For example, if you place a cookie recording visits to a specific results page of a mental health test (e.g. a page saying "you got 14-18 points on this test which implies foobar" or get a https://www.hotjar.com/ recording of what the user typed in that test, then that would be blatantly illegal, violating GDPR article 9.1. I'm not even talking about using that data for targeting ads, the default position (if no exceptions are met) is that you're not allowed to collect and store that data.
Collecting user browsing habits is not (in EU) "legal by default" - it may be legal, but it may be not (e.g. if sensitive data are collected as in this case) and it's the duty of data controller to ensure that all the requirements are met - if it turns out that it's too difficult for you to automatically distinguish which browsing habits you are allowed to collect and which not, then the only legal option is to assume that you're not allowed to collect them.
Having your health data not be collected by random companies is an important inalienable right (e.g. privacy as one of the core rights in EU charter of human rights); while collecting and storing browsing habits of other people is a privilege, you're allowed to do that only if you can meet all the required conditions.
1. Get addresses of mental care clinics and offices.
2. Geofence addresses
3. Correlate devices that visited geofence addresses (using LiveRamp data) with devices that saw your ads on Mental Health sites.
4. Bonus, look at the path on the pages to figure out what disease they were viewing when your ad was displayed if you weren't already targeting specific page content.
("absurd" is a strange word to use; it might be nicer to educate without condescension).
> > Correlate devices that visited geofence addresses (using LiveRamp data)
LiveRamp is hooked into a lot of ad services and a user's location information will routinely make its way to them. Played some ad-supported mobile game on your phone while in the Doctor's waiting room? LiveRamp has that location data.
Even if the user doesn't have GPS enabled for the game, they might have it enabled for some other background process that routinely asks for it, like Facebook or Twitter or FourSquare, who package that data for sale. Or you're on the Doctor's wifi, and most stable IPs like that are in location databases. Or they just buy it off your cell phone provider, since many happily sell location information.
LiveRamp is a gigantic business built entirely on knowing approximately where you are any time you interact with their tracking servers.
Location data is so easily available that is largely a commodity now, sources include GPS from "always on" apps like the Weather Network but also apps that are collecting this data without your permission. Apple and Google are constantly kicking apps that do this out of the store.
Also tricks like "local wifi" devices are being used, Apple just reduced apps ability to sniff networks for this reason. There is another response that lists some other data sources, your cell phone company being the worst offender for many reasons.
Healthcare targeting has been severely reduced in the past couple years because of concerns like these. You used to be able to target diseases/interest in diseases/etc but can't anymore.
*Please don't take this excessively literally.