What is the _gcl_au cookie?
_gcl_au is a first-party HTTP cookie set by Google Ads, typically through the global site tag (gtag.js) or Google Tag Manager, whenever a Google Ads conversion or remarketing tag is installed on a website.
It appears as soon as a visitor loads a page running Google Ads/Analytics code linked to a Google Ads account, even without clicking on an ad. It's widely used across sites running paid Google campaigns, including in Romania.
What data it stores
The cookie value is a randomly generated identifier used internally by Google to link site visits to any conversions that later originate from Google Ads. It doesn't contain directly identifying information such as a name or email address, but it is considered personal data because it allows tracking a visitor's behavior over time.
Data collected through this cookie is sent to Google's servers (including outside the EU, within Google's infrastructure), where it's used for conversion reporting and campaign optimization.
What it is used for
For Google, _gcl_au is part of the conversion linker mechanism, used to test the efficiency of ad conversion attribution across a site, particularly in contexts where third-party cookies are restricted by the browser.
For the site owner, this cookie helps accurately measure the results of Google Ads campaigns — how many ad-driven visits lead to a desired action such as a purchase, form submission, or call — information used to guide ad budget and optimization decisions.
Does it require consent?
In CookieFix's classification, _gcl_au falls under the marketing category (advertising/tracking). Since it's used to track visitor behavior for advertising purposes, it falls under ePrivacy rules (in Romania, Law 506/2004) and requires prior, explicit, informed consent from the visitor, consistent with GDPR principles.
- It must not be set before consent for the marketing category is obtained.
- It should be clearly disclosed in the cookie policy, including the provider (Google Ads) and actual retention period.
- The site owner must be able to demonstrate that active consent was given, not just passive notice.
How to block or delete _gcl_au
A visitor can manually delete or block _gcl_au from browser settings (Chrome, Firefox, Edge, Safari — cookies and site data management) or use ad-tracking blocking extensions. Deleting it doesn't affect site functionality, only the accuracy of Google Ads conversion reporting.
For site owners, the obligation is to prevent the Google Ads/gtag script from setting this cookie before consent is given. A CMP like CookieFix automatically blocks marketing scripts (including Google Ads tags) until the visitor gives consent, preventing the cookie from being set prematurely.
Frequently asked questions
It's set by Google Ads, typically through the gtag.js script or Google Tag Manager installed on a site, when an active Google Ads conversion or remarketing tag is present.
No. It's a marketing cookie used for ad conversion tracking and attribution, so it requires visitor consent before it can be set.
Its typical duration is about 3 months, after which it expires automatically, though it can be reset on a new visit if the visitor returns to the site.
The site works normally, but Google Ads may report conversions from that visitor's advertising campaigns less accurately.