Mobile Advertising ID
A Mobile Advertising ID (MAID) is a unique, resettable identifier that a mobile operating system assigns to a smartphone or tablet, allowing advertisers to recognize a device and track user activity across apps to deliver targeted advertising. It is described by industry sources as anonymous, though in practice it can often be linked to other data to identify or profile a user. Users can typically reset the identifier, and mobile platforms provide controls affecting whether and how it can be accessed.
A Mobile Advertising ID is a device-level identifier issued by a mobile operating system to support advertising and measurement across applications; the principal implementations are Apple's Identifier for Advertisers (IDFA) on iOS and the Google Advertising ID (GAID) on Android. Although vendors commonly characterize MAIDs as anonymous, they function as persistent-until-reset pseudonymous identifiers that can enable cross-app tracking, attribution, and profiling, and they can be combined with other information to single out or re-identify a user. Because a MAID is not a cookie, cookie-specific rules do not map to it directly; however, under EU and UK law the storing of or access to such an identifier on a user's device generally falls within the ePrivacy regime, and any associated profiling typically constitutes processing of personal data under the GDPR, so consent or another lawful basis may be required. Requirements and enforcement positions vary by jurisdiction and continue to evolve, and this definition does not resolve the contested question of whether a given MAID is anonymous or personal data in a specific factual context.
Why it matters
Mobile Advertising IDs sit at the center of the mobile advertising economy, enabling cross-app tracking, attribution, and profiling in a way analogous to how cookies operate on the web. While industry sources frequently describe MAIDs as anonymous, in practice a persistent-until-reset identifier can often be combined with other data to single out, profile, or re-identify a user. This gap between the marketing characterization and the practical reality is precisely what makes MAIDs a compliance-sensitive technology for privacy officers and legal teams.
For organizations operating in the EU and UK, the significance is twofold. The storing of or access to an identifier on a user's device generally falls within the ePrivacy regime, which governs device access independently of whether the identifier is treated as personal data. Separately, any profiling or behavioral targeting built on a MAID typically constitutes processing of personal data under the GDPR, meaning consent or another lawful basis may be required. Because a MAID is not literally a cookie, teams cannot simply assume that their existing cookie consent flows extend to it; the technology requires its own analysis even though similar legal principles apply.
The treatment of MAIDs varies considerably by jurisdiction, and the underlying question of whether a specific MAID is anonymous or personal data remains contested and fact-dependent. Enforcement positions and platform-level controls continue to evolve. This makes MAIDs an area where compliance teams should avoid relying on vendor characterizations alone and should document their own assessment of how the identifier is used and combined with other data in their particular context.
Who it's relevant to
Inside MAID
Common questions
Answers to the questions practitioners most commonly ask about MAID.