/FAQ

How to make your tracking setup GDPR compliant?

The General Data Protection Regulation (GDPR) regulation governs how personal data is collected, used, disclosed, stored, secured, and deleted, and allocates responsibilities between organisations that determine the purposes and means of processing and those that process data on their behalf. While a tagging host (like Stape) provides essential tools like EU servers, contractual data-processing terms, and technical and organisational security measures, you’re still responsible for deciding what data is collected, which tracking platforms receive it, and ensuring user consent is respected.

What do you have to do from your side?

As the data controller,  you maintain full responsibility for determining the scope of data collection, establishing the legal basis for processing, and managing the disclosure of information to third-party platforms. This includes ensuring that you collect and process data lawfully, transparently, and in accordance with applicable data protection laws. You are also responsible for obtaining and documenting any required consents, informing data subjects of their rights, responding to data subject requests, and ensuring that disclosures to third parties are lawful and appropriately governed. You must implement suitable technical and organisational measures to protect personal data and maintain adequate records demonstrating compliance.  For more information read Server-side tracking and GDPR.

!

Warning:

You remain responsible for determining your obligations as a data controller, including obtaining any required consent, deciding what personal data to collect, and ensuring that any disclosures to third parties are lawful. You should seek advice from qualified legal counsel regarding your specific circumstances. To the maximum extent permitted by law, we disclaim liability for any actions taken or not taken in reliance on this information.

  • Set up a CMP that collects explicit visitor consent. Use a platform that supports Google Consent Mode v2 or IAB TCF
  • Keep a log of consent choices

Server GTM (sGTM) doesn’t have a built-in consent mode. Therefore, it’s important to pass consent signals from your website and use them to control your tags accordingly.

  • Send consent from web GTM to sGTM
  • Pass at least the following parameters: analytics_storage, ad_storage, ad_user_data, ad_personalization
  • Fire tags only when the matching consent is granted

Anonymize data streams

Before data leaves sGTM to tracking platforms:

  • Strip plain-text PII – emails, phone numbers, full names, precise location
  • Hash remaining identifiers with SHA-256 where a vendor still needs a match key

Choose compliant server locations

  • Configure the sGTM container in a Stape region that matches user geography. If the audience is in EU, then use Stape Europe
  • Don’t use Google Cloud if the requirement is an EU company and EU servers

Sign DPAs with vendors

  • Accept the DPA with Stape
  • Sign a DPA with every tracking platform (GA, Google Ads, Meta, TikTok, and so on)

Maintain a transparent privacy policy

Update the site privacy policy and cookie policy so they explain:

  • That you use server-side data processing
  • Categories of data collected
  • Where data is stored (for example, EU)
  • Who receives it (Stape, analytics, ads platforms, other platforms)

Was this article helpful?

Comments

Can’t find what you are looking for?