Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
ID5 Universal ID is a shared advertising identity infrastructure that generates an encrypted, persistent identifier from hashed email addresses, IP addresses and browser signals. It enables cross-site user recognition for programmatic advertising without relying on third-party cookies. Publishers and SSPs integrate the ID5 API to participate in a common identity graph shared with demand-side platforms and advertisers. Processing requires valid IAB TCF v2.2 consent and is governed by GDPR and the ePrivacy Directive.
ID5 Universal ID is a shared identity infrastructure built by ID5 Technology SAS, a French company, designed to replace third-party cookies for cross-site user recognition in programmatic advertising. When a user visits a publisher page, the ID5 API collects available signals including a hashed email address (if the user is logged in), the IP address, user-agent string and other browser attributes. These signals are combined and processed server-side to generate an encrypted, persistent identifier that is stored in the user's browser via first-party storage or a dedicated synchronisation domain (id5-sync.com).
The resulting ID5 ID is then shared with demand-side platforms (DSPs), supply-side platforms (SSPs) and other programmatic partners via bid-stream transmission. Because the same deterministic or probabilistic ID can be recognised across multiple publishers participating in the ID5 network, it enables behavioural targeting, frequency capping and attribution that previously relied on third-party cookies. The ID persists even after cookie deletion because it can be reconstituted from first-party signals or server-side lookups, making it a high-continuity tracking mechanism.
ID5 processes the following categories of data: hashed email address (SHA-256 or MD5, where available from publisher login), IP address (used for geolocation and signal validation), user-agent string, browser language and timezone, referring URL, and the encrypted ID5 ID itself. The primary cookie written is id5id, a first-party or cross-domain persistent cookie with a 90-day lifetime stored on id5-sync.com and mirrored to publisher first-party domains via the ID5 API. A consent-status cookie (id5id_last) records the TCF consent state at the time the ID was generated. Additional pixels and redirect calls to eu-sync.id5-sync.com are used for partner identity synchronisation.
Under the GDPR, the generation and sharing of a persistent cross-site identifier derived from personal data constitutes high-risk processing. Article 35(3)(b) requires a DPIA for systematic large-scale profiling, which the ID5 identity graph unambiguously satisfies. The ePrivacy Directive Article 5(3) requires prior informed consent before storing or reading any information on the user's terminal device, which applies to the id5id cookie and all equivalent first-party storage operations. Neither legitimate interest nor any other legal basis is available: consent is the only permissible basis for this form of tracking.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
ID5 operates within the IAB TCF v2.2 framework as vendor ID 131. Valid consent for ID5 requires that the user's TC string contains affirmative consent for Purpose 1 (store and access information on a device) and at minimum Purposes 3 and 4 (create a personalised ads profile and select personalised ads). The ID5 API must check for a valid TC string before initialising and must not generate or share the ID5 ID until consent is confirmed. Publishers must ensure their CMP fires the TCF consent event before the ID5 API is called and must pass the TC string to ID5 via the standard API parameter. Consent must be granular, freely given, specific and documented.
ID5 Technology SAS is based in France and maintains EU data residency for its core processing. However, the ID5 ID is transmitted to demand-side and supply-side partners in the programmatic ecosystem, many of which are based in the United States. These transfers are conducted under Standard Contractual Clauses (SCCs) as mandated post-Schrems II, with supplementary measures including encryption of the ID in transit. The full list of ID5 downstream partners is published in the ID5 privacy documentation at id5.io/privacy. Publishers must ensure their privacy notices and DPIA documentation account for these onward transfers and that their CMP discloses third-country transfers to users before consent is collected.
To deploy ID5 Universal ID in a GDPR-compliant manner, publishers must: (1) complete a DPIA and have it approved by the DPO before go-live; (2) integrate a TCF v2.2-certified CMP and ensure ID5 vendor 131 appears with full purpose disclosures; (3) configure the ID5 API to read the TC string and abort if consent is absent or insufficient; (4) update the privacy policy and cookie notice to describe the ID5 identifier, its 90-day lifetime, the identity graph and cross-site targeting use; (5) implement the ID5 opt-out mechanism so users can exercise their GDPR right to withdraw consent; (6) conduct annual reviews of the ID5 partner list to capture changes in onward transfers; (7) maintain records of processing activities (ROPA) entries covering the ID5 deployment.
Websites using ID5 Universal ID must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is required before deploying ID5 Universal ID. The service creates a persistent cross-site identifier derived from personal data (email hash, IP address, browser fingerprint components), which constitutes high-risk processing under GDPR Article 35(3)(b) as systematic large-scale profiling. The DPIA must document: (1) the nature of the encrypted ID and its linkability to individuals across publishers; (2) the identity graph shared with third-party demand partners including US-based DSPs and SSPs; (3) the reliance on IAB TCF v2.2 consent strings as the lawful basis, including the risk of invalid or coerced consent; (4) data retention periods for the persistent ID (typically 90 days); (5) data subject rights mechanisms including opt-out via the ID5 Privacy Portal; (6) international transfer safeguards (SCCs with US partners); (7) the risk that the ID survives cookie deletion because it can be reconstituted from first-party storage or server-side signals. The DPO must sign off before go-live, and the DPIA must be reviewed whenever ID5 adds new downstream partners or changes its processing scope.
