A server-side event is still data collection. A hashed identifier is still not automatically anonymous. Measurement choices change where an event travels; privacy choices govern whether and how personal data may be used. This guide explains the general mechanics of browser and server tracking, cookies, consent tools and privacy transformations. It also separates technical controls from legal obligations. Laws and browser policies change, so use the linked primary guidance and qualified advice for your specific jurisdictions and processing.
🧭 Jump to a term
How events are collected: Client-side tracking · Server-side tracking · Tag manager · Tracking pixel
Browser storage and consent: First-party cookie · Third-party cookie · Consent management platform (CMP) · Consent record
Privacy laws and personal data: General Data Protection Regulation (GDPR) · California Consumer Privacy Act (CCPA) · California Privacy Rights Act (CPRA) · Personally identifiable information (PII)
Transform, reconcile and label data: Hashing · Pseudonymization · Anonymization · Event deduplication · Urchin Tracking Module parameters (UTM parameters) · Cross-domain tracking
⭐ Know these first
Start with Server-side tracking, Consent management platform (CMP), General Data Protection Regulation (GDPR), Pseudonymization, Event deduplication. Then follow the grouped learning order below.
📎 How to read this page
What it means gives the precise meaning. Operator translation gives the version you might hear in a real ecommerce meeting. In real life shows an illustrative example. Watch out and the confusion boxes show where a familiar term can mislead.
📈 Read the relationships first
These combinations are diagnostic hypotheses, not proof of causality. Compare the same period and scope, then investigate the mechanism.
🖥️ Client-side events ↓ + server events ↑
Usually means: The collection route may have changed, while consent and event eligibility still govern. Check next: Compare event IDs and destination rules.
🍪 Consent choices ↑ + advertising events flat
Usually means: The tag manager may not be applying the recorded signal, or the events may be blocked downstream. Check next: Test consent states end to end.
🔐 Hashed identifiers ↑ + match rate ↑
Usually means: Matching may improve, but hashing alone does not make data anonymous. Check next: purpose, access, retention and applicable privacy rules.
📊 Browser + server purchase events ↑ + orders flat
Usually means: Both paths may count the same purchase twice. Check next: Use a shared event identifier and a defined deduplication window.
How events are collected
01 · 🔵 Operations
Client-side tracking = Collection code running in a user’s browser or device
🧠 What it means
Collection code running in a user’s browser or device
💬 OPERATOR TRANSLATION
“Client-side tracking collects or sends events from code running in the visitor’s browser or app. Browser settings, blockers, consent and device conditions can limit what is observed.”
🛍️ In real life
A product-page script sends a view event from the shopper’s browser after applicable permission and configuration.

🔗 Related: Server-side tracking · Tag manager · Tracking pixel · ↑ all terms
02 · 🟢 Core
Server-side tracking = Collection or forwarding of events from a server environment
🧠 What it means
Collection or forwarding of events from a server environment
💬 OPERATOR TRANSLATION
“Server-side tracking processes or forwards event data from a server. It can improve control over routing but does not itself create consent, identity or permission to collect data.”
🛍️ In real life
A commerce backend forwards a completed order event to an analytics endpoint under the merchant’s data rules.

🔗 Related: Client-side tracking · Tag manager · Tracking pixel · ↑ all terms
03 · 🔵 Operations
Tag manager = Tool for deploying and controlling website tags or tracking code
🧠 What it means
Tool for deploying and controlling website tags or tracking code
💬 OPERATOR TRANSLATION
“A tag manager lets authorized users configure tags, triggers and variables, often without editing site code for each change. Governance and testing remain necessary.”
🛍️ In real life
An analytics team deploys a page-view tag when a page loads, following approved consent settings.

🔗 Related: Client-side tracking · Server-side tracking · Tracking pixel · ↑ all terms
04 · 🔵 Operations
Tracking pixel = Small request or code element used to signal an event to a service
🧠 What it means
Small request or code element used to signal an event to a service
💬 OPERATOR TRANSLATION
“A tracking pixel commonly refers to code or a remote request that signals a page view or interaction to a measurement service. The term does not guarantee a literal visible pixel.”
🛍️ In real life
Opening a page triggers an event request to an advertising platform when allowed by implementation and privacy rules.

