Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Marketing

_pbjs_userid_consent_data (Prebid) – what this cookie does

_pbjs_userid_consent_data is a cookie used by Prebid.js, an open-source header bidding library for online advertising. It stores the consent status passed to Prebid's User ID modules so they don't process data without permission. It falls under the marketing/advertising category and requires visitor consent under EU/Romanian law.

Name
_pbjs_userid_consent_data
Provider
Prebid
Category
Marketing
Type
HTTP cookie
Lifetime
1 month
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the _pbjs_userid_consent_data cookie?

Prebid is an open-source JavaScript library used by many publishers and media sites to run real-time header bidding auctions among multiple ad providers directly in the visitor's browser. The _pbjs_userid_consent_data cookie is part of Prebid.js's User ID module.

It is not set by Prebid as an organization, but by the Prebid.js code implemented on the site (or by its advertising partner/agency). It typically appears on the first page load, when the ad script initializes and the User ID modules start up.

What data it stores

The cookie stores information about consent status (for example, an allow/deny-type signal or a consent object, possibly linked to a TCF signal) used internally by Prebid to decide whether User ID modules may read or write identifiers. It generally does not contain direct contact details, only a technical consent indicator.

The exact value varies depending on each site's Prebid configuration and the User ID modules enabled. The data generally stays in the visitor's browser and is read by the advertising scripts loaded on the page; it can influence which identifiers are passed on to advertising partners in the auction.

What it is used for

The cookie's purpose is technical: it ensures Prebid's User ID modules respect the visitor's consent choice before generating or sharing identifiers used in ad auctions.

For the site, this cookie is part of the ad-monetization infrastructure — it helps header bidding auctions run correctly from a consent standpoint, reducing the risk that data is processed without permission.

Does it require consent?

Category: marketing/advertising. Because it is directly tied to user identification and tracking modules used for advertising, this cookie requires the visitor's prior consent under the ePrivacy Directive (2002/58/EC, transposed in Romania via Law 506/2004) and the GDPR (Regulation 2016/679).

Site owners must declare it correctly in their cookie policy, place it under the "marketing" category in the consent banner, and ensure the Prebid.js script does not run (or does not set this cookie) before the visitor gives explicit consent.

How to block or delete _pbjs_userid_consent_data

Visitors can delete or block this cookie via browser settings (Chrome, Firefox, Edge, Safari), through per-site cookie management, or by using ad-blocking/anti-tracking browser extensions. They can also refuse the "marketing" category in a properly implemented consent banner.

For site owners, the most effective approach is to automatically block the Prebid.js script until consent is given. A CMP such as CookieFix can block this type of script by default and only activate it once the visitor accepts the marketing category.

Frequently asked questions

It's a cookie set by Prebid.js, a library used for header bidding ad auctions, which stores the consent status for its User ID identification modules.

No, it's a technical consent flag rather than sensitive data like passwords or financial details, but it is tied to advertising and tracking infrastructure.

Yes, as a marketing/advertising cookie linked to user identification, it requires prior consent under the GDPR and Romania's Law 506/2004.

The typical duration is about one month, though it can vary depending on the site's Prebid configuration.

Updated 8 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.