GDPR compliant analytics without cookies

GDPR compliance belongs to the way a site processes data, and no analytics tool can supply it on its own. What a tool can do is collect so little that compliance is straightforward to demonstrate. Clientlog is built on that principle: in a default installation it processes no data that identifies a person.

This page sets out what that means in practice, for the developer installing it and for the person who will be asked to justify the decision.

What Clientlog records

Each event carries an action name you choose, a short JSON payload you control, a session identifier, the site and project, and a timestamp assigned on receipt.

Enrichment adds three groups of fields:

  • Browser and device, from the User-Agent header: browser family and version, operating system, device type, and whether the agent is a known bot.
  • Coarse location, from the IP address: country, region, city, timezone and network operator.
  • Query parameters, parsed from the page URL, so campaign tags are available to reporting.

The full field list is in events.

What Clientlog never records

  • Cookies of any kind.
  • Browser fingerprints: no canvas, font, audio or hardware probing.
  • Identifiers that work across sites or across visits.
  • Form field contents or keystrokes.
  • Mouse paths, screen recordings or DOM snapshots.
  • IP addresses on the event record. The address is used to look up a coarse location and is not written to your data.

The session identifier

The identifier looks like 1782693098872-7xzwuxbzd: a timestamp and a random suffix, generated in the browser and held in sessionStorage.

  • It lasts for one tab and one visit. Closing the tab ends it.
  • A return visit produces a new identifier with no link to the old one.
  • It is derived from nothing about the device or the person.
  • It is scoped to one site and one project.

Two sessions from the same person are indistinguishable from two sessions from two different people. That is the property that keeps a default installation outside the scope of personal data.

UK GDPR roles

Where personal data is processed, the site owner is the controller and Bay Information Systems is the processor, acting on the instructions expressed in the project configuration and rules. A data processing agreement is available on request.

In a default installation, the position is that no personal data is processed at all. Two configuration choices change that, and both are under the site owner’s control:

  • Replacing the session identifier. The sessionIdFn option can supply an authenticated user identifier. That creates identity linkage, and with it a lawful basis, a privacy notice and access and erasure handling to provide.
  • Putting personal data in payloads. The documentation recommends against it, and the payload is capped at 512 characters to discourage it.

GDPR governs personal data. The consent question for analytics comes from a different law: regulation 6 of PECR, which covers storing or reading anything on a visitor’s device. sessionStorage counts, in the same way a cookie does.

Since 5 February 2026, PECR includes an exception from consent for storage used only for statistical purposes, with conditions: clear information about the purpose, a simple and free means of objecting, and no sharing beyond those assisting with improvements to the service. The privacy page sets out how a default Clientlog installation relates to that exception, and the cookie banner guide covers the same ground for Google Analytics.

This is a description of how the product works and how we read the regulations, not legal advice.

Retention

Data Retention
Raw events 30 days
Enriched events 13 months
Session summaries and tags 13 months
Aggregates and digests Life of the account

Aggregates hold counts and distributions, not individual sessions. On account closure, project data is deleted within 30 days.

Where the data is

Amazon Web Services, London region (eu-west-2). AWS is the only subprocessor, and additions are notified to account holders before they take effect. Data stays in the United Kingdom, so no international transfer mechanism is involved.

Data sent to advertising platforms

None, unless you configure it. A conversion relay can send a conversion to Meta or Google Ads when a session matches a rule you choose. It is off by default and enabled per project. When it is on, the click identifier placed in the URL by the advertising platform is sent back to that platform, which is a decision with its own consent position.

What you still provide

  • A privacy notice entry saying the site measures visits with Clientlog, what is recorded, and why.
  • A way for visitors to object to measurement.
  • A decision about sessionIdFn and payload contents, recorded alongside the rest of your processing records.

Next