SEO Pillar

GDPR-Compliant Analytics

TODO — Full content: The keyword map (datascale-seo-keyword-map.md) isn't in the project yet. Once it is, H2 sections along Cluster 2 (IP anonymisation, Consent Mode V2, Schrems II, server-side tracking, Firebase + GDPR, Matomo vs Plausible, audit checklist) get filled in.

The four common tools compared

CriterionGA4Plausible CEPiwik PROMatomo
CookiesYes (first-party)NoneOptionalOptional
Consent bannerRequiredNot requiredConfigurableConfigurable
HostingUS (Google)Self-hosted EUEU (Poland)Self / EU Cloud
IP anonymisationDefaultNo IP storedConfigurableConfigurable
Marketing integrationsStrong (Ads)MinimalSolidSolid
Licence cost€0€0 (self-host)From €270/mo€0 / €19/mo Cloud
Best fitAds-heavy marketingContent sites, agenciesEnterprise, regulatedFlexible setups

Frequently asked

  • What does "GDPR-compliant analytics" mean?
    GDPR-compliant analytics means collecting visitor data only on a valid legal basis, processing it on EU infrastructure, and — where cookies or personal data are involved — obtaining informed consent before tracking begins.
  • Is Google Analytics 4 GDPR-compliant?
    Conditionally yes: with a DPA with Google Ireland, IP anonymisation enabled, Consent Mode V2 correctly configured, a clean CMP integration and limited data retention. Defaults are not compliant out of the box.
  • Does Plausible CE require a cookie banner?
    No. Plausible Community Edition sets no cookies, stores no IP addresses, and processes no personal data. A consent banner is not required.
  • What's the difference between Plausible and Matomo?
    Both are privacy-friendly alternatives to GA4. Plausible is cookie-free by default and minimal. Matomo is more powerful but can set cookies — depending on configuration a consent banner may still be needed. For marketing sites without deep attribution, Plausible is usually the better choice.
  • When does Piwik PRO make sense?
    Piwik PRO is the enterprise variant from Poland with EU servers and integrated CMP. It fits regulated industries (banking, healthcare) or organisations with strict EU-cloud requirements.
  • What is Consent Mode V2?
    Consent Mode V2 is Google's API for controlling tag behaviour based on consent state. Correctly implemented it sends aggregated signals even when consent is declined, powering conversion modeling. It complements a full GDPR-compliant CMP — it does not replace one.