Skip to main content
Category: Tracking Technologies

Behavioural Advertising

Also known as: OBA, Online Behavioural Advertising, Interest-Based Advertising, Cross-Context Behavioral Advertising, Behavioral Retargeting
Simply put

Behavioural advertising is the practice of showing people ads based on their browsing activity and interests, tracked over time and often across different websites or platforms. Rather than choosing ads based only on the page a person is currently viewing, advertisers build a picture of a user's inferred interests from their past behaviour. In most EU jurisdictions this typically involves tracking technologies that require the user's prior consent before they are used.

Formal definition

Behavioural advertising refers to the targeting of advertisements to individuals based on interests, characteristics, or contexts inferred from data about their online activity, which may be collected over time and across multiple sites, apps, or platforms (often described as cross-context behavioural advertising when it spans more than one service). It generally relies on tracking technologies such as cookies, pixels, SDKs, local storage, or device identifiers to observe behaviour and build profiles, and the resulting data commonly constitutes personal data. Because it typically involves both the placing of or access to information on a user's device and the subsequent processing of personal data, it generally engages both the ePrivacy rules (governing the tracking technologies) and the GDPR (governing profiling and processing) in the EU; in most EU and UK contexts these activities are not treated as strictly necessary and therefore typically require freely given, specific, informed, and unambiguous prior consent. Requirements differ elsewhere: several US state privacy frameworks, such as those in California, generally rely on an opt-out model (including recognition of signals such as Global Privacy Control) rather than opt-in consent. The precise lawful basis, consent standard, and permissibility depend on jurisdiction, the specific technologies used, and evolving regulatory guidance, and are outside the scope of this definition to resolve for any particular deployment.

Why it matters

Behavioural advertising sits at the intersection of two distinct legal regimes in the EU, which is why it attracts sustained regulatory attention. Because it typically relies on tracking technologies such as cookies, pixels, SDKs, or device identifiers, the placing of or access to information on a user's device generally engages the ePrivacy rules. Because it then builds profiles from data that commonly constitutes personal data, the subsequent processing and profiling generally engages the GDPR. A single behavioural advertising deployment can therefore trigger both consent obligations for the tracking and separate accountability obligations for the processing, and satisfying one does not automatically satisfy the other.

The stakes are heightened by the fact that behavioural advertising is, in most EU and UK contexts, not treated as strictly necessary. That means it typically requires freely given, specific, informed, and unambiguous prior consent before the relevant tracking technologies are used. Practices that fall short of that standard, pre-ticked boxes, consent implied from continued browsing, or cookie walls, are widely regarded as non-compliant in the EU, and the design of consent flows for behavioural advertising is frequently where compliance risk crystallises for publishers and advertisers alike.

The picture is not uniform across jurisdictions, which is precisely why organisations operating internationally cannot apply a single approach. Several US state privacy frameworks, such as those in California, generally rely on an opt-out model, including recognition of signals such as Global Privacy Control, rather than the opt-in consent expected in the EU. The correct lawful basis, consent standard, and permissibility for any specific deployment depend on the jurisdiction, the technologies involved, and evolving regulatory guidance, and these questions cannot be resolved in the abstract.

Who it's relevant to

Privacy and data protection officers
Behavioural advertising typically involves profiling of personal data as well as the use of tracking technologies, engaging both the GDPR and ePrivacy rules in the EU. DPOs are generally responsible for assessing lawful basis, transparency, and record-keeping, and for recognising that these questions differ by jurisdiction and by the specific technologies deployed.
Legal and compliance counsel
Counsel must navigate the divergence between EU and UK opt-in consent expectations and the opt-out models common in several US state frameworks, such as those in California that recognise signals like Global Privacy Control. Whether a given behavioural advertising practice is permissible depends on jurisdiction, technology, and evolving regulatory guidance, so counsel typically applies fact-specific judgment rather than a single global rule.
Marketing and advertising operations teams
Teams deploying interest-based or retargeting campaigns need to understand that the tracking technologies these campaigns rely on are generally not strictly necessary in the EU and typically require prior consent. This shapes which audience-building and cross-context targeting activities can proceed, and where consent status must gate the use of tracking data.
Web developers and CMP implementers
Developers implement the tracking technologies, cookies, pixels, SDKs, local storage, and device identifiers, and the consent management platforms that gate them. They typically need to ensure that behavioural advertising tags do not fire before valid consent is captured in EU contexts, while recognising that a CMP supports but does not guarantee compliance.
Publishers and site owners
Publishers monetising through behavioural advertising must design consent experiences that meet the applicable standard for the jurisdictions of their users. Practices such as pre-ticked boxes, implied consent, or cookie walls are widely regarded as non-compliant in the EU, making the design of these flows a significant area of compliance risk.

