FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Advertising
  4. BlokID

BlokID

MarketingWebsite

Related services

<

<model-viewer>

<model-viewer> is a marketing platform that equips businesses with tools to amplify their digital presence and drive customer acquisition. It supports audience segmentation, campaign automation, and cross-channel engagement. <model-viewer> provides real-time analytics and reporting dashboards for performance measurement and strategy optimization. By combining data intelligence with marketing execution, <model-viewer> helps deliver the right message to the right audience at the right time.

Marketing

33Across

33Across is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 33Across enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 33Across empowers marketing teams to achieve measurable growth.

Marketing

7moor

7moor is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. 7moor enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, 7moor empowers marketing teams to achieve measurable growth.

Marketing

A-Frame

A-Frame is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. A-Frame integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, A-Frame helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Aarki

Aarki is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. Aarki enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, Aarki empowers marketing teams to achieve measurable growth.

Marketing
A

Acquia Campaign Factory

Acquia Campaign Factory is a marketing campaign management platform that helps businesses plan, execute, and measure multi-channel marketing campaigns. It provides tools for audience segmentation, content creation, automated workflows, and performance tracking across email, social, web, and mobile. Acquia Campaign Factory enables personalized messages at scale, real-time campaign optimization, and detailed ROI reports, driving more effective marketing operations and measurable business growth.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does BlokID do?

BlokID is a privacy first identity and consent solution for the advertising supply chain, marketed as safe for child directed inventory. It combines deterministic and probabilistic identity resolution with IAB TCF 2.2 signals and COPPA aware controls, so publishers and advertisers can run addressable and contextual campaigns while honouring GDPR, ePrivacy and US children privacy rules. Typical integration happens server side or through a prebid.js wrapper, which means it processes IP addresses, hashed emails and consent strings on behalf of the publisher.

What BlokID actually does

BlokID is an identity and consent layer designed for the programmatic advertising supply chain. On the publisher side it resolves a visitor into a stable, hashed identifier (often from a logged in email, otherwise from a probabilistic signal combining IP address, user agent and first party cookies). On the advertiser side it exposes that identifier through prebid.js, server side header bidding adapters and a few DSP integrations, alongside the IAB TCF 2.2 consent string. The product is positioned as friendly to child directed and teen audiences because it can downgrade the identifier to a contextual only token when the publisher signals that the inventory is aimed at minors.

From a data protection perspective the publisher is controller, BlokID is processor under GDPR art. 28, and the downstream DSPs are independent or joint controllers depending on the contract. The CJEU IAB Europe ruling (C 604/22, March 2024) confirmed that the TCF consent string is personal data, which means every step of the pipeline must be covered by a valid legal basis and contractual safeguards.

Cookies and identifiers set on the user device

A typical BlokID deployment writes a first party cookie on the publisher domain (commonly named bk_id or bkuid) holding the hashed identifier, a TCF related cookie mirroring the euconsent v2 string, and a short lived synchronisation cookie used to pair the BlokID id with partner ids during cookie syncs. When the publisher activates the cookieless mode, the identifier is held in localStorage instead, but the same data categories are processed. All of these storage operations require prior consent under ePrivacy art. 5(3) regardless of whether the data is technically personal data, because the access to terminal equipment is the trigger.

Lawful basis and the role of consent

The only realistic lawful basis for BlokID on a public website or app is consent under GDPR art. 6(1)(a), collected through a CMP that supports IAB TCF 2.2. Legitimate interest is not available for ad personalisation following the EDPB guidance and the IAB Europe decision of the Belgian DPA. When the user is a minor below the digital age of consent (16 in Germany and the Netherlands, 15 in France, 14 in Italy and Spain, 13 in the United Kingdom and the US under COPPA), the publisher must obtain verifiable parental consent under GDPR art. 8 and, in the US, follow the FTC verifiable parental consent methods (signed form, credit card check, knowledge based authentication, video verification).

Refusal must be as easy as acceptance (CNIL deliberation 2020 091, EDPB guidelines 03/2022 on dark patterns), and consent must be granular per purpose. BlokID itself does not collect consent; it consumes the signal produced by the publisher CMP.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

International data transfers

BlokID operates from EU regions (typically Ireland) and US regions (typically Virginia). When the publisher uses the US endpoint, the hashed identifier, IP address and consent string leave the EEA. The transfer is covered by the EU US Data Privacy Framework (adequacy decision of 10 July 2023) for the US entity, and by Standard Contractual Clauses module 2 plus a transfer impact assessment for any onward transfer. Publishers should keep evidence of the active DPF certification (verifiable on dataprivacyframework.gov) and refresh the TIA at least annually, especially in light of the ongoing schrems III style litigation.

