Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Google Consent Mode

Conversion Modeling

Also known as: Conversion Model, Conversion Modelling
Simply put

Conversion modeling is a technique used in digital marketing to estimate conversions that cannot be directly observed or attributed, often because users declined cookies or tracking. Instead of counting every conversion individually, platforms use machine learning to predict the likely number of conversions based on historical campaign data and observable patterns. It is a way to fill measurement gaps rather than a direct count of what actually happened.

Formal definition

Conversion modeling refers to the use of predictive or machine learning algorithms, notably by platforms such as Meta and Google, to estimate conversions on traffic that cannot be directly attributed. In the consent context, this typically arises when users object to or decline cookies and tracking, leaving observed conversion data incomplete; models trained on historical campaign data infer the missing conversions. Because modeled conversions are statistical estimates rather than measured events, outputs are subject to accuracy limitations and drift over time, and the underlying data collection remains governed by applicable consent and data protection requirements. Note that the evidence describes marketing measurement functionality and does not establish that conversion modeling itself resolves or substitutes for consent obligations; the lawfulness of collecting or processing the input data depends on the relevant ePrivacy and GDPR (or equivalent) rules in the applicable jurisdiction and is out of scope of this definition.

Why it matters

As consent requirements under the ePrivacy Directive and GDPR in the EU, the UK's implementation, and various US state laws have made cookie-based tracking less comprehensive, advertisers face growing gaps in their conversion measurement. When users decline cookies or object to tracking, the conversions those users complete become unobservable through direct attribution. Conversion modeling has emerged as the way platforms such as Meta and Google attempt to fill these gaps, which matters to marketing and analytics teams who still need to assess campaign performance despite incomplete observed data.

The practical significance is that reported conversion figures increasingly reflect a mix of directly measured events and statistically estimated ones. Privacy officers and compliance teams should understand that modeled conversions are predictions rather than counts of what actually happened, and that these estimates are subject to accuracy limitations and can drift over time as underlying patterns change. Treating modeled figures as if they were precise measured results can lead to misplaced confidence in performance data.

Critically, conversion modeling addresses a measurement problem, not a compliance one. It does not resolve or substitute for consent obligations. The lawfulness of collecting and processing the input data that feeds these models still depends on the applicable ePrivacy and data protection rules in the relevant jurisdiction. Teams should not assume that because a platform can model missing conversions, the underlying data collection is compliant; those are separate questions that require independent legal judgment.

Who it's relevant to

Marketing and Analytics Teams
These teams rely on conversion modeling to assess campaign performance when consent-related gaps make direct attribution incomplete. They should interpret modeled figures as estimates rather than exact counts, remain aware that model accuracy can drift over time, and avoid overstating certainty when reporting results derived partly from predicted conversions.
Privacy Officers and Data Protection Professionals
This group should recognize that conversion modeling is a measurement technique and does not resolve consent obligations. The lawfulness of collecting and processing the input data still depends on applicable ePrivacy and GDPR (or equivalent) rules in the relevant jurisdiction, and requirements differ between the EU, the UK, and individual US states such as under the CCPA and CPRA.
Legal Counsel and Compliance Teams
Counsel may need to advise on whether the data feeding a conversion model was lawfully collected, particularly where users declined cookies or objected to tracking. Because enforcement positions and regulatory guidance continue to evolve, and because interpretations vary by jurisdiction, the use of modeled conversions should not be treated as evidence that the underlying data practices are compliant.
Web Developers and Ad Platform Implementers
Those configuring platform measurement tools should understand where conversion modeling is applied and how it interacts with consent signals and tag deployment. Enabling a platform's modeling functionality supports measurement continuity but does not replace the need to ensure that data collection respects the applicable consent framework.

Inside Conversion Modeling

Modeled conversions
Estimated conversion outcomes generated through statistical or machine-learning techniques rather than directly observed and attributed to individual users. Conversion modeling fills gaps in measurement that arise when direct tracking is unavailable, for example where a user has declined consent for analytics or advertising cookies, or where identifiers are otherwise limited.
Consent-driven measurement gaps
In most EU and UK contexts, analytics and advertising cookies typically require prior, freely given, specific, informed, and unambiguous consent under the ePrivacy rules and the GDPR. When users decline, conversions cannot lawfully be observed through those technologies, creating gaps that modeling attempts to estimate. The scope of what may be measured therefore depends on the consent choices actually collected.
Aggregated and inferred data inputs
Conversion modeling generally relies on aggregated, observed conversion data (from consented users or other lawful sources) to infer likely outcomes for the unobserved population. The specific inputs and methods vary by vendor and configuration, and the details are often not fully disclosed to the parties using the modeled outputs.
Relationship to legal regimes
The ePrivacy rules govern whether information may be placed on or read from a user's device (for example via cookies, pixels, SDKs, or local storage), while the GDPR governs any subsequent processing of personal data. Conversion modeling sits downstream of these obligations: it does not remove the need for a lawful basis to place tracking technologies or to process any personal data used as inputs.
Jurisdictional scope
The relevance and permissibility of conversion modeling depend on the applicable regime. EU and UK frameworks generally require opt-in consent for the underlying analytics and advertising technologies, whereas several US state laws (such as the CCPA and CPRA in California) typically rely on an opt-out model. This affects how much data is observed directly versus estimated.

Common questions

Answers to the questions practitioners most commonly ask about Conversion Modeling.

