Marketing Cookies
Marketing cookies are small files placed on your device that help websites and advertisers deliver personalized advertising and measure how those ads perform. Unlike essential cookies that a site needs to function, these cookies generally require your prior consent in the EU and UK before they are set. They are used to build a picture of your interests and tailor the ads you see across different sites.
Marketing cookies (also called advertising or targeting cookies) are text-based data files stored in a user's browser that support advertising-related functions such as ad personalization, audience targeting, frequency capping, and campaign measurement, often across multiple sites and via third-party ad networks. Because they are not strictly necessary for a service the user has requested, in most EU and UK jurisdictions they fall within the consent requirement of the ePrivacy rules (as implemented nationally), meaning valid prior consent that is freely given, specific, informed, and unambiguous is typically required before they are placed or read. Where these cookies process personal data, the GDPR applies additionally to that processing, and consent obtained for placing the cookie does not automatically satisfy every GDPR obligation. Similar tracking technologies used for the same advertising purposes, such as pixels, tags, SDKs, local storage, and fingerprinting, are generally treated under the same rules even though they are not literally cookies. Requirements differ under other regimes; for example, several US state privacy laws (such as California's CCPA/CPRA) commonly rely on an opt-out model rather than the opt-in approach used in the EU. The precise classification of a given cookie, and whether it is genuinely used for marketing purposes, depends on facts not resolvable from the name alone.
Why it matters
Marketing cookies sit at the center of most cookie consent disputes because they are, by definition, not strictly necessary for a service the user has requested. In most EU and UK jurisdictions this places them squarely within the consent requirement of the ePrivacy rules as implemented nationally, meaning valid prior consent must typically be obtained before they are set or read. For privacy officers and compliance teams, misclassifying an advertising or targeting cookie as essential, or setting it before consent is captured, is one of the more common sources of regulatory exposure, and the practical challenge is often ensuring that ad networks, tag managers, and embedded third-party technologies do not fire before a user has made an affirmative choice.
The stakes are heightened by the layered legal analysis these cookies require. The ePrivacy rules govern the placing of and access to information on the device, but where a marketing cookie processes personal data, the GDPR applies additionally to that processing. Consent obtained to place the cookie does not automatically satisfy every GDPR obligation, so teams cannot treat a single consent event as the end of their analysis. Similar tracking technologies used for the same advertising purposes, pixels, tags, SDKs, local storage, and fingerprinting, are generally treated under the same rules, which means an inventory limited to literal cookies will typically understate an organization's obligations.
Geographic scope compounds the complexity. The opt-in approach common in the EU and UK differs from the opt-out model that several US state privacy laws, such as California's CCPA and CPRA, commonly rely on. Organizations operating across regions therefore cannot apply a single consent posture everywhere, and the correct classification of any given cookie, including whether it is genuinely used for marketing, depends on facts that cannot be resolved from its name alone.
Who it's relevant to
Inside Marketing Cookies
Common questions
Answers to the questions practitioners most commonly ask about Marketing Cookies.

