Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
The Adobe Client Data Layer is an open source JavaScript library that provides a standardised, event driven data layer on a web page. It is bundled and served first party, and on its own it sets no cookies, uses no browser storage and sends no data anywhere. Its job is to let a tag manager and the analytics and marketing tags it deploys read and write structured page and interaction data in a consistent way. The library itself is a functional enabler that needs no consent, but the tags that consume the data layer are usually non essential and do require prior consent, so no personal data should be placed into the layer before consent is obtained.
The Adobe Client Data Layer is an open source JavaScript library that provides a single, standardised place on a web page to hold information about the page and the visitor interactions with it. It is bundled into the website code and served first party from the same origin as the page, rather than loaded from an Adobe server. Developers and tags write structured values and events into the layer, and other code subscribes to those events, which keeps data collection consistent and decoupled from the tools that use it.
By itself the Adobe Client Data Layer sets no cookies, uses no localStorage or other browser storage, and sends no data to any server. It is an in memory JavaScript object that lives only for the duration of the page view. The data it holds is whatever the website chooses to push into it, which can range from harmless page metadata to, if configured carelessly, personal data. The library never transmits that data on its own; separate tags read the values and decide what to do with them.
Because the library stores nothing on the visitor terminal and transmits nothing, its mere presence does not engage Article 5(3) of the ePrivacy Directive and processes no personal data on its own under the GDPR. The compliance question shifts to the content placed into the layer and the tags that read it. If personal data is written into the layer and then collected by a non essential tag, the responsibility for that processing rests with those tags and the choices made about them, which the CNIL in France, the German authorities under the TDDDG and the AEPD in Spain all assess as trackers.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The Adobe Client Data Layer itself is a functional building block and does not require consent to be present on the page. Consent becomes mandatory the moment a non essential tag, such as Adobe Analytics, Adobe Target or an advertising pixel, reads from the layer or writes tracking data to it, because that tag performs behavioural tracking. Prior, freely given, specific, informed and unambiguous consent is then required under Article 6(1)(a) GDPR and Article 5(3) ePrivacy. As a safeguard, no personal data should be pushed into the layer before that consent has been obtained.
The library transfers no data anywhere, so on its own it creates no transfer outside the European Economic Area. Any international transfer arises only from the separate tags that consume the layer. Where a tag such as Adobe Analytics or Adobe Target processes European data on Adobe infrastructure that may be located in the United States, that transfer must be covered by the EU Standard Contractual Clauses 2021/914 within the relevant Adobe agreement and by a documented Transfer Impact Assessment, in line with the Schrems II ruling.
Keep the data layer free of directly identifying or special category data, and never push personal data into it before consent. Gate every non essential tag that reads the layer behind your consent management platform so that Adobe Analytics, Adobe Target and any advertising pixels fire only after the relevant category is accepted. Document in your records of processing which attributes are written to the layer and which tags consume them. Describe those consuming tags, not the library, in your cookie policy, and complete a Transfer Impact Assessment for any tag that sends European data to a third country.
Websites using Adobe Client Data Layer must obtain user consent under GDPR regulations.
DPIA considerations
The Adobe Client Data Layer on its own rarely triggers a Data Protection Impact Assessment, because it stores nothing on the device and processes no personal data by itself. The assessment should instead focus on what is pushed into the layer and which tags read it. Document the data attributes written to the layer, confirm that no directly identifying or special category data is placed there before consent, and map the analytics and marketing tags, such as Adobe Analytics or Adobe Target, that consume the values and may transfer them to the United States. Ensure the tags are gated behind consent even though the library is not.
Sample consent text
This website uses a data layer to organise information about the page and your interactions so that our analytics and marketing tools can read it in a consistent way. The data layer itself stores nothing on your device. The tools that read it, such as Adobe Analytics and Adobe Target, only run and only receive your data if you click Accept.
Adobe Client Data Layer collects user analytics data — you legally need a consent banner. Try FlowConsent free.
None. The Adobe Client Data Layer is an in memory JavaScript object that sets no cookies and writes nothing to localStorage or any other browser storage. It exists only during the page view. Any cookies you observe come from the separate tags that read the data layer, such as Adobe Analytics, not from the library itself.
The library itself needs no consent, because it stores nothing on the device and processes no personal data on its own. Consent is required the moment a non essential tag, such as Adobe Analytics or an advertising pixel, reads the data layer or writes tracking data to it. Gate those tags, not the library, behind consent.
As a functional, first party building block that stores nothing and sends nothing, the library needs no separate legal basis. When a non essential tag consumes the layer, the legal basis for that tracking is consent under Article 6(1)(a) GDPR combined with the prior consent requirement of Article 5(3) of the ePrivacy Directive. Legitimate interest does not cover that tracking.
No. The library sends no data anywhere, so on its own it triggers no transfer. Transfers arise only from the tags that read the layer. If Adobe Analytics or Adobe Target processes European data on United States infrastructure, cover that transfer with the EU Standard Contractual Clauses 2021/914 and a Transfer Impact Assessment.
The library on its own rarely warrants a Data Protection Impact Assessment, because it processes no personal data by itself. Assess instead what is written into the layer and which tags read it. A DPIA may be needed for the consuming tags where they profile visitors at scale or transfer data to the United States.
Keep directly identifying and special category data out of the layer, and never push personal data before consent. Gate every non essential tag that reads the layer behind your consent management platform so it fires only after the relevant category is accepted. Record which attributes are written and which tags consume them, and describe those tags in your cookie policy.
Yes. You can use the generic W3C Customer Experience Digital Data Layer, the Google dataLayer used with Google Tag Manager, or a custom JavaScript data layer. Like the Adobe Client Data Layer, these are functional in themselves; the consent obligations come from the analytics and marketing tags that read them.
You do not need a cookie policy entry for the library, because it sets no cookies. Instead, document the tags that read the data layer, such as Adobe Analytics or Adobe Target, listing the cookies they set, their lifetimes and any transfer to the United States. Keep those entries aligned with your consent categories.