Does conversion modeling let us track individual users without consent?
No. Conversion modeling is designed precisely because individual-level tracking is unavailable, typically due to absent consent, blocked cookies, or platform restrictions. It uses aggregated and observed data to estimate conversions that cannot be directly measured, rather than identifying or tracking specific individuals. However, the fact that outputs are modeled does not automatically remove all compliance obligations: the underlying inputs may still involve processing personal data, and the placing of cookies or similar technologies used to collect observed conversions generally still requires consent under the ePrivacy rules in most EU jurisdictions. Whether any given implementation avoids processing personal data depends on the specific data flows, which fall outside what a general definition can determine.
If a conversion is modeled rather than directly measured, does that mean the GDPR and ePrivacy rules no longer apply?
Not necessarily. The use of statistical modeling to estimate results does not, by itself, place an activity outside the scope of EU data protection and ePrivacy law. The ePrivacy Directive and its national implementations govern the placing of and access to information on a user's device, so any cookies, pixels, SDKs, or similar technologies feeding the model generally require prior consent where they are not strictly necessary. Separately, the GDPR governs any processing of personal data used to build or train the model. Aggregation and modeling may reduce the personal data footprint in some cases, but whether the outputs or inputs constitute personal data is a fact-specific question that depends on identifiability and the details of the implementation.
How does conversion modeling interact with our consent management platform (CMP)?
A CMP typically captures and signals user consent choices, which then determine whether observed conversion data can be collected via cookies or similar technologies. Conversion modeling generally operates on the subset of conversions that are directly measured under valid consent, plus available aggregated signals, to estimate the conversions that could not be observed. The CMP does not perform the modeling itself; that generally occurs within analytics or advertising platforms. It is important to note that a CMP supports compliance by managing and logging consent but does not by itself guarantee that a modeling implementation is lawful, which remains a matter of legal judgment based on the specific data used.
What records should we keep about conversion modeling for compliance purposes?
Organizations generally maintain consent logs demonstrating that observed conversion data was collected on the basis of valid consent where required, along with documentation of which technologies were used and their categorization. Where personal data is processed as an input to modeling, record-keeping obligations under the GDPR, such as records of processing activities, may apply. Because conversion modeling is often carried out by third-party platforms, it is also common to document the roles of the parties and the contractual arrangements governing the data. The precise records needed depend on the jurisdiction and the facts of the implementation, and this definition does not prescribe a definitive checklist.
Does conversion modeling behave the same way across the EU, the UK, and US states?
No. The legal context differs by jurisdiction. In most EU jurisdictions and the UK, the collection of observed conversion data through non-essential cookies or similar technologies typically requires prior opt-in consent, which affects how much measured data is available to feed a model. Several US state privacy frameworks, such as the CCPA and CPRA in California, generally rely on an opt-out model rather than opt-in, which can change the volume and nature of available signals. As a result, the proportion of conversions that must be modeled versus directly observed may vary by region. Implementers should assess each jurisdiction separately rather than assuming a single approach applies everywhere.
Can we treat modeled conversions as equivalent to directly measured conversions when reporting results?
Modeled conversions are estimates rather than direct observations, so they carry inherent uncertainty and should generally be understood as approximations of unmeasured activity. Teams often distinguish measured from modeled conversions in reporting to preserve transparency about how figures are derived. From a compliance standpoint, the key point is that labeling a conversion as modeled does not resolve questions about the lawfulness of the underlying data collection, which depends on whether consent and other obligations were satisfied for the observed inputs. The accuracy and appropriate use of modeled figures for a given business or regulatory purpose fall outside the scope of this definition.

Common misconceptions

Conversion modeling lets you recover data from users who declined consent, so it is a workaround for consent requirements.
Modeling produces estimates; it does not observe or reconstruct individual behavior for users who declined consent. It also does not create a lawful basis to place tracking technologies or to process personal data. In most EU and UK contexts, the consent obligations under the ePrivacy rules and the GDPR continue to apply regardless of whether modeling is used, and modeling inputs must themselves be lawfully obtained.
Because modeled conversions are aggregated or estimated, no personal data is involved and privacy rules do not apply.
Whether personal data is involved depends on the inputs and methods used. The data feeding a model, and any identifiers or device signals used to generate estimates, may constitute personal data subject to the GDPR, and the technologies used to collect that data are generally subject to the ePrivacy rules. The presence of aggregation in the output does not by itself remove upstream obligations.
Enabling a vendor's conversion modeling feature makes measurement compliant.
A modeling feature is a tool, not a compliance guarantee. Its outputs do not substitute for a valid consent mechanism, a lawful basis, or proper record-keeping. Compliance depends on how the underlying technologies are deployed and on legal judgment applied to the specific facts and jurisdictions, not on activating a feature.

Best practices

Confirm that any data feeding a conversion model was collected on a lawful basis, including valid consent for analytics or advertising cookies where required under the ePrivacy rules and the GDPR in the EU and UK.
Do not treat conversion modeling as a substitute for a compliant consent mechanism; ensure consent is freely given, specific, informed, and unambiguous where opt-in applies, and honor opt-out signals such as Global Privacy Control where relevant under US state laws.
Document the geographic and legal scope of your measurement setup, recognizing that EU and UK opt-in expectations differ from the opt-out approach common under laws such as the CCPA and CPRA.
Assess whether the inputs to your modeling constitute personal data and, if so, address the corresponding GDPR obligations rather than assuming aggregated outputs exempt the processing.
Maintain consent and configuration records so you can demonstrate what was observed directly versus estimated, and retain evidence of the choices users actually made.
Seek qualified legal advice on contested points, since regulatory guidance on modeling and the treatment of its inputs may be unsettled and can evolve across jurisdictions.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide