EU (ePrivacy Directive) and UK (PECR)
ePrivacy and PECR
The Privatus Analytics tracker stores nothing on the visitor's device and reads nothing beyond what every web request carries. We believe this puts measurement with Privatus Analytics outside the consent requirement for most sites, but this is the least settled area of the law, and we don't claim a guarantee.
Our reasoning
What the tracker does on the device
No cookies, localStorage, sessionStorage or IndexedDB, and no fingerprinting APIs (canvas, WebGL, fonts, audio). The only exception is an opt-out flag that a visitor sets themselves.
EDPB Guidelines 2/2023
The European Data Protection Board reads Article 5(3) broadly, to include information a browser sends as part of a request when a script instructs it to. On that reading, sending a pageview beacon could be "access" that needs consent unless an exemption applies.
Audience-measurement exemptions
Several regulators, including France's CNIL, exempt audience measurement from consent under strict conditions. We map our design to those conditions: the purpose is limited to audience measurement, there's no cross-site tracking, data is aggregated for reporting, retention is limited and visitors can opt out.
Where the law is uncertain
National implementations of the ePrivacy Directive differ, and regulators and courts may take a stricter view than ours. Each site owner must assess their own position.
Template privacy-policy paragraph
Adapt it to your setup and have it reviewed. For a version matched to your settings, use the generator.
This is general information about how Privatus Analytics works and how we read the law. It is not legal advice. Laws and regulators' guidance change, and your obligations depend on your whole setup, so check your position with your own counsel.