hello@newnorth.nl+31 (0) 85 401 31 62
/Journal

What the GDPR means for your website, and how to comply

GuidePrivacy2022.10.26
Freek Kampen
Freek KampenCo-founder, New North Digital

Why that cookie banner exists, what the GDPR asks of you once you run Analytics, and a checklist to hold your own setup against.

What the GDPR is

The GDPR is a set of European data protection rules. They give people access to the information organisations hold about them, and limit what organisations may do with it.

The moment you put an analytics tool like GA4 on your site, you store personal data about your visitors. Being based outside the EU doesn't exempt you: it depends on who your visitors are, not where you are registered.

The seven principles

The full text runs to 99 articles, but it rests on seven principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability.

That last one is the one people underestimate. You don't just have to comply, you have to be able to demonstrate that you comply.

What happens if you don't

Enforcement sits with the national supervisory authorities. One of the best known fines came from the French regulator: 50 million euro for Google, because information about data processing was spread too thin and consent for personalised advertising was not validly obtained.

In 2022 the Austrian, French and Italian authorities each ruled that using Google Analytics breached the GDPR, because personal data flowed to the United States without an adequate level of protection. In July 2023 the European Commission adopted the EU-US Data Privacy Framework, which restores a legal basis for transfers to certified US companies. That takes the sharpest edge off those rulings, but the matter isn't settled: the two frameworks that preceded it were both struck down by the Court of Justice.

Three questions to hold your setup against

  • Do your tracking tools drop cookies before consent is given?
  • Is your analytics tool run by a US company, and if so, is it certified under the Data Privacy Framework?
  • Does your analytics tool run on servers owned by a US cloud provider?

What you can actually do

None of this is legal advice. When in doubt, ask a lawyer. What follows is the practical side, and note that anonymising IP addresses alone is not enough.

  • Ask before you collect. Put up a consent banner and make sure nothing is set before someone says yes.
  • Collect only what you need. Everything you store is something you are accountable for.
  • Secure what you keep. Two current, secure copies in two separate off-site locations.
  • Be able to edit and delete data. Including being able to prove that you did.
  • Write a real privacy and cookie policy. Be explicit about what you set and why.
  • Anonymise IP addresses. Most modern tools do this by default, but verify it.
  • Share nothing without a processing agreement. If you use an analytics tool, sign one.
  • Encrypt personal data in your own database.
  • Control what goes to third parties. Server-side tracking through GTM gives you that control, instead of the browser shipping everything directly.
  • Keep data in the EU. Servers belonging to US cloud providers don't automatically satisfy this.

The takeaway

The exact cookie requirements differ per country, so they are deliberately not listed here. For that part, legal advice or a dedicated consent vendor is the right route.

The rest is work you can start today. Most of it comes down to one question: do you know exactly what data your site collects and where it goes? If you can't answer that, start there.

Want to talk about this?

Let's talk data.

Tell us about your stack, your goals, the data you wish you had.

Takes 1 minute