Skip to main content
The state of ai impact assessment
Category: Cookie Types

Advertising Cookies

Also known as: Advertising cookie, Ad cookies, Targeting cookies, Marketing cookies
Simply put

Advertising cookies are small files placed on your device when you visit a website that record information about your browsing behaviour and interests. Websites and advertisers use them to build a picture of what you look at online so they can show you ads tailored to your apparent preferences. Because they involve tracking rather than being essential to a site working, they are generally treated differently under privacy rules than strictly necessary cookies.

Formal definition

Advertising cookies are a category of HTTP cookies (small blocks of data created by a web server and stored on the user's device) used in digital advertising to track user activity across a website, catalogue behaviour, collect data on interactions, and serve personalised advertising based on browsing history and inferred preferences. As a non-essential tracking technology, advertising cookies typically fall outside the 'strictly necessary' exemption and, in most EU and UK jurisdictions, generally require prior, freely given, specific, informed, and unambiguous consent both for placing/accessing the cookie under ePrivacy rules and, where personal data is processed, under the GDPR. Requirements differ under other regimes, such as certain US state privacy laws (e.g. the CCPA/CPRA in California), which more commonly rely on an opt-out model rather than opt-in consent. Note that similar tracking technologies used for advertising purposes, including pixels, SDKs, local storage, and device fingerprinting, generally fall within the same rules even though they are not literally cookies. The specific classification, retention, and lawful basis for any given advertising cookie depend on facts not covered by this general definition, and enforcement positions continue to evolve.

Why it matters

Advertising cookies sit at the centre of one of the most heavily scrutinised areas of online privacy compliance. Because they track user behaviour across a website to build a picture of interests and serve personalised ads, they generally fall outside the 'strictly necessary' exemption. In most EU and UK jurisdictions this means they typically require prior consent that is freely given, specific, informed, and unambiguous, both for placing or accessing the cookie under ePrivacy rules and, where personal data is processed, under the GDPR. Getting this wrong exposes organisations to regulatory complaints and enforcement action, and it undermines user trust.

The consent standard matters in practice. Pre-ticked boxes, implied consent from continued browsing, and cookie walls are widely considered non-compliant in the EU, so advertising cookies generally cannot be set before a user takes a clear affirmative action. This makes advertising cookies a common trigger for banner and consent management design decisions, and a frequent focus of data protection authority guidance. Requirements differ under other regimes, such as certain US state privacy laws like the CCPA and CPRA in California, which more commonly rely on an opt-out model rather than opt-in consent, so a single global consent approach rarely fits every jurisdiction.

Advertising cookies also matter because the same rules generally extend to functionally similar technologies. Pixels, SDKs, local storage, and device fingerprinting used for advertising purposes typically fall within the same legal framework even though they are not literally cookies. Teams that focus only on classic HTTP cookies may miss tracking technologies that carry the same obligations, and the precise classification, retention period, and lawful basis for any given advertising cookie depend on facts specific to each deployment rather than on this general category alone.

Who it's relevant to

Privacy and data protection officers
DPOs and privacy teams need to identify which cookies and similar technologies serve advertising purposes, confirm they are treated as non-essential, and ensure they are only set after valid consent in EU and UK contexts. They also need to account for jurisdictional differences, such as the opt-out orientation of certain US state laws, rather than assuming one standard applies everywhere.
Legal counsel and compliance teams
Counsel assess the lawful basis for placing advertising cookies and for any downstream processing of personal data, and advise on where practices such as pre-ticked boxes, implied consent, or cookie walls are likely to be non-compliant in the EU. They should note that the correct classification and lawful basis for a specific cookie depend on facts not captured by a general definition, and that enforcement guidance continues to evolve.
Web developers and engineering teams
Developers implement the technical controls that prevent advertising cookies, pixels, SDKs, local storage, and fingerprinting from firing before consent is captured. Because these technologies are functionally similar to cookies and generally fall within the same rules, engineers need to gate all advertising-related tracking, not only classic HTTP cookies.
Marketing and advertising operations
Marketing teams rely on advertising cookies to deliver personalised ads and measure campaigns, so they must understand that these cookies typically require consent in EU and UK jurisdictions and may be subject to opt-out rights elsewhere. This shapes what data is available for targeting and how tags and tracking pixels are deployed through consent management platforms.

Inside Advertising Cookies

Purpose and function
Advertising cookies are used to deliver, target, measure, or personalize advertising, including tracking users across websites to build profiles and serve behavioral or interest-based ads. They fall outside the category of strictly necessary cookies.
Consent requirement under EU/UK law
In most EU jurisdictions and the UK, the placing of and access to advertising cookies on a user's device is governed by the ePrivacy Directive (and its national implementations), which generally requires prior consent because these cookies are not essential to providing a service the user has requested.
GDPR overlay
Where advertising cookies process personal data, the GDPR applies in addition to the ePrivacy rules. Consent obtained for placing the cookie does not automatically satisfy every GDPR obligation, and any subsequent processing of personal data must have its own valid legal basis and meet transparency and other GDPR requirements.
Related technologies
Similar tracking technologies used for advertising, such as pixels, tags, software development kits (SDKs), local storage, and device fingerprinting, generally fall within the same consent rules even though they are not literally cookies.
Jurisdictional variation
Obligations differ by region. EU and UK frameworks typically rely on prior opt-in consent, while several US state privacy laws (for example the CCPA and CPRA in California) more commonly rely on an opt-out model for the sale or sharing of personal information and targeted advertising.
Consent management components
Advertising cookies are commonly managed through consent management platforms (CMPs), and in the advertising context often via the IAB Transparency and Consent Framework (TCF). Signals such as Global Privacy Control may be relevant in some jurisdictions, and consent records or logs may support record-keeping obligations.

