Skip to main content
Blog
Blog security

What Is Web Tracking? How Websites Identify and Follow Visitors

Web tracking is the collection of data about visitors' behavior across websites, using cookies, pixels, fingerprinting, and session-replay scripts. This guide explains how each technique works, who is doing the tracking, what the law requires, and how site owners can see what their own pages are collecting.

Aug 18, 2026 4 min read
What Is Web Tracking? How Websites Identify and Follow Visitors
Table of Contents

Web tracking is the collection of data about visitors' identity and behavior on and across websites. It uses cookies, tracking pixels, browser fingerprinting, and session-recording scripts to recognize people and record what they do. Tracking powers analytics, advertising, and personalization — and it is what consent banners, GDPR, and the current wave of health-privacy enforcement exist to regulate.

How does web tracking work?

Every tracking technique answers one of two questions: who is this visitor and what are they doing. The main mechanisms:

TechniqueHow it identifies youSurvives cookie clearing?
CookiesAn ID stored in the browser, sent with every request to the domain that set it
Tracking pixelsA tiny image or beacon request that reports a page view or event to a third party✗ (relies on cookies)
Browser fingerprintingCombines device and browser attributes (canvas, fonts, WebGL, hardware) into a stable identifier
Session recordingScripts that capture clicks, scrolls, and keystrokes for replay and heatmapsn/a — records behavior, not identity
Server-side taggingMoves the collection endpoint to the site's own domain, bypassing third-party blocking✓ (from the browser's view it is first-party)

Most commercial sites run several of these at once, usually loaded through a tag manager, and often through scripts that load other scripts — which is why the full tracking picture only exists in the browser at runtime.

Who is tracking, and why?

  • The site itself (first-party): analytics, A/B testing, remembering carts and logins. Broadly expected by users.
  • Advertising platforms: conversion pixels and remarketing tags from Google, Meta, Microsoft, TikTok connect on-site behavior to ad auctions elsewhere.
  • Ad exchanges and data brokers: the long tail of domains in your network tab — exchanges, identity-resolution services, data management platforms — that link activity across every site where they are present. Our field guide to tracker domains identifies the most common ones by name.
  • Measurement panels: audience-measurement beacons that feed industry ratings.

What does the law require?

In the EU, GDPR and the ePrivacy Directive require prior consent for non-essential tracking — the reason consent banners exist. In the US, state laws (CCPA/CPRA, Virginia, Colorado and others) grant opt-out rights, and sector regulators go further: health-related tracking through tools like Google Analytics and the Meta pixel has produced OCR enforcement and class actions, covered in our HIPAA website tracking guide.

The compliance failure mode is rarely a decision to over-track. It is a script added for one purpose that collects more than intended, on pages it was never meant to run on — which is a visibility problem before it is a legal one.

How do you monitor tracking on your own site?

The network tab shows one page load; the real answer changes daily as tags and vendors update. Continuous visibility requires watching real sessions at the browser layer: which scripts execute, what data they can read, and which domains receive it. That is what cside's privacy monitoring does — it inventories every script across your pages and flags when one starts sending data somewhere new, which is the same evidence consent audits and GDPR tooling reviews ask for.

Web tracking vs. web tracking detection

One nuance worth naming: the same signal science that trackers use to identify visitors is also used defensively. Device fingerprinting deployed by a site owner to recognize returning fraudsters — cside Device Intelligence — is architecturally similar to advertising fingerprinting but serves the opposite goal: protecting accounts and payments rather than building ad profiles, without cookies and scoped to the site that deploys it.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

FAQ

Frequently Asked Questions

No, but it is regulated. GDPR and the ePrivacy rules in Europe require a lawful basis and, for most non-essential tracking, prior consent. US state laws like CCPA/CPRA grant opt-out rights, and sector rules go further — health-related tracking has triggered HIPAA enforcement. What is illegal is tracking without the required consent or disclosures, which is usually a configuration failure rather than a deliberate choice.

First-party tracking is done by the site you are visiting, under its own domain, typically for analytics and personalization. Third-party tracking is done by outside companies whose code runs on that site — ad exchanges, social pixels, data brokers — and can link your activity across every site where the same third party is present. Browser restrictions on third-party cookies target the second category, which is why techniques like fingerprinting and server-side tagging have grown.

Open the browser's network tab and you will see every tracker request — but only for that one page load, and the set changes as tag managers and scripts load other scripts. For a continuous answer, you need browser-layer monitoring: cside watches real sessions, inventories every script that executes, and shows which domains receive data, which is also the evidence consent and privacy audits ask for.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead