Cross-Device Tracking
Cross-device tracking is a set of technologies that let companies follow and link a person's activity across the different devices they use, such as smartphones, tablets, laptops, computers, and smart TVs. By connecting these separate signals, organizations can build a unified profile of a single user or household and, for example, tie an advertisement seen on one device to activity on another. Because this involves identifying and profiling individuals, it typically raises consent and data protection considerations under EU and other privacy regimes.
Cross-device tracking refers to methods for identifying and connecting the activity of the same user or household across multiple devices (smartphones, tablets, laptops, personal computers, smart TVs, and similar endpoints) to create a unified profile and to attribute exposures, such as ad impressions, to a common identity. Techniques may rely on deterministic identifiers (for example, logged-in accounts or shared authentication) or probabilistic matching (for example, correlating IP addresses, device characteristics, or behavioral patterns), and can involve cookies as well as related technologies such as pixels, SDKs, local storage, and device fingerprinting. Where such technologies place or access information on a user's device, the ePrivacy rules implemented across EU member states generally apply, and any resulting processing of personal data is separately governed by the GDPR; obligations differ under the UK regime and under US state laws such as the CCPA/CPRA, which more commonly rely on opt-out mechanisms. The specific lawful basis, consent requirements, and permissibility of a given cross-device method depend on facts not addressed here, including the identification technique used and the jurisdiction, and remain subject to evolving regulatory guidance.
Why it matters
Cross-device tracking sits at the intersection of two distinct legal regimes, and understanding that distinction is essential for compliance. The techniques used to link a person's activity across devices frequently involve placing or accessing information on those devices, which in most EU member states falls under the ePrivacy rules and generally requires prior consent for non-essential purposes. Separately, because these methods identify and profile individuals or households, any resulting handling of personal data is governed by the GDPR, which requires a valid lawful basis. Consent obtained for one does not automatically satisfy the other, and organizations should not assume that a single consent banner discharges both sets of obligations.
The compliance stakes are heightened by the profiling nature of the activity. Connecting disparate signals into a unified profile of an individual or household is precisely the kind of processing that data protection authorities tend to scrutinize, particularly where probabilistic matching techniques such as device fingerprinting or IP correlation are used without the user's awareness. Where consent is the applicable basis under EU law, it must be freely given, specific, informed, and unambiguous, which typically rules out pre-ticked boxes and implied consent from continued browsing.
Obligations also vary by jurisdiction, so a cross-device program lawful in one region may not be permissible in another. The UK operates its own implementation of these rules, and US state laws such as the CCPA and CPRA more commonly rely on opt-out mechanisms rather than the opt-in consent standard prevalent in the EU. Because the permissibility of a given method depends heavily on the specific identification technique and the applicable jurisdiction, and because regulatory guidance in this area continues to evolve, teams should treat cross-device tracking as a fact-specific compliance question rather than a settled practice.
Who it's relevant to
Inside Cross-Device Tracking
Common questions
Answers to the questions practitioners most commonly ask about Cross-Device Tracking.

