I'm not doing anything shady: all the information I collect and why I collect it has always been in my privacy policy. But making people have to opt-in to see ads on the site is a big problem.
Mom and pop publishers who don't have the resources or ability to staff their own ad sales team are going to be in trouble. The big players who can work around this obstacle are going to be fine. I'm not happy about this.
Storing an IP address by itself and sharing it is not, by itself PII
[1] https://www.enterprisetimes.co.uk/2016/10/20/ecj-rules-ip-ad...
In the US, legally thats fine. In the EU they classify it as personal information.
One single ad unit may try and load several tracking services so that it can re-target you later, track that the ad was served, and also load in extra services (Facebook Like button) that in turn track you for their own reasons.
On any given Page Load you DO not know in advance what ads will be in your page.
In getting User Consent before you load ads you cannot possibly know what the services are that will eb injected into the page ahead of time.
Thats an impossible situation.
Even if, and I stress this is hard, even if you were able to limit your ads from one network to direct-sold campaigns under the control of just a few agencies that agree to use only a subset of trackers and other services, you might still be talking 20 to 80 items you need to provide the user in a Consent Form.