Inside OBA

Behavioural profiling
The practice of building a profile of a user based on their browsing activity, interests, and inferred characteristics over time, typically to serve advertisements considered relevant to that profile. This profiling generally constitutes processing of personal data under the GDPR where individuals are identifiable, even indirectly.
Tracking technologies involved
Behavioural advertising commonly relies on cookies, but also on similar technologies such as tracking pixels, local storage, mobile SDKs, and device fingerprinting. In the EU, the placing of or access to such information on a user's device is governed by the ePrivacy Directive and its national implementations, while any subsequent processing of personal data falls under the GDPR.
Cross-site and cross-context tracking
The linking of a user's activity across multiple websites, apps, or contexts to inform ad targeting. This element frequently involves third parties and data sharing, which affects the transparency and consent obligations that may apply.
Legal basis and consent
In most EU jurisdictions, non-essential cookies and similar technologies used for advertising typically require prior consent that is freely given, specific, informed, and unambiguous, expressed through a clear affirmative action. Behavioural advertising cookies are generally not treated as strictly necessary and therefore usually fall outside the consent exemption.
Ad-tech ecosystem and frameworks
Behavioural advertising often operates through an ecosystem of advertisers, publishers, and intermediaries. Consent management platforms (CMPs) and industry frameworks such as the IAB Transparency and Consent Framework (TCF) are commonly used to collect and communicate consent signals, though these tools support compliance rather than guarantee it.
Jurisdictional scope
Requirements differ by regime. In the EU and UK, an opt-in consent model generally applies before behavioural advertising technologies are deployed. Under several US state privacy laws, such as the CCPA and CPRA in California, obligations often rely on an opt-out model, including mechanisms to honour signals such as Global Privacy Control.

Common questions

Answers to the questions practitioners most commonly ask about OBA.