Practical compliance checklist

Sign the BlokID data processing agreement including TCF Annex; list BlokID and every downstream vendor in your privacy notice; run a DPIA under GDPR art. 35; configure your CMP to block BlokID before consent and to honour Global Privacy Control and the OptOut signals required by the California CPRA; verify that the BlokID tag never fires on pages flagged as child directed unless verifiable parental consent has been recorded; map the retention windows (90 days for the identifier, 13 months for TCF consent records under the CNIL recommendation); test the withdrawal flow end to end, including deletion from the BlokID identity graph within 30 days as required by GDPR art. 17.

Alternatives and exit strategy

If BlokID cannot be deployed in a compliant manner, publishers can fall back to fully contextual advertising solutions (Seedtag, Weborama Contextual, GumGum Verity), to publisher first party graphs limited to logged in users with explicit consent, or to clean room based audience activation that keeps raw identifiers on the publisher side. When discontinuing BlokID, ensure the processor confirms in writing the deletion of all identifiers and consent records, and update the IAB Global Vendor List subscription so that the BlokID vendor id is removed from your CMP within the next publication cycle.

GDPR consent category

Marketing

Websites using BlokID must obtain user consent under GDPR regulations.

Legal basisConsent (GDPR art. 6(1)(a) and ePrivacy art. 5(3)); parental consent for users under the COPPA age threshold and verifiable parental consent under GDPR art. 8 for users under the local digital age of consent.
Risk levelhigh
Applicable regulationsGDPR, ePrivacy Directive 2002/58/EC, IAB TCF 2.2, COPPA (US), CCPA/CPRA, UK Children Code (Age Appropriate Design Code), DSA art. 28, Digital Markets Act (where the publisher is a gatekeeper)

DPIA considerations

A Data Protection Impact Assessment under GDPR art. 35 is strongly recommended before deploying BlokID. The combination of large scale identity resolution, behavioural advertising and the explicit positioning toward child directed inventory triggers EDPB criteria 1 (evaluation/scoring), 3 (systematic monitoring), 4 (sensitive or highly personal data such as children data), 7 (data concerning vulnerable subjects) and 8 (innovative use of technology). The DPIA should document the legitimate need, describe the identity graph and TCF signal flow, evaluate re identification risk on hashed identifiers, justify any reliance on the EU US Data Privacy Framework, and define retention, deletion and parental consent workflows. Where the publisher operates an audience aimed at minors, the DPIA must reference the UK Children Code and, in France, the CNIL recommendations on minors online (deliberation 2021 069). Consultation of the supervisory authority under art. 36 may be required if residual risk remains high.

Sample consent text

We use BlokID, an identity and advertising consent service, to recognise your device, share a hashed identifier with our advertising partners and personalise the ads you see on this site. BlokID also relays your IAB TCF 2.2 preferences to those partners. If you are under the digital age of consent in your country (16 in much of the EU, 13 in the US under COPPA), we will only activate BlokID with verifiable parental authorisation. Your data, including a hashed email if you are logged in and your IP address, may be processed in the European Union and the United States under Standard Contractual Clauses and the EU US Data Privacy Framework. You can accept, refuse or withdraw your consent at any time from our cookie preferences panel.

Technical details

Tracking methodidentity_resolution_consent_string
Server locationEU and US (multi region edge with primary processing in Ireland and Virginia)
Cookieless tracking availableYes
Data transferred outside the EUTransfers to the United States rely on the EU US Data Privacy Framework certification of the US entity and on Standard Contractual Clauses (Module 2, controller to processor) supplemented by a transfer impact assessment. Hashed identifiers, IP address truncation and TCF 2.2 signals can leave the EU when the publisher integrates the US delivery endpoint.

Third-party domains contacted

blokid.comcdn.blokid.comid.blokid.comsync.blokid.comeu.blokid.comus.blokid.com

Cookies placed

NameTypeDurationPurpose
bk_idhttp_cookie90 daysFirst party cookie set on the publisher domain. Stores the hashed BlokID identifier used to recognise the visitor across sessions and to expose the id to prebid.js bidders and downstream DSPs.
bkuidhttp_cookie90 daysAlternative first party identifier name used by some publisher integrations. Same purpose as bk_id, kept for backward compatibility with older prebid wrappers.
bk_consenthttp_cookie13 monthsFirst party cookie that mirrors the IAB TCF 2.2 euconsent v2 string so BlokID can verify on each request that the user has granted purposes 1, 3, 4 and 7.
bk_synchttp_cookie24 hoursThird party cookie set on blokid.com during cookie sync operations. Used to pair the BlokID identifier with partner SSP and DSP identifiers.
bk_optouthttp_cookie5 yearsOpt out cookie set on blokid.com when the user refuses or withdraws consent. Prevents the BlokID tag from setting any other identifier on subsequent visits.
bk_id_lslocal_storage90 dayslocalStorage key written when the publisher activates the cookieless mode. Stores the same hashed identifier as bk_id and is governed by the same consent requirement under ePrivacy art. 5(3).
bk_child_flaghttp_cookie30 daysInternal flag indicating that the current page or audience has been declared child directed. Forces BlokID into contextual only mode and disables identity resolution.
bk_sessionhttp_cookiesessionShort lived session cookie used for request signing and replay protection on the BlokID identity API. Expires when the browser tab is closed.

