ADAM PULSE Knowledge Base
Security · Privacy · AdTech · GDPR · Telecom

Utiq: how telecom-operator tracking identifies a connection rather than a cookie

Short answer

Utiq is a European advertising identity service that identifies people through their internet connection at the telecom operator, rather than through a cookie in their browser.

That single design choice is why it is interesting, and why it sits awkwardly next to the advice most people have absorbed about online privacy. Clearing cookies, switching browsers and using private browsing are all defences aimed at browser storage. An identifier derived from the network connection is not stored where those defences look.

Three things a US business should know before reading further:

What Utiq is

What is Utiq?

In its own words, Utiq is:

a European AdTech company with a unique Telco-powered first party identifier, that harnesses Authentic Consent to enable responsible digital marketing

Stripped of the marketing: participating telecom operators can recognise which of their subscribers is behind a given IP address. Utiq turns that into a pseudonymous advertising identifier, with the user's consent, and hands it to publishers and advertisers.

Who owns Utiq?

Utiq SA/NV is incorporated in Brussels, Belgium, and is a joint venture owned in equal 25% shares by Deutsche Telekom, Orange, Telefónica and Vodafone.

This is not a self-reported detail. The European Commission cleared the joint venture unconditionally under the EU Merger Regulation in February 2023, and Deutsche Telekom's own announcement describes the four companies taking "equal 25% stakes in a newly-formed joint venture holding company, to be based in Belgium."

Was it previously called TrustPID?

Yes. And the best source for that is a regulator rather than the company.

Germany's federal data protection commissioner, the BfDI, publishes an FAQ on Utiq — at a URL whose path still reads FAQ-TrustPID — which states that Utiq is a joint venture of the four operators and that "previously there was, among others, a pilot operation in Germany under the name 'TrustPID'."

Two corrections to the version of this story that circulates:

Which operators and countries does it cover?

Be careful with the numbers here, because Utiq's own published figures have moved and the ones in circulation are stale.

Utiq's operative list — the one that actually governs whether the technology can activate, published in its privacy statement — covers five countries: France, Germany, Italy, Spain and the United Kingdom, naming 32 consumer-facing operator and MVNO brands between them.

Utiq's published operator coverage by country, from its own privacy statement
Country Operator brands listed Fixed-line broadband supported
France 7 All seven
Germany 16 Deutsche Telekom, O2 and Vodafone only
Italy 1 None — mobile only
Spain 5 Four of the five
United Kingdom 3 Vodafone only

Three things worth noting:

How it actually works

How does Utiq identify someone without a cookie?

The identification happens at the operator, not in the browser. Utiq's own description of the step:

Your telecom operator uses your IP address to match it to a telecom reference associated with the internet connection (e.g. telecom account number or mobile number). Once the match is done, your telecom operator uses a secure method, such as encryption, tokenisation or hashing ... to create a different value which acts as a stable pseudonymous identifier ... known as the "Network Signal"

Germany's BfDI describes the same mechanism independently: the operator determines the phone number from the IP address, and from that generates a unique pseudonymous network identifier for Utiq.

Is Utiq "cookieless"?

No, and this is worth getting right. Utiq removes the need for third-party cookies. It still uses first-party browser storage to carry the result — a connectId cookie with a 90-day lifetime, a consent-status cookie at 180 days, a consent-version cookie at 390 days, and a utiqPass value in local storage.

So "Utiq works without cookies" is wrong. The accurate statement is that it does not depend on third-party cookies, which is the thing browsers have been dismantling.

What are a consentpass and a martechpass?

Utiq's identifiers are layered, and the vocabulary matters if you are reading its documentation.

One detail that tells you something about the design: martechpass values are prefixed by connection type. Mobile passes begin mt1-, fixed-line passes begin mt2-. The identifier itself discloses whether the user is on mobile or broadband.

Does the identifier follow me across browsers?

Yes, and this is the actual selling point. Utiq's documentation:

The martechpass will always be the same for the same user, across browsers and across digital properties operated by the same data controller

Because the identifier is derived from the connection rather than from browser state, it survives the browser-level defences that break cookies. Switching from Chrome to Safari does not change it.

