Content Personalisation for Cross-Device Journeys
How to recognise customers across devices under UK consent rules, what device behaviour data actually shows, and where cross-device personalisation fails.
Most of your traffic arrives on a phone and most of your revenue completes somewhere else. A global benchmark covering roughly 99 billion sessions across more than 6,500 sites put mobile at about 70 per cent of measured traffic in the final quarter of 2025, while desktop conversion ran at 3.4 per cent against 2.0 per cent on mobile (1). That gap is the commercial case for cross-device personalisation in a single line.
The technical case is harder, and the legal case is harder still. Recognising the same person across a phone, a laptop and an application is a regulated act in the United Kingdom, not merely an engineering problem. Since 5 February 2026 the rules governing what you may store on and read from someone’s device have changed, and the penalties for getting it wrong have risen thirty-five fold.
This article sets out what the device data actually supports, what the law now requires before you connect two sessions, how to build the technical foundation, and how to measure whether any of it works. Where a claim rests on my own experience rather than on a source, it is written in the first person and marked as such.
Understanding Cross-Device Behaviour
Cross-device strategy usually starts with a set of inherited assumptions about how people use screens. Several of the most repeated ones do not survive contact with the evidence.
What the Device Data Supports
- Session length. Average session time in the Q4 2025 benchmark was 4 minutes 46 seconds on desktop and 2 minutes 20 seconds on mobile (1). The widely quoted claim that desktop sessions run beyond ten minutes is contradicted by this measurement, so plan against the shorter figure.
- Traffic against conversion. Mobile carried roughly 70 per cent of traffic while desktop converted higher, including in retail and in travel and hospitality (1). The benchmark does not identify individuals across devices, so it does not establish that the same person researched on mobile and bought on desktop. It shows two populations behaving differently, which is a weaker but more honest claim.
- Email. In a worldwide measurement of almost 8 billion opens between January and August 2021, 44.7 per cent were classified as mobile (2). Current device splits are less reliable than they look: privacy protection and image caching in major mail clients can obscure which device actually opened a message (3). Design for small screens because it is sensible, not because you have a trustworthy percentage.
- Time of day. A UK diary study of 1,512 adults found computer use concentrated across the working day and peaking at 3pm, while mobile use was relatively steady from 9am to 9pm and peaked at 1pm (4). It found no mobile peak in commuting windows, and the published analysis did not split weekdays from weekends. The study dates from 2016, so treat it as a caution against inherited commuting folklore rather than as a current schedule.
Back in 2017 I was working with a large consumer electronics retailer, and I went through several of its analytics accounts before touching the send schedule. Desktop traffic sat inside the working day. Mobile climbed after people finished work, roughly five to eight in the evening. So we split the calendar by device rather than by channel: email and desktop web push in the morning, application push and mobile web push around six. Click-through rates improved. That is a commercial observation rather than a rule, and those windows belonged to that market and that year.
The practical lesson is that the pattern is real but the timings are local. Read your own analytics before you copy anyone’s schedule, including mine.
The Recognition Problem
Connecting two sessions to one person is difficult for reasons that are partly technical and increasingly deliberate.
- Fragmented identifiers. A browser cookie on a phone is not the browser cookie on a laptop. Network addresses and browser configuration shift when people change networks or clear data.
- Browser defaults. Safari has blocked cookies for cross-site resources by default since March 2020, retaining a permissioned route for embedded services that genuinely need storage access (5). Firefox in its standard setting disables known cross-site tracking cookies and isolates the remainder to the top-level site, while its strict setting disables all cross-site cookies (6).
- The deprecation that did not happen. In April 2025 Chrome confirmed it would keep its existing third-party cookie controls and would not introduce a new standalone prompt (7). In October 2025 roughly ten Privacy Sandbox technologies were retired, including the main advertising ones, though several browser features such as CHIPS, FedCM and Private State Tokens continue to be supported (8). The UK competition commitments that had constrained this programme were released on the same day, and the investigation closed (9). Anyone still building a roadmap around imminent third-party cookie removal in Chrome is planning for an event that was cancelled.
