GDPR web analytics without cookies
GDPR and ePrivacy questions often start with cookies. Cookieless analytics like PureMetrix changes the analytics part of that question—not the rest of the tools on your website.
Cookies are not the whole GDPR
The GDPR is about processing personal data. ePrivacy rules are about accessing or storing information on the visitor’s device. Cookieless analytics removes the device-storage issue for analytics. You still need a legal basis for any personal data you process.
How PureMetrix works
No PureMetrix visitor cookie or localStorage ID. Visitors are counted with a hash that uses a daily changing salt. Hosted in the EU on Hetzner. DPA available.
What your lawyer should still check
- Marketing pixels and ad tags
- Chat and CRM widgets
- Heatmaps and session recordings
- Your own forms that collect email addresses
Steps in WordPress
- Install PureMetrix and exclude staff roles.
- List all other trackers still on your site.
- Update the analytics section of your privacy policy.
- Sign the DPA if required: DPA guide.
Note for Germany
See analytics under the TDDDG (formerly TTDSG) and EU-hosted analytics.
Disclaimer
This article explains the product; it is not legal advice. Whether you need a banner and which legal basis applies for your website is for your lawyer to decide.
Records of processing
Add a short analytics entry to your record of processing activities: purpose, data categories, retention period and processor. Update it when you switch on the proxy or add WooCommerce purchase events, so audits match reality.
Cookies are not the whole GDPR story
Without visitor cookies, analytics raises far fewer ePrivacy questions about device access. But the GDPR still asks about personal data, purposes and processors. Daily salted hashes and no visitor cookies are design choices—combine them with a clear privacy policy and a DPA, because you are the controller and PureMetrix is your processor.
Don’t use “GDPR compliant” as a slogan. Describe what you actually do: cookieless measurement, EU hosting on Hetzner, excluded staff roles, and which other providers still set cookies.
Cookie banner strategy
If analytics no longer needs consent, limit the banner to the providers that still do. Labelling ad cookies as “essential” brings back exactly the legal risk you wanted to leave behind with GA4.
Controller and processor
You (the website owner) are usually the controller for analytics; PureMetrix acts as your processor under a DPA when it processes personal data for you. Use these terms in your privacy policy. “We use a cookieless analytics service hosted in the EU on Hetzner” is clearer than vague claims like “privacy compliant”.
Name the purpose: measuring visitors and checking conversions—not personalising ads—unless you also run separate ad tools.
When a DPIA may be needed
Large-scale monitoring or sensitive data (e.g. health) may require a data protection impact assessment (DPIA). Counting pageviews alone is usually lower risk, but your lawyer decides. Keep the provider documents ready instead of improvising when asked.
Children’s websites and sensitive topics
Websites for children or about sensitive health topics need legal advice that goes beyond a typical company website. Cookieless defaults help, but they don’t settle the question. Hold back on marketing claims until the legal review is done.
Updating your records of processing
When you switch to PureMetrix, update your record of processing activities: purpose, data categories, processor, transfers, retention. Remove Google Analytics entries that no longer apply. Cookieless measurement alone won’t help if your paperwork is out of date.
Review it once a year, for example when you check your DPAs.
Legitimate interest
Some website owners rely on legitimate interest for analytics; others ask for consent. Cookieless design makes legitimate interest easier to argue for some lawyers—not all. PureMetrix provides the facts; your lawyer draws the conclusion. Keep the written assessment next to the DPA.
Don’t mix up DPAs from US ad networks with your analytics documents; keep the PureMetrix paperwork separate.
Requests from visitors about their data
Because the salt changes daily, you can’t retrieve one person’s history over a longer period—explain this in your process for data access requests. PureMetrix does not build profiles of people; agree with your lawyer how to answer before a request arrives.
If you still use session recording tools such as Hotjar, they still need consent—even if PureMetrix alone would not require a cookie banner for analytics.
Related reading
More guides HTML snippet WordPress Shopify Next.js
Last updated: September 2026