There is a real limit, though, and it is a meaningful one: the martechpass is scoped to a single publisher or advertiser, or a corporate group — and consent must be given on each property separately. It is not a cross-web identifier that follows you from one company's site to another's.

On home Wi-Fi, is the identifier mine or my household's?

Your household's. This is the most consequential fact about Utiq and the one most coverage leaves out. From Utiq's privacy statement:

The online secure identifiers are created either to represent an individual user or a household. This is because they are created based on the internet connection used, so anyone connecting their device and consenting to the Utiq technology on a given digital property will receive the same identifiers.

On a broadband connection, every consenting person in the house shares one identifier and their browsing is blended into a single profile. On a mobile connection it approximates one person, because mobile connections generally have one user.

Utiq has clearly thought about the consequences. Its consent portal deliberately hides the list of consented sites on broadband connections, showing only a count, so that housemates cannot see which sites each other visited. And withdrawal is household-wide: one person revoking consent revokes it for everyone on the connection.

Note also that Utiq's own definition of a broadband connection covers residential service only and excludes commercial connections.

Does it work over Wi-Fi or only mobile data?

The distinction is not Wi-Fi versus mobile. It is whose network the connection runs on.

Utiq activates only on "a supported internet connection provided by one of the participating telecom operators", and it notes that for some operators the technology is mobile-only while for others it extends to broadband. So a participating operator's home broadband works; arbitrary café or hotel Wi-Fi does not.

Does a VPN stop it?

Utiq states that a VPN, an ad blocker or Apple's Private Relay "may interfere" with its service, and it treats VPN state as a diagnostic input when troubleshooting.

The mechanism explains why. Utiq's onboarding documentation says its identification "relies on Utiq receiving the user's IP by connecting to Utiq's servers directly, without intermediate proxies or gateways." If Utiq cannot see the real operator-assigned IP address, the operator lookup that the whole system depends on cannot happen.

We would phrase this as Utiq does — that a VPN may interfere — rather than as a guarantee.

Does clearing cookies remove it?

Partly, and the nuance matters because both simplified versions are wrong.

Utiq's own text: clearing your history and browsing data "will also delete all Utiq consents stored there along with any marketing identifiers." So the local copy does go.

But the server-side records — the consentpass and Network Signal — are deleted "within 90 days" following that, not immediately. And because the identifier derives from the connection rather than from browser storage, consenting again on the same connection re-establishes the same linkage.

So: clearing cookies does remove the local identifiers, and "clearing cookies does nothing" is wrong. What it does not do is sever the underlying connection-based relationship.

Does it work in private or incognito browsing?

We do not know, and neither does anyone claiming otherwise. We checked Utiq's website, its full technical documentation and its privacy statement. None of them addresses private browsing in either direction.

Given the mechanism it is reasonable to expect that private browsing would not by itself prevent the operator-side lookup, since that does not depend on browser storage. But Utiq does not say so, and we are not going to assert a claim about a named company's product that its own documentation does not support. If you need a definitive answer, ask Utiq.

For what private browsing does and does not do generally, see our [Incognito mode article](/articles/incognito-mode-browsing-history-digital-footprint).

Does Utiq use browser fingerprinting?

Utiq explicitly says it does not. Its site lists, under a heading "What we don't do", a set of practices including "Probabilistic or fingerprinting techniques", "Identity graphs", "Data marketplace" and "Cross-industry identity resolution".

We report that as Utiq's stated position rather than as an audited fact, because no third party has verified it. It is at least internally coherent: a deterministic operator-side IP match has no need for fingerprinting.

Is my phone number given to websites?

No. The operator uses the phone number or account number internally to resolve the IP address, then hands over only a pseudonymous token.

Utiq states that no personal data which can directly identify a user — phone number, name or email — is stored in its platform, and that only the telecom operator can link the Network Signal back to a person. Publishers receive only the derived passes.

The BfDI's independent description matches this. It also flags the risk that matters: if a publisher joins the pseudonymous identifier to its own logged-in user account, re-personalisation becomes possible downstream. The protection is in the token, not in what the recipient chooses to do with it.

What is the utiq.example.com subdomain for?

