Cookies, Tracking Pixels and Link Decoration: What the ICO Says Storage and Access Technologies Include, and Where a VPN Does Not Reach

A VPN changes the network path between a device and the websites it visits, including the IP address a website sees. Many online tracking methods work differently: they rely on information kept on the device or passed in a link. The UK Information Commissioner’s Office (ICO) lists these methods in its guidance on “storage and access technologies”. This guide summarises that list and explains why a VPN is a different kind of tool. It is general information, covers the UK position, and does not assess any VPN product or tracker-blocking feature.

What the ICO guidance covers

The ICO guidance explains the Privacy and Electronic Communications Regulations (PECR), which apply in the UK. It says that PECR applies to any technology that stores information, or accesses information stored, on a subscriber’s or user’s “terminal equipment”. The rules apply in web browsers, mobile apps and connected devices. They allow use of these technologies in particular circumstances or with valid consent, and where the information is personal data the UK GDPR also applies. The guidance is addressed to organisations, so it describes what services do rather than how users should respond. Other countries, including EU member states and US states, have their own rules, which are not covered here.

The technologies the ICO lists

  • Cookies are small text files generated by a web server and stored by the user’s device, usually through the browser. The ICO notes uses such as recognising a device, remembering a shopping basket, supporting log-in or remembering that a user is logged in, analysing traffic, and tracking browsing behaviour.
  • Tracking pixels are small pieces of code, usually an image file, embedded in a web page or email that create communication between the user’s client and a server. The ICO’s email example records the time, location and operating system of the device used to read the message.
  • Link decoration and navigational tracking add extra information to the URL in a link. This can identify where traffic came from, and the ICO says it can also identify that a user of one site is the same person as a user on another, for example by adding a user ID to a URL.
  • Device fingerprinting collects pieces of information about a device’s software or hardware that can be combined to identify a particular device. The ICO lists examples such as device configuration, HTTP header information, clock information, installed fonts and plugins. It says these elements can also be combined with other information, such as IP addresses or unique identifiers.
  • Web storage (localStorage and sessionStorage) lets sites store data in the browser. The ICO notes that localStorage data may be kept permanently unless removed, and that the data is not transferred to a server unless this is done manually.
  • Scripts and tags are JavaScript snippets that collect additional information about visitors, often using the other technologies on this list.

Why the IP address is only part of the picture

In the ICO’s descriptions, the identifying information sits in the browser or device (cookies, web storage, fingerprint inputs), travels in the link (link decoration), or is requested by embedded content (pixels and tags). The IP address appears only as one possible extra input to fingerprinting. A VPN replaces the network address a site sees, as the guide to IP addresses as personal data explains. That does not remove a cookie already stored in a browser, change what is in web storage, or alter an identifier carried in a URL.

This is an inference from how the ICO describes the technologies, not a test result for any product. Individual VPN apps may bundle extra features, such as tracker blocking, which are separate claims that need their own evidence. The guide to browser fingerprinting covers one of these methods in more depth.

First-party, third-party and persistence

The ICO explains that the first-party or third-party label is not the main consideration for privacy purposes. What matters is who is responsible for the storage or access and why. It notes that third-party cookies can link people’s activity across different sites and devices, and that browsers have introduced limitations, including tracking protection features and restrictions on third-party cookies. In some cases, it says, resources once delivered by a third-party cookie are now delivered through a first-party cookie.

The guidance also separates session storage, which generally expires when the browser is closed or shortly afterwards, from persistent storage that lasts between visits. It adds that some session cookies can be restored by the browser in the next session, so the distinction is not absolute. Controls over these items sit in browser and device settings. The wider guide to online privacy basics covers how those controls fit with a VPN.

Common questions

Does a VPN stop cookies?

The ICO describes cookies as stored by the user’s device and sent back to the web server on later requests. A VPN does not appear in that description, so it should not be assumed to stop them.

Does the ICO say a VPN protects against these methods?

No. The guidance does not mention VPNs. It describes what services do, and the conclusion drawn here is an inference.

The bottom line

The ICO’s guidance treats cookies, tracking pixels, link decoration, device fingerprinting, web storage and scripts as technologies that store or access information on a device or travel with a link, all regulated in the UK under PECR. A VPN changes the network address a website sees, but the identifying information in these methods does not depend on that address alone. Claims that a VPN, or a bundled blocker, reduces tracking should be read as separate claims about particular features, to be checked against evidence rather than assumed from the VPN label.

Sources

  • What are storage and access technologies? (ico.org.uk, Guidance on the use of storage and access technologies)