- Application to web. On iOS, linking application data to data from other companies’ websites for advertising or advertising measurement counts as tracking, requires permission through the tracking transparency framework, and cannot be worked around with a hashed email address or device fingerprinting (10). On Android, the advertising identifier may be used for advertising and profiling purposes, but connecting it to personally identifiable information requires explicit user consent, and bridging a reset with another identifier is not permitted (11).
None of these platform permissions is the same thing as consent under UK law. They sit on top of it.
What UK Law Requires Before You Recognise a User
This section states obligations, so it is anchored to legislation and regulator guidance throughout. Nothing here rests on my authority.
The Consent Position Under PECR
Regulation 6 of the Privacy and Electronic Communications (EC Directive) Regulations 2003 prohibits storing information on, or gaining access to information stored on, a user’s terminal equipment unless one of the routes in Schedule A1 applies (12). Those routes were rewritten by section 112 and Schedule 12 of the Data (Use and Access) Act 2025 (13), commenced on 5 February 2026 (14).
There are six permitted routes: consent, transmission of a communication, strictly necessary service or legal compliance, statistical purposes, appearance or functionality, and emergency assistance (15). Three points matter for anyone building cross-device personalisation.
First, cross-site and cross-device tracking requires consent. It is not strictly necessary to provide the service, and no amount of commercial usefulness makes it so (15).
Second, the new statistical exception does not rescue you. It is confined to aggregate service-improvement statistics under strict conditions, and it excludes individual tracking, profiling, advertising measurement and cross-service monitoring (15).
Third, the appearance exception does not cover personalisation as marketers use the word. It permits adapting appearance or functionality to a stated preference. It does not permit changing content or selecting advertising according to known or inferred interests, behaviour or browsing history (15).
The regulations are also technology-neutral. The regulator’s finalised guidance, published on 29 April 2026, applies to tracking pixels, device fingerprinting, scripts, tags and web storage as much as to cookies, and covers mobile applications and connected devices, not only websites (16). Fingerprinting that stores or accesses device information falls within regulation 6 whether or not a cookie is involved, and combining fingerprint elements with network addresses does not remove the requirement (17). Probabilistic device identification is also in scope: the guidance works through an example in which a provider probabilistically identifies a device and concludes that regulation 6 applies (17).
Penalties now sit at the same level as data protection penalties. For an undertaking, the higher tier reaches the greater of £17.5 million or 4 per cent of total worldwide annual turnover (13).
Where UK GDPR Applies On Top
Assess the storage or access question first, then apply data protection law to any personal data involved. Where regulation 6 requires consent, the regulator’s position is that consent will normally also be the appropriate lawful basis for the resulting processing, and a legitimate interests argument cannot be used to cure consent that was never validly obtained (18).
The obligations most directly engaged by identity resolution are lawfulness, fairness and transparency, purpose limitation, a lawful basis for each purpose, the transparency duties, data protection by design and by default, and the assessment duty where processing is likely to result in high risk (19). Cross-device systems tend to accumulate the risk indicators that point towards a formal impact assessment: large-scale profiling, data matching and combining, systematic monitoring, and invisible processing. The regulator’s guidance on impact assessments is currently under review following the 2025 Act, with no published completion date, so check its status before relying on the detail (20).
If children are likely to access the service, the statutory children’s code applies whether or not the service is aimed at them, and profiling should be off by default absent a compelling reason (21).
What Is Under Review, and What Is Not
The regulator completed its review of regulation 6 in the context of online advertising and published advice to government on 18 May 2026, recommending that carefully framed exceptions be considered for certain lower-risk advertising. It stated at the same time that nothing had changed and that existing rules continued to apply (22). The accompanying report is more pointed on our subject: it observes that typical cross-device attribution processing is unlikely to satisfy a legitimate interests balancing test, and that present legal requirements are often not met (23). A possible future exception for privacy-preserving attribution is proposed there, not enacted.