Publishers create a CNAME subdomain on their own domain — Utiq's documentation uses utiq.example.com — pointing at Utiq's infrastructure.

Its documented purposes are two, both technical:

  1. Direct IP visibility. The connection must reach Utiq's servers without an intervening CDN, proxy or gateway, so that Utiq sees the real operator-assigned IP address. Without that, the operator lookup fails.
  2. First-party cookie context. Because the hostname sits under the publisher's own registrable domain, the cookies Utiq sets are first-party — which is exactly what survives Safari's and Firefox's anti-tracking restrictions.

This is the standard CNAME pattern used across the industry. One claim we want to correct: we have seen it said that the subdomain is designed to visually resemble the host site. Nothing in Utiq's documentation says or implies that. It is a DNS record pointing at infrastructure, not a rendered page.

Is Utiq opt-in or opt-out?

Opt-in, off by default, and per site. Utiq's privacy statement:

The Utiq technology is not enabled by default and can only be activated on your device if: you give your consent on a digital property ... and you are using a supported internet connection provided by a participating telecom operator.

Consenting on one website does not activate it on others. Deutsche Telekom's own announcement describes the platform as requiring "affirmative opt-in consent by the consumer."

How do I check or withdraw consent?

Through Utiq's portal, consenthub, which lists the sites you have consented on and allows withdrawal — either for one site via the "Manage Utiq" link in that site's footer, or for everything at once. Deletion follows within a maximum of 24 hours.

There is also a freeze option that blocks activation for a year even if consent is later given. Utiq publishes the honest caveat attached to it: to honour a freeze, it must retain the consentpass and Network Signal for that year.

Two practical limitations. Consenthub only works if you are on a supported connection at the time you visit it, so you cannot check your home broadband consents from a mobile connection. And ad blockers, VPNs and Private Relay can prevent access to it.

Consent, for the core processing. Utiq also relies on legitimate interests for several ancillary purposes — security, support and troubleshooting, service health monitoring, and internal analytics, reporting and billing.

Utiq is the data controller, a joint controller with publishers and advertisers for some operations, and an independent controller alongside the operator for the Network Signal step.

The parties describe the design as built to comply with GDPR and the ePrivacy Directive. That is a design claim by the companies involved, not a determination by any regulator, and it should be read as such.

Has a data protection authority taken a position?

Germany's BfDI has published guidance, and it is genuinely two-sided. It should be read in full rather than quoted selectively by either side.

On the "supercookie" label the press applied, the BfDI is dismissive: no, it says, that description is misleading, because Utiq is intended as an alternative to today's cookie-based personalised advertising.

On the substance, it calls the service "zwiespältig" — ambivalent. On one hand only pseudonymised data is processed, on the basis of consent. On the other:

telecommunications providers occupy a special position of trust, which the BfDI finds difficult to reconcile with tracking their users

and it flags the re-personalisation risk described above as something that must be examined and prevented.

Three limits on what that guidance is:

Has Utiq been challenged or fined?

We could not identify any published regulatory decision, enforcement action or formal complaint against Utiq from an EU data protection authority as of August 2026.

We want to be precise about what that sentence means. It means our searches of the regulators' own publications did not surface one. It is not a verified negative, and it should not be read as "Utiq has faced no challenge."

What this means in practice

Is Utiq available in the United States?

No. No US operator participates, and Utiq processes and stores data in the EU and UK. It cannot activate for a user on a US network.

For a US business the practical relevance is narrow: it is a way to reach audiences in France, Germany, Italy, Spain and the UK, and it is not a domestic identity solution.

Is this the death of cookies?

Not in the way the headline suggests, and the timing point cuts the other way.

Google abandoned its plan to deprecate third-party cookies in Chrome in April 2025 and reaffirmed that position later that year. Third-party cookies still work in ordinary Chrome browsing today. So the premise that the industry urgently needs a cookie replacement is weaker in 2026 than it was when Utiq was conceived.

What is true is narrower and more durable: browser-level defences do not reach an identifier established at the network layer. That is a structural point about where identification happens, and it does not depend on what Chrome does with cookies.

What should a business actually do about this?

For most of our readers the answer is short.

Frequently asked questions

What is Utiq?

