Web Beacons
A web beacon is a tiny, usually invisible graphic or file embedded in a web page or email that allows the sender or site operator to detect when the content has been viewed or opened. It is commonly used to track user behavior, gather analytics, and monitor how people interact with a page or message. Although not a cookie, it serves a similar tracking purpose and is often used alongside cookies.
A web beacon is a small, typically transparent or invisible object (often a 1x1 pixel image or other embedded resource) placed on a web page or within an email that, when loaded from a remote server, signals that the containing content has been accessed. The retrieval request can convey information such as access time and associated identifiers, enabling analytics and behavioral tracking, frequently in combination with cookies. Because web beacons involve reading from or writing to a user's device and may facilitate the processing of personal data, they generally fall within the same regulatory scope as cookies under EU frameworks such as the ePrivacy Directive and, where personal data is processed, the GDPR; consequently, non-essential beacons typically require prior consent in most EU jurisdictions, while requirements differ under other regimes such as US state privacy laws. The precise compliance treatment depends on the specific use, data collected, and applicable jurisdiction, which are outside the scope of this definition.
Why it matters
Web beacons matter because they extend tracking capabilities beyond cookies into contexts where cookies alone are limited, most notably email. When an email containing a beacon is opened, the remote request to load the invisible image can signal that the message was viewed, along with information such as access time and associated identifiers. This makes beacons a powerful tool for analytics and behavioral monitoring, but also one that can operate without a user's awareness, since the tracking element is typically invisible.
From a compliance standpoint, web beacons are significant because they are frequently treated in the same way as cookies under EU frameworks. The placing of or access to information on a user's device is governed by the ePrivacy Directive and its national implementations, and where the beacon facilitates the processing of personal data, the GDPR applies as well. As a result, non-essential beacons generally require prior consent in most EU jurisdictions, whereas requirements differ under other regimes such as US state privacy laws, which often rely on opt-out mechanisms. Because beacons are not literally cookies, organizations sometimes overlook them when building consent and disclosure practices, creating a compliance gap.
The precise treatment of any given beacon depends on how it is used, what data it collects, and the applicable jurisdiction, and these facts are outside the scope of a general definition. Organizations should assess each beacon deployment on its own terms rather than assuming that a technology which is not a cookie falls outside consent obligations.
Who it's relevant to
Inside Web Beacons
Common questions
Answers to the questions practitioners most commonly ask about Web Beacons.

