Skip to main content
Category: Tracking Technologies

Online Identifier

Also known as: Online Identifiers, Digital Identifier
Simply put

An online identifier is a piece of information linked to a person's device, browser, or online activity that can be used to recognize or single out that individual. Examples include IP addresses, cookie identifiers, and similar tags left behind as someone uses websites and apps. Under EU and UK data protection law, such identifiers can count as personal data, meaning their use may be subject to data protection rules.

Formal definition

Under the GDPR and UK GDPR, an online identifier is a category of information that may identify a natural person by associating the informational traces an individual leaves when operating online. Recital 30 of the GDPR references online identifiers provided by an individual's devices, applications, tools, and protocols, such as internet protocol (IP) addresses and cookie identifiers, as well as other identifiers like radio frequency identification (RFID) tags. Whether a given online identifier constitutes personal data depends on the facts, in particular whether the identifier, alone or combined with other information, can be used to identify or single out a natural person; identifiers that permit such identification generally fall within the scope of data protection law. This entry addresses the concept of online identifiers under EU/UK data protection frameworks and does not, on its own, resolve when placing or accessing such identifiers on a device requires consent under the ePrivacy rules, nor how equivalent concepts are treated under US state privacy laws.

Why it matters

Online identifiers matter because they determine whether much of the data collected through cookies, pixels, SDKs, and similar technologies falls within the scope of data protection law. Under the GDPR and UK GDPR, when an online identifier can be used to identify or single out a natural person, it is generally treated as personal data, which means its processing may trigger obligations around lawful basis, transparency, and data subject rights. This is why organizations cannot assume that data such as an IP address or cookie identifier is automatically outside the reach of these frameworks; whether it counts as personal data depends on the facts, including whether it can be combined with other information to identify someone.

For compliance teams, the concept is central to mapping which tracking technologies raise data protection questions. Recital 30 of the GDPR expressly references online identifiers provided by devices, applications, tools, and protocols, and this breadth means that identifiers left behind during ordinary browsing and app use may need to be accounted for in privacy assessments. Misjudging whether an identifier is personal data can lead to gaps in a compliance program, for example failing to provide adequate transparency or to honor rights requests.

It is important to keep the online identifier concept distinct from the separate question of when consent is required. The classification of an identifier as personal data under the GDPR or UK GDPR does not, on its own, resolve whether placing or accessing that identifier on a user's device requires consent under the ePrivacy rules, nor how equivalent concepts are handled under US state privacy laws. These are related but separate legal questions, and treating them as the same can produce incorrect compliance conclusions.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for compliance need to assess which online identifiers used by their organization may qualify as personal data under the GDPR and UK GDPR. This classification feeds into data mapping, transparency disclosures, and decisions about lawful basis, and it should be documented as a fact-specific judgment rather than a blanket assumption.
Legal counsel
Counsel advising on data protection must distinguish the question of whether an online identifier is personal data from the separate ePrivacy question of when placing or accessing identifiers on a device requires consent, and from how equivalent concepts are treated under US state privacy laws. Conflating these regimes can lead to unsound advice.
Web developers and technical teams
Developers implementing cookies, pixels, SDKs, and similar technologies determine which identifiers are generated, stored, and shared. Understanding that IP addresses, cookie identifiers, and comparable tags may constitute personal data helps technical teams flag processing that requires review before deployment.
Marketing and analytics teams
Teams that rely on tracking technologies for measurement and advertising should recognize that the identifiers underpinning these tools may be personal data under EU and UK law. This affects how such data can be collected and used and should inform coordination with privacy and legal functions.

Inside Online Identifier

IP address
A numerical identifier assigned to a device on a network. In the EU, IP addresses are generally treated as personal data where they can, alone or combined with other information, be linked to an identifiable individual, though the analysis can depend on whether the address is static or dynamic and on the means reasonably available to identify the person.
Cookie identifiers
Unique values stored in or read from cookies placed on a user's device. The act of storing or accessing these on the device is governed by the ePrivacy Directive and its national implementations, while any subsequent processing of the resulting identifier as personal data falls under the GDPR.
Device and advertising identifiers
Persistent identifiers such as mobile advertising IDs or values embedded in SDKs that can be used to single out a device or user across sessions or services, typically requiring the same consent analysis as cookies under EU law.
Fingerprinting signals
Combinations of device and browser characteristics (such as configuration, fonts, or screen attributes) used to distinguish a user without necessarily setting a cookie. Although not literally cookies, gaining access to information on the device for fingerprinting generally falls within the same ePrivacy rules, and the resulting identifier may constitute personal data under the GDPR.
Pixels, tags, and local storage values
Other client-side technologies that can assign or transmit identifiers. Where they involve storing or accessing information on a device, they are typically subject to ePrivacy consent requirements even though they differ technically from cookies.
Pseudonymous versus directly identifying character
Online identifiers often do not name a person directly but can still allow singling out or linking of activity. Under the GDPR, such identifiers may be personal data even where the identity behind them is not immediately known to the controller.

