Targeting Cookies
Targeting cookies are small files placed in your web browser that help advertising systems recognize your device or browser as you move between different websites. They are used to build a profile of your likely interests based on your browsing behavior, so that advertisers can show you ads matched to those interests. Because they track activity for advertising rather than being essential to a website's basic operation, they generally require your prior consent in the EU and UK.
Targeting cookies (also referred to as advertising cookies or cookie-based targeting) are browser cookies used to identify a device or browser across multiple sites, enabling advertising systems to construct interest or behavioral profiles from browsing history and preferences. Functionally, they support behavioral targeting by associating a persistent identifier with observed activity, and related technologies such as pixels, SDKs, and other identifiers may serve equivalent purposes and fall within the same regulatory treatment. Under the EU ePrivacy Directive and its national implementations, placing or reading such cookies generally requires prior consent, since they are not strictly necessary to deliver a service the user has requested; any subsequent processing of resulting personal data is separately governed by the GDPR, which requires that consent be freely given, specific, informed, and unambiguous. Consent standards differ by jurisdiction, several US state privacy frameworks rely on opt-out mechanisms rather than opt-in, so the applicable obligation depends on the geographic and legal scope. Note that industry responses such as cookieless targeting aim to reach audiences using first-party data and other methods without relying on these cookies; the precise categorization of a given cookie and its consent requirements depend on facts and evolving regulatory guidance not fully resolved by this definition.
Why it matters
Targeting cookies sit at the center of the tension between behavioral advertising and privacy law. Because they recognize a device or browser across multiple sites to build interest profiles, they are not strictly necessary to deliver a service the user has requested. Under the EU ePrivacy Directive and its national implementations, placing or reading such cookies generally requires prior consent, and any personal data processing that follows is separately governed by the GDPR. This makes targeting cookies one of the most scrutinized categories in consent management, and misclassifying them as essential or defaulting them to "on" is a common source of compliance risk in the EU and UK.
The stakes are heightened by the fact that consent standards differ by jurisdiction. In the EU and UK, valid consent must generally be freely given, specific, informed, and unambiguous, requiring a clear affirmative action before targeting cookies are set. By contrast, several US state privacy frameworks rely on opt-out mechanisms rather than opt-in, so the same advertising practice may carry different obligations depending on where the user is located. Organizations operating across regions cannot assume that a single consent approach satisfies every applicable regime.
Targeting cookies also matter because the same regulatory treatment extends to functionally equivalent technologies. Pixels, SDKs, and other persistent identifiers used for advertising fall within the same rules even though they are not literally cookies. As industry shifts toward cookieless targeting approaches that rely on first-party data and other methods, the categorization of a given identifier and its consent requirements remain fact-dependent and subject to evolving regulatory guidance, which is why careful, jurisdiction-aware classification remains essential.
Who it's relevant to
Inside Targeting Cookies
Common questions
Answers to the questions practitioners most commonly ask about Targeting Cookies.