🔗 Related: Client-side tracking · Server-side tracking · Tag manager · ↑ all terms
Browser storage and consent
05 · 🔵 Operations
First-party cookie = Cookie set in the context of the site being visited
🧠 What it means
Cookie set in the context of the site being visited
💬 OPERATOR TRANSLATION
“A first-party cookie is set by the site the user is visiting, under browser and site rules. Its availability and permitted use depend on settings, consent and applicable law.”
🛍️ In real life
A store uses a cookie to remember a basket preference on its own domain.

🔗 Related: Third-party cookie · Consent management platform (CMP) · Consent record · ↑ all terms
06 · 🔵 Operations
Third-party cookie = Cookie set in a context distinct from the site being visited
🧠 What it means
Cookie set in a context distinct from the site being visited
💬 OPERATOR TRANSLATION
“A third-party cookie is associated with a domain other than the site shown in the browser context. Browser support and policy restrictions vary and continue to change.”
🛍️ In real life
An embedded advertising service attempts to read its cookie while a shopper visits the retailer’s site.

🔗 Related: First-party cookie · Consent management platform (CMP) · Consent record · ↑ all terms
07 · 🟢 Core
Consent management platform (CMP) = Tool that presents choices and records consent signals
🧠 What it means
Tool that presents choices and records consent signals
💬 OPERATOR TRANSLATION
“A consent management platform presents privacy choices and stores or communicates consent signals. Its configuration must reflect applicable jurisdiction, purpose and implementation requirements.”
🛍️ In real life
A shopper selects analytics but declines advertising cookies, and the CMP records the chosen signal.

🔗 Related: First-party cookie · Third-party cookie · Consent record · ↑ all terms
08 · 🔵 Operations
Consent record = Evidence of a person’s choice or other recorded consent state
🧠 What it means
Evidence of a person’s choice or other recorded consent state
💬 OPERATOR TRANSLATION
“A consent record stores information such as the choice, time, notice version and relevant purposes. Required evidence and legal basis depend on jurisdiction and processing context.”
🛍️ In real life
A retailer retains a timestamped record of a customer’s marketing opt-in and the notice shown.

🔗 Related: First-party cookie · Third-party cookie · Consent management platform (CMP) · ↑ all terms
Privacy laws and personal data
09 · 🟢 Core
General Data Protection Regulation (GDPR) = EU data-protection regulation governing personal-data processing
🧠 What it means
EU data-protection regulation governing personal-data processing
💬 OPERATOR TRANSLATION
“The GDPR establishes rules for processing personal data in its territorial scope, including principles, rights and controller or processor duties. Determine applicability and lawful basis with qualified counsel.”
🛍️ In real life
An ecommerce business serving people in the EU maps the personal data it collects and its processing purposes.

🔗 Related: California Consumer Privacy Act (CCPA) · California Privacy Rights Act (CPRA) · Personally identifiable information (PII) · ↑ all terms
10 · 🔵 Operations
California Consumer Privacy Act (CCPA) = California privacy law granting covered consumers rights over personal information
🧠 What it means
California privacy law granting covered consumers rights over personal information
💬 OPERATOR TRANSLATION
“The CCPA, as amended, gives covered California consumers rights regarding personal information and places duties on covered businesses. Coverage and obligations depend on current law and facts.”
🛍️ In real life
A covered business handles a California resident’s request to know, correct or delete personal information under applicable rules.

🔗 Related: General Data Protection Regulation (GDPR) · California Privacy Rights Act (CPRA) · Personally identifiable information (PII) · ↑ all terms
11 · 🔵 Operations
California Privacy Rights Act (CPRA) = California ballot measure that amended and expanded the CCPA
🧠 What it means
California ballot measure that amended and expanded the CCPA
💬 OPERATOR TRANSLATION
“The CPRA is the 2020 measure that amended the CCPA; many current requirements are commonly discussed under the CCPA as amended. Check current statutory text and regulations for obligations.”
🛍️ In real life
A privacy lead checks current California rules on sensitive personal information and consumer requests.

🔗 Related: General Data Protection Regulation (GDPR) · California Consumer Privacy Act (CCPA) · Personally identifiable information (PII) · ↑ all terms
12 · 🔵 Operations
Personally identifiable information (PII) = Information that identifies or can be linked to a person
🧠 What it means
Information that identifies or can be linked to a person
💬 OPERATOR TRANSLATION
“PII is a context-dependent term for information that identifies or can be linked to an individual. Definitions differ across laws and policies; minimize collection and protect identifiers.”
🛍️ In real life
An email address combined with order details can identify a customer and needs appropriate safeguards.

