Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Tracking Technologies

Cross-Device Tracking

Also known as: Cross-Device Measurement
Simply put

Cross-device tracking is a set of technologies that let companies follow and link a person's activity across the different devices they use, such as smartphones, tablets, laptops, computers, and smart TVs. By connecting these separate signals, organizations can build a unified profile of a single user or household and, for example, tie an advertisement seen on one device to activity on another. Because this involves identifying and profiling individuals, it typically raises consent and data protection considerations under EU and other privacy regimes.

Formal definition

Cross-device tracking refers to methods for identifying and connecting the activity of the same user or household across multiple devices (smartphones, tablets, laptops, personal computers, smart TVs, and similar endpoints) to create a unified profile and to attribute exposures, such as ad impressions, to a common identity. Techniques may rely on deterministic identifiers (for example, logged-in accounts or shared authentication) or probabilistic matching (for example, correlating IP addresses, device characteristics, or behavioral patterns), and can involve cookies as well as related technologies such as pixels, SDKs, local storage, and device fingerprinting. Where such technologies place or access information on a user's device, the ePrivacy rules implemented across EU member states generally apply, and any resulting processing of personal data is separately governed by the GDPR; obligations differ under the UK regime and under US state laws such as the CCPA/CPRA, which more commonly rely on opt-out mechanisms. The specific lawful basis, consent requirements, and permissibility of a given cross-device method depend on facts not addressed here, including the identification technique used and the jurisdiction, and remain subject to evolving regulatory guidance.

Why it matters

Cross-device tracking sits at the intersection of two distinct legal regimes, and understanding that distinction is essential for compliance. The techniques used to link a person's activity across devices frequently involve placing or accessing information on those devices, which in most EU member states falls under the ePrivacy rules and generally requires prior consent for non-essential purposes. Separately, because these methods identify and profile individuals or households, any resulting handling of personal data is governed by the GDPR, which requires a valid lawful basis. Consent obtained for one does not automatically satisfy the other, and organizations should not assume that a single consent banner discharges both sets of obligations.

The compliance stakes are heightened by the profiling nature of the activity. Connecting disparate signals into a unified profile of an individual or household is precisely the kind of processing that data protection authorities tend to scrutinize, particularly where probabilistic matching techniques such as device fingerprinting or IP correlation are used without the user's awareness. Where consent is the applicable basis under EU law, it must be freely given, specific, informed, and unambiguous, which typically rules out pre-ticked boxes and implied consent from continued browsing.

Obligations also vary by jurisdiction, so a cross-device program lawful in one region may not be permissible in another. The UK operates its own implementation of these rules, and US state laws such as the CCPA and CPRA more commonly rely on opt-out mechanisms rather than the opt-in consent standard prevalent in the EU. Because the permissibility of a given method depends heavily on the specific identification technique and the applicable jurisdiction, and because regulatory guidance in this area continues to evolve, teams should treat cross-device tracking as a fact-specific compliance question rather than a settled practice.

Who it's relevant to

Privacy officers and data protection professionals
Cross-device tracking involves profiling individuals or households by linking activity across endpoints, which typically triggers both ePrivacy consent considerations and GDPR obligations in the EU. These professionals need to assess the lawful basis, ensure the two regimes are addressed separately, and account for the heightened scrutiny that probabilistic matching techniques such as fingerprinting tend to attract.
Legal counsel
Because permissibility varies between the EU, the UK, and individual US states such as under the CCPA and CPRA, counsel must map cross-device methods to the applicable regime and flag where opt-in versus opt-out standards diverge. The specific identification technique and jurisdiction drive the analysis, and unresolved regulatory questions in this area warrant qualified advice rather than definitive assurances.
Web developers and engineers
Those implementing cross-device linking work with deterministic identifiers, probabilistic matching, and technologies including cookies, pixels, SDKs, local storage, and fingerprinting. They need to understand that placing or accessing information on a device generally engages ePrivacy rules, and to build systems that can honor consent and opt-out signals rather than assuming any technique is inherently permissible.
Marketing and advertising compliance teams
Cross-device measurement supports attributing ad exposures to a unified customer profile, but teams must ensure that consent or opt-out requirements are satisfied before linking activity across devices. Requirements differ by jurisdiction, so a program acceptable in one market may require adjustment in another, and tools alone do not guarantee compliance.

Inside Cross-Device Tracking

Deterministic matching
A method of linking a user's activity across multiple devices using persistent identifiers the user actively provides, such as login credentials, email addresses, or account IDs. Because it typically relies on identifiers that constitute personal data, the associated processing generally falls within the scope of the GDPR in the EU, and the placing or reading of any identifiers on the device is separately governed by the ePrivacy rules.
Probabilistic matching
A method that infers that separate devices belong to the same user by statistically analysing signals such as IP address, browser and device characteristics, and behavioural patterns. This often overlaps with fingerprinting techniques, which in most EU jurisdictions are treated the same as cookies for consent purposes even though no cookie is set.
Underlying technologies
Cross-device tracking may be implemented through cookies, pixels, mobile SDKs, local storage, and device or browser fingerprinting. The ePrivacy rules on storing or accessing information on a device apply to these techniques regardless of whether a literal cookie is used, and any resulting processing of personal data engages the GDPR.
Consent and legal basis
Where cross-device tracking is used for analytics, advertising, or profiling, prior consent is typically required in the EU and UK before identifiers are placed or accessed, and a valid GDPR legal basis is generally needed for the subsequent processing. Consent must generally be freely given, specific, informed, and unambiguous, and given by a clear affirmative action.
Jurisdictional scope
Obligations differ by region. In the EU and UK, opt-in consent is generally expected for non-essential tracking, while several US state frameworks such as the CCPA/CPRA in California typically rely on opt-out mechanisms. The applicable rules depend on where users are located and which regime applies.
Transparency obligations
Because linking devices can be non-obvious to users, disclosures typically need to explain that activity may be combined across devices and for what purposes. What level of detail is sufficient can depend on specific data protection authority guidance and remains subject to evolving interpretation.

