Advertising ID
An advertising ID is a unique identifier assigned to a mobile device that lets advertisers recognize the device across apps in order to deliver and measure targeted ads, without directly using a name or email. On major mobile platforms, users can typically reset or delete this identifier, and platform-level controls may limit its availability. Although it is often described as anonymized, an advertising ID can still be treated as personal data under laws such as the GDPR because it can single out a device and its user.
An advertising ID is a device-scoped, user-resettable alphanumeric identifier used for advertising purposes such as attribution, frequency capping, conversion measurement, and audience targeting. The two most prominent examples are Apple's Identifier for Advertisers (IDFA), exposed via the AdSupport framework's advertisingIdentifier, and Google's Advertising ID (GAID) provided through Google Play services; each is intended for advertising use and can be reset or deleted by the user, with availability governed by platform-level consent and tracking-control mechanisms. Because an advertising ID can persistently distinguish a device and be linked to behavioral data, it is commonly regarded as personal data under EU and UK data protection law, meaning its collection and use for advertising generally requires a lawful basis under the GDPR and, where its storage or access on a user's device is involved, prior consent under the ePrivacy Directive and its national implementations; note that its regulatory treatment as an identifier rather than a literal cookie does not exempt it from these rules. The precise obligations depend on jurisdiction and factual context (for example, opt-in regimes in the EU versus opt-out approaches under certain US state laws), which is out of scope for this definition; platform frameworks and consent tooling support compliance but do not by themselves establish it.
Why it matters
Advertising IDs sit at the center of mobile ad targeting, attribution, and measurement, which makes them a focal point for privacy compliance. Because an advertising ID can persistently single out a device and be linked to behavioral data, it is commonly regarded as personal data under EU and UK data protection law rather than as a truly anonymous value. As a result, its collection and use for advertising generally requires a lawful basis under the GDPR, and where its storage on or access to a user's device is involved, prior consent may be required under the ePrivacy Directive and its national implementations.
A frequent misunderstanding is that because advertising IDs are described as anonymized and are not literally cookies, they fall outside consent rules. That treatment as an identifier rather than a cookie does not by itself exempt them; similar technologies such as pixels, SDKs, and other device identifiers generally fall within the same rules. Privacy and compliance teams therefore need to account for advertising IDs in the same way they account for cookies when assessing consent obligations and lawful bases.
Regulatory treatment also varies by jurisdiction. EU and UK frameworks generally rely on opt-in consent, while certain US state laws take an opt-out approach. The precise obligations depend on the geographic scope and the specific facts of a given processing activity, so a practice that is acceptable in one regime may not satisfy requirements in another. Platform frameworks and consent tooling can support compliance, but they do not establish it on their own.
Who it's relevant to
Inside Advertising ID
Common questions
Answers to the questions practitioners most commonly ask about Advertising ID.