Czym jest GDPR?
The EU's General Data Protection Regulation, governing how personal data is collected and processed, with fines up to 4 percent of global revenue.
The GDPR (General Data Protection Regulation) is the EU's data protection law, in force since 2018. It governs any processing of personal data belonging to people in the EU, regardless of where the company sits, and its definition of personal data is broad: anything relating to an identifiable person, including online identifiers like cookie IDs and, in most analytics contexts, IP addresses. Maximum fines reach 20 million euros or 4 percent of global annual revenue.
The core obligations: every processing activity needs a lawful basis (consent and legitimate interest are the two that matter for analytics), collection must be limited to what is needed, retention must be bounded, users hold rights of access and erasure, and vendors processing data on your behalf need data processing agreements. For analytics specifically, the pivotal question is whether you process personal data at all. Tools that store persistent visitor IDs do, and typically need a consent banner; tools designed not to store personal data avoid the consent requirement, though a privacy policy is still required either way.
The related ePrivacy rules add the device-storage consent rule that cookieless analytics is built around. The GDPR-compliant analytics guide walks through the analytics-specific details; none of this is legal advice.
Powiązane pojęcia
Zobacz te metryki na własnej stronie
Analyse śledzi każdą metrykę z tego słownika bez cookies i banera zgody. Analityka, lejki i silnik SEO w jednej karcie. Za darmo przez 14 dni.
Rozpocznij bezpłatny okres próbny