GDPR — Personal Data in Marketing and Analytics
What is GDPR?
GDPR — Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data — has applied since May 25, 2018. In Poland the same act is commonly called RODO, the Polish acronym; the two names refer to one regulation, not two regimes.
For marketing and analytics teams, GDPR is not a cookie law. It is a frame that says every act of processing personal data needs a purpose, a legal basis, and a time limit. Consent banners, tag configuration, and retention settings are consequences of that frame, not the frame itself.
This entry explains the concept and its technical consequences. It is not legal advice — assessing a specific setup is a job for a lawyer or a data protection officer.
Which marketing data falls under GDPR?
Personal data is any information relating to an identifiable person, directly or indirectly. In practice that covers far more than a name and an email address:
- Identifiers in cookies and browser storage —
_ga, advertising pixel identifiers, your own session ID - IP addresses — EU case law has treated them as personal data, particularly where the controller can link them to other information
- Events tied to an identifier — a path through the site, a submitted form, a viewed product
- Form submissions — a quote request, a newsletter signup, a chat conversation
- Data obtained from partners — audience lists uploaded into advertising platforms
If a record can be connected back to a person, the fact that it sits in an analytics tool rather than a customer database changes nothing.
Legal basis: consent and legitimate interest
Article 6 sets out a closed list of lawful bases. In marketing, two usually matter: the consent of the person concerned, and the legitimate interest of the controller. Choosing between them is not a matter of preference — it depends on what actually happens to the data and what the person could reasonably expect.
Storing or reading information on a user's device is a separate layer. That requirement comes from national rules implementing the ePrivacy Directive, not from GDPR itself. So the consent banner and the legal basis for processing are two distinct questions, and conflating them causes most of the confusion in this area.
The practical consequences show up directly in site code:
- Consent has to be an action — a pre-ticked box or a scroll down the page is not one
- Refusing must be as easy as agreeing — a reject control at the same level as the accept control
- Consent must be withdrawable — and withdrawal has to actually stop collection, not just hide the banner
- Scripts fire after the decision, not before it — if a pixel fires before the click, the banner is decoration
GDPR in analytics and advertising tools
The most common gap we find in audits looks like this: the privacy policy describes one state, and GTM loads another. Check in this order:
- Whether GA4 and advertising pixels fire only after the user decides
- Whether the consent signal reaches the tools (Consent Mode and its equivalents), instead of living only inside the banner
- Whether data that should never arrive is arriving anyway — an email address in a URL parameter, an order ID carrying customer details
- Whether server-side tracking bypasses the user's choice; moving collection to the server changes the technique, not the legal basis
- Who is the controller and who is the processor for each tool — and whether the corresponding agreement is signed
Transfers outside the EEA and retention periods
A large part of any marketing stack runs outside the European Economic Area. Transferring data to a third country needs its own basis: an adequacy decision, standard contractual clauses, or another mechanism from Chapter V of the regulation. The practical takeaway is unglamorous — you need to know where the data physically lands, and that comes from vendor documentation, not from assumption.
Retention works the same way. The regulation names no number of months; it requires that data not be kept longer than necessary for the purpose it was collected for. That translates into two verifiable things: the retention window configured in the analytics tool, and whether that setting matches what the privacy policy promises. A mismatch between the two is the easiest failure to detect and the one we see most often.
Example
An illustrative example: a store uploads a list of customer email addresses into an advertising platform to build a lookalike audience. The addresses were collected to fulfill orders. Shipping goods does not cover ad targeting, so a separate basis and separate notice to the customer are required. Having the address on file does not substitute for either.
Need help getting measurement and consent in order on your site? Book a free consultation — we will walk through the setup with you.
Related terms
- GA4 — the analytics tool where consent decisions surface fastest
- GTM — the tag manager, where what fires before consent is usually decided
- Server-side tracking — server-side measurement and its limits
- First-party data — data collected directly from the user
- Meta Pixel — an advertising pixel that requires consent before it loads
- Web analytics for businesses — how to organize measurement in practice