Skip to main content
Category: Tracking Technologies

Universal Identifiers

Also known as: UID, Universal ID, Universal IDs
Simply put

A universal identifier is a persistent code assigned to an individual that lets businesses recognize the same person across different websites, devices, and advertising platforms. Because these identifiers can single out and follow a person over time, using them generally involves processing personal data and, in most EU jurisdictions, may trigger consent and transparency obligations similar to those for cookies. The precise rules depend on how the identifier is created, stored, and shared, which is not fully addressed here.

Formal definition

A universal identifier is a unique, persistent identifier assigned to an individual to enable consistent recognition across platforms, devices, and ad tech environments, as an alternative or complement to third-party cookies. Although such identifiers are not literally cookies, in the EU and UK the ePrivacy rules on placing and accessing information on a user's device may apply where the identifier is stored on or read from the device, while any subsequent processing of the identifier as personal data is governed separately by the GDPR; consent obtained under one regime does not automatically satisfy the other. Where a universal identifier is used for analytics or advertising rather than a strictly necessary purpose, prior consent meeting the freely given, specific, informed, and unambiguous standard is typically required in most EU jurisdictions, whereas certain US state frameworks may instead rely on opt-out mechanisms; obligations vary by jurisdiction and the specific technical implementation. The term should not be confused with unrelated technical identifiers such as URIs or UUIDs, which are naming or numbering schemes rather than cross-platform user-tracking identifiers.

Why it matters

Universal identifiers have gained prominence as the advertising industry looks for alternatives or complements to third-party cookies. Because a universal identifier is designed to recognize the same individual consistently across websites, devices, and ad tech environments, it can single out and follow a person over time. This means that, even though such identifiers are not literally cookies, they raise many of the same privacy concerns and can attract similar regulatory obligations where personal data is involved.

For compliance teams, the key issue is that using a universal identifier generally involves processing personal data. In the EU and UK, this engages two distinct legal regimes that must each be considered on their own terms: the ePrivacy rules on placing and accessing information on a user's device may apply where the identifier is stored on or read from the device, while the GDPR governs any subsequent processing of the identifier as personal data. Consent obtained under one regime does not automatically satisfy the other, so treating a universal identifier as a straightforward cookie replacement without reassessing the legal basis can create compliance gaps.

The applicable requirements also vary by jurisdiction and by how the identifier is technically implemented. Where a universal identifier is used for analytics or advertising rather than a strictly necessary purpose, prior consent meeting the freely given, specific, informed, and unambiguous standard is typically required in most EU jurisdictions, whereas certain US state frameworks may instead rely on opt-out mechanisms. Because the precise rules depend on how the identifier is created, stored, and shared, organizations should assess each deployment on its facts rather than assuming a single approach is lawful everywhere.

Who it's relevant to

Privacy and data protection officers
Universal identifiers generally involve processing personal data because they can single out and follow individuals over time. Privacy officers need to assess the applicable legal basis under the GDPR and the separate ePrivacy obligations where the identifier is stored on or read from a device, and should document how consent or another basis is established for each implementation rather than assuming a cookie-based approach carries over.
Legal and compliance counsel
Because obligations vary between the EU, the UK, and individual US states, counsel must map how a given universal identifier deployment is treated in each relevant jurisdiction. In most EU jurisdictions, use for analytics or advertising may require prior consent meeting the freely given, specific, informed, and unambiguous standard, while certain US state frameworks may rely on opt-out. Counsel should also confirm that consent obtained under ePrivacy rules is not treated as automatically satisfying the GDPR, or vice versa.
Marketing and ad tech teams
Universal identifiers are often adopted as an alternative or complement to third-party cookies for cross-platform recognition. Teams deploying them should understand that they are not exempt from consent or transparency requirements simply because they are not cookies, and should coordinate with privacy and legal colleagues on how the identifier is created, stored, and shared before rolling it out across markets.
Web developers and engineers
How an identifier is technically implemented directly affects which rules apply, including whether it is stored on or read from the user's device and how it is shared between platforms. Engineers should design implementations that support consent capture, record-keeping, and opt-out signals where relevant, and should keep universal identifiers distinct from unrelated technical schemes such as URIs or UUIDs, which serve naming or numbering purposes rather than user tracking.

Inside UID

Persistent Identifier
A stable identifier assigned to a user or device that can be recognized consistently across multiple websites, sessions, or advertising platforms, enabling recognition without relying on traditional third-party cookies.
Hashed or Derived Values
Universal identifiers are frequently built from personal data such as email addresses or phone numbers that are hashed or otherwise transformed. Even when hashed, such values may still constitute personal data under the GDPR where they can be linked back to an individual.
Cross-Domain Matching Capability
The mechanism that allows the identifier to be shared or matched between publishers, advertisers, and ad-tech intermediaries, supporting audience targeting and measurement across the digital advertising ecosystem.
Storage and Access Layer
Universal identifiers may be stored in cookies, local storage, or other client-side or server-side means. Placing or accessing this information on a user's device generally falls within the scope of the ePrivacy Directive's national implementations in the EU, separately from any subsequent GDPR processing.
Consent and Legal Basis Dependencies
Because they typically involve non-essential tracking and the processing of personal data, universal identifiers generally require prior consent in most EU jurisdictions, while frameworks such as the CCPA and CPRA in California may instead rely on opt-out mechanisms.

Common questions

Answers to the questions practitioners most commonly ask about UID.

