Learn how to assess legal basis, consent, cookieless options, data minimisation, EU hosting and vendor contracts before choosing analytics.
It means designing website analytics around a defined purpose, an appropriate legal basis, transparent information and limited data collection. You must also protect the data, set retention periods, support visitor rights and document your decisions. Compliance depends on the complete setup, not solely on the analytics tool you choose.
The appropriate legal basis depends on what data you collect, why you need it and how the technology works. Consent is often required for non-essential tracking, while other narrowly defined processing may rely on a different basis. Document the assessment and seek qualified legal advice for your specific implementation.
Consent may be required when analytics stores information on, or accesses information from, a visitor’s device, or when personal data processing cannot rely on another suitable legal basis. Consent must be informed, specific and freely given, with a genuine option to refuse. Tracking that requires consent should remain inactive until consent is recorded.
No. Cookieless analytics avoids conventional analytics cookies, but it may still process IP addresses, device details, unique identifiers or other personal data. Some implementations may also access device information without using cookies. Assess the actual data flows, purpose, legal basis and retention period rather than relying on the cookieless label.
Collect only the information necessary for clearly defined measurement goals. Avoid full IP addresses, persistent identifiers and sensitive form content when aggregated metrics are sufficient. Mask inputs in Session Replays, restrict access and set short, justified retention periods. Delete or anonymise data when it is no longer needed.
No. EU hosting can reduce exposure to international data transfers, and a data processing agreement defines responsibilities between you and a processor. You must still review subprocessors, access locations, security controls, retention, deletion procedures and any transfer mechanisms. Your organisation remains responsible for choosing and configuring the setup.
Start with your measurement purpose and the minimum data required. Then check consent controls, cookieless analytics options, IP handling, masking, retention, visitor request workflows, EU hosting, subprocessors and data export or deletion. Review the vendor agreement and technical documentation, test the configuration, and record your decisions before deployment.