GDPR compliance refers to handling personal data in accordance with the EU's General Data Protection Regulation, which requires a lawful basis for processing — such as consent — transparency about what data is collected, data minimization, and giving individuals rights over their own data, including access and deletion.
For website analytics specifically, GDPR compliance most often comes up around whether tracking requires prior user consent — under the related ePrivacy rules, cookies used for anything beyond strictly necessary site functions generally need explicit opt-in consent before they're set, which is why so many EU websites show cookie banners. Setups that avoid identifying data altogether, such as cookieless tools with no persistent identifiers, can often operate on a legitimate-interest basis rather than consent.
A site using a traditional cookie-based analytics tool in the EU typically needs a consent banner and only starts tracking a visitor's identifier after they opt in — whereas a site using a tool that never sets an identifying cookie can often begin measuring aggregate traffic without waiting for that consent. This is the legal basis Orbit's cookieless script is designed around.
No — it applies to any organization processing the personal data of individuals in the EU or EEA, regardless of where the company itself is located, as long as it's offering goods, services, or monitoring behavior there.
Not always — it depends on whether the tool sets cookies or otherwise processes personal data in a way that requires consent; cookieless analytics tools that avoid personal identifiers can sometimes operate without triggering the requirement.
Personal data under GDPR is broadly defined and can include IP addresses, device identifiers, and cookie IDs when they can be linked to an identifiable individual, even without a name or email address being directly collected.