Protecting vulnerable audiences without killing your message
The case: a suicide-prevention tool that exposed the people it watched
On 29 October 2014 Samaritans launched Radar, a free web app that read the public tweets of accounts you followed, flagged phrases suggesting distress, and emailed you an alert so you could reachreachThe number of unique people exposed to your message in a given period. Unlike impressions, reach counts each person once, no matter how often they see it.View full definition → out. The intent was clean. The design was not. The people being monitored never opted in and were never told. Anyone could subscribe to watch anyone, including people who had already harassed them, and the alert stream amounted to a live list of who was struggling. Samaritans suspended Radar nine days later, on 7 November 2014.
No claim in that product was false. No money changed hands. The failure sat upstream of claims, in audience selection and data practice, which is exactly the ground this lesson covers. What you may assert is handled where the module deals with misleading claims; who signs it off is handled by the sign-off gate lesson. The question here is narrower and harder: your message is accurate, your funding is clean, your service is real, and it still lands on someone who cannot receive it the way you intended.
Vulnerability is a state, not a label
You do not need a diagnosis or a legal incapacity for the stricter test to apply. Both the ASA in the UK and the FTC in the US judge an ad by its likely effect on a reasonable member of the group actually targeted, not on an average adult. Bereavement, debt, a recent diagnosis, a night shift, a bad month: vulnerability is mostly transient, which means your segment is not a fixed population you can exclude once and forget.
The size of that population is also less knowable than planning decks assume. When the Gambling Commission moved to its new Gambling Survey for Great Britain methodology, the share of adults scoring 8+ on the PGSI came out around 2.5%, several times the fraction older telephone surveys had reported. The Commission warned the two numbers are not comparable. The planning point stands anyway: a "tiny minority" assumption baked into a targeting brief can be wrong by close to an order of magnitude, and the harm-weighted cost of being wrong is not symmetrical.
Practical rule: if your service exists *because* people are in a hard situation (housing insecurity, illness, debt, grief, addiction), assume the targeted-audience test applies to every asset, including the ones you consider generic.
The three fair-treatment tests regulators actually apply
1. Claims: is it accurate, and is it accurate *for this audience*?
A claim can be true and still mislead if the reader cannot verify or contextualise it. "You could lose your home" may hold in an edge case; put in front of someone already behind on rent, without qualification, it reads as a near-certainty. The question is whether the copy creates a false impressionimpressionThe total number of times an ad or piece of content is displayed, regardless of clicks. Each display counts as one impression, even to the same person.View full definition → of urgency, risk or eligibility for the person most likely to click.
2. Imagery: does the emotional load exceed what the message needs?
Distress imagery is legitimate where the consequence is the message. Road safety needs to show consequences. The test is proportionality, and it cuts both ways: safety messaging pitched wrong can move behaviour in the wrong direction. The gambling industry's "When the fun stops, stop" slogan was studied by researchers at Warwick, who found no protective effect and, in some conditions, slightly increased betting intentions. A warning that flatters the reader's sense of control is worse than no warning.
3. Targeting: did you choose this audience, and did you choose a trait to exploit?
This is where enforcement has moved fastest, and where platforms have started making the decision for you. Meta removed detailed targeting options tied to sensitive topics (health causes, sexual orientation, religious practice, political beliefs) on 19 January 2022. In the US, ads about housing, employment and credit must be declared under Meta's Special Ad Category, which strips out gender, narrow age bands and most detailed targeting, and widens the minimum location radius. The EU's Digital Services Act separately bars profiling-based ads using special category data and bars profiling-based ads to minors.
The trap is that removing the toggle does not remove the inferenceinferenceThe moment a trained AI model is put to work: it takes a new input and produces an answer, prediction or generated output.View full definition →. A lookalike audiencelookalike audienceAn audience created by ad platforms to target new prospects who resemble your best existing customers, based on shared traits and behaviors.View full definition → seeded from people who called a gambling helpline is a model of people who resemble help-seekers, built from special category data you never uploaded as such. You cannot see the seed. The optimiser can.
