Cookieless tracking is any way of measuring website visits, conversions or advertising results without storing a cookie in the visitor’s browser. It covers a wide range of methods, from privacy-focused analytics that count visits without identifying anyone, through server-side tagging and statistical modelling, to fingerprinting that recognises devices without asking.
How cookieless tracking works
The methods differ a great deal, and so do their privacy implications:
- Aggregate analytics. Tools such as Plausible and Fathom count page views and referrers, and tell repeat visits within a day apart by combining details such as the IP address and browser into a scrambled value that changes daily. You get trends, not individual journeys.
- Server logs. Your web server already records every request. Analysing those logs shows traffic without any tag in the browser.
- Server-side tagging. Data goes from the browser to your own server, then on to analytics or ad platforms. This changes where processing happens, not whether a browser identifier is involved; many server-side set-ups still use cookies.
- Modelling. Google’s Consent Mode, in Advanced mode, sends cookieless pings for visitors who have not consented, and Google estimates their behaviour from them.
- Fingerprinting. Combining device details such as screen size, fonts and browser settings to recognise a device without storing anything the visitor can see or clear. It is the most intrusive of the group.
Why it matters
Cookieless is often sold as meaning no consent needed. In the UK that is not automatically true. Regulation 6 of PECR covers storing information on a device or reading information from it, by any technology. Local storage, tracking pixels and fingerprinting can all fall within it, whatever the vendor calls them. The test is what the method does, not whether the word cookie appears.
The ICO has been especially clear about fingerprinting: it has said publicly that it does not regard fingerprinting as a fair way to track people, because they cannot see or control it. Separately from PECR, UK GDPR applies to any method that processes personal data, including IP addresses and device identifiers, whether or not consent is needed.
Used properly, cookieless methods are valuable. Where an aggregate analytics tool can lawfully run without consent, it gives a UK business a fuller count of visits than consent-dependent GA4, because it measures everyone in aggregate. The Data (Use and Access) Act 2025 also adds a narrow exception for some analytics, where visitors are told and can object easily; check the ICO’s current guidance on how it applies. Either way, aggregate tools complement GA4 rather than replace the journey-level data advertising relies on.
Common mistakes
- Assuming that cookieless means no banner, without checking what the tool stores or reads.
- Switching on fingerprinting features in an ad or analytics tool to recover lost data.
- Expecting cookieless analytics to reproduce GA4’s user-level reports or feed ad platforms.
- Leaving the privacy notice unchanged after adding a new measurement method.
- Running two analytics tools without deciding which one answers which question.
How to act on it
Decide what you need to know. If the question is how many people visit and where they come from, a cookieless aggregate tool may answer it well. If you need to tie an enquiry to a specific ad click, you need identifiers, and in the UK that usually means consent.
For any cookieless product, read its documentation for what it stores on the device, what it reads from it and where it sends data. Write down your reasoning on whether consent is needed, update your privacy notice, and review the decision when the ICO’s guidance changes. Where you still rely on cookies for advertising, server-side tracking can improve data quality for visitors who have consented.
Choosing a measurement set-up that is lawful and still shows which campaigns pay their way is part of my performance marketing service.
