Features Pricing GDPR cookie banner Google Consent Mode v2 WordPress plugin Cookiebot alternative For Agencies GDPR ePrivacy About Contact
RO | EN
Start Free →
Marketing

cto_bidid Cookie (Criteo) – What It Is and What It Does

cto_bidid is a marketing cookie set by Criteo, used to identify a visitor's browser during real-time advertising auctions and to serve personalized ads on other websites. It typically lasts 13 months and requires visitor consent under EU ePrivacy and GDPR rules.

Name
cto_bidid
Provider
Criteo
Category
Marketing
Type
HTTP cookie
Lifetime
13 months
Consent
Yes, before it is set (GDPR / ePrivacy)

What is the cto_bidid cookie?

cto_bidid is an HTTP cookie set by Criteo, one of Europe's largest retargeting and programmatic advertising providers. It appears on a site as soon as the Criteo tag script loads, usually through a tracking pixel added by the site owner or via a tag management platform.

Criteo deploys this cookie across a large network of partner sites (online stores, publishers), not just the site the user is currently visiting, which is why it is typically classified as a third-party cookie.

What data it stores

cto_bidid stores a unique identifier generated by Criteo for that browser, used as a „bid ID” in the automated ad-auction process. The value is an opaque alphanumeric string with no meaning to a human observer.

Data linked to this identifier (pages visited, products viewed, ad interactions) is sent to Criteo's servers, where it is used to build an interest profile of the visitor, later used to select which ads are shown across other sites in the Criteo network.

What it is used for

  • Lets Criteo recognize the same visitor across multiple sites and browsing sessions
  • Supports real-time bidding (RTB), which decides which ad is shown and at what price
  • Powers retargeting: displaying ads for products the user previously viewed
  • Helps site owners monetize traffic or re-engage visitors interested in specific products

Does it require consent?

Under CookieFix's classification, cto_bidid falls into the marketing (advertising/tracking) category. Since it is used for behavioral tracking and targeted advertising, it falls under Article 5(3) of the ePrivacy Directive (2002/58/EC), transposed in Romania via Law 506/2004, and requires the visitor's prior, explicit, informed consent, alongside compliance with the GDPR (Regulation 2016/679).

Site owners must disclose this cookie (or the Criteo category) in their cookie policy, obtain consent before the script loads, and allow it to be withdrawn as easily as it was given.

How to block or delete cto_bidid

A visitor can delete or block this cookie from their browser settings (Chrome, Firefox, Edge, Safari) under site data/cookie management, or use the opt-out options Criteo provides for personalized advertising. Ad-blocking extensions and private browsing modes also reduce the effectiveness of this type of tracking.

For site owners, the correct approach isn't manual deletion but preventing the Criteo script from loading before consent is given. A CMP like CookieFix automatically blocks this type of marketing script until the visitor gives consent, avoiding the cookie being set without a legal basis.

Frequently asked questions

Yes, since it is a marketing/tracking cookie used by Criteo for targeted advertising, it requires prior visitor consent under the ePrivacy rules and GDPR.

It typically lasts 13 months from the moment it is set, though this can vary depending on how Criteo is implemented on a given site.

Criteo is a programmatic advertising company specializing in retargeting, and it uses the cto_bidid cookie to identify a browser during real-time ad auctions.

The most effective way is using a CMP that blocks the Criteo script until consent is obtained; visitors can also block it manually via browser settings or Criteo's own opt-out page.

Updated 8 September 2026 · Information comes from the provider’s public documentation and CookieFix scans; it is not legal advice.