Where over-caution costs you reach
Strip out every proxy for hardship and you lose the people the service exists for. Deprivation-linked postcode targeting is the clearest example: drop it on duty-of-care grounds and your homelessness-prevention message is now weighted towards households who will never need it. Under Meta's Special Ad Category rules a US housing charity cannot aim an over-65s tenancy-rights message at over-65s at all, even when age is the entire point of the service.
The workable answer is to move the constraint from *who* you reach to *what* they get and *how often*. Keep the broad audience, then flatten the emotional intensity, cap frequency, and make the exit path obvious in the first line rather than after a phone call. Reach stays; pressure comes down. A campaign that raises panic calls from ineligible people is not overperforming, it is misallocating a helpline.
Duty-of-care checks a standard sign-off will miss
Assume the sequence of evidence files and approvals the sign-off lesson sets out is already running. These are the items it tends not to catch:
- Capacity before reach. Never buy media a response channel cannot answer. Samaritans says it responds to a call for help roughly every ten seconds, around the clock; most public bodies signposting to a service do not have that. If the line closes at 5pm, do not run distress-led creative at 1am, and say the opening hours in the ad.
- Frequency caps on anything fear-adjacent. The eleventh impression of a warning is a different message from the first.
- Suppression file governance. A list of people who contacted a self-harm or gambling service is the most sensitive dataset your organisation holds. Hashing it for upload to an ad platform changes the format, not the meaning, and not what a breach or a disclosure request would reveal.
- Seed provenance for every lookalike and custom audience, written down: where the source list came from and what consent it carried.
- Comprehension testing with people in the state you are targeting, not with colleagues. Read-back at low literacy and under stress is where "check your eligibility" turns into "you are being evicted".
- A written note of what you deliberately did not target, and why. It is the record that shows a choice was made.
🎬 [VIDEO: "How the ASA Regulates Advertising in the UK" - youtube.com - search for the ASA's own explainer series on how complaints are assessed and what rulings mean for advertisers]
Knowledge check
1. In the housing charity case, what was the core regulatory problem with the campaign?
2. How do regulators like the ASA generally determine whether an audience is 'vulnerable' for advertising purposes?
3. Why is this case described as a useful lesson even though the charity's service was genuine and not a scam?
4. Select ALL correct answers about the FTC's approach to judging whether an ad is unfair or deceptive toward a targeted audience.
Select all the correct answers.
5. Select ALL correct answers about factors that can make an audience 'vulnerable' in the eyes of regulators, according to this lesson.
Select all the correct answers.
What good looks like: naming the moment, not the person
GambleAware's Bet Regret campaign, launched in 2019, aimed at younger men placing impulsive in-play sports bets. Its creative attacked a moment (betting while bored, drunk or chasing a loss) rather than labelling the viewer an addict. That choice does most of the duty-of-care work on its own: nobody has to self-identify as a problem gambler to act on it, and the ad carries no implied accusation to anyone else who sees it. Media ran around live sport, where the behaviour happens, so the targeting logic maps to the behaviour rather than to a vulnerability proxy.
Worth stating plainly, because trust with this audience is fragile: GambleAware has historically been funded by donations from the gambling industry, with a statutory levy replacing that arrangement. Perceived independence is itself a duty-of-care variable when your audience is deciding whether to believe you.
On the data side, Samaritans came back from Radar in the more useful direction: publishing guidelines for online platforms and media on handling suicide and self-harm content, so the safeguarding logic sits with the organisations holding the data rather than in an app that broadcasts distress to strangers. Same goal, no monitored population.
Key takeaways
- Vulnerability is contextual and temporary, and prevalence estimates for it move with methodology, so build for the state rather than screening for a fixed group.
- Rulings turn on three things: whether claims hold for this specific audience, whether emotional intensity matches real risk, and whether a targeting parameter was chosen because it correlates with hardship.
- Platforms increasingly remove the toggle (Meta's sensitive-interest removals of January 2022, Special Ad Category, the DSA's profiling limits) without removing the inference: lookalikes rebuild what you were forbidden to select.
- Over-suppression has a cost. Constrain tone, frequency and the exit path before you constrain reach, or you will systematically miss the people the service exists for.
- Your suppression and help-seeker lists are the most sensitive data you hold. Governance of those files, and capacity behind the phone number, matter more than another round of copy approval.