Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Tracking Technologies

Retargeting

Also known as: Remarketing
Simply put

Retargeting is a form of online advertising that shows ads to people who have previously visited a website or interacted with a brand but did not make a purchase or otherwise convert. The goal is to remind those users of the brand and encourage them to return. Because it relies on tracking a user's earlier online activity, retargeting generally depends on technologies such as cookies, pixels, or similar identifiers.

Formal definition

Retargeting (also called remarketing) is a digital advertising tactic that serves tailored or personalized ads to users based on their prior engagement with a brand, such as visiting a website, browsing products, or abandoning a purchase. It typically operates by placing or accessing identifiers on a user's device (for example via cookies, tracking pixels, or comparable technologies) to recognize returning or previously identified visitors and deliver creative to them across subsequent browsing. Because retargeting involves both the placing of and access to information on a user's device and the processing of data about that user, it generally engages the ePrivacy rules governing device access (in most EU jurisdictions requiring prior consent) as well as, where personal data is processed, the GDPR; the specific legal obligations and consent standards vary by jurisdiction (for example EU/UK opt-in approaches versus opt-out mechanisms under certain US state laws). This definition describes the marketing concept only and does not resolve the applicable lawful basis or consent requirements for any particular implementation, which depend on facts outside this entry.

Why it matters

Retargeting is one of the most common triggers for cookie consent obligations because, by design, it depends on recognizing users across their browsing activity. To identify a returning or previously seen visitor, retargeting typically relies on placing or accessing identifiers on a user's device through cookies, tracking pixels, or comparable technologies. In most EU jurisdictions, this device access engages the ePrivacy rules and generally requires prior consent, while any accompanying processing of personal data separately engages the GDPR. These are distinct obligations: obtaining consent for one does not automatically satisfy the other.

Because retargeting is a form of advertising rather than a strictly necessary function, it is typically treated as a non-essential use that requires a clear affirmative action from the user before the underlying tracking technologies are deployed. Consent that is not freely given, specific, informed, and unambiguous, for example consent inferred from continued browsing or captured through pre-ticked boxes, is widely considered non-compliant in the EU. This makes retargeting a frequent focus of compliance review when organizations configure their consent management platforms and audit the trackers loading on their sites.

The applicable standard also varies by jurisdiction. EU and UK frameworks generally rely on an opt-in approach for advertising technologies of this kind, whereas certain US state laws, such as California's regime, may instead operate through opt-out mechanisms. Organizations running retargeting campaigns across multiple regions therefore cannot assume a single global approach will satisfy every applicable law, and the correct configuration depends on facts specific to each implementation.

Who it's relevant to

Marketing and advertising compliance teams
Teams running or commissioning retargeting campaigns need to understand that these campaigns generally depend on non-essential tracking technologies, which in most EU jurisdictions require prior consent before they load. They should coordinate with legal and consent management functions to ensure that retargeting tags are not deployed ahead of a valid affirmative action where such consent is required.
Privacy officers and data protection professionals
Because retargeting can engage both the ePrivacy rules on device access and the GDPR where personal data is processed, privacy professionals must treat these as distinct obligations rather than assuming one satisfies the other. They also need to account for jurisdictional differences, such as EU and UK opt-in expectations versus opt-out mechanisms under certain US state laws.
Web developers and consent management implementers
Developers responsible for deploying tags and configuring consent management platforms are typically the ones who control whether retargeting cookies, pixels, or SDKs fire before or after consent. Correct implementation, ensuring non-essential trackers are gated appropriately by geography and consent status, is essential, though tooling supports compliance rather than guaranteeing it.
Legal counsel
Counsel advising on advertising technology need to assess the lawful basis or consent standard applicable to a specific retargeting implementation, which depends on facts not resolved by a general definition. They should flag where regulatory interpretation is evolving or contested and where practice differs across the EU, UK, and individual US states.

Inside Retargeting

Behavioural tracking technologies
Retargeting typically relies on cookies, tracking pixels, SDKs, and similar identifiers placed on a user's device to record browsing activity. Because these technologies involve storing or accessing information on the device, their use is generally governed by the ePrivacy rules (and national implementations) in the EU and UK, in addition to the GDPR where personal data is processed.
Cross-site and cross-session profiling
The practice involves building a profile of a user's interests across multiple sites or visits in order to serve tailored advertising later. Where this involves personal data, the profiling itself is separately subject to GDPR requirements over and above the consent needed to place the tracking technology.
Third-party ad networks and data sharing
Retargeting frequently depends on third-party ad networks, exchanges, or advertising partners with whom user identifiers or activity data may be shared. Practitioners should identify the roles of the parties involved (for example controller, joint controller, or processor), as this affects transparency and legal-basis obligations.
Consent and legal basis
In most EU jurisdictions, retargeting cookies and similar technologies are not considered strictly necessary and therefore generally require prior, freely given, specific, informed, and unambiguous consent obtained through a clear affirmative action. Under US state privacy laws such as the CCPA/CPRA, comparable activity is often addressed through an opt-out model rather than opt-in.
Consent management and record-keeping
Consent management platforms (CMPs), and in some ecosystems the IAB Transparency and Consent Framework (TCF), are commonly used to obtain, communicate, and log consent for retargeting. These tools support compliance and record-keeping but do not by themselves guarantee that the underlying processing is lawful.

Common questions

Answers to the questions practitioners most commonly ask about Retargeting.

Does retargeting only rely on third-party cookies, so will it stop working once those are phased out?
No. While retargeting has historically depended heavily on third-party cookies, it also uses a range of other technologies, including tracking pixels, first-party cookies, local storage, mobile SDKs, device or browser fingerprinting, and server-side or ID-based matching. The decline of third-party cookies in some browsers is prompting a shift toward these alternatives rather than ending retargeting altogether. Importantly, these alternative technologies generally fall within the same legal rules as cookies: in most EU jurisdictions, the ePrivacy rules on placing or accessing information on a user's device typically apply regardless of the specific technology used, and any resulting processing of personal data engages the GDPR.
If a user visited our site voluntarily, can we retarget them without separate consent?
Generally not in the EU. Retargeting typically involves storing or accessing information on the user's device and processing personal data to serve targeted advertising, which in most EU jurisdictions requires prior consent that is freely given, specific, informed, and unambiguous. A user's decision to visit a website does not, on its own, constitute a clear affirmative action to consent to advertising tracking. The position differs under other frameworks: several US state privacy laws, such as the CCPA/CPRA in California, generally rely on an opt-out model for targeted advertising or the sale or sharing of personal information rather than prior opt-in consent. The applicable standard depends on the jurisdictions in which your users are located.
How should we configure a consent management platform (CMP) so retargeting tags do not fire before consent?
In most EU jurisdictions, retargeting pixels, tags, and SDKs should be blocked from loading until the user has given valid consent for the relevant advertising purpose. This is commonly implemented by placing advertising tags in a category that is disabled by default and gated behind the CMP, or by using a tag manager configured to fire those tags only on a positive consent signal. Whether a particular configuration is compliant depends on facts beyond the tool itself, including how consent is presented and recorded. A CMP can support this outcome but does not by itself guarantee legal compliance.
What records should we keep to demonstrate consent for retargeting?
Where consent is the basis for retargeting, organizations are generally expected under the GDPR to be able to demonstrate that valid consent was obtained. In practice this often involves logging information such as when consent was given, which purposes and vendors it covered, the version of the notice or CMP configuration presented, and how the user could withdraw consent. The specific record-keeping approach that is adequate can depend on national guidance and the facts of a given deployment, so this description is general rather than a fixed checklist.
How does the IAB Transparency and Consent Framework (TCF) relate to retargeting?
The TCF is an industry framework intended to standardize how consent and related signals are communicated between publishers, CMPs, and advertising vendors, including those involved in retargeting. It can help pass consent status through the advertising supply chain in a structured way. However, participation in the TCF does not by itself establish that consent was validly obtained or that a given retargeting activity is lawful; those questions turn on the underlying facts and applicable law. The framework and regulatory views on it have evolved, and specific aspects have been the subject of ongoing scrutiny.
How should Global Privacy Control (GPC) and opt-out signals be handled for retargeting?
Global Privacy Control is a browser or extension signal that communicates a user's preference to opt out of certain data practices, and it is particularly relevant under US state privacy frameworks that use an opt-out model, such as those in California. Where recognized, such a signal may need to be treated as a request to stop targeted advertising or the sale or sharing of personal information, which can require suppressing retargeting for that user. The extent to which a given signal must be honored depends on the applicable jurisdiction and its interpretation of the relevant law, so its effect on retargeting is not uniform across regimes.

Common misconceptions

Retargeting is exempt from consent because ads help fund free content.
Advertising-related cookies and identifiers used for retargeting are generally not treated as strictly necessary in the EU and UK, so their placement typically requires prior consent regardless of how the resulting revenue is used. A commercial justification does not remove the ePrivacy consent requirement.
Once a user consents to cookies generally, retargeting is covered everywhere.
Valid consent under the GDPR must be specific and informed, so a broad or bundled consent may not adequately cover retargeting purposes or the sharing of data with advertising partners. In addition, requirements differ by jurisdiction: the EU and UK generally rely on opt-in consent, while several US states rely instead on opt-out mechanisms, so a single approach may not satisfy all applicable regimes.
Using a CMP or the TCF makes retargeting automatically compliant.
A CMP or participation in a framework such as the TCF can help gather and document consent, but these tools support compliance rather than replace legal judgment. Whether a given retargeting setup is lawful depends on the facts, the parties involved, and the applicable rules, and enforcement positions in this area continue to evolve.

Best practices

Classify retargeting cookies, pixels, SDKs, and similar identifiers as non-essential in EU and UK contexts, and obtain prior consent through a clear affirmative action before deploying them.
Present retargeting as a distinct, specific purpose in your consent interface rather than bundling it into a single blanket consent, so that consent can be genuinely informed and specific.
Map the third parties, ad networks, and partners involved and clarify their respective roles, then reflect this in your transparency notices and any required agreements.
Maintain reliable consent records and logging, whether through a CMP or other means, so you can demonstrate when and how consent for retargeting was obtained.
Tailor your approach to each applicable jurisdiction, recognising that EU and UK regimes generally require opt-in consent while certain US state laws rely on opt-out signals and mechanisms.
Treat CMPs and frameworks such as the TCF as supporting tools and combine them with legal review, revisiting your configuration as regulatory guidance and enforcement positions evolve.
Application Security Isn’t Optional Anymore.