.
-
On 22 May 2023, Ireland's Data Protection Commission fined Meta 1.2 billion euros for unlawfully transferring EU and EEA Facebook users' personal data to the United States, the single largest fine ever issued under GDPR.
established Business & Human Rights Resource Centre, "Meta is fined a record 1.2 billion euros for violating GDPR" (2023).
-
Meta and its affiliated entities accrued roughly 2.8 billion dollars in cumulative GDPR fines over the four years following the regulation's stricter enforcement phase, far exceeding Google's smaller but escalating penalties of 100 million euros in 2020, 150 million euros in 2021, and 325 million euros in 2025.
established TechInformed, "Meta accrues $2.8 billion in GDPR fines," and Improvado's GDPR fines analysis.
-
Real-time bidding auctions, which underpin most behavioral-targeted advertising, transmit an individual user's device, location, and behavioral data to potentially hundreds of ad-tech intermediaries for a single webpage impression, a mechanism that has itself become a subject of GDPR and ePrivacy complaints in Europe.
established Wikipedia, "Real-time bidding," cross-referenced with EU regulatory reporting.
Calibration
What is proven, what is promising, what is unproven
| Evidence tier | Tactics | What the evidence says |
|---|---|---|
| established | The scale of ad-financed dependence on behavioral data (Alphabet's 82 percent ad-revenue share), the mechanics of real-time bidding, the documented facts of the Cambridge Analytica breach, and the GDPR fines against Meta and Google. | Drawn from company-reported financials, US and Irish regulatory actions, and contemporaneous reporting; each figure is a matter of public record rather than an estimate. |
| emerging | The most recent ad-share figures, 2024's 47.7 percent combined share, Amazon's roughly 12.9 percent, and the projected narrowing to a 3.2 percentage-point gap with Meta by 2025. | These come from industry forecasting firms tracking a fast-moving market; the historical years are solid readings, the forward-looking 2025 figure is a projection, not yet a closed-book result. |
| contested | Whether GDPR fines, including the record 1.2 billion euro penalty against Meta, function as a genuine deterrent to cross-border data transfer or have instead been absorbed as a routine cost of doing business. | Meta continued the practice the fine addressed and has faced repeated, escalating GDPR penalties since; regulators and privacy researchers read that record differently, some as slow but real pressure, others as evidence the fines are priced in rather than prohibitive. |
Reference
Glossary
- Real-time bidding (RTB)
- An automated auction, run in the fraction of a second it takes a webpage to load, in which advertisers bid for the right to show an ad to one specific visitor based on that visitor's device, location, and behavioral data.
- Behavioral targeting
- Advertising aimed at an individual based on a profile inferred from that person's past clicks, searches, purchases, and browsing, rather than on the demographics of a broad audience group.
- GDPR (General Data Protection Regulation)
- The European Union's data protection law, in force since 2018, which restricts how personal data of EU residents can be collected, processed, and moved outside the European Economic Area.
- Data sovereignty
- The principle that data generated by a jurisdiction's residents remains subject to that jurisdiction's law, regardless of where the company processing it is headquartered or where its servers sit.
- Ad-tech duopoly
- The informal term for Google and Meta's historically dominant, combined share of digital advertising spending, built on the two companies' unmatched depth of individual behavioral data.
- Retail media
- Advertising sold directly by an e-commerce or retail platform, such as Amazon, using first-party purchase data rather than the browsing-based behavioral data that built the earlier ad-tech duopoly.
Straight answers
Frequently asked questions
What actually changed about how digital platforms make money?
Early web advertising was priced roughly like broadcast advertising, by an anonymous audience count. Platforms discovered that an advertiser would pay far more for a prediction about one identified person's next decision, assembled from that person's own behavior, than for a rough demographic estimate. That shift, from selling attention to selling prediction, is what this account calls the data economy.
Why did Ireland fine Meta 1.2 billion euros?
Ireland's Data Protection Commission, Meta's lead GDPR regulator, found that the company had unlawfully transferred European users' personal data to the United States for processing, a violation of GDPR's rules on data leaving the European Economic Area. The fine, issued on 22 May 2023, targeted the data transfer itself and remains the largest penalty ever issued under GDPR.
What was the Cambridge Analytica scandal, briefly?
A personality-quiz app built in 2014 by researcher Aleksandr Kogan used Facebook's developer platform to collect data on the people who installed it and on their entire friend networks, ultimately exposing data from as many as 87 million users to the political consulting firm Cambridge Analytica. The US Federal Trade Commission later fined Meta 5 billion dollars over the episode.
Is the Google-Meta ad duopoly breaking up?
It is eroding, not breaking up. Their combined share of US digital ad spending fell from an estimated 50.5 percent in 2022 to 47.7 percent in 2024, mainly to Amazon, which sells advertising built on purchase data, and TikTok, which sells advertising built on engagement data. Both companies remain the two largest single holders of ad-financed wealth in media history.
Did GDPR actually stop platforms from moving data across borders?
Not entirely, and this is a genuinely contested point. Meta paid the record fine and has continued to face additional GDPR penalties since, which some regulators and researchers read as evidence the fines have become a cost of doing business rather than a deterrent. Others point to the scale and repetition of the enforcement as real, if slow, pressure on the practice.
Provenance
Sources
- Wikipedia, "Big Tech" (2026).en.wikipedia.org
- eMarketer, US digital advertising spending share estimates, 2022 to 2025.
- CNBC, "Facebook says the number of users affected by Cambridge Analytica data leak is 87 million" (2018).cnbc.com
- Huntress, "Cambridge Facebook Scandal Data Breach," threat-library summary.huntress.com
- Business & Human Rights Resource Centre, "Meta is fined a record 1.2 billion euros for violating GDPR" (2023).business-humanrights.org
- TechInformed, "Meta accrues $2.8 billion in GDPR fines."techinformed.com
- Improvado, GDPR fines analysis (Google penalty history).
- Wikipedia, "Real-time bidding."en.wikipedia.org
Every figure above is attributed to a real, dated source and tagged with its evidence tier. Where a claim could not be verified to a primary source, it is not stated as fact.