Analytics and Tracking

GDPR

Also called General Data Protection Regulation

The European Union's data protection law, which follows the person rather than the company and governs every use of personal data.

Quick facts: GDPR

Category
Analytics and Tracking
Also called
General Data Protection Regulation
Level
Intermediate
Affects
Consent design, analytics collection, list building, vendor contracts
Where to see it
Your consent platform, CRM data map, privacy notice, processor agreements
In this article4
  1. How GDPR works
  2. Why GDPR matters
  3. Where GDPR goes wrong
  4. How to act on it

How GDPR works

The law governs personal data: anything that identifies a living person on its own or in combination with something else. In marketing that net is wider than most people expect, taking in email addresses and phone numbers but also IP addresses, advertising cookie identifiers and the pseudonymous IDs inside your analytics. It applies to you if you offer goods or services to people in the European Union or monitor their behaviour, whatever country your business is registered in. A consultancy in Kathmandu selling to buyers in Germany is inside its scope.

Every use of personal data needs a lawful basis. Two matter most in marketing. Consent has to be a clear affirmative act, freely given, specific, and as easy to withdraw as it was to give — silence, pre-ticked boxes and continued scrolling are none of those things. Legitimate interests is the alternative, and it is not a free pass: you have to weigh your purpose against the person’s rights and write down that you did.

Why GDPR matters

Fines are the headline, but they are rarely what bites first. The everyday consequences are duller and more expensive. Rights requests arrive and have to be answered inside a fixed window, which is painful if you cannot say where a person’s data actually lives. Advertising platforms increasingly demand documented consent signals before they will run their audience features in Europe. And a mailing list built without provable permission has to be rebuilt from scratch, which is a marketing cost, not a legal one.

Where GDPR goes wrong

The biggest error is treating it as a cookie banner. The banner is the visible part; the substance is knowing what personal data you hold, why you hold it, who else touches it and when it gets deleted. A perfect banner on top of an unmapped CRM fixes very little.

Two others come up constantly. Buying a list and mailing it, on the theory that the seller obtained consent — that consent almost never names you, so it does not transfer. And a privacy notice copied from another site, describing analytics and advertising tools the business does not use while omitting the ones it does. I have seen both directions, and an inaccurate notice is worse than a short one because it is actively misleading.

How to act on it

Start with an inventory rather than a banner. List every place personal data enters — forms, chat, phone, checkout, ad platforms — then record why you hold each item, where it is stored, who processes it for you and how long it stays. Most of what follows falls out of that list.

Then make consent real where you rely on it, keep a record of it, set retention periods that someone actually enforces, and rewrite your notice to describe your real stack. If your tags fire before anyone has chosen, that is the first technical job, and a tracking audit will show you exactly what is loading and when.

Do and do not

Do

  • Map where personal data enters and where it rests
  • Record the lawful basis for each marketing use
  • Make your privacy notice describe the tools you actually run

Do not

  • Treat a cookie banner as the whole obligation
  • Buy a list and assume the seller's consent transfers
  • Bundle marketing consent into a form's submit action

Questions people ask about this

Does GDPR apply to a business outside Europe?

It can. The test is where the person is, not where the company is registered. If you deliberately offer goods or services to people in the European Union, or you monitor their behaviour with analytics and advertising tools, the law reaches you. A local business whose customers are all in one country outside Europe is usually outside it, but a site selling internationally rarely is.

Is a cookie banner enough to be compliant?

No. A banner deals with storing and reading things on someone's device. GDPR also asks what personal data you hold, on what lawful basis, who you share it with, how long you keep it, how someone gets a copy or a deletion, and whether your notice describes all of that truthfully. The banner is the smallest part of the work.

Can I email someone who filled in a contact form?

You can reply to their enquiry, because that is what they asked for. Adding them to a marketing list is a separate purpose and needs its own basis, usually a distinct tick box that is not pre-ticked and not bundled with sending the form. Keep the two decisions apart in your form and in your records, and honour opt-outs immediately.

Related terms

Found this useful?

Share it, or ask an AI to summarise it

Back to the glossary

Knowing the term is the easy part

Applying it to your own site and budget is the work. Book a call and I will tell you what actually applies to you.