Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Cookie Types

Marketing Cookies

Also known as: advertising cookies, targeting cookies
Simply put

Marketing cookies are small files placed on your device that help websites and advertisers deliver personalized advertising and measure how those ads perform. Unlike essential cookies that a site needs to function, these cookies generally require your prior consent in the EU and UK before they are set. They are used to build a picture of your interests and tailor the ads you see across different sites.

Formal definition

Marketing cookies (also called advertising or targeting cookies) are text-based data files stored in a user's browser that support advertising-related functions such as ad personalization, audience targeting, frequency capping, and campaign measurement, often across multiple sites and via third-party ad networks. Because they are not strictly necessary for a service the user has requested, in most EU and UK jurisdictions they fall within the consent requirement of the ePrivacy rules (as implemented nationally), meaning valid prior consent that is freely given, specific, informed, and unambiguous is typically required before they are placed or read. Where these cookies process personal data, the GDPR applies additionally to that processing, and consent obtained for placing the cookie does not automatically satisfy every GDPR obligation. Similar tracking technologies used for the same advertising purposes, such as pixels, tags, SDKs, local storage, and fingerprinting, are generally treated under the same rules even though they are not literally cookies. Requirements differ under other regimes; for example, several US state privacy laws (such as California's CCPA/CPRA) commonly rely on an opt-out model rather than the opt-in approach used in the EU. The precise classification of a given cookie, and whether it is genuinely used for marketing purposes, depends on facts not resolvable from the name alone.

Why it matters

Marketing cookies sit at the center of most cookie consent disputes because they are, by definition, not strictly necessary for a service the user has requested. In most EU and UK jurisdictions this places them squarely within the consent requirement of the ePrivacy rules as implemented nationally, meaning valid prior consent must typically be obtained before they are set or read. For privacy officers and compliance teams, misclassifying an advertising or targeting cookie as essential, or setting it before consent is captured, is one of the more common sources of regulatory exposure, and the practical challenge is often ensuring that ad networks, tag managers, and embedded third-party technologies do not fire before a user has made an affirmative choice.

The stakes are heightened by the layered legal analysis these cookies require. The ePrivacy rules govern the placing of and access to information on the device, but where a marketing cookie processes personal data, the GDPR applies additionally to that processing. Consent obtained to place the cookie does not automatically satisfy every GDPR obligation, so teams cannot treat a single consent event as the end of their analysis. Similar tracking technologies used for the same advertising purposes, pixels, tags, SDKs, local storage, and fingerprinting, are generally treated under the same rules, which means an inventory limited to literal cookies will typically understate an organization's obligations.

Geographic scope compounds the complexity. The opt-in approach common in the EU and UK differs from the opt-out model that several US state privacy laws, such as California's CCPA and CPRA, commonly rely on. Organizations operating across regions therefore cannot apply a single consent posture everywhere, and the correct classification of any given cookie, including whether it is genuinely used for marketing, depends on facts that cannot be resolved from its name alone.

Who it's relevant to

Privacy officers and data protection professionals
Marketing cookies require careful classification, since treating an advertising or targeting cookie as essential can undermine a consent program. These roles are typically responsible for maintaining an accurate cookie inventory that also captures equivalent technologies such as pixels, SDKs, and fingerprinting, and for confirming that both the ePrivacy consent requirement and any separate GDPR processing obligations are addressed where personal data is involved.
Legal counsel
Counsel advises on whether valid prior consent is required before marketing cookies are set in a given jurisdiction, and on the fact that consent to place a cookie does not automatically satisfy every GDPR obligation. Because requirements differ, opt-in in the EU and UK versus the opt-out model common under laws such as California's CCPA and CPRA, counsel must scope obligations to the relevant regions rather than assuming a single standard applies everywhere.
Web developers and engineering teams
Developers implement the technical controls that prevent marketing cookies and related tracking technologies from firing before consent is captured, typically through tag managers and consent management platforms. Accurate implementation depends on understanding that pixels, tags, SDKs, and local storage may serve the same advertising purposes as cookies and generally fall under the same rules.
Marketing compliance teams
These teams balance advertising objectives such as personalization, audience targeting, and campaign measurement against consent requirements. They need to understand that marketing cookies generally cannot be relied upon in the EU and UK until the user gives a clear affirmative choice, and that the correct treatment depends on the cookie's actual purpose and the applicable legal regime rather than its label.

Inside Marketing Cookies

Purpose and function
Marketing cookies (also called advertising or targeting cookies) are set to track users across websites and sessions in order to build profiles, measure ad performance, deliver targeted advertising, and support related purposes such as retargeting and frequency capping. They are not necessary for the basic operation of a website.
Related tracking technologies
The same rules that apply to marketing cookies generally extend to functionally similar technologies used for advertising, including tracking pixels, web beacons, local storage, mobile SDKs, and device fingerprinting, even though these are not literally cookies. In most EU jurisdictions the storing of or access to information on a user's device triggers the applicable rules regardless of the specific technology.
Consent obligation under EU/UK law
Under the ePrivacy Directive as implemented in EU member states and in the UK, placing marketing cookies typically requires prior consent because they are not strictly necessary. Where personal data is subsequently processed, the GDPR (or UK GDPR) also applies to that processing. Consent under the ePrivacy rules and a lawful basis under the GDPR are distinct requirements and should not be conflated.
Standard of consent
In the EU and UK, consent for marketing cookies must generally be freely given, specific, informed, and unambiguous, requiring a clear affirmative action. Pre-ticked boxes, implied consent from continued browsing, and cookie walls are widely regarded as non-compliant by EU data protection authorities, though interpretations continue to evolve.
Third-party involvement
Marketing cookies are frequently set by third parties such as ad networks and analytics or advertising vendors, which may raise additional questions about controllership, disclosure of recipients, and international data transfers. These downstream relationships are often central to how marketing cookie data is used.
Jurisdictional variation
Requirements differ by jurisdiction. Many EU and UK regimes generally rely on prior opt-in consent, whereas several US state privacy laws (for example the CCPA/CPRA in California) often rely on opt-out mechanisms and concepts such as sale or sharing of personal information rather than prior consent. The applicable scope depends on where users are located and which law applies.

