Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Tracking Technologies

Conversion Tracking

Also known as: conversion measurement, goal tracking
Simply put

Conversion tracking is a method advertisers and website operators use to record when a user completes a desired action, such as making a purchase, signing up, or filling out a form, after seeing or clicking an advertisement. It helps businesses understand how well their marketing campaigns perform against their goals. Because it often relies on cookies, pixels, SDKs, or similar technologies that store or access information on a user's device, it typically triggers consent and data protection requirements in many jurisdictions.

Formal definition

Conversion tracking is the measurement of goal completions or specifically mapped data points attributed to media or campaign activity, evaluated against defined key performance indicators (KPIs). It commonly operates by placing a tag, pixel, cookie, SDK, or similar identifier that fires when a user reaches a designated event (for example a purchase or registration) and attributes that event back to a prior ad interaction, whether on the web or within mobile applications where a mobile measurement partner may perform the attribution. From a compliance standpoint, the technologies used to implement conversion tracking generally fall within the scope of the ePrivacy Directive's rules on storing or accessing information on a user's device, which in most EU jurisdictions require prior consent because such tracking is typically not strictly necessary; any resulting processing of personal data separately engages the GDPR. Requirements differ outside the EU, for example under US state privacy laws such as the CCPA and CPRA in California, which often rely on opt-out rather than opt-in mechanisms. This definition describes the concept and general legal context only; the lawfulness of a specific implementation depends on facts, jurisdiction, and the technologies involved that are outside the scope of this entry.

Why it matters

Conversion tracking sits at the heart of digital advertising measurement, allowing businesses to attribute completed actions such as purchases, sign-ups, or form submissions back to specific campaigns and to evaluate performance against their key performance indicators. Because it typically relies on cookies, pixels, SDKs, or similar identifiers that store or access information on a user's device, it generally falls within the scope of the ePrivacy Directive's rules in the EU, which in most EU jurisdictions require prior consent for tracking that is not strictly necessary. Any personal data processed as part of that tracking separately engages the GDPR, meaning organisations may need both a valid consent basis for the device access and a lawful basis and transparency for the processing that follows.

For compliance teams, this dual layer is a frequent source of risk. Conversion tracking is rarely essential to delivering the service a user requested, so treating it as exempt from consent can expose an operator to enforcement in EU jurisdictions where analytics and advertising technologies are expected to be consent-gated. The obligations differ outside the EU: US state privacy laws such as the CCPA and CPRA in California often rely on opt-out rather than opt-in mechanisms, so an implementation that is lawful in one jurisdiction may not meet requirements in another. Because enforcement positions and regulatory guidance continue to evolve, organisations generally cannot assume a single global approach to conversion tracking will satisfy every applicable regime.

The lawfulness of any specific deployment depends on facts that fall outside a general definition, including the technologies used, whether identifiers are shared with third parties, and the jurisdictions in which users are located. This entry describes the concept and its general legal context and does not resolve those fact-specific questions.

Who it's relevant to

Marketing and advertising compliance teams
These teams rely on conversion tracking to measure campaign performance against KPIs, but must ensure that the pixels, tags, and SDKs used are only activated where a valid legal basis exists. In most EU jurisdictions this generally means obtaining prior consent before firing conversion tags, while US state laws such as the CCPA and CPRA in California may instead require honouring opt-out mechanisms.
Privacy officers and data protection professionals
Conversion tracking typically raises both ePrivacy questions, concerning access to a user's device, and GDPR questions, concerning any resulting processing of personal data. Privacy professionals need to assess both layers separately and cannot assume that satisfying one automatically satisfies the other, particularly where identifiers are shared with advertising partners.
Web and mobile developers
Developers implement the tags, pixels, cookies, and SDKs that make conversion tracking function, including integrations with mobile measurement partners that perform attribution within apps. They generally need to ensure these technologies are gated behind consent signals where required and do not fire before a user's choice has been captured.
Legal counsel
Because the lawfulness of a specific conversion tracking implementation depends on the technologies involved, how data is shared, and the applicable jurisdiction, legal counsel is often needed to interpret whether consent, opt-out, or another mechanism applies. Given that regulatory guidance and enforcement positions continue to evolve, counsel can help organisations avoid treating one jurisdiction's rules as universal.

Inside Conversion Tracking

Tracking mechanism
The technical means by which a conversion is attributed, often a pixel, tag, SDK, or script placed by an advertising or analytics provider. These technologies frequently store or access information on the user's device and may set cookies or use local storage, bringing them within the scope of the ePrivacy Directive and its national implementations in the EU.
Conversion event
The user action being measured, such as a purchase, form submission, sign-up, or download. Defining which events count as conversions is a configuration decision made by the site operator or advertiser.
Attribution logic
The method used to connect a conversion back to a prior interaction, such as a click on an advertisement. Attribution may rely on cookies, device identifiers, or other signals, and the specific approach affects both accuracy and the legal analysis of what data is processed.
Personal data processing
Where conversion tracking involves identifiers or data that relate to an identifiable individual, the GDPR applies to that processing in addition to any ePrivacy consent obligation. The two regimes address distinct questions: the placing of or access to information on a device, and the subsequent processing of personal data.
Data sharing with third parties
Conversion tracking often transmits data to advertising platforms or measurement vendors, which may act as processors or independent controllers depending on the arrangement. This transfer typically requires an appropriate lawful basis and, in most EU jurisdictions, prior consent for the underlying storage or access.

Common questions

Answers to the questions practitioners most commonly ask about Conversion Tracking.

