Floodlight Tags
Floodlight tags are pieces of tracking code, provided by Google's Campaign Manager 360 and related advertising platforms, that businesses place on their websites to record when a user completes an action such as a purchase or sign-up after seeing or clicking an ad. They typically work together with cookies to connect these actions back to specific ad campaigns. Because they track user activity and may involve reading or storing information on a user's device, they generally fall within the scope of cookie consent and privacy rules in many jurisdictions.
Floodlight tags are HTML- and JavaScript-based tracking snippets used within Google's Campaign Manager 360 (formerly DoubleClick) and DV360 ecosystems to measure conversions, revenue, and post-click or post-impression user actions attributed to advertising campaigns. Each tag is customized with account authentication identifiers and, per the evidence, works in conjunction with cookies to attribute conversions across user journeys. As a tracking technology that involves the setting and reading of cookies or similar identifiers on a user's device, Floodlight tags generally engage the ePrivacy Directive's rules on storing or accessing information on terminal equipment in most EU jurisdictions, typically requiring prior consent, while any resulting processing of personal data separately engages the GDPR. Requirements differ under other regimes, such as US state privacy laws that often rely on opt-out mechanisms. This definition describes the technology at a general level; specific consent obligations, configuration options, and the classification of the cookies involved depend on implementation details and applicable jurisdictional guidance not addressed in the evidence.
Why it matters
Floodlight tags sit at the intersection of advertising performance measurement and privacy compliance. Because they record when users complete actions such as purchases or sign-ups after seeing or clicking an ad, and because they typically rely on cookies or similar identifiers to attribute those actions back to campaigns, they generally count as non-essential tracking technologies. In most EU jurisdictions this means that placing and reading such identifiers on a user's device engages the ePrivacy Directive's rules and typically requires prior consent, while any processing of personal data that follows separately engages the GDPR. Organizations that deploy Floodlight tags without addressing these obligations may find that a core part of their conversion measurement rests on a questionable legal footing.
The practical significance is that Floodlight tags are frequently central to how marketing teams measure return on ad spend, so there is often commercial pressure to fire them as early and as broadly as possible. That pressure can conflict with the requirement, widely applied across the EU, that consent must be obtained before non-essential trackers are set. Firing a Floodlight tag before a user has given a clear affirmative signal, or firing it regardless of the user's choice, is the kind of practice that data protection authorities in the EU tend to scrutinize. The classification of the specific cookies involved and the exact consent obligations depend on implementation details not addressed here.
Requirements also differ by jurisdiction, and treating one regime's rules as universal is a common source of compliance error. Under several US state privacy laws, for example, obligations often center on offering an opt-out and honoring signals such as Global Privacy Control, rather than requiring opt-in consent before tracking begins. An organization operating across the EU, the UK, and multiple US states may therefore need different configurations of when and how Floodlight tags fire for different audiences, rather than a single global approach.
Who it's relevant to
Inside Floodlight Tags
Common questions
Answers to the questions practitioners most commonly ask about Floodlight Tags.