Answers to the questions practitioners most commonly ask about LSO.
Are Flash cookies exempt from consent because they are a different technology from standard HTTP cookies?
No. Although Flash cookies (Local Shared Objects) are stored by the Adobe Flash Player rather than by the browser's ordinary cookie mechanism, EU rules on storing or accessing information on a user's device are generally technology-neutral. In most EU jurisdictions the ePrivacy rules apply to Flash cookies in the same way they apply to standard cookies, pixels, local storage, and similar technologies. The relevant question is typically the purpose (for example analytics or advertising) rather than the storage format. It is also worth noting that Adobe Flash Player reached end-of-life on 31 December 2020, so Flash cookies are now largely obsolete and encountering them in current deployments is uncommon.
Does deleting browser cookies also remove Flash cookies?
Not necessarily. Flash cookies were historically stored separately from browser cookies, so clearing cookies through browser settings did not always delete Local Shared Objects. This separation is one reason Flash cookies were sometimes associated with so-called respawning, where deleted browser cookies were restored from a Flash-stored copy. Such practices raise concerns under both the ePrivacy rules on device access and, where personal data is involved, the GDPR. Because Adobe Flash Player reached end-of-life on 31 December 2020, this persistence issue is now largely historical, though legacy systems may still warrant review.
How should we handle Flash cookies during a cookie audit of an existing site?
Given that Adobe Flash Player reached end-of-life on 31 December 2020 and modern browsers no longer support it, most current audits will not find active Flash cookies. However, an audit may still identify legacy code, references, or documentation referring to Local Shared Objects. Where such references are found, the practical step is generally to confirm whether any Flash-dependent functionality remains and, if so, to plan its removal or migration. Any historic consent records or data collected via Flash cookies should be reviewed against your current retention and record-keeping obligations. This is a factual and technical exercise; specific compliance conclusions will depend on your circumstances and applicable jurisdiction.
If our legacy application still references Flash cookies, what are the implementation options?
Because the Flash Player is at end-of-life and unsupported by current browsers, the typical implementation path is to migrate any functionality that previously relied on Flash cookies to supported alternatives, such as standard cookies or browser local storage, and to remove obsolete Flash code. Whichever mechanism replaces it will generally fall under the same consent and disclosure rules, so the replacement should be integrated with your consent management platform and classified by purpose. This entry does not prescribe a specific technical migration approach; that will depend on your architecture and should be assessed alongside legal and security input.
Should a consent management platform (CMP) still account for Flash cookies?
In most current deployments a CMP will not need to manage Flash cookies, since the Flash Player reached end-of-life on 31 December 2020 and is no longer supported. Where legacy systems are involved, any storage technology that persists information on or reads it from a user's device should in principle be brought within the scope of the CMP and classified by purpose. A CMP supports consent management but does not by itself guarantee compliance; legal judgment remains necessary to determine how any residual technologies are treated.
What should we do about data or consent records historically collected through Flash cookies?
Historic data collected via Flash cookies should be treated like any other legacy personal data: reviewed for whether a valid basis existed, checked against your retention schedule, and deleted or documented accordingly. Consent logs from that period, if retained, may still be relevant to demonstrating past processing. Because the technology is now obsolete following the 31 December 2020 end-of-life of the Flash Player, the practical focus is usually remediation and documentation rather than ongoing collection. The appropriate action depends on facts not covered by this definition and may vary by jurisdiction, so specific advice should be sought where uncertainty exists.