Does conversion tracking count as a "strictly necessary" function that is exempt from consent?
Generally no. Conversion tracking is used to measure the effectiveness of advertising or marketing activity, which is typically treated as a marketing or analytics purpose rather than something strictly necessary to deliver a service the user has requested. In most EU jurisdictions, the placing of and access to information on the user's device for conversion tracking therefore requires prior consent under the ePrivacy rules, and any resulting processing of personal data must also have a lawful basis under the GDPR. The exemption for strictly necessary cookies is narrow, and conversion measurement generally falls outside it. Whether a specific implementation could ever qualify depends on the facts and on the position of the relevant data protection authority, so this should not be assumed.
If conversion tracking uses a pixel or SDK rather than a cookie, do the consent rules still apply?
Yes, in most cases. The ePrivacy rules in the EU apply to the storing of information on, or gaining access to information already stored on, a user's device, regardless of the specific technology used. Tracking pixels, local storage, software development kits (SDKs), and similar mechanisms generally fall within the same requirements as cookies where they involve storing or accessing information on the device. The label attached to the technology does not change the analysis. Any associated processing of personal data is also subject to the GDPR. Requirements differ under other frameworks, such as certain US state privacy laws, so scope should be confirmed for the jurisdictions in which you operate.
How should conversion tracking be configured to respect a user's consent choices?
A common approach in the EU is to withhold the loading or firing of conversion tracking tags until the user has given valid consent through a clear affirmative action, and to suppress that tracking where consent is refused or withdrawn. This is often managed through a consent management platform (CMP) that gates tag execution based on the user's recorded preferences. Consent must be specific and informed for the relevant purpose, so bundling conversion tracking with unrelated purposes may undermine validity. Tools can support this configuration but do not by themselves guarantee compliance, and legal judgment about purposes and lawful bases remains necessary.
What should be documented to demonstrate that conversion tracking is consent-compliant?
Where consent is the basis for conversion tracking, organizations generally maintain records showing that consent was obtained, including what the user was told, which purposes they agreed to, and when. Consent logging maintained through a CMP can support this record-keeping, and it is often useful to record when tracking was suppressed for users who declined. The specific record-keeping expectations depend on the applicable framework and on guidance from the relevant data protection authority, which can evolve. This definition does not address the full scope of accountability obligations, which should be assessed against the requirements applicable to your operations.
How does conversion tracking interact with signals such as Global Privacy Control or opt-out mechanisms in the US?
Requirements differ by jurisdiction. In the EU, the general model is opt-in consent before conversion tracking is placed or accessed. Under several US state privacy laws, the model is often opt-out, and mechanisms such as the Global Privacy Control (GPC) may be relevant where a jurisdiction requires businesses to honor opt-out preference signals. How conversion tracking must respond to such signals depends on the specific state law and its scope. Because obligations vary between the EU, the UK, and individual US states, the applicable rules should be determined for each jurisdiction rather than assumed to be uniform.
What happens to conversion tracking when a user withdraws consent?
Where conversion tracking relies on consent, withdrawal should generally be as easy as giving it, and tracking should stop for that user going forward once consent is withdrawn. In practice this typically means the CMP updates the user's recorded preference and the relevant tags are no longer fired. Withdrawal does not necessarily require deletion of data already lawfully collected, though other obligations under the GDPR, such as data subject rights, may apply to that data. The precise handling depends on the applicable framework and on facts not covered by this definition, so specific retention and deletion practices should be assessed separately.

Common misconceptions

Conversion tracking is essential to running a website, so it qualifies as a strictly necessary technology exempt from consent.
In most EU jurisdictions, the exemption for strictly necessary cookies is interpreted narrowly and applies to what is essential to provide a service the user has requested. Conversion tracking generally serves the operator's marketing and measurement purposes rather than the user's requested service, so it typically requires prior consent under the ePrivacy rules. Whether an exemption applies depends on the specific facts.
If a conversion pixel does not set a cookie, no consent is needed.
The ePrivacy rules apply to storing or gaining access to information on a user's device regardless of the specific technology. Pixels, local storage, SDKs, and fingerprinting can fall within the same requirements as cookies. The absence of a literal cookie does not by itself remove the need for consent, and any associated personal data processing remains subject to the GDPR.
Consent requirements for conversion tracking are the same everywhere.
Obligations vary by jurisdiction. In the EU, valid consent must generally be freely given, specific, informed, and unambiguous and obtained before non-exempt tracking. Several US state frameworks, such as those in California, more commonly rely on an opt-out model. The applicable scope should be assessed for each region where users are located.

Best practices

Map every conversion tracking technology in use, including pixels, tags, SDKs, and any local storage, and document whether each stores or accesses information on the user's device.
Treat non-exempt conversion tracking as requiring prior consent in EU jurisdictions, and configure it so that tracking does not fire until a clear affirmative action has been recorded, avoiding pre-ticked boxes or reliance on continued browsing.
Separately analyze the GDPR lawful basis for any personal data processing that follows, rather than assuming that ePrivacy consent alone resolves all obligations.
Clarify the roles of advertising and measurement vendors, distinguishing processors from independent controllers, and ensure appropriate agreements and disclosures are in place.
Adjust consent handling by jurisdiction, applying opt-in approaches where required in the EU and UK and honoring opt-out mechanisms, including recognized signals, where applicable under US state frameworks.
Maintain records of consent and configuration decisions to support accountability, while recognizing that a consent management platform supports compliance but does not replace legal judgment or guarantee it.
Promotional banner for the Penetration Report Template Kit