Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
MGID is a native advertising and content-recommendation network that renders sponsored "recommended content" widgets on publisher pages. It sets persistent tracking cookies and fires behavioural pixels for audience profiling, frequency capping and retargeting across sites. MGID is incorporated in the United States and transfers personal data internationally, including to US-based advertising partners. Full consent under IAB TCF v2.2 is required before the MGID widget may load.
MGID is a native advertising and content-recommendation network that places sponsored content widgets on publisher pages, typically appearing as recommended content panels. When a user visits a page carrying the MGID JavaScript tag, the widget loads ad content from jsc.mgid.com and simultaneously fires impression pixels and sets tracking cookies. These cookies identify the browser across MGID's publisher network, allowing MGID to build a behavioural profile covering which articles the user read, which ads they saw and clicked, and how frequently they were exposed to specific campaigns.
MGID enriches this first-party data by synchronising its user identifier with those of third-party data providers and demand-side platforms via cookie-matching redirects routed through servicer.mgid.com and cdn.mgid.com. The resulting audience segments are used for behavioural targeting, retargeting and frequency capping across all publishers in the MGID network. Because MGID has no cookieless mode, the widget cannot function without setting persistent cookies on the user's device.
MGID sets persistent tracking cookies through mgid.com and jsc.mgid.com domains. The primary cookie (typically named mgid or a hashed variant) has a lifetime of up to 13 months and stores a pseudonymous user identifier. Additional cookies track session activity, ad exposure counts for frequency capping, and click attribution. Pixel calls transmit the user's IP address, user-agent, referrer URL, page URL, ad slot identifiers and the pseudonymous MGID ID to MGID's servers. Click events send additional data including the clicked content item and timestamp.
MGID's behavioural tracking and cross-site profiling constitute high-risk processing under GDPR Article 35(3)(b), requiring a DPIA. The ePrivacy Directive Article 5(3) mandates prior informed consent before setting tracking cookies, and this applies to every MGID cookie. MGID cannot rely on legitimate interest for behavioural advertising: the EDPB has confirmed that cross-site tracking for advertising purposes requires consent. Publishers who deploy MGID without valid consent expose themselves to enforcement action under both national ePrivacy legislation and the GDPR.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
MGID participates in the IAB TCF v2.2 framework. The MGID widget must not load until the publisher's CMP has collected a valid TC string with affirmative consent for at least Purpose 1 (store and access information on a device), Purpose 2 (use limited data to select advertising), Purpose 3 (create a personalised ads profile), Purpose 4 (select personalised ads) and Purpose 7 (measure ad performance). The CMP must list MGID as a vendor and present purpose-level disclosures. Publishers must ensure the widget load is technically blocked until the consent event fires.
MGID Inc. is incorporated in Delaware, USA, and processes personal data on infrastructure located in the United States as well as EU nodes. Transfers of personal data from the EEA to the US are conducted under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework (DPF). Publishers must disclose these international transfers in their privacy notices and ensure their CMPs inform users before consent is collected. The DPIA must assess the adequacy of these transfer mechanisms and document supplementary safeguards.
To deploy MGID in a GDPR-compliant manner, publishers must: (1) complete a DPIA and obtain DPO sign-off before go-live; (2) integrate a TCF v2.2-certified CMP and ensure MGID is listed with full purpose disclosures including Purposes 1, 2, 3, 4 and 7; (3) technically block the MGID JavaScript tag until consent is obtained, using a tag management system or consent wrapper; (4) update the privacy policy and cookie notice to describe MGID cookies, their duration, the behavioural profiling use and the US transfer; (5) implement and test the MGID consent withdrawal mechanism; (6) maintain ROPA entries for MGID processing; and (7) review MGID data processing terms and partner disclosures annually.
Websites using MGID Native Advertising must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is required before deploying MGID native advertising widgets. MGID conducts large-scale behavioural profiling across publisher sites by combining click data, browsing history and cross-site cookie synchronisation. This constitutes high-risk processing under GDPR Article 35(3)(b) (systematic large-scale profiling) and Article 35(3)(a) (automated processing producing significant effects). The DPIA must cover: (1) the nature and scope of behavioural profiling performed by MGID for targeting and retargeting; (2) the cookie-matching redirects that sync MGID user identifiers with third-party data providers and DSPs; (3) the US corporate structure of MGID Inc. and international transfers of personal data, including the adequacy of Standard Contractual Clauses and DPF safeguards; (4) the IAB TCF v2.2 consent dependency and the risk that consent is not validly obtained or that users are not meaningfully informed; (5) the absence of a cookieless alternative, meaning the widget cannot operate without device-level tracking; (6) user rights including opt-out mechanisms; and (7) data retention periods. The DPO must approve the DPIA before go-live and revisit it whenever MGID updates its data-processing terms or partner list.
