GDPR
General Data Protection Regulation
In short
The GDPR (General Data Protection Regulation) is the EU law protecting personal data. Since May 2018 it applies to anyone processing data of people in the EU.
The GDPR (General Data Protection Regulation) is the European Union regulation that governs how personal data may be processed. It has applied directly in all EU member states since May 25, 2018, and affects every company that processes data of people in the EU – including US companies running ads to European audiences.
Core principles
Among other things, the GDPR requires:
- Legal basis: Every processing activity needs a basis under Article 6, e.g. consent, performance of a contract or legitimate interest.
- Purpose limitation and data minimization: Only as much data as necessary, only for defined purposes.
- Transparency: People must be informed clearly, for example in a privacy policy.
- Data subject rights: Access, rectification, erasure, objection.
- Data processing agreements: Service providers that process data on your behalf need a data processing agreement (DPA).
What it means for performance marketing
In marketing, the GDPR mainly affects three areas:
- Website tracking: Marketing cookies usually require consent, which you collect through consent management. The ePrivacy rules add further requirements for accessing users' devices.
- Sharing data with ad platforms: Sending customer data like email addresses to Meta or Google via the Conversion API is processing that needs a legal basis. Hashing pseudonymizes the data but doesn't make it anonymous.
- International transfers: Many ad platforms are based in the US. Transfers need appropriate safeguards, for example the EU-US Data Privacy Framework.
GDPR in lead generation
Leads are personal data by definition: name, email, phone number. If you collect leads, document exactly what the data is used for, which tools process it and on what legal basis data is sent to ad platforms.
LeadMetrics provides a DPA and hashes customer data with SHA-256 before it goes to ad platforms via the Conversion API. How to assess this data sharing legally is best clarified with your data protection officer.
Common mistakes
- Treating hashed data as anonymous: It's still personal data.
- No DPA with your tools: Every tool that processes lead data on your behalf needs an agreement.
- Outdated privacy policy: New tracking tools get added but never documented.
Note: This article is not legal advice.
Ready for better tracking?
Frequently asked questions
Related terms
All termsConsent Management
Consent management means collecting, storing and managing your website visitors' consent, for example for analytics and marketing cookies.
Hashing
Hashing turns data like email addresses into a fixed string using a one-way function (e.g. SHA-256), so the original can't be calculated back from it.
First-Party Cookies
First-party cookies are set by the domain you are currently visiting. They store things like logins, shopping carts or tracking IDs for that same website.
Server-Side Tracking
Server-side tracking sends tracking data to ad and analytics platforms from a server instead of the browser – more robust and under your control.
App Tracking Transparency
App Tracking Transparency (ATT) is Apple's rule since iOS 14.5: apps must ask users before tracking them across other companies' apps and websites.