Anti Malvertising Policy
Digital East GmbH, Axel-Springer-Platz 3, 20355 Hamburg, Germany
Version: v2609 | Effective: 1 September 2026 | Replaces: all previous versions
1. Our position
Digital East keeps malvertising out of its platform and out of its partners’ ad properties. Malvertising is a threat to users, to the publishers and supply partners whose inventory carries it, and to our business. We scan for it, we block it, we trace it to the party that introduced it, and we recover what it costs us.
This policy forms part of the Master Services Agreement between you and Digital East GmbH. It applies to every advertiser, agency and buyer using the Digital East demand-side platform, marketed as DESSY. It applies to all of them equally, and we make no exceptions for size or spend.
2. What malvertising is
Malvertising is the use of display advertising or ad landing pages to distribute malware. Common vectors include malicious code hidden inside a creative, auto-redirecting ads that lead to phishing or exploit pages, and click-bait that sends users to social engineering content.
Malware is software designed to harm a device or a network, or to take information from it — card numbers, passwords, account access. It can be installed with or without the user’s knowledge, typically through a compromised site, a seemingly harmless download, or a silent browser extension. For the purposes of this policy, malware also covers phishing and social engineering: a fraudulent entity presenting itself as a trustworthy one in order to obtain sensitive information.
3. How we protect the platform
- Internal review. Uploaded display, video and audio creatives are reviewed within 3 hours as a standard; tag-based creatives may take up to 24 hours.
- Pre-launch scanning. Every tag and creative is then scanned and verified by third-party scanning providers for up to 48 hours before it goes live. Verification covers the targeting parameters the campaign will run against, including geography and device medium.
- Continuous scanning. Once live, tags are scanned every hour for as long as they remain active in the system.
- Real-time blocking. When something is detected, the first step is to block it. Analysis follows.
- Full-path analysis. We analyse the complete delivery path, pre-click and post-click, together with the history of the tag.
- Incident report. We share the incident report and the supporting detail with the advertiser and require an explanation.
These are standard timings rather than guarantees. We may clear a creative sooner, and we take longer where something needs investigating. A creative that is rejected and resubmitted starts the sequence again.
4. What we record, and on what basis
For each incident we record:
- the exact time of the incident;
- the country of the affected user, derived from geolocation;
- the browser and user agent;
- a description of the attack and the delivery path.
This is processing for security, fraud prevention and debugging. We rely on our legitimate interests under Art. 6(1)(f) GDPR, corresponding to Special Purpose 1 of the IAB Europe Transparency and Consent Framework, under which Digital East is registered as Global Vendor ID 665. Incident and monitoring records containing personal data are kept for 90 days and are then deleted. Our Privacy Policy sets out the full picture, including your rights and how to exercise them.
5. Prohibited practices
The following are prohibited. Each is a material breach of the Master Services Agreement, whether or not malware is ultimately delivered, and whether or not a user is ultimately harmed.
5.1 Malicious delivery
- Malicious code in a creative, a tag or any resource either of them loads.
- Redirects that are not initiated by the user.
- Phishing, social engineering and credential harvesting, at any point in the delivery path.
- Drive-by downloads and any attempt to install software without the user initiating it.
- Exploit kits and any attempt to probe or compromise a user’s device or browser.
5.2 Deception of our review process
Deliberately presenting one thing for review and running another is treated as seriously as delivering malware, because it is how malware reaches users.
- Cloaking: serving different content to scanners, to our review process, to particular geographies or to particular device types than is served to ordinary users.
- Post-approval substitution: changing a creative, a tag’s destination or a landing page after approval so that what runs differs from what was reviewed.
- Category switching: obtaining approval for one category of advertising and delivering another.
- Bait and switch: a creative that advertises one offer while the landing page presents another, including a landing page that redirects to a different category after arrival.
- Delayed payloads: tags that behave as approved for a period and then change behaviour.
- Obfuscation of code, destinations or redirect chains designed to defeat scanning.
- Reusing an approved tag, creative or domain to deliver content that was not approved.
- Misrepresenting the identity of the advertiser or the destination domain.
6. What happens when we detect it
- We block the tag or creative immediately. We do not wait for an explanation to stop delivery.
- We suspend the affected campaign and, where the circumstances require it, the account.
- We send you the incident report and require an explanation within the period stated in it.
- We examine your other active campaigns and tags, and may suspend them while we do so.
- Where the breach is material or is not remedied, we terminate the Master Services Agreement for good cause and close the account permanently.
6.1 What it costs you
Delivery stops, the account closes, and we recover what the incident costs us and our partners. Fees and media cost already incurred remain payable; we do not credit back spend on delivery we had to stop. Where a breach is deliberate we cooperate fully with law enforcement and with any authority that asks. How costs are recovered is set out in the Master Services Agreement.
None of this limits any other right or remedy available to us.
7. Reporting to third parties
Where we are lawfully entitled to do so, we report confirmed incidents to the security vendors we work with and to the supply-side platforms and exchanges concerned, including Google, which takes reports at https://anti-malvertising.withgoogle.com/report. A report identifies the tag, the creative and the party that supplied it. We report what we have established, not what we suspect — and what we have established, we report.
8. What we control, and what we do not
We control what enters the platform and what we are able to detect. Every tag is scanned before launch and every hour while it is live, we block on detection, and we act on reports. Section 3 is what we do, not what we aspire to.
We do not control an advertiser’s own business. Once a user clicks through and arrives on the advertiser’s landing page, the user is on the advertiser’s property and dealing with the advertiser. What is offered there, what is sold, what is claimed, what is collected and what happens afterwards is between the user and the advertiser. Digital East is not a party to that relationship, exercises no control over it, and is not the controller of personal data the advertiser collects on its own site. The advertiser is responsible for it and answers for it, including under the indemnity in the Master Services Agreement.
This is how programmatic advertising works. An intermediary can scan what it carries and refuse what fails; it cannot supervise the conduct of every advertiser’s business. Our obligation is to detect and remove what breaches this policy, and we take it seriously.
Nothing in this section limits liability that cannot be limited: liability for intent and gross negligence, for injury to life, body or health and under the Produkthaftungsgesetz is unaffected, as are the rights of data subjects under Art. 82 GDPR.
9. Reporting a suspected incident to us
If you believe advertising delivered through our platform is malicious, tell us at privacy@digitaleast.mobi. Include the creative or tag identifier, the site or app, the time, and the country if you know it. We acknowledge reports and investigate them on the path described in section 3.
10. Changes
We may amend this policy. An amendment that is purely technical, or that responds to a new security or malvertising threat, takes effect on publication. Any other amendment takes effect 30 days after we notify you in text form, and you may terminate with effect from that date if you do not accept it.
11. Contact
General: info@digitaleast.mobi. Data protection: privacy@digitaleast.mobi.