Sample consent text
We use ID5 Universal ID, provided by ID5 Technology SAS (France), to recognise your browser across websites for personalised advertising. ID5 generates an encrypted identifier from your hashed email address (if provided), IP address and browser signals, and shares this identifier with our advertising partners. This involves storing information on your device and transferring data to third parties, including partners outside the European Economic Area. This processing is based solely on your consent. You can withdraw your consent at any time via our privacy settings or by visiting the ID5 Privacy Portal at id5.io/privacy. Withdrawing consent will stop future ID5 processing but will not affect processing already carried out.
Third-party domains contacted
id5-sync.comid5.ioeu-sync.id5-sync.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| id5id | persistent | 90 days | Stores the encrypted ID5 Universal Identifier used for cross-site user recognition in programmatic advertising |
| id5id_last | persistent | 90 days | Records the IAB TCF v2.2 consent string state at the time the ID5 identifier was generated, used to detect consent changes |
| id5-sync | persistent | 30 days | Synchronises the ID5 identifier across participating publisher domains via the id5-sync.com synchronisation endpoint |
| id5_ab | session | Session | A/B test allocation cookie used by ID5 to route requests between processing infrastructure variants |
| id5_fs | persistent | 90 days | First-party storage mirror of the id5id value written to the publisher domain when first-party storage delegation is enabled |
ID5 Universal ID places tracking cookies for advertising — comply with GDPR using FlowConsent.
ID5 sets a primary persistent cookie called id5id on the id5-sync.com domain with a 90-day lifetime; this cookie stores the encrypted universal identifier. A companion cookie id5id_last records the IAB TCF consent string state at the time the ID was generated. When publishers use first-party storage delegation, equivalent values are written to the publisher's own domain. Redirect calls to eu-sync.id5-sync.com facilitate partner identity synchronisation and may set additional short-lived session cookies.
Yes, consent is mandatory. ID5 stores and reads information on the user's device and generates a cross-site tracking identifier, both of which require prior informed consent under Article 5(3) of the ePrivacy Directive. Under GDPR, the processing of personal data to build the identity graph requires a valid legal basis, and only consent (Article 6(1)(a)) is appropriate for this purpose. The ID5 API must not be initialised until a valid IAB TCF v2.2 consent string confirming vendor 131 consent is available.
The sole permissible legal basis is consent under GDPR Article 6(1)(a), in conjunction with ePrivacy Directive Article 5(3) for device access. Legitimate interest is not available because ID5 involves systematic cross-site profiling for advertising, which the Article 29 Working Party and EDPB have consistently held cannot rely on legitimate interest. The consent must be freely given, specific, informed, unambiguous and documented via a TCF v2.2-certified CMP with ID5 listed as vendor 131.
Yes. While ID5 Technology SAS is based in France and maintains EU data residency for core processing, the ID5 identifier is transmitted to demand-side and supply-side partners in the programmatic bid stream, many of which are US-based. These transfers rely on Standard Contractual Clauses (SCCs) as the transfer mechanism under GDPR Chapter V. Publishers must disclose these third-country transfers in their privacy notices before collecting consent, and the DPIA must assess the adequacy of SCC-based safeguards for each US partner.
Yes, a DPIA is required before deployment. ID5 constitutes systematic large-scale profiling of individuals across websites, which triggers the mandatory DPIA threshold under GDPR Article 35(3)(b). The DPIA must assess the cross-site linkability of the encrypted ID, the identity graph shared with third-party partners, the risk of re-identification, international transfer safeguards, and data subject rights mechanisms. The DPO must review and approve the DPIA, and it must be updated whenever ID5 changes its processing scope or partner list.
Compliant implementation requires: integrating a TCF v2.2-certified CMP with ID5 listed as vendor 131 and all relevant purposes disclosed; ensuring the ID5 API initialisation is gated on a valid TC string with affirmative consent for Purposes 1, 3 and 4; completing and documenting a DPIA approved by the DPO; updating the cookie policy and privacy notice to describe the ID5 identifier and cross-site targeting; implementing the ID5 opt-out so users can exercise their right to withdraw consent; and maintaining ROPA entries for the ID5 processing activity.
Contextual advertising does not require any persistent identifier and is fully compliant with GDPR and ePrivacy without consent. Server-side first-party identity solutions tied to authenticated user sessions can achieve personalisation within a single publisher without cross-site sharing. Other cookieless identity frameworks such as Unified ID 2.0 or RampID similarly require consent and introduce comparable risks. If personalised advertising is a business requirement, ID5 with rigorous consent management remains a viable option, but publishers should weigh the compliance burden and DPIA obligations against the revenue uplift.
The cookie policy must include a dedicated entry for the id5id cookie describing: the cookie name and domain (id5-sync.com), its 90-day duration, its purpose (cross-site advertising identifier), the identity of the controller (ID5 Technology SAS), the fact that the identifier is shared with programmatic partners including those outside the EEA, and the user's right to withdraw consent and opt out via id5.io/privacy. The policy must be updated before deploying ID5 and reviewed whenever ID5 publishes material changes to its data processing or partner list.