EU Advertising Obligations Affecting an APAC Advertiser: An Operational Guide (Not Legal Advice)
An APAC company — from Hong Kong, Singapore, mainland China, Taiwan, Japan, Korea or any other market — that decides to run advertising campaigns on Meta, Google, TikTok or LinkedIn targeting European audiences faces a denser regulatory ecosystem than the Asian or American one. GDPR, DSA, DMA, ePrivacy, sector obligations (fintech, health, alcohol, gambling, pharma, infant food), advertiser identification in political advertising and now also in commercial advertising on VLOP (Very Large Online Platforms). This article is an operational guide on which obligations affect the day-to-day advertising work — how a campaign is configured, what can be said in a creative, what must be visible in the ad copy, which tracking is allowed and under what conditions. It is not legal advice. For the DPO, privacy policy, formal DSA registration, Art. 27 GDPR EU representative appointment or DSA Art. 34 risk assessment, the APAC client needs a specialized European legal firm — with which we coordinate but which we do not replace.
The APAC advertiser in Europe faces: (1) Consent Mode v2 mandatory in Meta and Google since March 2024 for EU traffic; (2) DSA Transparency Rules — payer identification, creative retention and data in a public database; (3) sector restrictions for fintech (MiCA, DORA), health (EMA), alcohol and gambling (varying by country); (4) obligation to identify the ultimate advertiser in political ads and increasingly in commercial ads. Our operational role: configure campaigns and tracking respecting these obligations. Our NON-operational role: DPO, formal DSA registration, Art. 27 representative, algorithmic risk assessment — that is European legal firm territory.
Which "advertising obligations" this article covers (and which it does not)
We cover obligations that affect the operational configuration of digital advertising campaigns on Meta, Google Ads, TikTok Ads and LinkedIn Ads targeting EU audiences from an APAC advertiser. Specifically:
1. Consent Mode v2 and its impact on tracking (Meta CAPI, GA4, offline conversions); 2. DSA Transparency (payer identification, public ad repository, creative retention); 3. Sector restrictions per product or service advertised (fintech, health, alcohol, gambling, pharma, infant food, tobacco, crypto); 4. Ultimate advertiser identification in ad copy and campaign data; 5. Names, prices and claims allowed in creatives (Unfair Commercial Practices Directive, "original" prices and discounts, comparatives); 6. Retention and accessibility of creatives for regulatory review.
Explicitly out of this article: DPA implementation with providers, DPO selection and appointment, privacy policy, cookie policy (banner), Art. 27 GDPR representative designation, formal registration with data protection authorities, breach notification, DPIA (Data Protection Impact Assessment), DSA Art. 34 compliance (systemic risk assessment for VLOPs), AI Act compliance for AI use in creatives or targeting, litigation on advertising practices. All of that is European legal firm territory, not eXprimeNet.
Operational framework · How we configure an APAC→EU campaign complying with advertising obligations
The operational configuration is structured in four layers — the same structure of the APAC Advertising Bridge Framework applied to advertising compliance. On each layer we identify what we do and what stays with the client legal advisor.
- Layer 1 · Account setup and advertiser identificationIn Meta and Google we configure the advertiser identity correctly: the ad account lives in our BM/MCC but the "advertiser" declared in the ad copy and in the billing information available to the user (via "About this ad" in Meta and "Why this ad" in Google) is the client APAC company — not the agency. This is an operational DSA Transparency requirement (Art. 39 DSA: identification of the "natural or legal person on whose behalf the advertisement is presented"). We coordinate with the client to obtain correct legal name, address, VAT/Business Number. Out of scope: formal Art. 27 GDPR EU representative appointment — required for processors outside the EU that process EU residents data — that is legal firm territory.