Common questions

Answers to the questions practitioners most commonly ask about Cross-Device Tracking.

Is cross-device tracking only a concern when it uses cookies?
No. While cookies are one mechanism, cross-device tracking often relies on other technologies such as device identifiers, SDKs in mobile apps, pixels, local storage, and probabilistic techniques like fingerprinting. In most EU jurisdictions, the ePrivacy Directive's rules on storing or accessing information on a user's device apply to these technologies too, not only to cookies literally defined. To the extent the resulting linkage involves personal data, the GDPR also applies. You should therefore assess the full range of identifiers and methods, not just cookie-based ones.
Does obtaining consent on one device automatically cover tracking across a user's other devices?
Not necessarily. Consent under the GDPR must be specific and informed, which generally means users should understand that their activity may be linked across multiple devices. Consent captured in a single-device context may not clearly extend to cross-device linkage if that purpose was not disclosed. In most EU jurisdictions you would need to ensure the purposes presented at the point of consent adequately describe cross-device tracking. Whether a given implementation meets this standard depends on the specific facts and on evolving guidance from data protection authorities.
How should the purpose of cross-device tracking be described in a consent notice?
The description should be clear enough that a user understands their activity may be combined or linked across multiple devices, and for what purposes (for example, advertising or measurement). Because valid EU consent must be informed and specific, generic language about analytics or advertising may be insufficient if it does not convey the cross-device dimension. The exact wording that satisfies regulators can vary by jurisdiction and is subject to changing guidance, so legal review of notice language is advisable. This entry does not prescribe specific wording.
What records should be kept to demonstrate consent for cross-device tracking?
As with other consent-dependent processing, organizations generally maintain logs showing what was presented to the user, the choices made, and when. For cross-device tracking, it may also be relevant to record that the cross-device purpose was disclosed. Consent management platforms typically support this logging, but a tool does not by itself establish that the consent was valid or that the record-keeping meets a given regulator's expectations. Record-keeping obligations and their scope differ across the EU, UK, and other regimes.
How does cross-device tracking differ in opt-out jurisdictions such as certain US states?
Several US state privacy laws, such as those in California, generally rely on an opt-out model rather than the EU's prior opt-in consent, and some require honoring signals such as Global Privacy Control. This means the compliance posture for cross-device tracking can differ significantly by geography: prior opt-in may be expected in most EU jurisdictions, while an opt-out mechanism may be the relevant requirement elsewhere. You should map obligations to the applicable jurisdiction rather than applying one standard universally, and confirm current requirements against the relevant law.
Can a consent management platform ensure cross-device tracking is compliant?
A CMP can support compliance by capturing choices, presenting purposes, enforcing preferences, and maintaining consent logs, and frameworks such as the IAB TCF can help structure vendor and purpose disclosures. However, no tool guarantees compliance. Whether cross-device tracking is lawful depends on factors such as the adequacy of the disclosed purposes, the validity of the consent or applicable opt-out mechanisms, and the specific jurisdictions involved. These require legal judgment that a platform cannot replace.

Common misconceptions

Cross-device tracking is only a concern when cookies are used, so cookieless methods avoid consent requirements.
In most EU jurisdictions, techniques such as fingerprinting, SDKs, pixels, and local storage are treated the same way as cookies under the ePrivacy rules on storing or accessing information on a device. Avoiding literal cookies does not by itself remove consent obligations, and any resulting processing of personal data still engages the GDPR.
If a user consented to tracking on one device, that consent automatically covers linking their activity across all their devices.
Consent under the GDPR must generally be specific and informed. Combining data across devices is a distinct purpose that users may not expect, so consent obtained in a narrow context should not be assumed to extend automatically to cross-device linkage. The adequacy of any given consent depends on how it was presented and remains fact-specific.
The same cross-device tracking setup can be deployed globally because consent rules are broadly the same everywhere.
Requirements differ between the EU, the UK, and individual US states. EU and UK regimes generally expect opt-in consent for non-essential tracking, while frameworks such as the CCPA/CPRA in California often rely on opt-out. A single approach may not satisfy every applicable regime.

Best practices

Map every technology used for cross-device tracking, including cookies, pixels, SDKs, local storage, and fingerprinting, and assess each against both the ePrivacy rules on device access and the GDPR rules on processing personal data separately.
Where cross-device linkage is used for analytics, advertising, or profiling in the EU or UK, obtain prior consent through a clear affirmative action and avoid pre-ticked boxes, implied consent, or reliance on continued browsing.
Disclose plainly that user activity may be combined across devices and for what purposes, so that any consent can be considered specific and informed.
Determine the applicable jurisdictions based on user location and tailor mechanisms accordingly, recognising that EU and UK regimes generally expect opt-in while several US state laws rely on opt-out.
Maintain records of consent and of the identifiers and matching methods used, so decisions can be evidenced if a data protection authority requests them.
Use consent management tooling to support these obligations, but treat legal review as necessary because tools support compliance rather than guarantee it, and regulatory guidance in this area continues to evolve.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps