What is the cto_optout cookie?
cto_optout is an HTTP cookie placed by Criteo, an international ad tech company specializing in retargeting and product recommendation ads. It doesn't appear on first contact with a random website; instead, Criteo's servers (.criteo.com domain) set it when a user goes through an opt-out mechanism — for example, Criteo's ad preferences page or an unsubscribe link for targeted advertising.
In practice, cto_optout only appears for users who have actively chosen to refuse Criteo's marketing-related tracking, not for every site visitor.
What data it stores
The cookie essentially stores a flag indicating that the user has opted out of Criteo's personalized advertising. The exact value format isn't publicly documented in detail and may vary, but functionally it serves as an opt-out marker rather than an active advertising identifier.
Since it's set on the .criteo.com domain, the information is sent to Criteo's servers, not to the website embedding a Criteo script (e.g., via retargeting tags or product recommendation widgets).
What it is used for
The cookie's purpose is strictly functional: it remembers the opt-out choice so Criteo stops showing personalized ads or building a targeting profile for that user for the duration of the cookie's lifespan.
For a site owner, this cookie is only relevant if the site embeds Criteo scripts (retargeting, similar-product recommendations, etc.) — in that case, cto_optout is part of how Criteo honors the user's choice.
Does it require consent?
Under CookieFix's classification, cto_optout is categorized as strictly necessary. Since its sole function is to enforce an explicit opt-out preference expressed by the user, it doesn't serve tracking or profiling itself — it does the opposite.
- Site owners should still list this cookie in their cookie policy, including its purpose and provider (Criteo).
- If the site uses Criteo for retargeting/marketing beyond this opt-out mechanism, those Criteo scripts remain subject to prior consent under GDPR and the ePrivacy rules.
- It's good practice to periodically verify that the Criteo integration actually respects the consent state set through the CMP.
How to block or delete cto_optout
A visitor can delete or block this cookie from browser settings (Chrome, Firefox, Edge, Safari — the per-site cookie management section, searching for "criteo.com"), or use third-party tracking protection features.
For site owners, a consent management platform like CookieFix can automatically block Criteo scripts (and any related mechanisms) from loading until the visitor consents to the marketing category, ensuring the correct order: consent first, script activation second.
Frequently asked questions
It's a cookie set by Criteo on the .criteo.com domain to remember a user's choice to opt out of Criteo's personalized advertising.
Not in the traditional sense — its role is to block ad tracking rather than enable it, which is why it's classified as strictly necessary.
Its typical duration is around 5 years, during which the opt-out preference stays remembered.
Not for this cookie itself, but it should be disclosed in the cookie policy, while any Criteo scripts used for marketing purposes still require prior consent.