Do universal identifiers avoid consent requirements because they are not technically cookies?
No. Under EU law, the ePrivacy Directive governs the storing of or gaining access to information on a user's device regardless of the technology used, so identifiers stored via local storage, SDKs, or similar mechanisms generally fall within the same consent rules as cookies. Separately, where a universal identifier relates to an identifiable individual, its processing typically also engages the GDPR. The absence of a literal cookie does not by itself remove either the ePrivacy consent obligation or GDPR processing obligations. The precise analysis depends on the specific implementation and jurisdiction.
Does hashing or pseudonymising an email address before creating a universal identifier mean it is no longer personal data?
Not necessarily. Pseudonymisation, including hashing, generally reduces risk but does not by itself take data outside the scope of the GDPR, because a hashed identifier that can be linked back to an individual or used to single them out typically remains personal data. Whether a given identifier is personal data is a fact-specific question that depends on the means reasonably likely to be used to re-identify the individual. This entry does not resolve that question for any particular deployment, and where an identifier is used to target or recognise a person it will often continue to be treated as personal data in the EU and UK.
What consent or opt-out approach applies when deploying universal identifiers across different jurisdictions?
The applicable standard varies by region. In most EU jurisdictions and in the UK, prior consent meeting the freely given, specific, informed, and unambiguous standard is generally required before setting or accessing an identifier used for advertising or analytics, subject to any applicable exemptions. Under several US state frameworks, such as those in California, obligations may instead center on providing an opt-out of sale or sharing and honoring signals like Global Privacy Control. Organizations operating across regions typically need to map identifier use to each applicable regime rather than applying a single approach everywhere. Specific obligations depend on the facts and current regulatory guidance.
How should universal identifiers be integrated with a consent management platform (CMP)?
As a general matter, the deployment of a universal identifier should be gated by the consent or preference state captured by the CMP, so that the identifier is not set or shared before a valid legal basis exists where one is required. This may involve mapping the identifier to the relevant purpose categories, respecting signals the CMP surfaces, and suppressing identifier activity when consent is withheld or an opt-out is exercised. Where the IAB Transparency and Consent Framework is used, the identifier's vendors and purposes would typically need to align with the framework's signals. A CMP can support this orchestration but does not by itself guarantee compliance; legal judgment about scope and configuration remains necessary.
What record-keeping considerations apply to universal identifiers?
Where consent is the legal basis, organizations are generally expected to be able to demonstrate that valid consent was obtained, which typically involves logging the consent state, the purposes covered, and the ability to evidence the affirmative action, consistent with accountability principles. For identifiers governed by opt-out regimes, maintaining records that opt-out requests and relevant signals were received and honored may be relevant. The specific retention and record-keeping expectations depend on the applicable jurisdiction and current regulatory guidance, which this entry does not enumerate.
How should a withdrawal of consent or an opt-out be handled once a universal identifier has been created?
In general, withdrawing consent should be as easy as giving it, and once consent is withdrawn or an opt-out is exercised, the ongoing setting, reading, or sharing of the identifier for the affected purposes would typically need to stop. Depending on the implementation and the applicable regime, this may also raise questions about the continued use of, or the need to address, data already associated with the identifier, including downstream partners with whom it was shared. The precise operational steps and whether previously shared data must be addressed depend on facts not covered by this definition and on the applicable legal framework.

Common misconceptions

Universal identifiers are a privacy-safe replacement for third-party cookies and therefore do not require consent.
Universal identifiers generally serve tracking and targeting purposes similar to third-party cookies and, in most EU jurisdictions, are treated under the same rules. Placing or accessing them on a device typically triggers ePrivacy consent requirements, and processing the associated personal data triggers GDPR obligations. Being cookieless does not exempt a technology from these frameworks.
Hashing an email address or other identifier means it is no longer personal data, so privacy law does not apply.
Hashing typically pseudonymizes rather than anonymizes data. Where a hashed value can still be linked back to an individual, directly or indirectly, it is generally still personal data under the GDPR, and the relevant obligations continue to apply.
Consent obtained to set a universal identifier in one jurisdiction covers its use everywhere.
Consent standards and legal bases differ across regimes. Opt-in consent in the EU and UK is not equivalent to the opt-out approach used under some US state laws such as the CCPA and CPRA, and consent under the ePrivacy rules does not automatically satisfy the separate GDPR requirements for processing the resulting personal data.

Best practices

Map where universal identifiers are stored and accessed (cookies, local storage, or server-side), and treat the placing of and access to that information as subject to ePrivacy consent requirements in relevant EU jurisdictions.
Assess separately whether the identifier or its underlying values constitute personal data under the GDPR, including hashed or derived values, and document an appropriate legal basis for the subsequent processing.
Obtain prior, freely given, specific, informed, and unambiguous consent through a clear affirmative action before setting non-essential universal identifiers where consent is required, avoiding pre-ticked boxes, implied consent, and cookie walls in the EU.
Differentiate consent handling by jurisdiction, applying opt-in approaches in the EU and UK while accommodating opt-out mechanisms and signals such as Global Privacy Control where US state laws like the CCPA and CPRA apply.
Use a consent management platform to signal and log user choices to downstream ad-tech partners, while recognizing that such tools support but do not guarantee compliance or replace legal judgment.
Maintain records of consent and the vendors or partners with whom identifiers are shared, and review these arrangements as regulatory guidance on cross-domain and cookieless tracking continues to evolve.