Cookieless Tracking: GDPR-Compliant Tracking Alternatives

Last updated:
19.01.2022
Third-party cookies, which are set when visiting almost any website, are set to be phased out. This poses a problem for many advertisers, as cookie-based tracking is a massive market. So, what is the alternative? And is it more compliant with data protection regulations?
Cookieless Tracking: GDPR-Compliant Tracking Alternatives
Key Takeaways
  • Third-party cookies are being phased out; cookieless tracking is the alternative.
  • GDPR requires consent for tracking cookies.
  • Cookieless tracking: server-side tracking instead of client-side tracking.
  • Alternatives: device fingerprinting, cohort targeting, user ID tracking, ID graph tracking, eTracker.
  • The requirement for consent for personal data remains in effect.

For a long time, cookies on the internet were handled like the Wild West: there seemed to be no rules. That changed with the introduction of the GDPR, which established guidelines to better protect the personal data of internet users from tracking via cookies without their consent. Furthermore, the ePrivacy Regulation was intended to provide final clarity on the subject of cookie tracking. The problem: the ePrivacy Regulation was supposed to be completed in 2020, but it still hasn't been. And while this legislation, which is intended to regulate the correct use of cookies among other things, is still being debated, technology has once again outpaced the law. Cookieless tracking is the new trend. But how is it supposed to work? And what does this mean for internet users and advertisers?

Tracking & Data Privacy: Cookies Only with Consent

The GDPR is constantly being "refined"—including in relation to cookies. For example, it must be possible for users to select cookies individually and thus opt out of non-technically necessary cookies so that they can visit a website completely free of analysis and tracking cookies. However, other questions regarding cookies have still not been finally resolved. While there is still debate, for example, over whether web shop operators should be allowed to run cookies based on legitimate interest from the start, technology is already a step ahead—in the post-cookie era. Background: With the decline of cookies and the lack of consent for analysis and tracking cookies, it is becoming difficult or sometimes impossible to track users—which means billions in losses for advertisers, among others. The new method of choice: tracking without cookies, also known as cookieless tracking. This method is now intended to avert the catastrophe feared in online marketing. But how does it work? And what does the GDPR say about this topic?     

What is Cookieless Tracking?

Tracking without cookies is also called server-side tracking because this tracking runs via an internet server rather than through the browser (client) as with "conventional" tracking using cookies (also called client-side tracking). With previous cookie-based tracking, a lot of information about a person surfing the internet is collected and assembled into a profile. This works by tracking the user across many websites on the internet using cookies. In this way, data about them can be collected bit by bit—though this is primarily device-specific. If said person suddenly uses a different device, for example a new smartphone on a different Wi-Fi network, it takes a while before all of this can be assigned to the existing profile. This is made possible by the digital footprint that is left behind on the internet, which varies in size while surfing. Tracking without cookies now works differently—and there are various possibilities.

Tracking Without Cookies: Alternatives Companies Can Use

The most frequently used tracking methods that do not require cookies are:

  • Transmission of technical profiles, also known as device fingerprint tracking: Here, information about the users' devices is collected. For example, the technical hardware used, installed updates, or features like Google Fonts can provide a fairly accurate picture of a person. Someone surfing on an ancient laptop with outdated browser settings will receive different advertising offers than someone entering the internet from the latest smartphone equipped with many technical plugins. The insidious part: unlike with cookies, no data is stored locally on the users' devices—and therefore cannot be blocked or deleted. Even surfing in private mode or with an ad blocker no longer helps here. However, the common browser providers have already reacted to this and, through various settings, only allow the transmission of restricted technical profiles. This cookieless tracking method is therefore not very accurate. Also important to know: users must actively consent to or reject this tracking method when visiting a website (consent requirement).
  • Cohort Targeting: This is a method used by companies like Facebook. Users are divided into different cohorts, or groups, using browser data. A single group usually consists of several thousand people. However, this tracking is by no means inaccurate: if Person X is in the "sports car," "luxury watch," and "long-distance travel" cohorts, a fairly accurate picture of them emerges. This tracking method, however, requires an enormous amount of data so that a person can be placed into many cohorts—this is the only way to create the most accurate picture possible.
  • ID-based targeting or User-ID tracking: This is particularly interesting for websites that offer a login area. If a user logs into a member area on a website, their behavior can be precisely evaluated and tracked across devices (so-called cross-device tracking) by following the activities associated with an ID. This allows for very detailed profiles to be created—but only if the users are logged in and consent to the tracking.
  • ID Graph Tracking (also called deterministic and probabilistic matching): Here, all data that users voluntarily leave behind while surfing is collected, for example in form fields: email addresses, addresses, or phone numbers. This data is collected under a randomly generated ID—essentially, a profile is created under a pseudonym. This profile is gradually enriched with other cookieless information, such as browser data. If the person surfs the internet using a different device, the newly emerging profile is compared with existing virtual profiles. If two profiles overlap due to very similar surfing behavior, they are matched. Recognizing and merging related (deterministic matches) or comparable (probabilistic matches) profiles is done using AI, or artificial intelligence, and algorithms. This allows users to be reliably recognized time and again and profiles to be expanded. Important: This tracking requires user consent, as personal data is being processed.
  • eTracker without cookies: eTracker cookieless is a website analytics tool from Germany that provides privacy-friendly website analysis. It can be operated with or without cookies and is considered a more privacy-compliant alternative to Google Analytics.

Tracking without cookies – GDPR compliant?

Some of the methods mentioned above are privacy-friendly because they do not collect personal data. However, profiles of users are still created. Other cookieless tracking methods do collect personal data and therefore strictly require user consent. It is clear that tracking without cookies will become increasingly important on the internet—especially now that the TTDSG is in effect, and even more so once the ePrivacy Regulation is introduced and the guidelines for "classic" cookies are tightened further. Accordingly, more and/or more sophisticated methods for cookieless tracking will enter the market in the foreseeable future. This should please advertisers, as it helps secure further advertising revenue. For internet users, however, the advice remains the same: engage with the cookie banner (which will apply to cookieless tracking in this or a similar form in the future) on websites and choose the tracking settings you are most comfortable with.

Do you have further questions on this topic? Our experts will be happy to advise you free of charge.

If you're looking for a partner to support you on your journey to data protection and information security, feel free to contact our team of experienced experts.
60+ Expertinnen und Experten
Book a consultation
Topics
Editorial
Alexander Ingelheim
Co-Founder & CEO
Alexander Ingelheim is Co-founder and CEO of Proliance. His driving force from day one has been to support companies with the hurdles and challenges of data protection and GDPR. He brings extensive experience from his work in international consulting, including positions at Bregal Unternehmerkapital GmbH and McKinsey & Company. He is also a certified Data Protection Officer (TÜV & DEKRA).
Zum Autorenprofil
Zum Expertenprofil
About Proliance
Proliance stands for Professional Compliance for businesses. We are a digitally driven Legal Tech company based in Munich, established in 2017 and now with over 90 privacy enthusiasts. Our more than 2,500 clients include start-ups, medium-sized businesses, and corporate groups from almost all industries.
About us
Latest Articles

Topics you might be interested in