Glossary · Privacy & compliance

What is GDPR, and what does it mean for analytics?

GDPR, the General Data Protection Regulation (Regulation (EU) 2016/679), is the European Union law that governs how personal data about people in the EU is collected, used and stored, in force since May 25, 2018.

Also called: General Data Protection Regulation, Regulation (EU) 2016/679

Updated

Does GDPR apply to website analytics?

Usually yes. GDPR covers any information relating to an identifiable person, and the EU Court of Justice has held that IP addresses can be personal data (Breyer, 2016). Cookie ids, device ids and hashed identifiers are typically personal data too. GDPR applies to organizations established in the EU and to those outside it that offer services to or monitor people in the EU.

What GDPR requires of analytics

  • A lawful basis (Article 6). For analytics, usually consent or legitimate interests. Where the ePrivacy Directive requires consent for cookies, consent is effectively the basis for that tracking.
  • Transparency — a privacy policy naming the tool, what's collected and why.
  • Data minimization — collect what you need, not everything you can.
  • A data processing agreement (Article 28) with your analytics vendor.
  • Lawful international transfers. Moving EU data to the US relies on the EU–US Data Privacy Framework (adopted July 2023) or standard contractual clauses; before it, several EU regulators found specific Google Analytics setups unlawful after the Schrems II ruling.
  • Data subject rights — access and deletion requests.

GDPR fines

Maximum fine = the higher of €20 million or 4% of worldwide annual turnover

That's the ceiling for the most serious infringements; a lower tier (€10 million or 2%) applies to others. Regulators also order processing to stop, which for analytics can be more disruptive than the fine.

GDPR example for a small SaaS

A five-person SaaS in Lisbon uses analytics with a first-party cookie and Meta's pixel. Under ePrivacy, both need consent; under GDPR, the processing needs a lawful basis, a privacy policy, a DPA with each vendor and a transfer mechanism for the US vendor. Switching to cookieless analytics removes the device-storage consent question for analytics, but the privacy policy, DPA and lawful basis remain.

GDPR and VisitTrack

VisitTrack never stores IP addresses: they're used in memory for country lookup, bot checks and, in cookieless mode, a daily-salted hash. It doesn't build cross-site profiles or share data with ad networks. Bot-detection browser signals are discarded after the verdict. Session replays are opt-in, mask every form field and are deleted after 30 days. People traits you send with identify are personal data you control, and can be deleted per person. A DPA is available at /dpa. This is general information, not legal advice.

Frequently asked questions

Is an IP address personal data under GDPR?

Yes, it can be. The EU Court of Justice held in 2016 (Breyer) that a dynamic IP address can be personal data when the site operator has legal means to identify the person, and regulators generally treat IP addresses as personal data.

Can I use legitimate interests for analytics under GDPR?

Often, for privacy-friendly analytics that doesn't require consent under ePrivacy, legitimate interests is the basis used, supported by a balancing test. Where cookies or device storage need ePrivacy consent, rely on that consent.

Related terms

Tools and guides

See which channels actually bring paying customers

VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.