Privacy & Consent

GDPR

General Data Protection Regulation

In short

The GDPR is the EU regulation protecting personal data. It defines when websites may process data such as IP addresses, cookie IDs or click IDs.

Also known as: General Data Protection Regulation, DSGVO

The GDPR (General Data Protection Regulation) is the EU regulation that has governed how personal data may be processed since May 2018. For advertisers, it is the legal framework behind every conversion tracking setup on a website.

How does the GDPR apply to tracking?

The GDPR requires a legal basis for every processing of personal data, such as consent or legitimate interest. Personal data is not just names and email addresses. IP addresses, cookie IDs and click IDs like the gclid are often treated as personal data too. In practice, advertising tracking is almost always based on consent.

In addition, the ePrivacy rules (in Germany the TDDDG, formerly TTDSG) govern when information may be stored on or read from a device. That is why most sites running ads need a cookie banner before any tracking pixel such as the Meta Pixel loads.

Core principles include data minimisation, purpose limitation, transparency and accountability. Accountability means you need to be able to prove that consent was given.

What does the GDPR mean for advertisers?

  • Consent before marketing tracking: ad pixels should only load after the visitor agrees.
  • Proof: consent decisions need to be recorded.
  • Signal loss: visitors who decline are missing or only partially visible in platform data. Google Consent Mode v2 lets Google model part of that gap.
  • Minimisation: user data like email addresses is pseudonymised through hashing before it is sent. Hashed data is still not automatically anonymous.

Example

A shop pastes the Meta Pixel straight into its page template, so it fires on every page view, before any consent. Under the common interpretation of the rules, that is a problem. The cleaner setup: the pixel only loads after the visitor accepts the "Marketing" category, and the consent decision is stored with a timestamp.

This entry is a general explanation, not legal advice. Talk to a privacy professional about your specific situation.

GDPR with LeadSignal

LeadSignal ships with a built-in cookie banner with consent categories (Necessary, Preferences, Statistics, Marketing, Unclassified). Consent records are stored with a timestamp and consent ID, so you have proof for audits. Without marketing consent, no ad pixels load and no persistent identity is created. Visits before consent are counted with a daily-rotating salted hash, with nothing stored on the device, and IP addresses are anonymised.

For the full setup, read our guide to GDPR-compliant tracking.

Frequently asked questions

Is conversion tracking without consent GDPR-compliant?+

Usually not, as soon as personal data is processed for advertising or information is stored on or read from the device. In those cases you typically need consent. Check your specific setup with a privacy professional.

Does the GDPR apply to websites outside the EU?+

Yes, if the site targets people in the EU or monitors their behaviour, for example through tracking. Where the company is based is not the deciding factor.

Is an IP address personal data under the GDPR?+

In many cases, yes. EU courts and regulators generally treat IP addresses as personal data, which is why many tools anonymise them.

Guides on this topic

Articles on this topic

Related terms