Skip to main content
green gradient background, "The Future of Application Security Is Already Here." and a read the report button.
Category: Cookie Types

Targeting Cookies

Also known as: Advertising Cookies, Cookie-Based Targeting, Behavioral Targeting Cookies
Simply put

Targeting cookies are small files placed in your web browser that help advertising systems recognize your device or browser as you move between different websites. They are used to build a profile of your likely interests based on your browsing behavior, so that advertisers can show you ads matched to those interests. Because they track activity for advertising rather than being essential to a website's basic operation, they generally require your prior consent in the EU and UK.

Formal definition

Targeting cookies (also referred to as advertising cookies or cookie-based targeting) are browser cookies used to identify a device or browser across multiple sites, enabling advertising systems to construct interest or behavioral profiles from browsing history and preferences. Functionally, they support behavioral targeting by associating a persistent identifier with observed activity, and related technologies such as pixels, SDKs, and other identifiers may serve equivalent purposes and fall within the same regulatory treatment. Under the EU ePrivacy Directive and its national implementations, placing or reading such cookies generally requires prior consent, since they are not strictly necessary to deliver a service the user has requested; any subsequent processing of resulting personal data is separately governed by the GDPR, which requires that consent be freely given, specific, informed, and unambiguous. Consent standards differ by jurisdiction, several US state privacy frameworks rely on opt-out mechanisms rather than opt-in, so the applicable obligation depends on the geographic and legal scope. Note that industry responses such as cookieless targeting aim to reach audiences using first-party data and other methods without relying on these cookies; the precise categorization of a given cookie and its consent requirements depend on facts and evolving regulatory guidance not fully resolved by this definition.

Why it matters

Targeting cookies sit at the center of the tension between behavioral advertising and privacy law. Because they recognize a device or browser across multiple sites to build interest profiles, they are not strictly necessary to deliver a service the user has requested. Under the EU ePrivacy Directive and its national implementations, placing or reading such cookies generally requires prior consent, and any personal data processing that follows is separately governed by the GDPR. This makes targeting cookies one of the most scrutinized categories in consent management, and misclassifying them as essential or defaulting them to "on" is a common source of compliance risk in the EU and UK.

The stakes are heightened by the fact that consent standards differ by jurisdiction. In the EU and UK, valid consent must generally be freely given, specific, informed, and unambiguous, requiring a clear affirmative action before targeting cookies are set. By contrast, several US state privacy frameworks rely on opt-out mechanisms rather than opt-in, so the same advertising practice may carry different obligations depending on where the user is located. Organizations operating across regions cannot assume that a single consent approach satisfies every applicable regime.

Targeting cookies also matter because the same regulatory treatment extends to functionally equivalent technologies. Pixels, SDKs, and other persistent identifiers used for advertising fall within the same rules even though they are not literally cookies. As industry shifts toward cookieless targeting approaches that rely on first-party data and other methods, the categorization of a given identifier and its consent requirements remain fact-dependent and subject to evolving regulatory guidance, which is why careful, jurisdiction-aware classification remains essential.

Who it's relevant to

Privacy officers and data protection professionals
These professionals are responsible for classifying targeting cookies correctly and ensuring they are not treated as essential. They must confirm that prior consent is obtained where required in the EU and UK, and that opt-out mechanisms are honored in jurisdictions that rely on them, while recognizing that the same rules typically extend to pixels, SDKs, and other identifiers used for advertising.
Legal counsel and compliance teams
Counsel advising on advertising practices need to assess how consent standards differ across the EU, UK, and individual US states, since obligations range from opt-in to opt-out. They also weigh unresolved questions of categorization and evolving regulatory guidance rather than assuming any single consent approach is lawful everywhere.
Web developers and CMP implementers
Developers implement the technical controls that prevent targeting cookies and equivalent technologies from being set before consent is captured. This includes wiring advertising tags to a consent management platform's signals so that placement occurs only after the applicable consent or opt-out status has been resolved.
Marketing and adtech teams
Marketers who rely on behavioral targeting need to understand that these cookies build interest profiles from browsing behavior and generally require prior consent in the EU and UK. As the industry moves toward cookieless targeting using first-party data and other methods, these teams must adapt their audience strategies while remaining within the applicable legal scope.

Inside Targeting Cookies

Purpose of targeting cookies
Targeting cookies (also called advertising or marketing cookies) are typically used to build profiles of user interests, deliver behaviourally targeted advertising, measure ad campaign performance, and share data with advertising partners or networks.
Consent classification
In most EU and UK contexts, targeting cookies are not considered strictly necessary and therefore generally require prior, informed consent under the ePrivacy Directive (as nationally implemented) before they are placed or accessed on a user's device.
Related non-cookie technologies
Targeting frequently relies on technologies beyond literal cookies, such as tracking pixels, web beacons, local storage, mobile SDKs, and device fingerprinting. These generally fall within the same consent rules where they involve storing or accessing information on a device.
Two-layer legal analysis
Placing or reading a targeting cookie is governed by the ePrivacy rules, while any subsequent processing of personal data derived from it (for example, profiling for ad targeting) is separately governed by the GDPR in the EU. Consent for one does not automatically satisfy the other.
Third-party and cross-site dimension
Targeting cookies are often set by third parties and used to track users across multiple sites, which raises additional questions around joint responsibility, transparency about recipients, and international data sharing.
Jurisdictional variation
Treatment differs by regime: EU and UK approaches generally rely on opt-in consent, whereas several US state laws such as California's CCPA/CPRA typically operate on an opt-out model for the sale or sharing of personal information and targeted advertising.

