Live data from Hacker News

How we built a GDPR-compliant website analytics platform without using cookies

usefathom.com

1–10 of 129 posts

Re: How we built a GDPR-compliant website analytics platform without using cookies

#3

We are incredibly open to any ideas, comments or concerns on how we're doing this. This is a big step up from what we had previously, but there’s always room for improvement. Happy to hear thoughts in the comments.

How do you guard against hash collision?

Re: How we built a GDPR-compliant website analytics platform without using cookies

#5

We are incredibly open to any ideas, comments or concerns on how we're doing this. This is a big step up from what we had previously, but there’s always room for improvement. Happy to hear thoughts in the comments.

How do you guard against hash collision?

https://crypto.stackexchange.com/a/47810

Re: How we built a GDPR-compliant website analytics platform without using cookies

#7

Looks decent, but pricing is insanely high for the extremely limited set of stats.

Totally fair, as that's an opinion :) Luckily our customers are happy with the price, and other folks use the open-source (100% free) version. Cheers!

Re: How we built a GDPR-compliant website analytics platform without using cookies

#8

Earlier quoted context omitted.

How do you guard against hash collision?

https://crypto.stackexchange.com/a/47810

Based on the blog - anyone who shares a IP address (such as inside a company network) would effectively look the same.

Re: How we built a GDPR-compliant website analytics platform without using cookies

#9

We are incredibly open to any ideas, comments or concerns on how we're doing this. This is a big step up from what we had previously, but there’s always room for improvement. Happy to hear thoughts in the comments.

Hi Paul, thanks for being open about this. I have a big, important question.

ICO, the agency in charge of enforcing GDPR and related legislation in England, released guidance earlier this month on the topics of cookies. One of the most notable parts of this guidance is that "device fingerprinting" is treated the same as a cookie[1]. And also that website analytics requires consent to use cookies or similar technologies[2] ("similar technologies" including device fingerprinting).

Now, the above guidance is related to PECR rather than GDPR, which is what your post is about. But, given the above, do you think that your software is compliant/exempt from PECR or do you think that organizations will still have to take extra steps to be compliant with privacy legislation?

[1] https://ico.org.uk/for-organisations/guide-to-pecr/guidance-...

[2] https://ico.org.uk/for-organisations/guide-to-pecr/guidance-...

Re: How we built a GDPR-compliant website analytics platform without using cookies

#10
I think the GDPR was enacted into law not to prevent cookies, but to prevent collecting data on regular people. This seems to circumvent the technicalities of the law but not the spirit. The risk is that they enact a new law that puts even further restrictions on website operators.

I'm not sure this is a good idea.

Post reply on HN