Two comparisons are worth drawing carefully, because they are routinely collapsed. In the European Union, the requirement for consent before storing or accessing information on terminal equipment comes from national implementation of the ePrivacy Directive rather than from the General Data Protection Regulation itself (24). In California, the regime is built principally on notice and opt-out rights rather than prior opt-in consent (25). Neither is UK law, and neither should be cited as though it were.
Device-Specific Personalisation Strategies
With the legal position settled, the design question is what to vary and where.
Email, Applications and Web
- Email. Adaptive modules let you vary imagery, recommendations and calls to action by device class and prior behaviour. Sequencing across devices works, but the underlying permission does not come from your personalisation platform. Unsolicited marketing email or text to an individual subscriber needs prior consent or a complete soft opt-in, which requires details obtained directly during a sale or negotiations for a sale, marketing of your own similar products, and an opt-out both at collection and in every message (26). Browsing your site is not negotiation for a sale, and no purchased list qualifies (27).
- Applications. Contextual notifications work best on genuine real-time signals such as in-application behaviour or stock changes. Progressive interfaces that surface saved items and recent activity on launch reduce the work of getting started. Remember that linking application activity to web activity is the regulated act described above, not a configuration detail.
- Web. Source-aware landing pages, recognition-based recommendations and exit treatments that reference activity elsewhere all depend on lawful recognition first. Build the consent layer before the experience layer, or you will build the experience twice.
Responsive Content Experiences
Responsive design is a content strategy, not a layout setting. Structure campaigns as interchangeable components so the system can assemble the right combination. Offer condensed summaries on small screens with a route to the fuller version. Vary media weight by connection and capability. Preserve progress, baskets and reading position so a transition costs the customer nothing.
The same treatment does not travel across verticals. In fashion I could shorten the path to the basket, or send people arriving from an advert straight to a category page, and it worked. I tried the identical thing for a car manufacturer and bounce rates rose slightly. We stopped the campaign and rebuilt the product detail pages to read more easily instead, which improved both bounce and overall engagement. Device context is one variable. What the person is buying is another, and it is usually the stronger one. That is a commercial judgement, not a legal one.
There is more on assembling modular content systems in our guide to personalisation CMS platforms.
The Technical Foundation for Cross-Device Experiences
Identity Resolution
Deterministic matching uses an explicit shared identifier such as an authenticated account. It is the strongest available method, but “deterministic” describes the processing, not the truth: no verified general accuracy rate exists, and a shared identifier does not prove that it is current, correctly entered or controlled by one person.
Probabilistic matching infers a connection from behavioural and network signals. The most frequently repeated accuracy claims in this market come from vendors selling the capability. The strongest independent measurement is a peer-reviewed 2017 study that reached an F1 value of 0.91 connecting mobile to desktop devices, using network address and browsing history similarity across a dataset of 126 users (28). That is a classifier result on one research dataset. It is not a market match rate, and it is not a 91 per cent probability that any two devices belong to the same person. Treat vendor match-rate claims as marketing until they show you a method.
On industry identifiers, note the geography. Unified ID 2.0 operates in North America and parts of Asia; the European framework, which expressly covers the United Kingdom, is European Unified ID, and the two are separate frameworks with non-interchangeable tokens (29). Governance is also worth understanding before you commit: current documentation names a single commercial administrator, with independent governance described as a future transition (30).
The most uncomfortable data practice I saw in ten years was not sinister. One of the largest cosmetics groups I worked with had never reconciled its offline database with its several online ones. When a customer bought through a channel they had not used before, the system stored them as a new person. Category tracking was broken badly enough that the most purchased category field they sent us contained names that meant nothing. They were counting everything wrongly, and they eventually paid a CRM supplier heavily to clean it up.