BlokID places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

Which cookies and identifiers does BlokID set on my website?

A standard BlokID deployment writes a first party cookie on the publisher domain, typically named bk_id or bkuid, which stores a hashed identifier valid for up to 90 days. A second first party cookie mirrors the IAB TCF 2.2 consent string (euconsent v2). When cookie syncs are enabled, a short lived third party cookie on the blokid.com domain (often bk_sync) lasts a few minutes for partner pairing. In cookieless mode, the identifier moves to localStorage but the same logic applies. ePrivacy art. 5(3) requires consent for every one of these storage operations, even when stored in localStorage.

Is user consent required before activating BlokID?

Yes. BlokID processes identifiers for advertising personalisation, which under GDPR art. 6(1)(a) and the IAB Europe ruling of the Belgian DPA can only rely on consent. The tag must remain blocked by the CMP until the user gives a freely given, specific, informed and unambiguous opt in, with refusal made as easy as acceptance per CNIL deliberation 2020 091 and EDPB guidelines 03/2022. Consent must be re collected after 13 months or whenever the purposes or vendors materially change.

What is the lawful basis and how does it interact with COPPA and GDPR art. 8?

Consent under GDPR art. 6(1)(a) is the only viable basis for identity based ad personalisation. Where the user is under the local digital age of consent (16 in Germany and the Netherlands, 15 in France, 14 in Italy and Spain, 13 in the UK), verifiable parental consent under GDPR art. 8 is mandatory. For users under 13 in the US, COPPA applies and the publisher must use one of the verifiable parental consent methods accepted by the FTC (signed form, credit card, knowledge based authentication, video verification). BlokID has a child directed mode that disables identity resolution and keeps only contextual signals; using it does not replace the need for parental consent when behavioural advertising is intended.

Does BlokID transfer data outside the European Economic Area?

Yes when the publisher integrates the US delivery endpoint. Hashed identifiers, IP addresses and TCF consent strings are transferred to BlokID infrastructure in the United States (Virginia region). The transfer relies on the EU US Data Privacy Framework adequacy decision of 10 July 2023 for the certified US entity, supplemented by Standard Contractual Clauses module 2 and a transfer impact assessment for any onward transfer to sub processors. The certification must be checked on dataprivacyframework.gov and renewed annually. Publishers operating only on EU traffic should pin the integration to the EU endpoint and document this in the record of processing activities.

Do I need a Data Protection Impact Assessment to use BlokID?

In almost every case yes. BlokID triggers at least five of the nine EDPB criteria for mandatory DPIA: evaluation/scoring, systematic monitoring, sensitive or highly personal data (children), vulnerable data subjects and innovative technology. The CNIL list of processing operations requiring a DPIA (2018 update) explicitly cites profiling for advertising. The DPIA must cover the identity graph, TCF signal flow, retention windows, withdrawal and deletion workflows, parental consent verification, and the EU US transfer. If residual risk remains high, prior consultation with the supervisory authority under GDPR art. 36 is required before go live.

How is BlokID implemented on a publisher site?

There are three common patterns. First, a client side prebid.js wrapper loads the BlokID userId module, which reads or sets the bk_id cookie and exposes the identifier to the bidders. Second, a server to server integration calls the BlokID identity API from the publisher edge, which is preferred for performance and for keeping the identifier off the client. Third, a tag manager template fires the BlokID pixel only after the CMP grants TCF purposes 1, 3, 4 and 7. In all three cases, the publisher must wire the consent gating in the tag manager or in the prebid consentManagement module to prevent any network call before opt in.

What are the credible alternatives if I cannot deploy BlokID?

For child directed inventory, fully contextual solutions are the safest option (Seedtag, Weborama Contextual, GumGum Verity, Illuma). For logged in audiences, a first party identity graph activated through a clean room (LiveRamp ATS, InfoSum, Habu) keeps raw identifiers on the publisher side. Publishers serving the US market can also consider Universal ID 2.0 with strict opt in flows. None of these alternatives removes the need for a CMP and a documented DPIA, but they reduce the cross border transfer and minors exposure that drive the BlokID risk profile.

How should I update my cookie policy and CMP after installing BlokID?

List BlokID by name in the cookies section, describe the bk_id, bk_sync and TCF cookies with their retention (90 days for bk_id, session for bk_sync, 13 months for the TCF consent record), and reference IAB TCF 2.2 purposes 1, 3, 4 and 7. Update the third party recipients table to include the BlokID US entity and add the EU US Data Privacy Framework link. In the CMP, register the BlokID Global Vendor List id, enable the vendor only after explicit opt in, and link to the BlokID privacy notice. Republish the cookie policy with a version date so users can see the change history required by EDPB guidelines on transparency.