Does obtaining cookie consent under the ePrivacy rules mean I can use the data for behavioural advertising without any further GDPR basis?
No. These are two distinct legal regimes and satisfying one does not automatically satisfy the other. The ePrivacy Directive (and its national implementations) governs the placing of and access to information stored on a user's device, such as cookies, pixels, or SDKs used for behavioural advertising. The GDPR separately governs the processing of any personal data that follows, including profiling users to serve targeted ads. In most EU jurisdictions you need to address both the device-access step and a lawful basis for the subsequent processing, and consent for one is not treated as consent for the other. Where these interact remains subject to evolving guidance from data protection authorities.
Is behavioural advertising treated the same way everywhere, so a single opt-out approach will work globally?
No. Obligations vary significantly between jurisdictions. In most EU jurisdictions and the UK, behavioural advertising typically requires prior, opt-in consent that is freely given, specific, informed, and unambiguous, given the non-essential nature of the tracking involved. By contrast, several US state privacy frameworks, such as the CCPA and CPRA in California, often rely on an opt-out model, including opt-outs for targeted advertising and the sale or sharing of personal information. Because the underlying standards differ, a single approach designed for one regime may not meet the requirements of another, and you should scope any practice to the specific jurisdictions in which you operate.
How should the consent request for behavioural advertising cookies be presented on my site?
In most EU jurisdictions, consent for behavioural advertising should be sought through a clear affirmative action before the relevant cookies, pixels, or similar technologies are placed. This generally means no pre-ticked boxes, no reliance on continued browsing as implied consent, and a genuine choice to refuse that is as accessible as the choice to accept. Cookie walls that condition access on acceptance are widely considered problematic in the EU. The specific presentation that will be considered valid depends on facts and on evolving regulatory guidance, so legal review of your particular banner and flow is advisable.
What technologies beyond cookies do I need to account for when configuring behavioural advertising controls?
Behavioural advertising frequently relies on technologies other than cookies, including tracking pixels, local storage, mobile SDKs, and device fingerprinting. In the EU, these generally fall within the same rules governing access to and storage of information on a user's device, even though they are not literally cookies. When implementing consent controls, you should ensure your consent management platform accounts for these technologies and that they are not activated before consent is obtained where consent is required. A tool can support this but does not by itself guarantee compliance.
Can a consent management platform or the IAB Transparency and Consent Framework handle behavioural advertising consent for me?
A consent management platform (CMP), and frameworks such as the IAB Transparency and Consent Framework (TCF), can help structure how consent for behavioural advertising is collected, communicated to advertising partners, and logged. However, these tools support compliance rather than replace legal judgment. You remain responsible for how the CMP is configured, whether the choices presented meet the applicable consent standard in each relevant jurisdiction, and whether your record-keeping is adequate. Configuration errors or overly broad default signals can undermine the validity of consent regardless of the tool used.
What records should I keep about consent for behavioural advertising, and how do signals like Global Privacy Control fit in?
For behavioural advertising, it is generally advisable to maintain consent logs that record whether, when, and on what basis a user consented or refused, to help demonstrate accountability where required. Separately, signals such as Global Privacy Control communicate a user's opt-out preference and are relevant chiefly under frameworks that operate on an opt-out model, such as certain US state privacy laws, rather than under the EU opt-in standard. How you honour such signals depends on which jurisdictions apply to your users, and the precise expectations continue to develop through regulatory guidance.

Common misconceptions

Behavioural advertising only involves cookies, so blocking cookies stops it.
Behavioural advertising may also rely on pixels, local storage, mobile SDKs, and fingerprinting. In the EU these similar technologies generally fall within the same ePrivacy and GDPR rules, so addressing cookies alone does not necessarily cover all tracking used for targeting.
If a user continues browsing or a pre-ticked box is used, valid consent for behavioural advertising has been obtained.
In most EU jurisdictions, implied consent from continued browsing and pre-ticked boxes are widely considered non-compliant. Valid consent generally requires a clear affirmative action and must be freely given, specific, informed, and unambiguous.
Consent rules for behavioural advertising are the same everywhere.
Obligations vary by jurisdiction. The EU and UK generally require opt-in consent before deploying behavioural advertising technologies, whereas several US state laws such as the CCPA and CPRA often rely on opt-out mechanisms. Claims about lawfulness should always state their geographic and legal scope.

Best practices

Classify advertising cookies and similar technologies separately from strictly necessary ones, and do not deploy behavioural advertising trackers before obtaining consent where consent is required in the applicable EU or UK jurisdiction.
Obtain consent through a clear affirmative action that is freely given, specific, informed, and unambiguous, avoiding pre-ticked boxes, implied consent from continued browsing, and reliance on cookie walls in EU contexts.
Map the full range of tracking technologies used for targeting, including pixels, local storage, SDKs, and fingerprinting, since these generally fall within the same rules as cookies in the EU.
Tailor consent mechanisms to each applicable regime, applying an opt-in approach in the EU and UK while supporting opt-out signals such as Global Privacy Control where US state laws like the CCPA and CPRA apply.
Use a consent management platform and, where relevant, frameworks such as the IAB TCF to collect and communicate consent, while recognising that such tools support but do not replace legal judgment or guarantee compliance.
Maintain records of consent and configuration decisions to support accountability and demonstrate the basis for deploying behavioural advertising technologies, and seek legal advice on contested or evolving points rather than assuming a single practice is lawful everywhere.