That is the ordinary failure mode. Not surveillance, but arithmetic.
Real-Time Data Architecture
Once identity is resolved lawfully, latency becomes the constraint. Stream interaction data into a central pipeline rather than batching it overnight. Keep recent state in fast storage so a decision can be made inside a page load. Expose personalisation decisions through dedicated endpoints that each channel queries, so logic lives in one place. Coordinate across channels to suppress duplicate messaging. Instrument everything by device, campaign and segment.
One governance point belongs in the architecture rather than in a policy document: withdrawal of consent and objection must propagate. If someone objects, the storage or access has to stop, and the regulator is explicit that you cannot rely solely on browser settings as evidence that a user has not objected (15). Build suppression into the pipeline, because retrofitting it is painful.
Recognition From the Customer’s Side
Cross-device recognition feels different from the outside than it does in a planning document.
UK evidence on attitudes is more qualified than the industry usually admits. A government tracker survey of 4,947 online respondents found 58 per cent agreeing that data is useful for creating products and services that benefit them (31). That is a statement about usefulness, not a willingness to be tracked across devices for advertising. Regulator-commissioned research with 4,000 UK adult internet users found that in a simulated consent-or-pay choice roughly 95 per cent chose consent, but fewer than half fully understood what was being collected or shared, and 48 per cent reported feeling pressured (32). A high consent rate is not evidence of enthusiasm.
What would surprise most shoppers is not that a brand records what they buy. It is what gets inferred from it. In ten years inside this industry I watched companies read purchase histories and derive when someone’s salary lands, how many people they are shopping for, and what triggers their decisions. None of that is announced. Consent notices tend to describe categories of data rather than the conclusions drawn from them, and the gap between those two things is where trust is lost.
The design response is not to collect less for its own sake. It is to make the inference legible: say what you work out, not only what you collect.
Measuring Cross-Device Personalisation
Measurement is where cross-device programmes most often flatter themselves, because the metrics that are easiest to produce are the ones least able to establish incremental effect.
The evidence here is strong. Across 663 advertising experiments, non-experimental estimates frequently produced substantially larger apparent effects than randomised holdout estimates (33). An earlier comparison of observational approaches against 15 randomised experiments, covering roughly 500 million user-experiment observations, found that even with unusually rich user data the observational methods often failed to reproduce the experimental result, because exposed and unexposed populations differed systematically (34). A campaign can record conversions, engagement and attributed revenue while contributing very little.
The practical consequence is that a holdout group is not a refinement. It is the measurement.
Everyone in personalisation believes that if something wins once it will keep winning. Ten years on the account side taught me otherwise. I watched permanent winners decay, because the audience and the behaviour change underneath a test that nobody has looked at since it was declared. So I leave the test running against a smaller control group, or I re-run it roughly every six months. That is a commercial habit rather than a compliance requirement, and it is the cheapest insurance available on a personalisation programme.
Beyond incrementality, track the transition itself: what proportion of journeys involve more than one device, how often a session resumes rather than ends at a device switch, and how recognition accuracy differs between authenticated and anonymous visitors. Establish those baselines before you deploy anything, because afterwards you will not be able to.
Conclusion
Cross-device personalisation is now three problems rather than one. There is a behavioural problem, where the honest reading of the evidence is thinner than the industry’s confident summaries. There is a legal problem, which since February 2026 has a clearer answer than it used to: recognising a person across devices requires consent, and the newer exceptions do not reach it. And there is a measurement problem, where the published research is unambiguous that uncontrolled comparisons overstate effect.
Start where recognition is lawful and reliable, which means authenticated customers. Fix identity before buying orchestration, because a unified profile assembled from unreconciled records will produce confident nonsense at speed. Instrument the transitions. Hold something back so you can tell whether any of it worked.
The brands that do this well are not the ones with the largest identity graphs. They are the ones that know which of their matches they can trust. Our companion piece on customer journey mapping covers the stage-by-stage view that sits underneath this.
