Set up consent mode, cookieless tracking, data residency, retention, and DPAs with a practical checklist for your website or shop.
A compliant setup has a documented purpose and legal basis for each data category, collects only what is needed, explains processing clearly, limits access, and deletes data on schedule. You also need contracts with processors and a consent mechanism where required. No analytics product is compliant by default; your configuration and use determine the result.
Consent is generally the practical choice when analytics uses non-essential cookies, persistent identifiers, or similar tracking methods. Essential processing may follow a different legal basis, but labeling analytics as essential does not make it so. Document your decision and ensure the site does not load optional tags before the required opt-in.
Set the default state to denied for non-essential analytics, then update it only after an explicit opt-in. Connect the analytics tool to your consent management platform, prevent tags from firing early, and purge queued events when consent is declined. Test acceptance, rejection, withdrawal, expired consent, and pages opened in a new tab.
No. Cookieless analytics removes one tracking mechanism, but it may still process personal data through IP addresses, device details, event payloads, or fingerprint-like identifiers. Check what is collected, how sessions are created, and whether users can be recognized over time. Properly minimized cookieless analytics can reduce risk and consent dependency, but it is not an automatic exemption.
Confirm where data is stored, processed, backed up, and accessed by support teams. EU or EEA hosting can simplify the assessment, but hosting location alone does not establish compliance. If data is transferred internationally, identify the transfer mechanism, subprocessors, access locations, and supplementary technical controls before approving the vendor.
The DPA should define processing instructions, data types, purposes, confidentiality, security measures, deletion, incident support, audits, and subprocessor rules. Check that responsibilities match the actual product configuration. For privacy friendly analytics, also review IP handling, input masking, retention controls, access permissions, and whether personal data can enter custom Events.
Use a fresh browser session and inspect network requests before consent, after acceptance, after rejection, and after withdrawal. Confirm that analytics tags, Heatmaps, and Session Replays remain blocked when required. Check checkout and form pages for captured inputs, review Events for personal data, verify retention settings, and record the final configuration for future audits.