Compliance
Analytics compliance, explained honestly
For each law: our position, the reasoning behind it, what stays your responsibility, and template text for your privacy policy. Where the law is unsettled, we say so.
GDPR
How Privatus Analytics approaches the GDPR as cookieless analytics: controller and processor roles, lawful basis, data minimization, transfers and your duties.
UK GDPR
How Privatus Analytics approaches the UK GDPR and the Data Protection Act 2018, including transfers from the UK and what stays your responsibility.
ePrivacy and PECR
Our reading of ePrivacy Article 5(3) and PECR Regulation 6 for cookieless analytics, including EDPB Guidelines 2/2023 and what they mean for cookie banners.
CCPA/CPRA and US state laws
How Privatus Analytics fits the CCPA/CPRA and the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other states.
LGPD
How Privatus Analytics approaches Brazil's General Data Protection Law (LGPD) for cookieless web analytics, from data minimization to your responsibilities.
PIPEDA
How Privatus Analytics approaches Canada's PIPEDA and provincial privacy laws for cookieless web analytics, from data minimization to your responsibilities.
Swiss FADP
How Privatus Analytics approaches Switzerland's revised Federal Act on Data Protection (FADP) for cookieless web analytics, including transfers to the US.
How the privacy model works
Every field we store, and why.
Where your data lives
US storage and processing, transfer safeguards.
Data Processing Agreement
Article 28 terms with SCCs, included in our terms.
This is general information about how Privatus Analytics works and how we read the law. It is not legal advice. Laws and regulators' guidance change, and your obligations depend on your whole setup, so check your position with your own counsel.