Glossary · Privacy & compliance
What is GDPR, and what does it mean for analytics?
GDPR, the General Data Protection Regulation (Regulation (EU) 2016/679), is the European Union law that governs how personal data about people in the EU is collected, used and stored, in force since May 25, 2018.
Also called: General Data Protection Regulation, Regulation (EU) 2016/679
Updated
Does GDPR apply to website analytics?
Usually yes. GDPR covers any information relating to an identifiable person, and the EU Court of Justice has held that IP addresses can be personal data (Breyer, 2016). Cookie ids, device ids and hashed identifiers are typically personal data too. GDPR applies to organizations established in the EU and to those outside it that offer services to or monitor people in the EU.
What GDPR requires of analytics
- A lawful basis (Article 6). For analytics, usually consent or legitimate interests. Where the ePrivacy Directive requires consent for cookies, consent is effectively the basis for that tracking.
- Transparency — a privacy policy naming the tool, what's collected and why.
- Data minimization — collect what you need, not everything you can.
- A data processing agreement (Article 28) with your analytics vendor.
- Lawful international transfers. Moving EU data to the US relies on the EU–US Data Privacy Framework (adopted July 2023) or standard contractual clauses; before it, several EU regulators found specific Google Analytics setups unlawful after the Schrems II ruling.
- Data subject rights — access and deletion requests.
GDPR fines
Maximum fine = the higher of €20 million or 4% of worldwide annual turnover
That's the ceiling for the most serious infringements; a lower tier (€10 million or 2%) applies to others. Regulators also order processing to stop, which for analytics can be more disruptive than the fine.
GDPR example for a small SaaS
A five-person SaaS in Lisbon uses analytics with a first-party cookie and Meta's pixel. Under ePrivacy, both need consent; under GDPR, the processing needs a lawful basis, a privacy policy, a DPA with each vendor and a transfer mechanism for the US vendor. Switching to cookieless analytics removes the device-storage consent question for analytics, but the privacy policy, DPA and lawful basis remain.
GDPR and VisitTrack
VisitTrack never stores IP addresses: they're used in memory for country lookup, bot checks and, in cookieless mode, a daily-salted hash. It doesn't build cross-site profiles or share data with ad networks. Bot-detection browser signals are discarded after the verdict. Session replays are opt-in, mask every form field and are deleted after 30 days. People traits you send with identify are personal data you control, and can be deleted per person. A DPA is available at /dpa. This is general information, not legal advice.
Frequently asked questions
Is an IP address personal data under GDPR?
Yes, it can be. The EU Court of Justice held in 2016 (Breyer) that a dynamic IP address can be personal data when the site operator has legal means to identify the person, and regulators generally treat IP addresses as personal data.
Can I use legitimate interests for analytics under GDPR?
Often, for privacy-friendly analytics that doesn't require consent under ePrivacy, legitimate interests is the basis used, supported by a balancing test. Where cookies or device storage need ePrivacy consent, rely on that consent.
Related terms
- ePrivacy DirectiveThe ePrivacy Directive (Directive 2002/58/EC, amended in 2009) is the EU law on privacy in electronic communications whose Article 5(3) requires consent before storing information on, or reading it from, a user's device — which is why it's called the "cookie law."
- Consent bannerA consent banner, or cookie banner, is the notice a website shows to ask visitors for permission before storing or reading non-essential cookies and similar identifiers on their device, and to record their choice.
- Cookieless trackingCookieless tracking is web analytics that counts visitors without storing any identifier on the visitor's device — no cookies, localStorage or similar — typically by deriving a short-lived anonymous id on the server instead.
- IP anonymizationIP anonymization is the practice of removing, truncating or otherwise obscuring a visitor's IP address in an analytics or logging system so the stored data can't be traced back to a specific connection.
- PECRPECR, the Privacy and Electronic Communications Regulations 2003, is the UK law that implements the ePrivacy Directive's rules on cookies and similar technologies, electronic marketing and communications security, enforced by the Information Commissioner's Office (ICO).
- CCPAThe CCPA, the California Consumer Privacy Act — as amended by the California Privacy Rights Act (CPRA) — is California's consumer privacy law, giving California residents rights over their personal information and requiring covered businesses to honor opt-outs from selling or sharing it.
Tools and guides
See which channels actually bring paying customers
VisitTrack is cookie-free analytics with revenue attribution built in. One script tag, no consent banner, live in two minutes. 14 days free, no card required.