Universal Identifiers
A universal identifier is a persistent code assigned to an individual that lets businesses recognize the same person across different websites, devices, and advertising platforms. Because these identifiers can single out and follow a person over time, using them generally involves processing personal data and, in most EU jurisdictions, may trigger consent and transparency obligations similar to those for cookies. The precise rules depend on how the identifier is created, stored, and shared, which is not fully addressed here.
A universal identifier is a unique, persistent identifier assigned to an individual to enable consistent recognition across platforms, devices, and ad tech environments, as an alternative or complement to third-party cookies. Although such identifiers are not literally cookies, in the EU and UK the ePrivacy rules on placing and accessing information on a user's device may apply where the identifier is stored on or read from the device, while any subsequent processing of the identifier as personal data is governed separately by the GDPR; consent obtained under one regime does not automatically satisfy the other. Where a universal identifier is used for analytics or advertising rather than a strictly necessary purpose, prior consent meeting the freely given, specific, informed, and unambiguous standard is typically required in most EU jurisdictions, whereas certain US state frameworks may instead rely on opt-out mechanisms; obligations vary by jurisdiction and the specific technical implementation. The term should not be confused with unrelated technical identifiers such as URIs or UUIDs, which are naming or numbering schemes rather than cross-platform user-tracking identifiers.
Why it matters
Universal identifiers have gained prominence as the advertising industry looks for alternatives or complements to third-party cookies. Because a universal identifier is designed to recognize the same individual consistently across websites, devices, and ad tech environments, it can single out and follow a person over time. This means that, even though such identifiers are not literally cookies, they raise many of the same privacy concerns and can attract similar regulatory obligations where personal data is involved.
For compliance teams, the key issue is that using a universal identifier generally involves processing personal data. In the EU and UK, this engages two distinct legal regimes that must each be considered on their own terms: the ePrivacy rules on placing and accessing information on a user's device may apply where the identifier is stored on or read from the device, while the GDPR governs any subsequent processing of the identifier as personal data. Consent obtained under one regime does not automatically satisfy the other, so treating a universal identifier as a straightforward cookie replacement without reassessing the legal basis can create compliance gaps.
The applicable requirements also vary by jurisdiction and by how the identifier is technically implemented. Where a universal identifier is used for analytics or advertising rather than a strictly necessary purpose, prior consent meeting the freely given, specific, informed, and unambiguous standard is typically required in most EU jurisdictions, whereas certain US state frameworks may instead rely on opt-out mechanisms. Because the precise rules depend on how the identifier is created, stored, and shared, organizations should assess each deployment on its facts rather than assuming a single approach is lawful everywhere.
Who it's relevant to
Inside UID
Common questions
Answers to the questions practitioners most commonly ask about UID.