Skip to main content
Category: Tracking Technologies

Floodlight Tags

Also known as: DoubleClick Floodlight, Floodlight tracking tags
Simply put

Floodlight tags are pieces of tracking code, provided by Google's Campaign Manager 360 and related advertising platforms, that businesses place on their websites to record when a user completes an action such as a purchase or sign-up after seeing or clicking an ad. They typically work together with cookies to connect these actions back to specific ad campaigns. Because they track user activity and may involve reading or storing information on a user's device, they generally fall within the scope of cookie consent and privacy rules in many jurisdictions.

Formal definition

Floodlight tags are HTML- and JavaScript-based tracking snippets used within Google's Campaign Manager 360 (formerly DoubleClick) and DV360 ecosystems to measure conversions, revenue, and post-click or post-impression user actions attributed to advertising campaigns. Each tag is customized with account authentication identifiers and, per the evidence, works in conjunction with cookies to attribute conversions across user journeys. As a tracking technology that involves the setting and reading of cookies or similar identifiers on a user's device, Floodlight tags generally engage the ePrivacy Directive's rules on storing or accessing information on terminal equipment in most EU jurisdictions, typically requiring prior consent, while any resulting processing of personal data separately engages the GDPR. Requirements differ under other regimes, such as US state privacy laws that often rely on opt-out mechanisms. This definition describes the technology at a general level; specific consent obligations, configuration options, and the classification of the cookies involved depend on implementation details and applicable jurisdictional guidance not addressed in the evidence.

Why it matters

Floodlight tags sit at the intersection of advertising performance measurement and privacy compliance. Because they record when users complete actions such as purchases or sign-ups after seeing or clicking an ad, and because they typically rely on cookies or similar identifiers to attribute those actions back to campaigns, they generally count as non-essential tracking technologies. In most EU jurisdictions this means that placing and reading such identifiers on a user's device engages the ePrivacy Directive's rules and typically requires prior consent, while any processing of personal data that follows separately engages the GDPR. Organizations that deploy Floodlight tags without addressing these obligations may find that a core part of their conversion measurement rests on a questionable legal footing.

The practical significance is that Floodlight tags are frequently central to how marketing teams measure return on ad spend, so there is often commercial pressure to fire them as early and as broadly as possible. That pressure can conflict with the requirement, widely applied across the EU, that consent must be obtained before non-essential trackers are set. Firing a Floodlight tag before a user has given a clear affirmative signal, or firing it regardless of the user's choice, is the kind of practice that data protection authorities in the EU tend to scrutinize. The classification of the specific cookies involved and the exact consent obligations depend on implementation details not addressed here.

Requirements also differ by jurisdiction, and treating one regime's rules as universal is a common source of compliance error. Under several US state privacy laws, for example, obligations often center on offering an opt-out and honoring signals such as Global Privacy Control, rather than requiring opt-in consent before tracking begins. An organization operating across the EU, the UK, and multiple US states may therefore need different configurations of when and how Floodlight tags fire for different audiences, rather than a single global approach.

Who it's relevant to

Privacy and data protection officers
Floodlight tags are a common example of advertising trackers that must be brought within a consent or preference framework. DPOs generally need to confirm that these tags are inventoried, correctly categorized as non-essential, and gated appropriately for each jurisdiction the organization serves, recognizing that opt-in and opt-out requirements differ between the EU, the UK, and individual US states.
Marketing and advertising compliance teams
Because Floodlight tags underpin conversion and revenue measurement, marketing teams have a direct interest in how consent gating affects the data they receive. They should understand that firing tags before consent (where opt-in applies) may be non-compliant, and that measurement configurations may need to vary by audience and region rather than following a single global setup.
Web developers and tag management engineers
Developers who implement Floodlight tags, often through a tag manager, are typically responsible for wiring the tag firing to consent signals so that tags do not set or read identifiers before the required legal basis exists. The exact configuration depends on the platform, the consent management setup, and applicable guidance not addressed in this definition.
Legal counsel advising on adtech
Counsel assessing an organization's advertising stack may treat Floodlight tags as a case study in how the ePrivacy Directive's rules on device storage and the GDPR's rules on personal data processing apply to the same technology. They can help determine the appropriate legal basis and consent approach for each relevant regime, given that enforcement positions and guidance continue to evolve.

Inside Floodlight Tags

Conversion Tracking Tag
Floodlight tags are conversion tracking tags used within Google Marketing Platform (notably Campaign Manager 360 and Display & Video 360) to record user actions such as page visits, purchases, or sign-ups after exposure to an advertisement.
Counter and Sales Tag Types
Floodlight typically distinguishes between counter tags, which count the number of times an action occurs, and sales tags, which capture transaction values and quantities. The specific configuration determines what data is collected.
Cookies and Similar Identifiers
Floodlight tags generally rely on cookies and, depending on configuration, other identifiers to attribute conversions across ad exposures. Because they place or access information on a user's device, they fall within the scope of the ePrivacy Directive and its national implementations in the EU, and any resulting personal data processing is governed by the GDPR.
Advertising and Measurement Purpose
Floodlight tags serve advertising, attribution, and measurement functions rather than being strictly necessary for a website to operate, which is why they typically require prior consent in most EU jurisdictions.
Custom Floodlight Variables
Configurations may include custom variables that pass additional parameters about the conversion event. Depending on what is transmitted, these variables may contain or relate to personal data, engaging GDPR obligations.