Sample consent text
We use MGID, a native advertising service provided by MGID Inc. (United States), to display sponsored content recommendations on this site. MGID sets cookies and tracking pixels to build an audience profile based on your browsing behaviour, deliver personalised native advertisements, cap the frequency of ads you see, and measure the performance of advertising campaigns. Your data may be transferred to and processed in the United States and shared with MGID's advertising partners. This processing is based solely on your consent. You can withdraw your consent at any time by adjusting your privacy settings or by visiting the MGID opt-out page at mgid.com/privacy.
Third-party domains contacted
mgid.comjsc.mgid.comservicer.mgid.comcdn.mgid.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| mgid | persistent | 13 months | Primary pseudonymous user identifier used by MGID for cross-site behavioural profiling, native ad targeting and frequency capping |
| mgid_sess | session | Session | Session-level tracking cookie used by MGID to attribute page views and clicks within a single browsing session |
| mgid_ab | persistent | 30 days | A/B test allocation and ad variant selection cookie used by MGID to route traffic between content recommendation algorithm variants |
| mgiduid | persistent | 13 months | User identifier cookie written during cookie-matching synchronisation with third-party demand and data partners on jsc.mgid.com |
| mgid_fc | persistent | 30 days | Frequency capping counter cookie recording how many times a user has been shown a specific advertiser campaign within the MGID network |
MGID Native Advertising places tracking cookies for advertising — comply with GDPR using FlowConsent.
MGID sets a primary persistent tracking cookie (commonly named mgid or a hashed variant) on the mgid.com domain with a lifetime of up to 13 months, storing a pseudonymous user identifier. Additional cookies manage session tracking, frequency capping (counting how many times a user sees a specific ad) and click-through attribution. Cookie-matching pixels may also set short-lived cookies on third-party domains during user-identifier synchronisation with data partners. All these cookies require prior consent under the ePrivacy Directive.
Yes, explicit consent is required before any MGID JavaScript or pixel loads. MGID sets tracking cookies and processes personal data for behavioural profiling and targeted advertising, both of which require prior informed consent under ePrivacy Directive Article 5(3) and GDPR Article 6(1)(a). Legitimate interest is not a valid legal basis for cross-site behavioural advertising. The MGID widget must be technically blocked until a valid IAB TCF v2.2 consent string confirming the user's consent for MGID's purposes is received.
The only permissible legal basis is consent under GDPR Article 6(1)(a) and ePrivacy Directive Article 5(3). MGID builds cross-site behavioural profiles and delivers targeted native advertising, which the EDPB has confirmed cannot rely on legitimate interest. Consent must be freely given (not pre-ticked), specific to MGID's purposes (at minimum Purposes 1, 2, 3, 4 and 7 in the IAB TCF framework), informed and documented. Publishers should collect consent via a TCF v2.2-certified CMP with MGID listed as a vendor.
Yes. MGID Inc. is incorporated in Delaware, USA, and processes personal data on US infrastructure in addition to EU nodes. Data may also be shared with US-based advertising technology partners during cookie synchronisation. Transfers from the EEA to the US are conducted under Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework (DPF). Publishers must disclose these transfers to users in their privacy notices before collecting consent, and the DPIA must assess the adequacy of the transfer safeguards in place.
Yes. MGID conducts systematic large-scale behavioural profiling across multiple publisher sites, which triggers the mandatory DPIA requirement under GDPR Article 35(3)(b). The DPIA must address the scope of cross-site tracking, cookie-matching with third-party data providers, the US transfer of personal data, the absence of a cookieless alternative, data retention periods, and user rights. The DPO must approve the DPIA before go-live and update it whenever MGID changes its data processing scope or partner list.
Compliant deployment requires: using a TCF v2.2-certified CMP with MGID listed as a vendor, with full purpose disclosures for Purposes 1, 2, 3, 4 and 7; technically blocking the MGID tag until a valid consent string is received (use a tag manager or consent wrapper); completing a DPIA approved by the DPO; updating the privacy policy and cookie notice to describe MGID cookies and US data transfers; implementing a functional consent withdrawal mechanism; and maintaining records of processing activities for MGID operations.
Contextual advertising networks (which target based on page content rather than user behaviour) do not require consent and are fully GDPR-compliant. In-house content recommendation systems that do not track users across sites avoid the cross-site profiling risk entirely. If native advertising revenue is essential, publishers can consider alternative TCF-registered networks with stricter data minimisation policies. Any replacement should be evaluated for its own GDPR compliance posture before deployment.
The cookie policy must include a dedicated MGID section describing: the cookie name (mgid or equivalent) and its domain (mgid.com), the 13-month duration, the purpose (cross-site behavioural profiling and native ad targeting), the controller (MGID Inc., USA), the fact that data is transferred to the US and shared with advertising partners, and the user's right to withdraw consent. The policy must be live before MGID is deployed and updated within 30 days of any material change to MGID's data processing terms.