DPE-2026-0016

Identifier synchronisation between parties

Two parties exchange each other's identifier so their separate records of the same person can be joined.

In het NederlandsIdentificatiemerken uitwisselenWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Chain webapp status active
Not a vulnerabilityNothing is broken and nothing is exploited. The exchange is a deliberate feature that both parties built and both benefit from, which is exactly why it has no place in a vulnerability register.

What it is

One party calls the other and passes its own identifier for the visitor in the request; the other answers, sets or reads its own identifier, and returns the pairing. Usually this runs as a short chain of redirects or invisible image requests at page load. Afterwards each party can translate its own identifier into the other's.

Why it is a separate entry

Two separate records become one. Data collected in one place, under one story about what it is for, can from that moment be matched with data collected somewhere else entirely. The person cannot see this happen, and deleting a cookie at one party does not undo the mapping already stored at the other.

How it arises

Not to be confused with

Passing an identifier to one recipient for that recipient's own use is ordinary tracking. What distinguishes this entry is the exchange: the value of party A appears in a request to party B, and the purpose of that request is the pairing rather than any content.

How to establish it

A request to a host under one registrable domain whose URL, body or redirect location contains, verbatim or trivially encoded, an identifier value that another registrable domain set as a cookie or returned in the same capture. The match of the two values is the finding, and it holds equally where no cookie is set anywhere and the value only travels in the requests.

method network-with-identifierQoD 92

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itDoes any of your partners receive an identifier that another partner issued, and where is the arrangement between them?
In a DPIA, verify this

Verify whether any recipient receives an identifier belonging to another recipient, rather than assessing each recipient in isolation.

As a procurement clause

No party in the chain receives an identifier issued by another party, demonstrated by a capture in which no identifier value appears across two registrable domains.

With a complaint, hand over

A HAR with the redirect chain intact, the cookie value as set by the first party, and the request to the second party containing that same value.

Reproduction

Legal framing

Case law

Objections, and the answer

“This is purely technical plumbing between suppliers.”

Deciding to make two datasets joinable is a decision about the purpose and the means. That the mechanism is a redirect does not make it a technicality.

“The identifiers are pseudonymous.”

Pseudonymous data is personal data under the regulation, and the entire purpose of the exchange is to keep recognising the same person across contexts.

“Users can delete their cookies.”

Deleting a cookie at one party does not remove the mapping already stored at the other. The exchange survives the deletion.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0016 (Identifier synchronisation between parties)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0016
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0016/index.json
Full
DPE Catalogue. DPE-2026-0016: Identifier synchronisation between parties. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0016
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0016, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.