Frequently Asked Questions
There are two methods, and they are not equivalent. Deterministic matching uses an explicit shared identifier, most commonly an authenticated account or an email address supplied at login. When someone signs in on a phone after browsing anonymously on a laptop, those sessions can be connected reliably. Probabilistic matching infers a connection from behavioural and network signals such as address similarity, device configuration and browsing patterns. Published independent measurement of probabilistic accuracy is scarce, and the strongest peer-reviewed result comes from a small research dataset rather than from live commercial systems, so vendor accuracy claims should be treated with caution until a method is disclosed. Both methods require consent under UK rules when they involve storing information on or accessing information from a device for cross-device recognition. Begin with authenticated users, where the match is strongest and the consent position is clearest.
No. Since 5 February 2026 there are additional exceptions to the consent requirement, but personalisation as marketers use the term is not among them. The statistical exception is confined to aggregate statistics collected to improve the service, under strict conditions, and it excludes individual tracking, profiling and advertising measurement. The appearance exception permits adapting how a service looks or functions to a stated user preference, such as a language setting, but it does not permit changing content or selecting advertising according to known or inferred interests, behaviour or browsing history. Cross-site and cross-device tracking continues to require consent and is not treated as strictly necessary to provide a service. The rules are also technology-neutral, so switching from cookies to fingerprinting, pixels or web storage does not avoid them. Penalties for getting this wrong now match data protection levels.
They can work, but the accuracy figures circulating in this market deserve scepticism. Match rates in the region of 80 to 90 per cent are commonly quoted by suppliers and are rarely accompanied by a disclosed method, sample or definition of a match. Independent measurement is thin. The practical approach is to diversify rather than to chase a single number: authenticated sessions give you the most reliable link, first-party data collected through your own channels gives you a durable foundation, and server-side collection reduces dependence on client-side mechanisms. If you are evaluating an industry identity framework, check which geography it actually serves, since the framework covering the United Kingdom is not the same one that operates in North America and the tokens are not interchangeable. Ask any supplier how a match is defined and measured before accepting a rate.
Start with incrementality, because the rest is decoration without it. Published research comparing hundreds of advertising experiments has repeatedly found that non-experimental estimates overstate effect relative to randomised holdouts, so a control group is the measurement rather than a refinement of it. Beyond that, track the proportion of journeys involving more than one device, the rate at which sessions resume rather than end at a device switch, order values for multi-device journeys compared with single-device ones, and recognition accuracy split between authenticated and anonymous visitors. Watch more than one statistic at a time: a conversion rate improvement sitting alongside a fall in average order value is not a win. Establish baselines before deployment, because you cannot reconstruct them afterwards, and re-test periodically rather than assuming a past winner still wins.
Audit before you buy. Establish what identity resolution, data collection and consent capability you already have, and where the gaps sit. Then begin with authenticated customers, where recognition is most reliable and the permission position is cleanest. Fix data quality before orchestration: a unified profile built on records that were never reconciled will produce confident and wrong personalisation faster than a manual process would. Pick one or two high-value transition points, such as basket persistence or resuming a browsing session on a second screen, and instrument them properly with a holdout group. Expand only once those show a measurable effect. Build consent withdrawal and objection handling into the data pipeline from the beginning, since retrofitting suppression across channels is considerably harder than designing it in.