Common questions

Answers to the questions practitioners most commonly ask about Floodlight Tags.

Are Floodlight tags exempt from consent because they are conversion-tracking tools rather than cookies?
No. Floodlight tags typically rely on cookies or similar tracking technologies to attribute conversions, and in most EU jurisdictions the ePrivacy rules apply to the placing of and access to information on a user's device regardless of whether a tool is labelled a cookie, pixel, or tag. Because Floodlight tags generally serve advertising and measurement purposes, they are not usually treated as strictly necessary and therefore typically require prior consent before firing under EU law. Separately, any personal data processed through them falls under the GDPR. The consent position may differ under US state frameworks, which often rely on opt-out mechanisms rather than prior opt-in.
Does having consent for Google Analytics or other Google products also cover Floodlight tags?
Not automatically. Consent under the GDPR must be specific and informed, which generally means users should be able to understand and agree to the particular purposes involved. Advertising and conversion-measurement purposes served by Floodlight tags are typically distinct from analytics purposes, so consent obtained for one purpose does not necessarily extend to another. In addition, valid placement of the tag under ePrivacy rules and lawful processing of the resulting personal data under the GDPR are separate questions, and satisfying one does not automatically satisfy the other. Whether a given consent covers Floodlight tags depends on how purposes were presented and is a matter for legal judgment on the specific facts.
How should Floodlight tags be configured so they do not fire before consent is obtained?
In EU jurisdictions where prior consent is generally required for advertising and measurement technologies, Floodlight tags should typically be gated so they do not load or set identifiers until the relevant consent signal is present. This is commonly achieved by managing the tags through a tag management system integrated with a consent management platform (CMP), so that the tag only fires when the corresponding consent category is granted. Configuration details vary by deployment, and tooling supports compliance but does not replace an assessment of whether the setup meets the applicable legal standard.
How do Floodlight tags interact with a consent management platform (CMP)?
A CMP is generally used to capture, store, and communicate the user's consent choices, and it can pass a signal to the tag management layer indicating which categories the user has permitted. Floodlight tags are typically mapped to an advertising or measurement category so that the CMP signal controls whether they fire. Some organisations rely on frameworks such as the IAB Transparency and Consent Framework (TCF) or on consent-mode style integrations to relay these signals. The specifics depend on the CMP and the surrounding stack, and a CMP integration supports but does not by itself guarantee compliance.
What should be recorded for accountability when Floodlight tags rely on consent?
Where consent is the basis for firing Floodlight tags, organisations generally need to be able to demonstrate that valid consent was obtained, which typically involves logging the consent choice, the purposes presented, and the time it was given, consistent with record-keeping expectations under the GDPR. The precise records to retain, and how long to keep them, depend on the applicable framework and internal policy. This entry does not prescribe specific retention periods, which should be determined based on legal advice and relevant regulatory guidance.
Do Floodlight tags need to be handled differently for users outside the EU?
Potentially, yes. Cookie and tracking obligations vary by jurisdiction: EU and UK rules generally require prior consent for advertising-related tags, whereas several US state frameworks, such as those in California, often rely on opt-out mechanisms and may recognise signals like the Global Privacy Control. As a result, the same Floodlight tag may need to be governed by different logic depending on the user's location and the applicable regime. How to segment users and apply the correct rules is an implementation and legal-scoping question that depends on where you operate and is not resolved by the tag configuration alone.

Common misconceptions

Floodlight tags are not cookies, so cookie consent rules do not apply to them.
Even where a technology is not literally a cookie, the ePrivacy rules in the EU generally apply to any placing of or access to information on a user's device, and similar technologies such as pixels, tags, and identifiers fall within the same framework. Where Floodlight tags rely on cookies or comparable identifiers, consent is typically required in most EU jurisdictions before they fire.
Because Floodlight tags are provided by Google's advertising platform, they can be treated as essential and loaded without consent.
Floodlight tags serve advertising, attribution, and measurement purposes and are generally not considered strictly necessary or essential. In most EU jurisdictions they typically require prior, valid consent, and being a widely used vendor tool does not change that analysis.
Consent obligations for Floodlight tags are the same everywhere.
Requirements vary by jurisdiction. In the EU and UK, advertising tags generally require prior opt-in consent, whereas several US state frameworks such as the CCPA and CPRA in California often rely on opt-out mechanisms. The applicable scope depends on where users are located and which regime applies.

Best practices

Configure Floodlight tags to fire only after a user has provided valid consent in jurisdictions requiring prior opt-in, and gate them through your consent management platform (CMP) rather than loading them by default.
Classify Floodlight tags as advertising or measurement technologies in your cookie inventory rather than as strictly necessary, and document the categorization and its rationale.
Review any custom Floodlight variables to identify whether personal data is being transmitted, and ensure the corresponding GDPR processing purposes and legal bases are addressed.
Align tag behavior with applicable regional requirements, honoring opt-in consent in the EU and UK and opt-out signals such as Global Privacy Control where US state laws apply, and confirm the correct scope for each user.
Maintain consent logs and records so you can demonstrate that consent was obtained before Floodlight tags fired, recognizing that a CMP supports but does not replace legal judgment.
Periodically audit deployed Floodlight tags and their triggers to confirm they are not firing prior to consent, and update configurations as regulatory guidance and enforcement positions evolve.