Common questions

Answers to the questions practitioners most commonly ask about Targeting Cookies.

Are targeting cookies the same thing as advertising cookies, or a separate category?
The terms overlap heavily and are often used interchangeably. Targeting cookies (sometimes labelled advertising or marketing cookies) are generally those used to build profiles, track users across sites, and deliver personalised advertising or measure ad performance. Cookie categorisation is not standardised in law, so the label a consent management platform applies matters less than the actual purpose of the cookie. What is consistent across most EU and UK guidance is that cookies serving these purposes are not treated as strictly necessary and typically require prior consent. You should classify based on function rather than assume any fixed taxonomy applies universally.
If a user has accepted cookies once, can targeting cookies keep running indefinitely without asking again?
Not necessarily. Consent under the GDPR must remain freely given, specific, informed, and unambiguous, and it can be withdrawn as easily as it was given, so users must have an ongoing means to change their choice. Many data protection authorities in the EU suggest that consent should be refreshed periodically rather than treated as permanent, though there is no single harmonised interval mandated across all jurisdictions. Requirements also differ under US state frameworks, which more commonly rely on opt-out mechanisms rather than a one-time opt-in. Treat a prior acceptance as a current, revocable permission rather than an indefinite licence, and confirm the position under the specific regime that applies to your users.
When should targeting cookies actually be set on a user's device?
In most EU and UK contexts, targeting cookies should generally be set only after the user has given a clear affirmative consent, because the ePrivacy rules govern the placing of and access to information on a device and require prior consent for non-essential cookies. This typically means they must not fire on page load before a choice is made. Under some US state laws the model differs, often permitting the cookies to run subject to an opt-out. The correct timing depends on the applicable jurisdiction, so configure your consent management platform to reflect the regime governing each user rather than a single global default.
How should targeting cookies be presented in a consent banner?
Targeting cookies are generally presented as a distinct, non-essential category that the user can accept or reject separately, reflecting the requirement in most EU jurisdictions that consent be specific and granular rather than bundled. The description should be clear enough for the user to understand the purpose, and reject options are widely expected to be as accessible as accept options. Pre-ticked boxes and designs that pressure acceptance are widely considered non-compliant in the EU. Note that these expectations derive from regulatory guidance that continues to evolve, and the exact presentation appropriate for US state regimes may rely on an opt-out rather than an opt-in interface.
What records should be kept for consent to targeting cookies?
Organisations subject to the GDPR are generally expected to be able to demonstrate that valid consent was obtained, which in practice means logging information such as what the user consented to, when, and the state of the banner they were shown. A consent management platform can support this record-keeping, but it does not by itself guarantee compliance or replace legal judgement about whether the underlying consent was valid. The specific records that are sufficient are not exhaustively prescribed and can depend on regulator expectations, so this definition does not set a fixed retention or format standard.
Do the same rules apply if I use pixels, SDKs, or fingerprinting instead of cookies for targeting?
In most EU and UK contexts, yes. The ePrivacy rules on placing and accessing information on a device are generally understood to cover similar technologies such as tracking pixels, local storage, mobile SDKs, and device fingerprinting, even though these are not literally cookies. Where such technologies are used for targeting, they typically attract the same prior-consent expectations, and any resulting processing of personal data is separately governed by the GDPR. Whether a specific technique falls within scope can depend on how it operates and on evolving regulatory interpretation, so assess each technology on its facts rather than assuming a cookie-only rule.

Common misconceptions

Targeting cookies can be set as soon as the page loads, as long as a banner is shown.
In most EU and UK jurisdictions, non-essential cookies such as targeting cookies should generally not be placed before the user gives a clear affirmative consent. Merely displaying a banner, relying on continued browsing, or using pre-ticked boxes is widely considered insufficient for valid consent.
Only technologies literally called 'cookies' are subject to these consent rules.
Similar tracking technologies used for targeting, including pixels, local storage, SDKs, and fingerprinting, generally fall within the same rules where they involve storing or accessing information on a user's device, even though they are not technically cookies.
The same opt-in consent approach for targeting cookies applies everywhere.
Requirements vary by jurisdiction. EU and UK frameworks generally require opt-in consent, while several US state privacy laws typically rely on an opt-out mechanism for targeted advertising and the sale or sharing of personal information. Scope and enforcement positions continue to evolve.

Best practices

Block targeting cookies and equivalent tracking technologies (pixels, SDKs, local storage, fingerprinting) from firing until the user has given a clear affirmative, specific opt-in where required in EU and UK contexts.
Present targeting cookies as a distinct, granular category so users can consent to or refuse them separately, rather than bundling them with strictly necessary or other cookie types.
Provide clear, accessible information about the purposes of targeting, the third parties or categories of recipients involved, and any cross-site tracking, to help satisfy the informed element of valid consent.
Address both legal layers: obtain consent for placing or reading the cookie under ePrivacy rules and ensure a lawful basis and transparency for the downstream processing of personal data under the GDPR.
Tailor the consent approach to each jurisdiction, distinguishing opt-in requirements in the EU and UK from opt-out mechanisms and signals (such as Global Privacy Control) recognized under certain US state laws.
Use a consent management platform and consent logging to support record-keeping and enforcement of user choices, while recognizing that such tools support but do not replace legal judgment or guarantee compliance.
Promotional banner for the Pentest Readiness checklist download