Utiq is a European advertising identity service that identifies users through their internet connection at the telecom operator rather than through a browser cookie. It is a joint venture incorporated in Brussels and owned in equal 25% shares by Deutsche Telekom, Orange, Telefonica and Vodafone, cleared unconditionally by the European Commission in February 2023.

Was Utiq previously called TrustPID?

Yes. Germany's federal data protection commissioner states that Utiq was preceded by a pilot in Germany called TrustPID, run on Vodafone's and Deutsche Telekom's networks. The pilot was not shut down under regulatory pressure; it fed into the joint venture that launched commercially as Utiq in 2023.

Which countries does Utiq operate in?

Utiq's own published operator list covers five countries: France, Germany, Italy, Spain and the United Kingdom. Austria appears in Utiq's 2025 press releases but not in its current operator list, and we could not establish its status from primary sources.

Is Utiq available in the United States?

No. No US telecom operator participates, and Utiq cannot activate for a user on a US network. It processes and stores data in the EU and UK. For a US business it is relevant only for reaching European audiences.

How does Utiq identify someone without a cookie?

The telecom operator matches the user's IP address to the telecom account or mobile number, then generates a pseudonymous value called the Network Signal and shares that with Utiq. The identification happens at the operator, not in the browser.

Is Utiq cookieless?

No. Utiq removes the need for third-party cookies but still uses first-party browser storage to carry the result, including a connectId cookie with a 90-day lifetime, a consent status cookie at 180 days, a consent version cookie at 390 days, and a utiqPass value in local storage.

What is a martechpass?

A martechpass is the identifier Utiq issues to a single publisher or advertiser with the user's consent, derived from an internal value called the consentpass. It is persistent for 90 days. Mobile passes are prefixed mt1- and fixed-line passes mt2-, so the identifier itself discloses the connection type.

Does Utiq track me across browsers?

Yes. Because the identifier derives from the network connection rather than browser storage, the same martechpass applies across browsers and devices on the same connection. It is scoped to one publisher or advertiser or corporate group, however, and consent is required on each property separately, so it is not a cross-web identifier.

On home Wi-Fi, is the Utiq identifier mine or my household's?

Your household's. Utiq's privacy statement states that identifiers are created based on the internet connection used, so on a broadband connection anyone in the household who consents receives the same identifiers and their browsing is blended. On a mobile connection it approximates a single user. Withdrawal is household-wide.

Does Utiq work over Wi-Fi?

It works when the Wi-Fi is a participating operator's home broadband, in which case the identifier is household-scoped. It does not work on arbitrary Wi-Fi such as a cafe or hotel network. Which operators support fixed-line varies by country; in Italy Utiq is mobile-only.

Does a VPN stop Utiq?

Utiq states that a VPN, an ad blocker or Apple's Private Relay may interfere with its service. The mechanism explains why: Utiq's documentation says identification relies on receiving the user's IP directly, without intermediate proxies or gateways, so if it cannot see the real operator-assigned IP the operator lookup cannot happen.

Does clearing cookies remove Utiq?

Partly. Utiq states that clearing browsing data deletes the Utiq consents and marketing identifiers stored in the browser. However the server-side records are deleted within 90 days rather than immediately, and because the identifier derives from the connection, consenting again on the same connection re-establishes the same linkage.

Does Utiq work in incognito or private browsing?

Utiq's website, technical documentation and privacy statement do not address private browsing in either direction, so there is no supportable answer. Given the mechanism it would be reasonable to expect private browsing not to prevent an operator-side lookup, since that does not depend on browser storage, but Utiq does not state this.

Does Utiq use browser fingerprinting?

Utiq explicitly says it does not. Its site lists probabilistic and fingerprinting techniques, identity graphs and cross-industry identity resolution among practices it does not use. This is Utiq's stated position rather than an audited fact, though it is internally coherent since a deterministic operator-side match does not need fingerprinting.

Is my phone number shared with websites?

No. The operator uses the phone number or account number internally to resolve the IP address and hands over only a pseudonymous token. Utiq states it stores no directly identifying personal data and that only the operator can link the Network Signal back to a person. Publishers receive only the derived passes.

Is Utiq opt-in or opt-out?