References
- Contentsquare, “Why intent is the key to engagement in 2026: 4 key takeaways”, measurement benchmark guide, no reference number, published 9 March 2026, last updated 9 March 2026. Approximately 99 billion sessions across more than 6,500 sites, global, comparing Q4 2024 with Q4 2025. https://contentsquare.com/guides/digital-experience-benchmark/engagement/
- Litmus, “2021 State of Email Engagement”, measurement report, no reference number, published 2021 with no stated day or month, no last-updated date shown. Almost 8 billion opens, worldwide with 77.9 per cent originating in the United States, collected 1 January to 31 August 2021. https://www.litmus.com/wp-content/uploads/pdf/2021_State_of_Email_Engagement.pdf
- Litmus, “The State of Email Client Market Share”, continuing measurement report, no reference number, no single publication date as this is an ongoing monthly resource, current as of 1 June 2026 at the time of checking. https://www.litmus.com/email-client-market-share
- Ofcom, “Communications Market Report 2016”, regulator research report, no reference number, published 4 August 2016, no last-updated date shown. Diary study of 1,512 UK adults aged 16 and over, fieldwork February to April 2016. Historic. https://www.ofcom.org.uk/siteassets/resources/documents/research-and-data/cmr/cmr16/uk/cmr_uk_2016.pdf
- WebKit, “Full Third-Party Cookie Blocking and More”, browser engine engineering announcement, no reference number, published 24 March 2020, no last-updated date shown. Not UK law: global browser engine policy. https://webkit.org/blog/10218/full-third-party-cookie-blocking-and-more/
- Mozilla, “Third-party cookies and Firefox tracking protection”, product support documentation, no reference number, no publication date shown, last updated 15 June 2026. Not UK law: global browser vendor documentation. https://support.mozilla.org/en-US/kb/third-party-cookies-firefox-tracking-protection
- Google, “Next steps for Privacy Sandbox and tracking protections in Chrome”, developer announcement, no reference number, published 22 April 2025, last updated 22 April 2025. Not UK law: global browser vendor policy. The statement in this post that IP Protection was planned for Q3 2025 was superseded by the announcement at reference 8. https://privacysandbox.google.com/blog/privacy-sandbox-next-steps
- Google, “Update on Plans for Privacy Sandbox Technologies”, developer announcement, no reference number, published 17 October 2025, last updated 17 October 2025. Not UK law: global platform engineering decision. Records a retirement decision; phaseout processes followed thereafter. https://privacysandbox.google.com/blog/update-on-plans-for-privacy-sandbox-technologies
- Competition and Markets Authority, “Decision to release commitments previously accepted by the CMA in respect of Google’s Privacy Sandbox Proposals”, final Competition Act 1998 decision, Case 50972, published 17 October 2025, no last-updated date shown. Commitments released and no longer binding from that date. https://assets.publishing.service.gov.uk/media/68f213ce06e6515f7914c728/Decision_to_release_the_commitments_previously_accepted_by_the_CMA_in_respect_of_Google_s_Privacy_Sandbox_proposals.pdf
- Apple, “User Privacy and Data Use”, App Store developer requirements, no reference number, no publication date shown, no last-updated date shown. Not UK law: private platform policy, which does not substitute for UK consent requirements. https://developer.apple.com/app-store/user-privacy-and-data-use/
- Android Developers, “Best practices for unique identifiers”, platform developer guidance, no reference number, no publication date shown, last updated 14 July 2026. Not UK law: private platform guidance. https://developer.android.com/identity/user-data-ids
- Secretary of State and UK Parliament, “The Privacy and Electronic Communications (EC Directive) Regulations 2003”, statutory instrument, SI 2003/2426, made 18 September 2003, continuously revised text with no single last-updated date. In force as amended; regulation 6 and Schedule A1 have applied in their current form since 5 February 2026. https://www.legislation.gov.uk/uksi/2003/2426
- UK Parliament, “Data (Use and Access) Act 2025”, Act, 2025 c. 18, Royal Assent 19 June 2025, continuously revised text with no single last-updated date. In force in stages; section 112 and Schedule 12 made the regulation 6 changes and section 115 and Schedule 13 changed the penalty framework. https://www.legislation.gov.uk/ukpga/2025/18
- Secretary of State for Science, Innovation and Technology, “The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026”, statutory instrument, SI 2026/82 (C. 10), made 29 January 2026, no last-updated date shown. Brought section 112 into force on 5 February 2026. https://www.legislation.gov.uk/uksi/2026/82/made