- Layer 2 · Consent Mode v2 and tracking architectureConsent Mode v2 is mandatory since March 2024 for EU traffic in Meta and Google. Our operational work: (a) verify that the CMP (Consent Management Platform — Cookiebot, OneTrust, Didomi, Iubenda) installed on the client site sends the correct signals (ad_storage, ad_user_data, ad_personalization, analytics_storage) to GTM/GA4/Meta Pixel; (b) configure Meta Pixel + CAPI to respect the consent signal (conversion modeling if consent denied); (c) configure GA4 for conversion modeling; (d) if applicable, configure Consent Mode on TikTok Pixel and LinkedIn Insight Tag. Out of scope: (1) initial CMP selection and configuration (usually the client already has one, or we recommend and contract separately); (2) cookie policy as legal text — your legal advisor; (3) country-specific ePrivacy Directive compliance (some member states require additional configurations) — your advisor.
- Layer 3 · Sector restrictions per advertised productEach vertical has specific EU restrictions. Fintech and crypto: MiCA applicable from December 2024, some jurisdictions (Spain CNMV, France AMF) require prior advertiser registration and specific disclaimers ("crypto-asset investments are unregulated, may not be suitable..."). Health and medical devices: EMA rules for OTC, prohibition of direct-to-consumer advertising for prescription drugs. Alcohol: varies by country (total ban in France with exceptions — loi Évin), audience restrictions (targeting <18 prohibited). Gambling: local license required per destination country. Infant food: WHO Code + EU regulation. Tobacco: total ban. Our operational role: apply minimum age targeting, apply geographic exclusions when client license does not cover a market, include disclaimers in creatives per product category, activate age gate on landing if applicable. Out of scope: obtaining sector licenses (CNMV, AMF, BaFin, Ofcom, sector regulatory authority), legal validation of advertising claims (that the product can actually claim what the creative says), regulatory approval of the campaign by sector authority when applicable.
- Layer 4 · DSA Ad Repository and creative retentionDSA (Digital Services Act) since February 2024 requires VLOPs (Meta, Google, TikTok, LinkedIn, X, Amazon) to maintain a public database of creatives served for 12 months after campaign end, with: (a) ad content; (b) payer and beneficiary identity; (c) service period; (d) main targeting parameters (no personal data) — what age range, aggregated location, targeting criteria; (e) total number of EU recipients per country. Our operational role: ensure campaign metadata is correct so the platform DSA Ad Repository reflects the correct APAC client as payer and beneficiary; document internally each creative served with timestamp, target and variations; retain creative assets for 18 months after campaign in case the client needs audit. Out of scope: DSA designation on the client side if they operate their own platform (marketplace, internal social network) — that is their legal firm; representation before DSA authorities (Digital Services Coordinator in each member state, and European Commission for VLOPs).
What Consent Mode v2 is and what changes for the APAC advertiser
Consent Mode v2 (unlike v1) requires that consent signals transmitted by the CMP include two additional parameters over v1: ad_user_data (user grants consent to processing of their data for advertising) and ad_personalization (user grants consent to use their data for ad personalization). Without these signals being correctly sent from the CMP to Meta Pixel + CAPI and to Google Ads, platforms begin to limit features: Meta Advantage+ Shopping stops being available without CAPI + consent, Google Enhanced Conversions requires ad_user_data granted. In March 2024 Google marked Consent Mode v2 as a requirement for eligibility on advanced algorithmic features.
For the APAC advertiser this means that if the site has EU traffic, the CMP must be correctly configured regardless of whether the client is domiciled in Hong Kong, Singapore or Taiwan. The geography of the company does not reduce the obligation — the obligation is triggered by the audience (EU traffic / EU residents). Our operational work: audit the client existing CMP, verify correct signaling, adjust GTM tags if needed, activate Advanced Consent Mode (conversion modeling when consent is denied) so we do not lose full conversion signal.
What we do NOT do: recommend specific consent banner texts (that can be considered legal advice in several EU jurisdictions); implement the CMP initially (sub-contractable, or the client has one); sign the DPA with the CMP provider (that is the client).