Common questions

Answers to the questions practitioners most commonly ask about Online Identifier.

Is an online identifier only personal data if it directly reveals someone's name?
No. An online identifier does not need to reveal a person's name or real-world identity to be treated as personal data. Under the GDPR, identifiers such as IP addresses, cookie identifiers, device identifiers, and similar values can constitute personal data where they can be used, alone or in combination with other information, to single out or distinguish an individual. The relevant question is generally whether the identifier makes a person identifiable, not whether it names them.
Since online identifiers are just technical strings, aren't they outside the scope of privacy law?
Not necessarily. The technical nature of an identifier does not exclude it from privacy law. Where an online identifier relates to an identifiable individual, it is generally treated as personal data under the GDPR and subject to its rules. Separately, the placing of or access to identifiers stored on a user's device is typically governed by the ePrivacy Directive and its national implementations in the EU, independently of whether the identifier is also personal data. The two regimes can apply together, and a purely technical framing does not remove either obligation.
How should we determine whether a particular online identifier counts as personal data in our setup?
Assess whether the identifier can be linked, directly or indirectly, to an identifiable individual given the means reasonably likely to be used, including other data your organization or third parties hold. Because identifiability depends on the specific facts, context, and available linking information, this is a case-by-case analysis rather than a fixed rule. Where the outcome is uncertain or contested, it is prudent to document your reasoning and, where appropriate, seek legal advice, as regulatory interpretations in this area continue to evolve.
Do we need consent before setting cookies or similar identifiers on a user's device?
In most EU jurisdictions, the ePrivacy rules generally require prior consent to place or access identifiers on a user's device unless the identifier is strictly necessary for a service the user has requested. This applies to cookies as well as similar technologies such as pixels, local storage, SDKs, and device fingerprinting. Requirements differ by jurisdiction: the UK follows a broadly similar approach, while several US state frameworks such as the CCPA and CPRA typically rely on opt-out mechanisms rather than opt-in consent. Confirm the obligations applicable to the regions where your users are located.
How should online identifiers be handled in records of processing and consent logs?
Where online identifiers are processed as personal data, they should generally be reflected in your record-keeping, including documentation of the categories of data, purposes, and legal basis. Where consent is the basis for placing or accessing identifiers, maintaining records that demonstrate valid consent is typically expected under EU frameworks. Consent management platforms can support this logging, but they support compliance rather than guarantee it, and the adequacy of your records still depends on legal judgment and the applicable jurisdiction's requirements.
Can honoring an opt-out or Global Privacy Control signal affect how we process online identifiers?
Yes, depending on the applicable regime. Under certain US state frameworks, opt-out signals such as Global Privacy Control may need to be recognized and acted upon, which can require limiting or ceasing certain processing tied to online identifiers. Under EU rules, the emphasis is generally on obtaining prior consent rather than opt-out. Because the mechanisms and their legal weight differ by jurisdiction and continue to develop, map your identifier-processing activities to the signals and choices you are required to honor in each relevant region.

Common misconceptions

Online identifiers are not personal data because they do not contain a person's name.
In the EU, an identifier can be personal data where it allows an individual to be singled out or linked to other information, even without a name. Whether a given identifier is personal data depends on the facts and the means reasonably available to identify the person, so the analysis is case-specific rather than automatic.
If a technology is not technically a cookie, cookie consent rules do not apply.
The ePrivacy rules on storing or accessing information on a user's device generally extend to pixels, local storage, SDKs, device identifiers, and fingerprinting, not only to cookies. Similar technologies are typically caught by the same requirements even though they are not literally cookies.
Consent to place a cookie automatically covers all processing of the resulting identifier.
The placing of or access to information on the device is governed by the ePrivacy Directive, while processing the identifier as personal data is governed by the GDPR. These are distinct legal questions, and satisfying one does not automatically satisfy the other.

Best practices

Assess each identifier on its facts to determine whether it is personal data under the GDPR, considering whether it can single out an individual or be linked to other information using means reasonably available to you.
Inventory the full range of technologies that read or store identifiers on user devices, including cookies, pixels, tags, local storage, SDKs, and fingerprinting, so none fall outside your consent analysis.
Separate the ePrivacy question of storing or accessing information on the device from the GDPR question of processing the resulting identifier, and document a lawful basis for each where required.
Where prior consent is required in EU jurisdictions for non-essential identifiers, ensure it meets the GDPR standard of being freely given, specific, informed, and unambiguous through a clear affirmative action, avoiding pre-ticked boxes or implied consent.
Tailor your approach to the applicable jurisdiction, recognizing that obligations differ between the EU, the UK, and individual US states, and that some regimes rely on opt-out rather than opt-in.
Maintain records of consent and of the identifiers and technologies in use, and treat consent management tools as support for, rather than a substitute for, legal judgment and case-specific review.