Common questions

Answers to the questions practitioners most commonly ask about Marketing Cookies.

Are marketing cookies the same thing as advertising cookies?
The terms are often used interchangeably, but it is worth being precise. Marketing cookies is a broad label commonly applied to cookies and similar technologies used to build user profiles, track behavior across sites, and deliver or measure targeted advertising. Advertising cookies are typically a subset focused specifically on ad delivery, frequency capping, and campaign measurement. In practice, CMPs and cookie taxonomies categorize these differently, so you should rely on the specific definitions used in your own consent notice rather than assuming a universal meaning. Regardless of the label, these technologies generally require prior consent in most EU jurisdictions because they are not strictly necessary.
If a user consents to marketing cookies, does that also cover the processing of the personal data those cookies collect?
Not necessarily, and it is important not to conflate the two legal steps. In the EU, the placing of and access to information on a user's device is governed by the ePrivacy Directive as implemented nationally, while any subsequent processing of personal data is governed by the GDPR. Consent obtained for storing or reading a marketing cookie addresses the ePrivacy requirement, but the downstream processing of the resulting personal data must still have a valid basis under the GDPR. Many organizations rely on consent for both steps, but the relationship between ePrivacy consent and the GDPR lawful basis remains a subject of ongoing regulatory discussion, and you should confirm your approach against current guidance and legal advice.
When should marketing cookies be set on our website?
In most EU jurisdictions, marketing cookies and equivalent technologies (such as pixels, tags, or SDKs used for advertising) should generally not be placed until the user has given prior, valid consent through a clear affirmative action. This means they should not fire on page load before the user interacts with the consent banner, and pre-ticked boxes or implied consent from continued browsing are widely considered non-compliant in the EU. Under some US state frameworks, such as those in California, the model is often opt-out rather than opt-in, so the timing and default behavior may differ by jurisdiction. Confirm the specific requirements for the regions where your users are located.
How should we categorize marketing cookies in our consent management platform?
Marketing cookies are typically placed in a dedicated advertising or marketing category within a CMP, separate from strictly necessary, functional, and analytics categories, so that users can make specific choices. Because valid consent under the GDPR must be specific and informed, bundling marketing cookies together with essential cookies or presenting them without adequate description may undermine the validity of consent in the EU. Note that a CMP supports this categorization but does not by itself guarantee compliance, and the accuracy of your categorization depends on correctly identifying what each cookie or similar technology actually does.
What information should we disclose about marketing cookies before obtaining consent?
For consent to be informed, users generally need clear information about the purposes of the marketing cookies, the parties involved (including third parties where relevant), and typically details such as cookie duration and the fact that data may be used for profiling or cross-site tracking. Because similar technologies like pixels, local storage, and SDKs fall within the same rules even though they are not literally cookies, disclosures should cover those where they are used for the same purposes. The precise level of detail expected can vary by jurisdiction and evolving guidance from data protection authorities, so treat this as a general framing rather than a fixed checklist.
How should we handle consent records and withdrawal for marketing cookies?
Organizations relying on consent generally need to keep records demonstrating that valid consent was obtained, and to make withdrawal of consent as easy as giving it. In practice this often means logging the consent choices captured through the CMP and providing an accessible mechanism for users to change or revoke their marketing cookie preferences. When consent is withdrawn, the associated marketing cookies and similar technologies should stop being set, and you should consider what happens to previously collected data. The specific record-keeping expectations and withdrawal mechanics can differ across the EU, the UK, and US state regimes, and tools assist with these obligations but do not replace legal judgment about what your particular circumstances require.

Common misconceptions

Marketing cookies can be set as soon as the page loads, before the user interacts with the banner.
In most EU and UK jurisdictions, marketing cookies generally require prior consent, meaning they should not be placed until the user has taken a clear affirmative action. Setting them before consent is widely viewed as non-compliant, though enforcement positions vary and continue to evolve.
Only technologies literally called cookies are subject to these rules.
Similar technologies used for advertising purposes, such as pixels, web beacons, local storage, SDKs, and fingerprinting, generally fall within the same rules where they involve storing or accessing information on a user's device, even though they are not literally cookies.
The same opt-in consent approach for marketing cookies applies everywhere.
Consent standards are not universal. EU and UK regimes generally require prior opt-in consent, while several US state laws often rely on opt-out mechanisms. The correct approach depends on the applicable jurisdiction and the location of the users concerned.

Best practices

Block or suppress marketing cookies and equivalent advertising technologies until the user has given a clear affirmative consent, where prior consent is required in the applicable jurisdiction.
Inventory all marketing-related technologies, including pixels, local storage, SDKs, and any fingerprinting, rather than only cookies, so that consent controls cover functionally similar technologies.
Treat the ePrivacy consent requirement and the GDPR lawful basis for any resulting personal data processing as separate obligations, and address both rather than assuming one satisfies the other.
Clearly identify third-party recipients and the purposes for which marketing cookie data is used in your notice, and account for any international transfers those relationships involve.
Configure consent mechanisms to reflect the applicable jurisdiction, applying opt-in approaches for EU/UK users and appropriate opt-out mechanisms where US state laws apply, based on user location and the governing law.
Maintain records of consent and of the technologies deployed, and review configurations periodically, recognizing that a CMP or similar tool supports but does not replace legal judgment or guarantee compliance.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide