The GDPR (General Data Protection Regulation) is the EU regulation that has governed how personal data may be processed since May 2018. For advertisers, it is the legal framework behind every conversion tracking setup on a website.
How does the GDPR apply to tracking?
The GDPR requires a legal basis for every processing of personal data, such as consent or legitimate interest. Personal data is not just names and email addresses. IP addresses, cookie IDs and click IDs like the gclid are often treated as personal data too. In practice, advertising tracking is almost always based on consent.
In addition, the ePrivacy rules (in Germany the TDDDG, formerly TTDSG) govern when information may be stored on or read from a device. That is why most sites running ads need a cookie banner before any tracking pixel such as the Meta Pixel loads.
Core principles include data minimisation, purpose limitation, transparency and accountability. Accountability means you need to be able to prove that consent was given.
What does the GDPR mean for advertisers?
- Consent before marketing tracking: ad pixels should only load after the visitor agrees.
- Proof: consent decisions need to be recorded.
- Signal loss: visitors who decline are missing or only partially visible in platform data. Google Consent Mode v2 lets Google model part of that gap.
- Minimisation: user data like email addresses is pseudonymised through hashing before it is sent. Hashed data is still not automatically anonymous.
Example
A shop pastes the Meta Pixel straight into its page template, so it fires on every page view, before any consent. Under the common interpretation of the rules, that is a problem. The cleaner setup: the pixel only loads after the visitor accepts the "Marketing" category, and the consent decision is stored with a timestamp.
GDPR with LeadSignal
LeadSignal ships with a built-in cookie banner with consent categories (Necessary, Preferences, Statistics, Marketing, Unclassified). Consent records are stored with a timestamp and consent ID, so you have proof for audits. Without marketing consent, no ad pixels load and no persistent identity is created. Visits before consent are counted with a daily-rotating salted hash, with nothing stored on the device, and IP addresses are anonymised.
For the full setup, read our guide to GDPR-compliant tracking.