What is the uuid2 cookie?
uuid2 is an HTTP cookie placed by domains associated with AppNexus (adnxs.com), an ad-tech company acquired by AT&T and later rebranded as Xandr, and since 2022 part of Microsoft Advertising. AppNexus operates one of the larger real-time bidding platforms for web advertising.
The cookie typically appears when a site runs an ad tag, retargeting pixel, or script from a partner using AppNexus/Xandr infrastructure to buy or sell ad inventory. It is not set directly by the site owner, but by a third-party script embedded on the page (for example via Google Ad Manager, an SSP, or a DSP partner).
What data it stores
uuid2 stores a randomly generated unique identifier assigned to the visitor's browser, used to recognize it on later visits across different sites in the AppNexus network. The exact value format may vary and is not documented in detail by the provider.
Data linked to this identifier (ad impression history, ad interactions, matching with other partners' IDs) is sent to AppNexus/Xandr servers, hosted within Microsoft's infrastructure, and may be shared with other parties in the programmatic advertising chain (agencies, SSPs, DSPs) that AppNexus works with.
What it is used for
The main purpose of uuid2 is cookie syncing — matching identifiers between different advertising partners so the same person can be recognized across multiple platforms involved in automated ad auctions.
For the provider, this cookie enables building interest profiles based on browsing behavior and delivering more relevant targeted ads, which increases advertising revenue. For the site owner, its presence is part of how third-party ad networks monetize the ad space shown to visitors.
Does it require consent?
uuid2 falls under the marketing / advertising category, used for cross-site tracking and behavioral targeting. Under Romania's Law 506/2004 (transposing the ePrivacy Directive) and the GDPR, this type of cookie requires prior, explicit user consent obtained through a valid consent banner before the script that sets it runs.
- The site owner must list uuid2 in the cookie policy, along with the provider and purpose.
- The third-party script that sets the cookie must be technically blocked until consent is given.
- Refusing consent must not affect access to the site's content.
How to block or delete uuid2
A visitor can manually delete or block this cookie from browser settings (Chrome, Firefox, Safari, Edge — cookie management for the site or the adnxs.com domain), use ad-blocking/tracking-protection extensions, or opt out of AppNexus/Xandr targeted advertising through industry opt-out platforms such as the Digital Advertising Alliance (youronlinechoices.eu).
For a site owner, the only GDPR-compliant approach is technically blocking the AppNexus script before consent is given, not merely showing an informational banner. A CMP such as CookieFix automatically blocks marketing-category scripts, including those setting uuid2, until the visitor explicitly accepts that cookie category.
Frequently asked questions
It doesn't directly contain a name or email, but the unique identifier is considered personal data under GDPR because it allows a person to be identified and tracked online.
It's set by third-party scripts tied to AppNexus/Xandr, usually loaded through an ad server, SSP, or programmatic advertising partner, not directly by the site owner.
Its typical duration is about 3 months, after which it expires automatically, though it can be renewed on a new visit to a site in the network.
Yes, as a marketing/tracking cookie it requires prior visitor consent under GDPR and Law 506/2004, and the script must be technically blocked until consent is granted.