https://european-alternatives.eu/category/web-analytics-serv...
That isn't actually true (or at least is only allowed in the "it's a small enough violation of the law that the enforcers have bigger fish to fry" sense).
Cookie banners are required to gather informed consent, which is relevant for two EU legislations: the ePD, which requires it to access or store _any_ data from terminal equipment, and the GDPR which requires it for personally identifiable data. Most people only consider the latter, but the former is a much bigger hurdle to pass.
Despite Plausible's claim of not requiring cookie banners, their processing still accesses data from the terminal equipment. That was made very explicitly clear in a 2023 guideline from the EDPB[1].
The one saving grace for Plausible is that the ePD is a Directive, so the actual implementation into law differs by Member country. The claim might be true for some EU countries, but certainly isn't for all.
I've written a longer analysis of this in the context of Plausible for anyone interested[2] (although it might be worth skipping the first section, to get to the meat of the issue).
[1] https://www.edpb.europa.eu/our-work-tools/our-documents/guid... [2] https://jfagerberg.me/blog/2022-06-09-analytics-cookie-compl...
Since Plausible is selling a product that clearly claims this, who is on the hook in case a user of Plausible gets a fine?
But GDPR enforcement is more like 'you need to fix this, if you don't you get the fine' - if you are actually helpful and do your duty to improve the process the fine is usually reduced.
As someone living in Europe who watches the EUs best and brightest mostly go to work in consulting firms because the only growth industry in the EU is “companies spending money on regulatory compliance,” it pains my soul.
The funniest part about GDPR is that currently any organization that uses pretty much any US tech is in violation of the latest rulings, including much of the EU government itself running on Microsoft tech.
If you've just been consuming journalist or internet comment narratives on this topic you have no idea.
But please also share the more nuanced take on the GDPR of your lawyer. You can't go around making claims like that without substantiating them ;).
With GA, google uses cookies, fingerprinting and all other possible options to track correct attribution from various channels.
So even with ad blockers you can get a pretty accurate picture. It is also tightly integrated with google ads.
Plausible can tell you what users do inside your app. But honestly this is so basic you can pretty much build same functionality with a few sql queries.
if you're tracking users for analytics using cookies, fingerprinting, or any other method that identifies them (even probabilistically), you generally need explicit consent under GDPR and similar privacy laws. The key point is that it's not just about cookies; any persistent tracking requires consent.
The law mandates that you inform the user if you are setting any type of cookies. So its necessary to have a banner even if you don't need to get consent. You could inform the user in other ways, but cookie banners are easier.
0
The end result is that you get mixed messages, depending on where the information ultimately came from.
I personally don't know how hard it actually is to comply with GDPR, but I know that it has to be easier than it's made out to be.
This decreases the attack surface for loopholes. What is desirable is the end result, not the technical details.
The law is actually clearer because the intent is clearly spelt out. The point of the law is to protect privacy, not cover every screen with cookies banners.
This leaves room for different implementations and flexibility (yay, competition).
It makes the law more resilient, because it does not need to be re-engineered every time anything happens. 10 years from now, even if cookies and banners have completely vanished, the core of the law will still be relevant.
This is why debates about the spirit and the letter of laws translate poorly across the Atlantic. Different places have different approaches.
These are trying times.
Article 6
Lawfulness of processing
1. Processing shall be lawful only if and to the extent that at least one of the following applies:
(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
Point (a) covers purposes that require cookie-banner. Point (b) covers login or shopping cart cookies, as these are necessary for the performance of a contract to which the data subject is party.Member States shall ensure that the use of electronic communications networks to store information or to gain access to information stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.
https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX...