Supercookies
A supercookie is a persistent tracking mechanism used to identify and follow a user across websites, often in ways that are harder to detect and remove than ordinary cookies. Unlike standard cookies stored as small files that users can typically clear from their browser, supercookies may be inserted at the network level or stored in less obvious locations, allowing a tracker to link together visits to different sites. The term covers a range of techniques rather than a single technology.
"Supercookie" is a general term for a range of persistent tracking techniques that assign and retain a unique identifier for a user or device in a manner more resistant to deletion than conventional HTTP cookies. Documented mechanisms include identifiers injected into HTTP headers at the network layer to observe browsing activity, as well as browser fingerprinting approaches that store or reconstruct an identifier through browser features such as favicons, enabling re-identification even after standard cookies are cleared. Because these techniques store information on, or access information about, a user's device and can be used to build cross-site profiles, they generally fall within the same legal regimes as cookies: the ePrivacy Directive (and its national implementations) governs the storing of or gaining access to information on the device, while the GDPR governs any resulting processing of personal data. Where such tracking is not strictly necessary for a service requested by the user, prior consent is typically required in most EU jurisdictions, though the precise treatment of any given technique depends on its technical operation and on evolving guidance from data protection authorities. The evidence provided describes the concept and example techniques but does not establish enforcement positions, so the lawfulness of specific supercookie implementations is out of scope for this definition.
Why it matters
Supercookies matter because they can undermine the transparency and control that cookie consent frameworks are designed to provide. When a tracking identifier is inserted at the network level within HTTP headers, or reconstructed through browser features such as favicons, it can persist even after a user clears their standard cookies. This means a user who takes deliberate steps to reset their tracking preferences may still be re-identified and followed across websites, defeating the choices that consent mechanisms are meant to honor.
For compliance teams, supercookies are significant because they generally fall within the same legal regimes as ordinary cookies. In most EU jurisdictions, the ePrivacy Directive (and its national implementations) governs the storing of or gaining access to information on a user's device, while the GDPR governs any resulting processing of personal data. A technique being harder to detect than a conventional cookie does not place it outside these rules; where the tracking is not strictly necessary for a service the user has requested, prior consent is typically required. Organizations that rely on such techniques, or whose vendors do, may therefore carry consent and transparency obligations they have not accounted for.
The practical challenge is that supercookies are not a single technology but a family of techniques, and their treatment depends on how each one operates. The evidence here describes the concept and example mechanisms but does not establish enforcement positions, so the lawfulness of any specific implementation cannot be assumed and depends on facts and on evolving guidance from data protection authorities.
Who it's relevant to
Inside Supercookies
Common questions
Answers to the questions practitioners most commonly ask about Supercookies.
