Skip to main content
Category: Tracking Technologies

Advertising ID

Also known as: IDFA, GAID, Google Advertising ID, Identifier for Advertisers, Ad ID
Simply put

An advertising ID is a unique identifier assigned to a mobile device that lets advertisers recognize the device across apps in order to deliver and measure targeted ads, without directly using a name or email. On major mobile platforms, users can typically reset or delete this identifier, and platform-level controls may limit its availability. Although it is often described as anonymized, an advertising ID can still be treated as personal data under laws such as the GDPR because it can single out a device and its user.

Formal definition

An advertising ID is a device-scoped, user-resettable alphanumeric identifier used for advertising purposes such as attribution, frequency capping, conversion measurement, and audience targeting. The two most prominent examples are Apple's Identifier for Advertisers (IDFA), exposed via the AdSupport framework's advertisingIdentifier, and Google's Advertising ID (GAID) provided through Google Play services; each is intended for advertising use and can be reset or deleted by the user, with availability governed by platform-level consent and tracking-control mechanisms. Because an advertising ID can persistently distinguish a device and be linked to behavioral data, it is commonly regarded as personal data under EU and UK data protection law, meaning its collection and use for advertising generally requires a lawful basis under the GDPR and, where its storage or access on a user's device is involved, prior consent under the ePrivacy Directive and its national implementations; note that its regulatory treatment as an identifier rather than a literal cookie does not exempt it from these rules. The precise obligations depend on jurisdiction and factual context (for example, opt-in regimes in the EU versus opt-out approaches under certain US state laws), which is out of scope for this definition; platform frameworks and consent tooling support compliance but do not by themselves establish it.

Why it matters

Advertising IDs sit at the center of mobile ad targeting, attribution, and measurement, which makes them a focal point for privacy compliance. Because an advertising ID can persistently single out a device and be linked to behavioral data, it is commonly regarded as personal data under EU and UK data protection law rather than as a truly anonymous value. As a result, its collection and use for advertising generally requires a lawful basis under the GDPR, and where its storage on or access to a user's device is involved, prior consent may be required under the ePrivacy Directive and its national implementations.

A frequent misunderstanding is that because advertising IDs are described as anonymized and are not literally cookies, they fall outside consent rules. That treatment as an identifier rather than a cookie does not by itself exempt them; similar technologies such as pixels, SDKs, and other device identifiers generally fall within the same rules. Privacy and compliance teams therefore need to account for advertising IDs in the same way they account for cookies when assessing consent obligations and lawful bases.

Regulatory treatment also varies by jurisdiction. EU and UK frameworks generally rely on opt-in consent, while certain US state laws take an opt-out approach. The precise obligations depend on the geographic scope and the specific facts of a given processing activity, so a practice that is acceptable in one regime may not satisfy requirements in another. Platform frameworks and consent tooling can support compliance, but they do not establish it on their own.

Who it's relevant to

Privacy officers and data protection professionals
Because an advertising ID can single out a device and its user, it is commonly regarded as personal data under EU and UK law. Privacy teams need to identify a lawful basis for its use in advertising and assess whether prior consent applies where storage on or access to a device is involved, rather than assuming the identifier is exempt because it is anonymized or not a cookie.
Legal counsel and compliance teams
Obligations differ across jurisdictions, with EU and UK regimes generally relying on opt-in consent and certain US state laws relying on opt-out. Counsel should scope advice to the applicable regime and factual context, and recognize that platform frameworks and consent tooling support but do not by themselves establish compliance.
Mobile app developers and engineering teams
Developers work directly with platform APIs such as Apple's advertisingIdentifier and Google's Advertising ID, and must account for platform-level consent and tracking-control mechanisms that may limit availability. They should also implement handling that respects the user's ability to reset or delete the identifier.
Marketing and advertising compliance teams
Advertising IDs underpin frequency capping, conversion measurement, attribution, and audience targeting. Teams relying on them for these purposes should ensure the underlying consent or opt-out requirements are met for each jurisdiction in which the campaigns run, since the identifier's role in advertising brings it within data protection and ePrivacy rules.

Inside Advertising ID

Resettable device identifier
An advertising ID is a user-resettable identifier assigned by a mobile operating system (such as Apple's IDFA or Google's Advertising ID/AAID) that apps and advertising SDKs can read to identify a device for advertising and measurement purposes. Because it can be reset or cleared by the user, it differs from permanent hardware identifiers.
Access via SDKs, not literal cookies
Advertising IDs are typically accessed through software development kits (SDKs) embedded in mobile apps rather than through browser cookies. Under EU law, however, reading or storing such an identifier on a user's device generally falls within the same ePrivacy rules that govern cookies and similar technologies, even though it is not literally a cookie.
Personal data status
In most EU interpretations an advertising ID is treated as personal data because it can single out a device or user and be combined with other data, meaning any subsequent processing is generally subject to the GDPR in addition to the ePrivacy rules governing access to the device.
Platform-level user controls
Mobile operating systems provide settings that let users reset the identifier or limit ad tracking. On some platforms the identifier may be withheld or zeroed out unless the user grants permission, though the exact mechanism and its legal sufficiency vary by platform and jurisdiction.
Advertising and measurement use
The identifier is used to build advertising profiles, attribute conversions, cap ad frequency, and measure campaign performance across apps. These uses generally constitute processing that requires a lawful basis and, in most EU jurisdictions, prior consent.