DSA Transparency: What it means in practice for your Meta or Google campaign
DSA Article 39 requires VLOPs (platforms with >45 million monthly EU users, which includes Meta, Google, TikTok, LinkedIn) to maintain a public ad repository. In Meta you find it at the Meta Ad Library (facebook.com/ads/library) — existing since 2018 but expanded post-DSA. In Google, at the Google Ads Transparency Center (adstransparency.google.com), launched in 2023. In TikTok at the Commercial Content Library. All accessible publicly, no login.
What gets published: (a) the ad creative; (b) advertiser and payer name; (c) service dates; (d) non-personal targeting parameters (age range, country, generic interests); (e) aggregate impressions.
For the APAC advertiser this means two practical things: (1) the correct client company name (not the agency) must appear as advertiser — it is our operational obligation to ensure ad account configuration respects this; (2) served creatives are public and auditable by competitors, press, NGOs, regulators — every ad must be treated as a public document. Many APAC clients are not used to this level of advertising transparency (mainland China has no equivalent, Hong Kong / Singapore only partially). We flag this during discovery so there is no surprise.
Retention: creatives public for 12 months after service end. Our internal copies of the original asset, 18 months. If the client needs internal audit or defense before an advertising practices complaint in an EU country, we have the assets.
Advertising restrictions per vertical: What we do handle and what stays out of scope
Fintech, investment and crypto: MiCA (Markets in Crypto-Assets Regulation) applicable from 30 December 2024 for crypto in EU. Member States can require prior advertiser registration (Spain CNMV via Circular 1/2022 and updates, France AMF via PSAN registration, Italy OAM). Before launching a campaign, we verify the APAC client has the required registration for the destination country if applicable. If the client does not have it, we do not launch in that country — pause until registration is obtained (managed by their legal firm, not us). Mandatory country-specific disclaimers on creative: we apply per country.
Health and OTC: we apply age gate if product is sensitive, include disclaimers, avoid non-validated medical claims. Prescription drugs: total ban on direct-to-consumer advertising in EU — we do not manage this type of campaign to EU.
Alcohol: we comply with minimum 18 targeting (25 in some jurisdictions like Sweden). In France (loi Évin) there are strong format and content restrictions on the creative — if the client sells alcohol to France, their French legal firm validates every creative before service.
Gambling: we only launch a campaign in countries where the client operator has a valid license. License verification is client responsibility but we request it in writing before configuring the campaign.
Infant food (infant formula, follow-on): WHO Code prohibits 0-6 months formula advertising. EU Regulation 2016/127 applies. We do not serve initial formula advertising. Follow-on and infant snacks with restrictions — we validate with the client on specific restrictions.
Tobacco (includes vaping in many EU jurisdictions): total ban in most EU countries. We do not manage campaigns in this vertical to EU.
OTC pharma: we apply EMA restrictions. Prescription: no.
What we do NOT do in any vertical: legal validation of the specific claim (that the product can affirm X property, X efficacy, X discount percentage) — that is your sector advisor. Obtaining licenses, permits or regulatory registrations — your legal firm.
FAQ · APAC → EU advertising obligations
Do I need to appoint an Art. 27 GDPR representative if my company is in Hong Kong or Singapore?
Yes, if you process EU resident personal data. Art. 27 GDPR requires controllers and processors established outside the EU to designate an EU representative when processing EU resident data by offering goods/services or monitoring behavior. This is a legal firm topic — not eXprimeNet. We recommend resolving it before or during the first 30 days of campaign. We can recommend specialized firms.
Does Consent Mode v2 also apply if I only do retargeting to my existing list?
Yes. The obligation is triggered by processing EU resident personal data, not by campaign type. Existing customer list uploaded to Meta Custom Audience: valid consent (clear opt-in for advertising use) required at the moment the data was captured. If you do not have it, you cannot upload the list. Here you can have a real problem — solve it with your DPO / legal firm before launching retargeting.
Can you sign the DPA (Data Processing Agreement) with us?
