What is GDPR?
The General Data Protection Regulation is the European Union law governing the processing of personal data, in force since May 2018. It applies to any organisation handling the data of people in the EU regardless of where that organisation is. Analytics falls under it whenever it collects personal data — and much less of it applies when the analytics collects none.
This page explains how the regulation is generally understood. It is not legal advice, and your obligations depend on your jurisdiction and circumstances. Talk to a lawyer about your specific case.
What it covers
The GDPR governs the processing of personal data — anything relating to an identified or identifiable person. That definition is broader than most people expect and explicitly includes online identifiers such as IP addresses and cookie identifiers, which is why conventional analytics sits squarely inside it.
Processing requires a lawful basis. For analytics the two candidates are consent and legitimate interest, and it also brings data-subject rights (access, erasure, portability), records of processing, and a data processing agreement with each processor.
The consent question is not really the GDPR’s
The obligation to ask before storing or reading anything on a visitor’s device comes from the ePrivacy Directive and its national implementations, such as the UK’s PECR — not from the GDPR. That rule applies to the storage access itself, regardless of whether what is stored counts as personal data.
The practical consequence is the one worth remembering: analytics that stores nothing on the device and collects no personal data avoids the ePrivacy consent trigger and has substantially less GDPR surface to manage. It does not become exempt from the regulation; there is simply much less being processed.
How sonex approaches it
No cookies and no device storage, so nothing triggers the ePrivacy consent requirement. No fingerprinting. IP addresses are used transiently to derive coarse country-level geography and a rotating salted hash, and are never stored. Data is deletable per website or per account on request.
That posture is why sonex needs no consent banner — not a claim of exemption, but the result of not collecting the things that create the obligation.