Common questions

Answers to the questions practitioners most commonly ask about Advertising Cookies.

Do advertising cookies only require consent under the GDPR?
No. The placing of and access to advertising cookies on a user's device is governed primarily by the ePrivacy Directive (and its national implementations), which generally requires prior consent for non-essential cookies. The GDPR governs any personal data processing that follows once those cookies are read or set. These are two distinct legal bases, and satisfying one does not automatically satisfy the other. In most EU jurisdictions you must address both the ePrivacy consent requirement for accessing the device and the GDPR requirements applicable to the resulting personal data processing.
Can I rely on continued browsing or a pre-ticked box to obtain consent for advertising cookies?
In the EU this approach is widely considered non-compliant. Valid consent under the GDPR must be freely given, specific, informed, and unambiguous, requiring a clear affirmative action. Pre-ticked boxes and implied consent inferred from continued browsing generally do not meet that standard, and cookie walls are also widely regarded as problematic. Requirements differ under other frameworks, such as certain US state privacy laws, which often rely on an opt-out model rather than prior opt-in, so the applicable standard depends on the geographic scope of your users.
What geographic scope should I consider before deploying advertising cookies?
Obligations vary between the EU, the UK, and individual US states such as California under the CCPA and CPRA, as well as other regimes. In most EU jurisdictions advertising cookies typically require prior consent, while some US state frameworks generally rely on opt-out mechanisms. Because enforcement positions and regulatory guidance evolve, you should map where your users are located and apply the standard appropriate to each jurisdiction rather than assuming one region's rules apply universally. Determining the precise obligations for a given jurisdiction may require legal advice that is out of scope for this definition.
How should advertising cookies be handled before a user makes a consent choice?
In most EU jurisdictions, non-essential cookies such as advertising cookies should not be placed or read before the user has given a clear affirmative consent. This typically means suppressing the relevant tags, pixels, SDKs, and scripts until consent is recorded. Note that similar technologies used for advertising, including tracking pixels, local storage, and fingerprinting, generally fall within the same rules even though they are not literally cookies. The exact sequencing and technical implementation depend on your setup and are not fully determined by this definition.
What role does a consent management platform play in managing advertising cookies?
A consent management platform (CMP) can help present consent choices, gate the firing of advertising tags, and maintain records of consent. Some CMPs integrate with the IAB Transparency and Consent Framework (TCF) for the advertising ecosystem. However, a CMP supports compliance but does not replace legal judgment, and no tool guarantees compliance on its own. You remain responsible for configuring it correctly, verifying that tags respect the user's choices, and ensuring the arrangement reflects the requirements of the applicable jurisdictions.
What record-keeping should accompany consent for advertising cookies?
Consent logging and record-keeping are generally treated as important to demonstrate that valid consent was obtained, which is typically expected under the GDPR's accountability principle in EU jurisdictions. This may involve retaining information about what the user was shown, what choices they made, and when. The specific details that should be logged and applicable retention practices depend on facts not covered by this definition and may be subject to evolving guidance from data protection authorities, so you should confirm the appropriate approach for your circumstances.

Common misconceptions

Advertising cookies can be set as soon as a user lands on a page, before any interaction.
In most EU jurisdictions and the UK, advertising cookies generally require prior consent, meaning a clear affirmative action before they are placed. Pre-ticked boxes, implied consent from continued browsing, and cookie walls are widely considered non-compliant in the EU. Approaches differ under US state laws, which often rely on an opt-out mechanism instead.
If a user consents to advertising cookies, all GDPR requirements for the resulting data processing are automatically met.
The ePrivacy rules govern the placing of and access to cookies, while the GDPR governs the processing of any personal data that follows. Consent to place a cookie does not by itself discharge separate GDPR obligations such as ensuring a valid legal basis, transparency, and data subject rights for downstream processing.
Only literal browser cookies used for advertising need consent.
Similar technologies such as pixels, tags, SDKs, local storage, and fingerprinting used for advertising generally fall within the same consent rules, even though they are not technically cookies.

Best practices

Block advertising cookies and equivalent tracking technologies from loading until valid consent is obtained where prior opt-in consent applies, such as in most EU jurisdictions and the UK.
Ensure consent for advertising cookies meets the standard of being freely given, specific, informed, and unambiguous through a clear affirmative action, and avoid pre-ticked boxes, reliance on continued browsing, or cookie walls in the EU.
Identify all advertising-related technologies in scope, including pixels, tags, SDKs, local storage, and fingerprinting, rather than limiting review to literal cookies.
Map the applicable legal regimes separately, treating the ePrivacy rules on placing cookies and the GDPR rules on processing personal data as distinct obligations that each must be satisfied.
Tailor consent mechanics to jurisdiction, applying opt-in approaches in the EU and UK and opt-out mechanisms where required under US state laws such as the CCPA and CPRA, and consider relevant signals such as Global Privacy Control.
Use a consent management platform and, where appropriate, the IAB TCF to capture and log consent, while recognizing that these tools support compliance but do not replace legal judgment or guarantee compliance.
Promotional banner for the Pentest Readiness checklist download