- Information Commissioner’s Office, “What are the exceptions?”, chapter of regulator guidance, no reference number, published 20 December 2024 as part of the parent guidance, last updated 29 April 2026. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-the-exceptions/
- Information Commissioner’s Office, “Guidance on the use of storage and access technologies”, regulator guidance, no reference number, published 20 December 2024, last updated 29 April 2026. Final following two consultations; no under-review banner displayed. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/
- Information Commissioner’s Office, “What are storage and access technologies?”, chapter of regulator guidance, no reference number, published 20 December 2024 as part of the parent guidance, last updated 29 April 2026. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/what-are-storage-and-access-technologies/
- Information Commissioner’s Office, “How do the PECR rules relate to the UK GDPR?”, chapter of regulator guidance, no reference number, published 20 December 2024 as part of the parent guidance, last updated 29 April 2026. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-the-use-of-storage-and-access-technologies/how-do-the-pecr-rules-relate-to-the-uk-gdpr/
- Retained and amended for UK domestic law, “Regulation (EU) 2016/679 of the European Parliament and of the Council”, assimilated direct legislation commonly called the UK GDPR, Regulation (EU) 2016/679, original instrument published 4 May 2016, continuously revised domestic text with no single last-updated date. Articles 5, 6, 12 to 14, 25 and 35 are the provisions relied on here. https://www.legislation.gov.uk/eur/2016/679/contents
- Information Commissioner’s Office, “Data Protection Impact Assessments (DPIAs)”, regulator guidance, no reference number, no publication date shown, no last-updated date shown. Under review: the page states that the guidance is under review following changes made by the Data (Use and Access) Act and may change, with no completion date published. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/accountability-and-governance/data-protection-impact-assessments-dpias/
- Information Commissioner’s Office, “Age appropriate design: a code of practice for online services”, statutory code of practice issued under sections 123 to 125 of the Data Protection Act 2018, no separate code number, published 12 August 2020, no last-updated date shown. In force since 2 September 2020, transition period ended 2 September 2021. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/childrens-information/childrens-code-guidance-and-resources/age-appropriate-design-a-code-of-practice-for-online-services/
- Information Commissioner’s Office, “Our advice to government on potential changes to online advertising rules”, regulator blog, no reference number, published 18 May 2026, no last-updated date shown. Advice to government only; not legislation and not an enforcement moratorium. No official timetable for a government decision has been published. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/05/our-advice-to-government-on-potential-changes-to-online-advertising-rules/
- Information Commissioner’s Office, “ICO report for DSIT: Advice on a viable approach to creating online advertising exception(s) to regulation 6 PECR”, formal regulator advice to government, no reference number, published May 2026, no last-updated date shown. Published advice, not UK law; the proposed exception is not in force and government consideration remains outstanding. https://ico.org.uk/media2/yefdqvk4/20260505-report-for-dsit-on-changes-to-regulation-6-pecr-for-online-advertising.pdf
- European Parliament and Council of the European Union, “Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications)”, EU directive, Directive 2002/58/EC, published 31 July 2002, consolidated version dated 19 December 2009. Not UK law: European Union, requiring implementation by member states. https://eur-lex.europa.eu/eli/dir/2002/58/2009-12-19/eng
- California Legislature, “California Consumer Privacy Act of 2018”, US state statute as codified and amended, California Civil Code sections 1798.100 to 1798.199.100, no single publication date for the continuously amended codification, no single update date displayed. Not UK law: State of California, United States. https://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?division=3.&lawCode=CIV&part=4.&title=1.81.5
