GDPR and website analytics
The GDPR governs the processing of personal data. Choosing privacy-focused analytics helps reduce what you collect, while your purpose, configuration, and responsibilities still matter.
Who is responsible for what?
When you decide why and how to measure activity on your website, you generally act as the controller. Fathom’s data processing agreement governs processing on your behalf. Fathom’s handling of its own customer account and billing information is a separate matter, described in our privacy policy.
Personal data and visitor signatures
Fathom’s collection process uses request information, including IP address and user-agent, to generate site-specific signatures. Daily salt rotation limits continuity between days; it does not delete previously stored event records. Detected bot traffic is handled separately from ordinary pageviews. See the data journey for the distinctions.
Pseudonymized information remains personal data where a person can still be identified using additional information. Whether information is anonymous requires an assessment of reasonably available means of identification. Hashing or a fixed period of time alone does not settle that question. GDPR, Recital 26 and Article 4.
Your compliance review
Establish and document a lawful basis for personal-data processing, provide appropriate privacy information, and apply data minimization and retention limits. If relying on legitimate interests, assess necessity and the effect on visitors rather than treating that basis as automatic. Controller–processor arrangements and security measures also need to reflect the processing involved. GDPR, Articles 5, 6, 13, 28 and 32.
For your Fathom setup, review:
- The DPA and subprocessors.
- Which URLs, event names, and integrations send information to analytics.
- Your privacy notice, retention needs, and handling of visitor requests.
- Any relevant international transfers.
Consent is a separate question
A GDPR lawful basis does not replace consent required under device-access rules. Review ePrivacy or PECR for the places where you operate.
These guides explain privacy requirements and how they relate to Fathom. They are general information, not legal advice. Your obligations depend on your website, its visitors, and how you use analytics. Contact us for information about your setup.