Analytics tools that store data in the EU, whose vendors say no consent banner is needed

Entry price is the lowest monthly price the vendor lists; “Free” means a free plan or free self-hosting. “At 100k” is the monthly price for 100,000 units, as the vendor bills them. Dates under statuses, prices and script sizes show when we checked them. See how we check every value.

What this list actually shows

Two conditions put a tool on this page: the vendor states that a consent banner is not needed, and its hosted service stores data in the EU or lets you choose an EU region.

The first is a statement, and the page records it as one: the vendor’s own words, shown on each card as the vendor’s position rather than as our reading of the law. The second is closer to a fact you can look up, since vendors document where their servers are.

The list does not say that a tool meets the requirements of the GDPR, or that your site will: that depends on what you collect, how you configure the tool, what else your pages load and the rules in your country. This directory does not give legal advice.

The other two conditions used on the privacy-friendly page are not applied here. One tool on this page keeps a lasting identifier in the visitor’s browser, and for a few the vendor makes no plain statement about personal data.

Where the data is stored and who processes it

Storage location and company location are different things: a card shows where a company is based, which is an address, not a description of where processing happens. A vendor based outside the EU can store data in the EU, and a vendor based in the EU can rely on services that are not.

Subprocessors are the gap here. A hosted service usually runs on somebody else’s infrastructure and sends email, watches for errors and answers support through other services. None of that is in our data; the vendor’s privacy page and its subprocessor list are where you find it.

Ten of the tools here can also be installed on your own server: the location is then wherever you install them, and access, security and deletion become your work. Where a vendor offers a choice of region, check when that choice is made.

No. The EU rules on storing or reading information on a device are written around the act, not the technique: the European Data Protection Board’s guidelines on the technical scope of Article 5(3) of the ePrivacy Directive state that the article does not apply exclusively to cookies, but also to similar technologies. Data protection law applies separately to personal data, and an IP address can be personal data.

Three things beyond the tool shape the answer: what else the pages load, such as advertising tags; how the tool is configured, from identifying signed-in users to sending personal data in event properties; and the national rules that apply. The cookieless page goes through the mechanics.

How to choose

  1. Storage location first, because moving it later means starting the history again. A tool you run yourself keeps data wherever you install it.
  2. Read the vendor’s statement in full rather than the summary on a feature page, and look for the setup it assumes: a default configuration, a plan level, a feature switched off.
  3. Check the contract, not the marketing page: a data processing agreement you can sign, a named list of subprocessors and a way of being told when it changes. The directory does not record these.
  4. Check retention: the Data retention row on a card shows the period on the cheapest paid plan.
  5. Compare the price at your traffic last, in the unit each vendor bills; the methodology covers the columns.

Questions and answers

The answer has moved over time, and this directory does not give legal advice. In June 2022 the Italian data protection authority reprimanded a website operator over its use of Google Analytics, finding that visitor data went to the United States without adequate safeguards. In July 2023 the European Commission adopted an adequacy decision for the EU-U.S. Data Privacy Framework, under which personal data can flow to US companies certified under it; the Commission reviews the framework periodically. What that means for one site is a question for a lawyer who can see the setup.

What is a data processing agreement?

It is the contract between you, the party that decides why visitor data is collected, and the vendor, which processes it on your instructions. The GDPR requires it in writing, including in electronic form. Guidance from the European Data Protection Board sets out what it has to settle: the subject matter, duration, nature and purpose of the processing, the type of personal data and the people concerned, confidentiality, security, the use of other processors and what happens to the data at the end. Most vendors publish a standard version.

Is storing data in the EU enough?

Not on its own. Location answers one question out of several: who can reach the data, under which law, with which subprocessors and for how long. A service storing data in the EU can still pass something abroad through a support tool.

How is this page different from the list of tools without cookies?

The cookieless page is about one measured property: what the tracking script stores in the browser by default. This page is about two documented ones: the consent-banner statement and where the hosted service keeps the data. The lists overlap heavily, since most tools here set no cookies.

Guides on this topic

Other collections