Online Identifier
An online identifier is a piece of information linked to a person's device, browser, or online activity that can be used to recognize or single out that individual. Examples include IP addresses, cookie identifiers, and similar tags left behind as someone uses websites and apps. Under EU and UK data protection law, such identifiers can count as personal data, meaning their use may be subject to data protection rules.
Under the GDPR and UK GDPR, an online identifier is a category of information that may identify a natural person by associating the informational traces an individual leaves when operating online. Recital 30 of the GDPR references online identifiers provided by an individual's devices, applications, tools, and protocols, such as internet protocol (IP) addresses and cookie identifiers, as well as other identifiers like radio frequency identification (RFID) tags. Whether a given online identifier constitutes personal data depends on the facts, in particular whether the identifier, alone or combined with other information, can be used to identify or single out a natural person; identifiers that permit such identification generally fall within the scope of data protection law. This entry addresses the concept of online identifiers under EU/UK data protection frameworks and does not, on its own, resolve when placing or accessing such identifiers on a device requires consent under the ePrivacy rules, nor how equivalent concepts are treated under US state privacy laws.
Why it matters
Online identifiers matter because they determine whether much of the data collected through cookies, pixels, SDKs, and similar technologies falls within the scope of data protection law. Under the GDPR and UK GDPR, when an online identifier can be used to identify or single out a natural person, it is generally treated as personal data, which means its processing may trigger obligations around lawful basis, transparency, and data subject rights. This is why organizations cannot assume that data such as an IP address or cookie identifier is automatically outside the reach of these frameworks; whether it counts as personal data depends on the facts, including whether it can be combined with other information to identify someone.
For compliance teams, the concept is central to mapping which tracking technologies raise data protection questions. Recital 30 of the GDPR expressly references online identifiers provided by devices, applications, tools, and protocols, and this breadth means that identifiers left behind during ordinary browsing and app use may need to be accounted for in privacy assessments. Misjudging whether an identifier is personal data can lead to gaps in a compliance program, for example failing to provide adequate transparency or to honor rights requests.
It is important to keep the online identifier concept distinct from the separate question of when consent is required. The classification of an identifier as personal data under the GDPR or UK GDPR does not, on its own, resolve whether placing or accessing that identifier on a user's device requires consent under the ePrivacy rules, nor how equivalent concepts are handled under US state privacy laws. These are related but separate legal questions, and treating them as the same can produce incorrect compliance conclusions.
Who it's relevant to
Inside Online Identifier
Common questions
Answers to the questions practitioners most commonly ask about Online Identifier.