Privacy

GDPR

General Data Protection Regulation

In short

The GDPR (General Data Protection Regulation) is the EU law protecting personal data. Since May 2018 it applies to anyone processing data of people in the EU.

The GDPR (General Data Protection Regulation) is the European Union regulation that governs how personal data may be processed. It has applied directly in all EU member states since May 25, 2018, and affects every company that processes data of people in the EU – including US companies running ads to European audiences.

Core principles

Among other things, the GDPR requires:

  • Legal basis: Every processing activity needs a basis under Article 6, e.g. consent, performance of a contract or legitimate interest.
  • Purpose limitation and data minimization: Only as much data as necessary, only for defined purposes.
  • Transparency: People must be informed clearly, for example in a privacy policy.
  • Data subject rights: Access, rectification, erasure, objection.
  • Data processing agreements: Service providers that process data on your behalf need a data processing agreement (DPA).

What it means for performance marketing

In marketing, the GDPR mainly affects three areas:

  1. Website tracking: Marketing cookies usually require consent, which you collect through consent management. The ePrivacy rules add further requirements for accessing users' devices.
  2. Sharing data with ad platforms: Sending customer data like email addresses to Meta or Google via the Conversion API is processing that needs a legal basis. Hashing pseudonymizes the data but doesn't make it anonymous.
  3. International transfers: Many ad platforms are based in the US. Transfers need appropriate safeguards, for example the EU-US Data Privacy Framework.

GDPR in lead generation

Leads are personal data by definition: name, email, phone number. If you collect leads, document exactly what the data is used for, which tools process it and on what legal basis data is sent to ad platforms.

LeadMetrics provides a DPA and hashes customer data with SHA-256 before it goes to ad platforms via the Conversion API. How to assess this data sharing legally is best clarified with your data protection officer.

Common mistakes

  • Treating hashed data as anonymous: It's still personal data.
  • No DPA with your tools: Every tool that processes lead data on your behalf needs an agreement.
  • Outdated privacy policy: New tracking tools get added but never documented.

Note: This article is not legal advice.

Ready for better tracking?

Try LeadMetrics free for 10 days and see which campaigns actually drive revenue.
Start a 10 day trial

Frequently asked questions

Yes, if they offer goods or services to people in the EU or monitor their behavior, for example through website tracking. What matters is whose data is processed, not where the company is based.

Related terms

All terms