Yes, we sign a DPA as data processor when the project requires it. In advertising operations our EU resident personal data processing is limited (campaign aggregates, no individual PII), but we sign the DPA by default to have a clear legal frame. The standard DPA is a European template — if your legal firm requires specific clauses, we review them. Signing the DPA with Meta, Google, TikTok or the CMP provider is your direct responsibility with each provider — we do not do it for you.
Can you run crypto advertising in the EU under MiCA?
We can technically operate the campaign. We do NOT validate that the client is correctly registered before CNMV (Spain), AMF (France), BaFin (Germany) or OAM (Italy). Before launching, we require written evidence that the registration is active in the destination country. If the client does not have it, we pause until they obtain it — their legal firm. Country-specific disclaimers are applied on creative and landing under legal indication from the client.
And political advertising?
We do not operate it. It is out of scope. Specific regulation (EU Regulation 2024/900 on political advertising transparency) has dedicated compliance requirements that need legal and operational specialization we do not offer. Applies also to communication on political issues, referendums, elections. If your product or vertical touches this (organizations, think tanks, party-affiliated media), we are not the right agency.
What happens if one of our ads is reported under DSA?
DSA allows any user to report advertising content they consider illegal or abusive. The platform (Meta, Google, TikTok, LinkedIn) reviews and can remove the ad if it concludes there is a policy or regulatory violation. Our process: immediate notification to the client, complaint analysis, re-launch with adjustments if applicable, or pause if prudent until clarification. If the complaint escalates to regulatory authority (Digital Services Coordinator of the member state), it is your legal firm territory — we provide the operational documentation (creative, targeting, reach).
Does my APAC company campaign data stay on EU servers?
Depends on platform. Meta, Google, TikTok and LinkedIn have global infrastructure. GDPR allows international personal data transfer under SCC (Standard Contractual Clauses) or adequacy decisions. Transfer from EU to Hong Kong, Singapore, Taiwan, China is a compliance topic for your DPO — we as agency intermediate but are not the controller. The GTM server (if we use it) we configure in EU region to minimize transfers — our operational default unless the client indicates otherwise for specific reasons.
What do you recommend to an APAC client starting EU campaigns for the first time?
Before the first campaign, verify 4 things with your European legal firm: (1) Art. 27 GDPR representative designated; (2) CMP installed on the site with Consent Mode v2 signaling correctly; (3) privacy policy and cookie policy updated and accessible; (4) if the vertical requires it, sector registration (CNMV, AMF, BaFin, etc.) obtained for the destination country. Our discovery includes a checklist of these 4 points — if any is missing, we delay launch. We do not launch an EU campaign knowing there is operational non-compliance that can result in ad account closure or fine to the client.
Can you recommend European legal firms?
Yes, we have contacts of Spanish and European firms that work with APAC clients and understand the interaction between GDPR / DSA / MiCA / sector regulation and digital advertising. We recommend 2-3 options with no exclusivity and no referral commission — the choice is the client.
Does the AI Act apply to AI-generated creatives you use?
The AI Act (EU Regulation 2024/1689) has specific obligations for "AI-generated content" including advertising. From August 2026 the obligation to label deepfakes and synthetic content in advertising applies. Our policy: if we generate a creative with generative AI tools (image, video), we document it internally and apply labeling if the platform requires it. We are still monitoring implementation per country and awaiting detailed EDPB / Commission guidelines. We coordinate with your legal firm on the evolution.
Operational reference · Configuring EU campaigns from APAC advertisers respecting advertising obligations
Our operational role covers account configuration with correct APAC advertiser identification, Consent Mode v2, application of sector restrictions on targeting and creative, and tracking architecture respectful of GDPR + DSA. Out of scope: Art. 27 representative appointment, privacy policy, sector registration, advertising litigation, DSA Art. 34 risk assessment, detailed AI Act compliance. We coordinate with your European legal firm but we do not replace it.