- Secretary of State and UK Parliament, “The Privacy and Electronic Communications (EC Directive) Regulations 2003”, statutory instrument, SI 2003/2426 regulation 22, made 18 September 2003 with principal provisions commenced 11 December 2003, no page-level update date shown. Current as amended. https://www.legislation.gov.uk/uksi/2003/2426/regulation/22
- Information Commissioner’s Office, “Guidance on direct marketing using electronic mail”, regulator guidance, no reference number, publication date not stated on the landing page, last updated 28 April 2026. https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/guidance-on-direct-marketing-using-electronic-mail/
- USENIX Association, “A Privacy Analysis of Cross-device Tracking”, peer-reviewed conference paper, USENIX Security 17 pages 1391 to 1408, ISBN 978-1-931971-40-9, published August 2017, no last-updated date. Historical research, not a current standard or operational programme. https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/zimmeck
- Unified ID 2.0 documentation project, “Unified ID 2.0 glossary”, technical reference, no reference number, no publication date shown, last updated 27 July 2026. Not UK law: private advertising identity framework documentation. https://unifiedid.com/docs/ref-info/glossary-uid
- Unified ID 2.0 documentation project, “Overview of UID2 participants”, governance role documentation, no reference number, no publication date shown, last updated 27 July 2026. Not UK law: private technical governance documentation. Records that the transition to independent governance remains prospective. https://unifiedid.com/docs/overviews/participants-overview
- Department for Science, Innovation and Technology, Responsible Technology Adoption Unit, “Public attitudes to data and AI: Tracker survey (Wave 4) report”, government survey report, no reference number, published 16 December 2024, no last-updated date shown. 4,947 online interviews plus 200 telephone interviews with digitally disengaged UK adults, fieldwork 15 July to 16 August 2024. https://www.gov.uk/government/publications/public-attitudes-to-data-and-ai-tracker-survey-wave-4/public-attitudes-to-data-and-ai-tracker-survey-wave-4-report
- Information Commissioner’s Office, research conducted by Thinks Insight & Strategy, “Exploring people’s understanding of and attitudes towards online ‘consent or pay’ models”, regulator-commissioned research report, no reference number, no publication date shown on the landing page or report cover, no last-updated date shown. Nationally representative quota survey of 4,000 UK adult internet users, fieldwork 23 February to 6 March 2026. https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/consent-or-pay-models/
- INFORMS, “Close Enough? A Large-Scale Exploration of Non-Experimental Approaches to Advertising Measurement”, peer-reviewed research article in Marketing Science, DOI 10.1287/mksc.2022.1413, published 7 November 2022 with issue date July to August 2023, version of record with no last-updated date. Not UK evidence: United States advertising experiments. https://pubsonline.informs.org/doi/10.1287/mksc.2022.1413
- INFORMS, “A Comparison of Approaches to Advertising Measurement: Evidence from Big Field Experiments at Facebook”, peer-reviewed research article in Marketing Science, DOI 10.1287/mksc.2018.1135, published 4 April 2019 with issue date March to April 2019, version of record with no last-updated date. Not UK evidence: United States platform experiments. https://pubsonline.informs.org/doi/10.1287/mksc.2018.1135
Position stated as at 29 July 2026. Guidance in this area changes frequently. Reference 20 is expressly under review following the Data (Use and Access) Act 2025 with no published completion date, and references 22 and 23 describe advice to government on possible future exceptions to regulation 6 that are not in force and carry no published implementation timetable. Verify the current position before relying on any of it.
Written by
İlkem Erul
Contributor
I have over nine years of experience in digital marketing, account management, and B2C loyalty. I've helped global brands grow, and now, as a co-founder of Herm.io, I work on smarter, safer shopping experiences for consumers.
More from İlkemRelated Articles
What is a Personalisation CMS and How Does It Work?
A practical guide to personalisation CMS platforms: core features, selection criteria, and how to increase conversions.
How to Use Personalisation to Improve Customer Experience
Discover how personalization transforms customer experience with tailored journeys, dynamic UX design, and continuous feedback loops for lasting loyalty.
The Customer Journey: Mapping and Optimization
Map and optimize your customer journey to unlock growth. Discover actionable tips to enhance every touchpoint and build lasting relationships.