UET with Consent Mode – Cookies still being set before consent

Guðni Páll Guðnason 20 Reputation points
2025-09-24T10:47:58.87+00:00

I am using UET with Consent Mode, with the default set to 'ad_storage': 'denied'. I’ve observed that the _uetsid and _uetvid cookies are still being set before consent, by requests to https://bat.bing.com/p/insights.

When consent is denied, the cookie values begin with null|…. Once consent is granted, the null| prefix is replaced by an identifier.

Is this the intended behavior, and can you confirm whether this is considered GDPR compliant?

If so, how should CMPs reliably detect whether the cookie/service is compliant, given that the usual method is simply to check whether a cookie is present when consent is denied?

Microsoft Advertising API
Microsoft Advertising API
A Microsoft API that provides programmatic access to Microsoft Advertising to manage large campaigns or to integrate your marketing with other in-house systems.
0 comments No comments
{count} votes

Answer accepted by question author
  1. MS Advertising - Dagmara 310 Reputation points Microsoft External Staff Moderator
    2025-09-24T13:28:44.54+00:00

    Hello Guðni Páll Guðnason,

    Thank you for using our Microsoft Advertising Learn Q&A Platform!
    Thanks for raising this important question, it’s a nuanced topic, and I’m happy to help clarify.

    When using Microsoft Advertising’s Universal Event Tracking (UET) with Consent Mode and 'ad_storage': 'denied', the behavior you’re observing is expected and intentional. The cookies _uetsid and _uetvid may still be initialized with placeholder values (e.g., null|...) before consent is granted. These placeholders do not contain personal identifiers and are not used for tracking until the user provides consent.

    Once consent is granted, those placeholder values are replaced with actual identifiers, enabling full tracking functionality. This design ensures that no personal data is stored or accessed before consent, aligning with GDPR requirements.

    From the Microsoft Advertising and GDPR page:

    “Microsoft Advertising does not collect or use personal data for ad personalization unless the user has provided valid consent.”

    This means that even if a cookie is technically present, its content and usage determine compliance. A cookie with a null| prefix and inactive tracking logic is not considered a violation of GDPR.

    For CMP detection: It’s important to go beyond simply checking for the presence of a cookie. CMPs should evaluate:

    Whether the cookie contains identifiable data.

    Whether tracking behavior is active.

    Whether Consent Mode signals are properly passed and respected.

    Microsoft’s Consent Mode is thoughtfully built to integrate smoothly with Consent Management Platforms (CMPs), helping ensure that user choices around privacy and data usage are respected throughout the advertising journey.

    Setting up UET for Consent Mode
    Transparency and Consent Framework (TCF) for UET

    Our support teams are happy to discuss your account in more detail via phone, chat or email to provide review assistance, please see our support page to reach out! 

    I hope the information provided here answered your question. If you have any additional questions, please do not hesitate to reach out to our support. I have also sent you a private message asking for further details. You are more than welcome to respond to me so that I can begin the investigation on my end.

    Kind regards, 

    Dagmara | Microsoft Advertising Support Specialist | 800-518-5689

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.