Choose GDPR compliant analytics with confidence

Set up consent mode, cookieless tracking, data residency, retention, and DPAs with a practical checklist for your website or shop.

What makes an analytics setup GDPR compliant?

A compliant setup has a documented purpose and legal basis for each data category, collects only what is needed, explains processing clearly, limits access, and deletes data on schedule. You also need contracts with processors and a consent mechanism where required. No analytics product is compliant by default; your configuration and use determine the result.

Do I need consent before analytics starts?

Consent is generally the practical choice when analytics uses non-essential cookies, persistent identifiers, or similar tracking methods. Essential processing may follow a different legal basis, but labeling analytics as essential does not make it so. Document your decision and ensure the site does not load optional tags before the required opt-in.

How should consent mode be configured?

Set the default state to denied for non-essential analytics, then update it only after an explicit opt-in. Connect the analytics tool to your consent management platform, prevent tags from firing early, and purge queued events when consent is declined. Test acceptance, rejection, withdrawal, expired consent, and pages opened in a new tab.

Is cookieless analytics automatically compliant without consent?

No. Cookieless analytics removes one tracking mechanism, but it may still process personal data through IP addresses, device details, event payloads, or fingerprint-like identifiers. Check what is collected, how sessions are created, and whether users can be recognized over time. Properly minimized cookieless analytics can reduce risk and consent dependency, but it is not an automatic exemption.

How should I assess data residency and international transfers?

Confirm where data is stored, processed, backed up, and accessed by support teams. EU or EEA hosting can simplify the assessment, but hosting location alone does not establish compliance. If data is transferred internationally, identify the transfer mechanism, subprocessors, access locations, and supplementary technical controls before approving the vendor.

What should I check in an analytics vendor’s DPA?

The DPA should define processing instructions, data types, purposes, confidentiality, security measures, deletion, incident support, audits, and subprocessor rules. Check that responsibilities match the actual product configuration. For privacy friendly analytics, also review IP handling, input masking, retention controls, access permissions, and whether personal data can enter custom Events.

How do I verify the setup before launch?

Use a fresh browser session and inspect network requests before consent, after acceptance, after rejection, and after withdrawal. Confirm that analytics tags, Heatmaps, and Session Replays remain blocked when required. Check checkout and form pages for captured inputs, review Events for personal data, verify retention settings, and record the final configuration for future audits.