Advertising pixel from Criteo
Criteo OneTag and website tracking lawsuits
What Suitcast knows about Criteo OneTag
High risk
- Type
- Advertising pixel
- Complaints naming it, 12 months
- 1
Requests the scanner matches to it
- dynamic.criteo.com
- static.criteo.net
- sslwidget.criteo.com
- gum.criteo.com
- .criteo.com
- .criteo.net
The short answer
Criteo OneTag is an advertising pixel from Criteo. Suitcast rates its risk under the California Invasion of Privacy Act, CIPA, as high, because complaints describe scripts like it recording visitors before they consent. It is named in 1 verified complaints in the last 12 months. The fix is to load it only after a visitor accepts, or to remove it when it is not used.
Why complaints name it
Complaints describe it as building a shopping profile and sharing it with an ad network before consent.
The act allows $5,000 per violation, which is why firms look for scripts that run the moment a page opens.
The fix
How to stop Criteo OneTag firing before consent
Ask your developer to fire the tag only after your banner records an accept, or give it an ad_storage consent requirement in Google Tag Manager.
Remove it if your Criteo campaigns have ended.
How the scan checks this
- Loads your pages like a first visit. A real browser, nothing clicked, nothing accepted.
- Checks every request before the banner is answered. A request to dynamic.criteo.com is matched to Criteo OneTag and recorded with the millisecond it fired.
- Clicks reject and watches again. When the banner has a reject button, the scan presses it; if Criteo OneTag keeps firing, the report says so.
Scanner rules and limits are on the methodology page.
Trend
Complaints naming Criteo OneTag, month by month
Website accessibility (ADA) Website tracking (CIPA)
October 2025 to September 2026, current month to dateIndustries
Industries sued over Criteo OneTag
By the defendant's industry
Verified filings, 12 monthsCourt records
Latest verified complaints naming Criteo OneTag
- TrackingCourt recordfor Pearson v. Hims & Hers Health, Inc. (opens in a new tab)
Pearson v. Hims & Hers Health, Inc.
N.D. California, filed by Schubert Jonckheer & Kolbe. Attributed to California
Same type
Other advertising pixels the scanner checks
Questions owners ask
- Is having Criteo OneTag on my site illegal?
- No. The complaints do not claim the script is illegal; they claim it recorded a visitor before the visitor consented, or kept recording after the visitor declined. Loading Criteo OneTag only after consent, or removing it when it is not used, is what removes the pattern the complaints describe.
- How do I know if Criteo OneTag fires before consent on my site?
- Run the free scan. It loads your pages without clicking anything and checks every request that leaves the browser against its tracker catalog, recording the millisecond each match fired. If Criteo OneTag appears, it fired before consent. When your banner has a reject button, the scan clicks it and reports whether the script kept firing.
- Where do the case counts on this page come from?
- From the complaint text of verified California Invasion of Privacy Act filings. When a complaint names this script, the case is linked to it. Complaints that are not yet available in the public record are not counted, so the number is a floor.
Keep going
- Every tracking script the scanner recognizesGrouped by type, with the risk and fix for each.
- Which scripts appear most in privacy lawsuitsWhat each records and how to gate it.
- I got a CIPA demand letter. What now?What the letter means and the first week.
- Website lawsuits in CaliforniaWhere most tracking suits are filed.
Does Criteo OneTag fire before consent on your site?
Suitcast identifies risk indicators. It is not legal advice and does not determine compliance.