Opt-in and off by default, and consent is required on each website separately. Consenting on one site does not activate it elsewhere.

How do I withdraw Utiq consent?

Through Utiq's consenthub portal, which lists consented sites and allows withdrawal for one site or for all at once, with deletion within a maximum of 24 hours. There is also a freeze option that blocks activation for a year. Consenthub only works while you are on a supported connection, and ad blockers, VPNs and Private Relay can block access to it.

Has a regulator approved Utiq?

No. Germany's BfDI has published advisory guidance, not an approval. It rejects the supercookie label but describes the service as ambivalent, noting that telecom providers occupy a special position of trust it finds difficult to reconcile with tracking their users, and flagging re-personalisation risk if the pseudonymous identifier is joined to a website login. The BfDI also states it is not the competent regulator for Utiq itself; that is the Belgian authority.

Has Utiq been fined or formally challenged?

We could not identify any published regulatory decision, enforcement action or formal complaint against Utiq from an EU data protection authority as of August 2026. That is a null search result rather than a verified negative.

Does Utiq mean cookies are dead?

Not in the way the headline suggests. Google abandoned its plan to deprecate third-party cookies in Chrome in April 2025 and reaffirmed that position later that year, so third-party cookies still work in ordinary Chrome browsing. The durable point is narrower: browser-level defences do not reach an identifier established at the network layer.

What is the utiq.example.com subdomain for?

Publishers create a CNAME subdomain on their own domain pointing at Utiq's infrastructure. Its two documented purposes are to let Utiq see the user's real IP address without an intervening proxy or CDN, and to place Utiq's cookies in first-party context so they survive browser anti-tracking restrictions. Utiq's documentation does not describe any visual-resemblance purpose.

References

Primary sources only — Utiq's own privacy statement and developer documentation, the German federal data protection commissioner, the European Commission, and the shareholders' own announcements. Where Utiq's published figures conflict with each other, both are dated and attributed.

  1. Utiq — consenthub privacy statement— the operative document. Source for the operator and country list, the Network Signal mechanism, the household identifier, browser storage lifetimes, consent basis, and the withdrawal and freeze mechanics.
  2. Utiq — This is Utiq— corporate self-description and the statement that Utiq is backed by Deutsche Telekom, Orange, Telefónica and Vodafone.
  3. Utiq — Our service— the "What we don't do" list, including probabilistic and fingerprinting techniques, identity graphs and cross-industry identity resolution.
  4. Utiq developer documentation — Utiq technology— definitions of consentpass, martechpass, adtechpass and attributionpass, their lifetimes, and the cross-browser claim.
  5. Utiq developer documentation — Integration checklist and onboarding— the CNAME subdomain requirement and the statement that identification relies on receiving the user's IP without intermediate proxies or gateways.
  6. BfDI — FAQ zu Utiq— Germany's federal data protection commissioner. Confirms the TrustPID lineage, rejects the "supercookie" label, describes the service as ambivalent, flags re-personalisation risk, and states the BfDI is not the competent authority for Utiq itself.
  7. European Commission — Merger clearance, Deutsche Telekom / Orange / Telefónica / Vodafone joint venture— 10 February 2023. Unconditional clearance of the joint venture under the EU Merger Regulation.
  8. Deutsche Telekom — European telcos establish joint venture— the equal 25% shareholding structure, the Vodafone origin of the project, the German trial, and the opt-in consent requirement.
  9. Utiq — Utiq launches in the UK— 25 June 2025. Utiq's own most recent public partner count, "28 Telco partners" across five markets, superseding an earlier figure of 26 published three weeks before.
  10. Google Privacy Sandbox — Next steps for Privacy Sandbox and tracking protections— 22 April 2025. Google's decision not to deprecate third-party cookies in Chrome, which undercuts the premise that the industry urgently needs a replacement.
Prepared by ADAM Pulse (USA Telecom Consulting LLC)

Managed network and security services, SDVOSB. We are a telecom consultancy, which is why this article is careful about what an operator can and cannot see — and why we would rather tell you that Utiq's documentation is silent on private browsing than guess. If you need someone to read a vendor's actual documentation before you sign, that is the work. Support: (888) 989-4872 · support@adampulse.us