Common questions

Answers to the questions practitioners most commonly ask about Advertising ID.

Is an advertising ID anonymous because it isn't tied to my name?
No. Although an advertising ID does not contain a user's name, it is a persistent, unique identifier that can single out a device or user profile and be combined with other data to track behaviour over time. In most EU jurisdictions it is therefore generally treated as personal data under the GDPR, even where it is described as pseudonymous rather than directly identifying. The absence of a name does not by itself make the identifier anonymous.
Does the fact that an advertising ID isn't technically a cookie mean cookie consent rules don't apply?
Not generally. The EU ePrivacy rules on storing or accessing information on a user's device are not limited to cookies; they can extend to mobile advertising IDs, SDKs, and similar technologies where information is read from or written to the device. The processing of personal data that follows is then governed by the GDPR. So the technology being an advertising ID rather than a cookie does not by itself remove it from the same broad legal framework, though the precise application can depend on the technical mechanism and national implementation.
When do we need consent before accessing an advertising ID?
In most EU jurisdictions, consent is generally required before accessing or using an advertising ID for purposes such as advertising, measurement, or profiling, because these are typically not considered strictly necessary. The consent must meet the GDPR standard of being freely given, specific, informed, and unambiguous through a clear affirmative action. Whether a particular use is exempt depends on the facts, so this should be assessed case by case. Requirements differ outside the EU; some US state frameworks rely on an opt-out model rather than prior opt-in.
How should an advertising ID be handled when a user declines or withdraws consent?
Where consent is the legal basis, declining or withdrawing it should generally stop the collection and use of the advertising ID for the relevant purposes, and withdrawal should be as easy as giving consent. In practice this typically means suppressing the ID from advertising and measurement calls and honouring platform-level signals where applicable. The exact implementation depends on your stack and the guidance of the relevant data protection authority, so legal review of your specific configuration is advisable.
What should we record when relying on consent for advertising ID processing?
Consent record-keeping obligations generally point toward retaining evidence of what the user was told, what they agreed to, when, and through what mechanism. For advertising IDs this may include linking the consent state to the relevant purposes and vendors and keeping a log that can demonstrate compliance if questioned. A consent management platform can support this logging but does not replace the need for legal judgment about whether the consent obtained was valid.
How do consent signals and frameworks interact with advertising ID processing?
Consent management platforms, the IAB Transparency and Consent Framework, and signals such as Global Privacy Control can be used to communicate a user's choices to downstream vendors that rely on advertising IDs. These tools help operationalise consent and opt-out preferences but do not by themselves guarantee compliance, and their appropriateness depends on the jurisdiction and the specific purposes involved. This entry does not address the detailed technical configuration of any particular framework.

Common misconceptions

Because an advertising ID is not a cookie, cookie consent rules do not apply to it.
In most EU jurisdictions, accessing or storing an identifier on a user's device is governed by the same ePrivacy rules that apply to cookies, regardless of the underlying technology. Advertising IDs, pixels, local storage, and SDK identifiers generally fall within scope, so consent may be required in the same way.
An advertising ID is anonymous because it is not a name.
In most EU interpretations an advertising ID is treated as personal data, since it can single out a device or user and be combined with other information. Any processing that follows is therefore generally subject to the GDPR in addition to the ePrivacy rules on device access.
A platform's built-in ad-tracking permission prompt automatically satisfies all legal consent requirements.
Platform controls support user choice but do not necessarily meet every requirement under applicable law. Valid GDPR consent must be freely given, specific, informed, and unambiguous, and requirements differ across the EU, the UK, and US state regimes such as the CCPA/CPRA, which often rely on opt-out. Whether a platform prompt is sufficient depends on facts and may be contested, so legal judgment is still needed.

Best practices

Treat access to advertising IDs the same way you treat cookies for consent purposes, obtaining any required prior consent before an SDK reads the identifier in jurisdictions where opt-in consent applies, such as most EU member states.
Map where advertising IDs are collected across your apps and SDKs, and document the purposes (profiling, attribution, frequency capping, measurement) so you can identify the applicable lawful basis and consent requirements.
Tailor your approach to the geographic scope of your users, recognizing that EU and UK rules generally require opt-in consent while several US state laws (for example California's CCPA/CPRA) often rely on opt-out mechanisms.
Respect and correctly implement platform-level user controls for resetting or limiting the advertising ID, and confirm your SDK behavior honors those signals, while not assuming the platform prompt alone discharges your legal obligations.
Maintain records of the consent or choice obtained for advertising ID access, since consent logging and record-keeping obligations generally apply to identifiers just as they do to cookies.
Seek qualified legal review for advertising ID processing, as interpretations, enforcement positions, and the sufficiency of platform prompts remain contested and evolving; treat consent tools and platform controls as support for compliance rather than a guarantee of it.