Advertising Cookies
Advertising cookies are small files placed on your device when you visit a website that record information about your browsing behaviour and interests. Websites and advertisers use them to build a picture of what you look at online so they can show you ads tailored to your apparent preferences. Because they involve tracking rather than being essential to a site working, they are generally treated differently under privacy rules than strictly necessary cookies.
Advertising cookies are a category of HTTP cookies (small blocks of data created by a web server and stored on the user's device) used in digital advertising to track user activity across a website, catalogue behaviour, collect data on interactions, and serve personalised advertising based on browsing history and inferred preferences. As a non-essential tracking technology, advertising cookies typically fall outside the 'strictly necessary' exemption and, in most EU and UK jurisdictions, generally require prior, freely given, specific, informed, and unambiguous consent both for placing/accessing the cookie under ePrivacy rules and, where personal data is processed, under the GDPR. Requirements differ under other regimes, such as certain US state privacy laws (e.g. the CCPA/CPRA in California), which more commonly rely on an opt-out model rather than opt-in consent. Note that similar tracking technologies used for advertising purposes, including pixels, SDKs, local storage, and device fingerprinting, generally fall within the same rules even though they are not literally cookies. The specific classification, retention, and lawful basis for any given advertising cookie depend on facts not covered by this general definition, and enforcement positions continue to evolve.
Why it matters
Advertising cookies sit at the centre of one of the most heavily scrutinised areas of online privacy compliance. Because they track user behaviour across a website to build a picture of interests and serve personalised ads, they generally fall outside the 'strictly necessary' exemption. In most EU and UK jurisdictions this means they typically require prior consent that is freely given, specific, informed, and unambiguous, both for placing or accessing the cookie under ePrivacy rules and, where personal data is processed, under the GDPR. Getting this wrong exposes organisations to regulatory complaints and enforcement action, and it undermines user trust.
The consent standard matters in practice. Pre-ticked boxes, implied consent from continued browsing, and cookie walls are widely considered non-compliant in the EU, so advertising cookies generally cannot be set before a user takes a clear affirmative action. This makes advertising cookies a common trigger for banner and consent management design decisions, and a frequent focus of data protection authority guidance. Requirements differ under other regimes, such as certain US state privacy laws like the CCPA and CPRA in California, which more commonly rely on an opt-out model rather than opt-in consent, so a single global consent approach rarely fits every jurisdiction.
Advertising cookies also matter because the same rules generally extend to functionally similar technologies. Pixels, SDKs, local storage, and device fingerprinting used for advertising purposes typically fall within the same legal framework even though they are not literally cookies. Teams that focus only on classic HTTP cookies may miss tracking technologies that carry the same obligations, and the precise classification, retention period, and lawful basis for any given advertising cookie depend on facts specific to each deployment rather than on this general category alone.
Who it's relevant to
Inside Advertising Cookies
Common questions
Answers to the questions practitioners most commonly ask about Advertising Cookies.