🔗 Related: General Data Protection Regulation (GDPR) · California Consumer Privacy Act (CCPA) · California Privacy Rights Act (CPRA) · ↑ all terms
Transform, reconcile and label data
13 · 🔵 Operations
Hashing = One-way transformation that maps data to a fixed-length value
🧠 What it means
One-way transformation that maps data to a fixed-length value
💬 OPERATOR TRANSLATION
“Hashing transforms input into a fixed-length output using a hash function. It is not encryption and does not by itself anonymize data; predictable inputs may be guessed or linked.”
🛍️ In real life
A platform requests normalized, hashed email values for matching, but the retailer still treats the source and output carefully.

🔗 Related: Pseudonymization · Anonymization · Event deduplication · ↑ all terms
14 · 🟢 Core
Pseudonymization = Processing that replaces direct identifiers while retaining a re-linking path
🧠 What it means
Processing that replaces direct identifiers while retaining a re-linking path
💬 OPERATOR TRANSLATION
“Pseudonymization reduces direct identification by replacing identifiers with pseudonyms, while additional information can reconnect data to a person. It remains personal data under GDPR when linkable.”
🛍️ In real life
A research dataset replaces customer IDs with tokens while a separately controlled key allows authorized re-linking.

🔗 Related: Hashing · Anonymization · Event deduplication · ↑ all terms
15 · 🔵 Operations
Anonymization = Processing that makes identification no longer reasonably possible
🧠 What it means
Processing that makes identification no longer reasonably possible
💬 OPERATOR TRANSLATION
“Anonymization aims to remove the ability to identify people from data, considering reasonably likely means and auxiliary information. Removing names alone is not enough; legal assessments are context-specific.”
🛍️ In real life
A team tests whether released aggregate data can be combined with outside datasets to identify individuals.

🔗 Related: Hashing · Pseudonymization · Event deduplication · ↑ all terms
16 · 🟢 Core
Event deduplication = Identification and removal or merging of repeated event records
🧠 What it means
Identification and removal or merging of repeated event records
💬 OPERATOR TRANSLATION
“Event deduplication detects multiple records representing the same intended event, often using shared identifiers and rules. Keep the key and window explicit so distinct valid events are retained.”
🛍️ In real life
Browser and server purchase events share an event ID, allowing the analytics pipeline to count one purchase.

🔗 Related: Hashing · Pseudonymization · Anonymization · ↑ all terms
17 · 🔵 Operations
Urchin Tracking Module parameters (UTM parameters) = URL parameters used to label campaign traffic
🧠 What it means
URL parameters used to label campaign traffic
💬 OPERATOR TRANSLATION
“UTM parameters are query-string labels, commonly for source, medium and campaign, that help analytics classify incoming traffic. Naming conventions and redirects determine whether values survive.”
🛍️ In real life
An email link includes campaign labels so sessions can be grouped under that newsletter promotion.

🔗 Related: Hashing · Pseudonymization · Anonymization · ↑ all terms
18 · 🔵 Operations
Cross-domain tracking = Measurement setup that connects activity across multiple domains
🧠 What it means
Measurement setup that connects activity across multiple domains
💬 OPERATOR TRANSLATION
“Cross-domain tracking links measurement across domains under configured identity and privacy rules. Domains, consent signals and referral exclusions must be tested; it does not guarantee a complete user journey.”
🛍️ In real life
A retailer links its storefront and hosted checkout domains so eligible activity can be analyzed across the handoff.

🔗 Related: Hashing · Pseudonymization · Anonymization · ↑ all terms
🔀 First-party data vs first-party cookie
First-party data describes a relationship or source context; a first-party cookie is browser storage set by the visited site.
🔀 Server-side tracking vs permission
Server-side describes where processing or forwarding runs. It does not create consent or a legal basis.
🔀 Hashing vs pseudonymization vs anonymization
Hashing transforms a value. Pseudonymization can be reversed with separately held information. Anonymization requires re-identification to be no longer reasonably possible in context.
🔀 Consent banner vs consent record
The banner presents choices. The record preserves the choice and context needed to evidence what happened.
🤔 Still confused?
Follow this thread: Client-side tracking → First-party cookie → General Data Protection Regulation (GDPR) → Hashing. That sequence moves from the basic object or relationship to the decisions and checks it supports.
Sources and scope
Primary documentation checked on 27 September 2026. Platform features and eligibility can change; examples and cartoon situations are illustrative.

