GDPR-Compliant Ad Tracking in the EU | Metrikia
Media buying strategy
Stratégie & Scaling8 minFeb 20, 2026Updated Aug 7, 2026
BN

Baptiste Noel

Growth and co-founder of Metrikia

  • Master en neurosciences et neuropsychologies cliniques
  • Master en entraînement et optimisation de la performance
  • Créateur SaaS et de contenu, 20 000+ abonnés LinkedIn

Co-founder of Metrikia, Baptiste is building a SaaS from scratch and shares the growth journey unfiltered. A former clinical-neuroscience researcher and physical-performance coach, he built then left a coaching business generating over 70,000 EUR per month before focusing on product. He writes about growth strategy, acquisition and scaling.

LinkedIn

Your US tracking tool can become illegal overnight

A US tracking tool sits on a legal fault line since Schrems II. The five criteria of GDPR-compliant tracking, and why it measures better, not worse.

Partager

In 2011, a twenty-four-year-old Austrian law student named Max Schrems asked Facebook for a copy of his personal data. He received a file of more than a thousand pages. What he found in it launched him into a legal crusade that would, twice, bring down the entire framework for data transfers between Europe and the United States: Safe Harbor in 2015, then Privacy Shield in 2020. One man, twice, made illegal overnight what a good part of online advertising rested on.

This story is not a lawyer's anecdote. It is the fault line your tracking tool sits on, if it is American. Hyros, TripleWhale, Cometly, Wicked Reports: most ad measurement tools route your customer data through servers in the United States, subject to the Cloud Act and to Section 702 of FISA. In other words, you hand the vault of your data to a provider whose keys a foreign state legally holds a copy of. And since Schrems II, the legal ground under that transfer has never stopped shaking.

This article does not sell a tool. It sets the standard for GDPR-compliant ad tracking, and it defends a counterintuitive thesis: done right, this tracking does not cost you performance, it measures better. Because the gestures compliance requires, first-party data, hashing, consent, are exactly the ones that keep measurement standing in a world without third-party cookies. Metrikia comes at the end, as what meets the grid.

What is GDPR-compliant ad tracking?

GDPR-compliant ad tracking is a system that measures your conversions without ever exposing your users' personal data or transferring it outside a legal framework. Concretely: data is processed in the European Union, identifying information (email, phone, name) is hashed and never stored in clear text, users' consent is respected and passed to the platforms, retention is limited and purged automatically, and no stealth technique like fingerprinting is used to bypass that consent. It is not a layer added afterward, it is an architecture.

It is the difference between two houses. One is rented on ground the regulator floods every five years, with your data visible through the windows. The other is built on your own soil, data under lock, foundations designed for the rule. Both measure your sales; only one stays standing when the law changes, and the law changes often.

In this article, you will see:

  • What a media buyer or an agency truly risks, beyond the fear of a fine.
  • Why American tools are a legal fault line, and where the law stands today.
  • The five criteria of compliant tracking, and what each one protects AND measures better.
  • Why compliance and performance do not oppose each other, they converge.

What you truly risk

Since GDPR came into force in 2018, penalties no longer target only the giants. Meta was hit with 1.2 billion euros for illegal data transfers to the United States in 2023, TikTok with 345 million for processing minors' data the same year, Google with 90 million by the CNIL for its cookie banners in 2021. These amounts make the headlines, but they hide the real risk for a mid-sized agency or advertiser.

That risk is twofold. First, shared responsibility: if your tracking tool processes personal data without a legal basis, you are liable as the party commissioning it, not only the software vendor. Second, and this is the most insidious, the measurement risk. The day a user withdraws consent, a platform cuts a feature for lack of Consent Mode, or a data transfer is ruled illegal, it is not only a legal exposure, it is a hole in your measurement. Non-compliance does not only cost you a potential fine, it continuously degrades the data you decide on.

American tools, a fault line

The heart of the problem is one word: transfer. When your customer data leaves the European Union for American servers, it enters a zone where European law no longer protects it alone. The Cloud Act lets US authorities demand access to data held by a company under their jurisdiction, wherever it is stored. Section 702 of FISA authorizes surveillance of non-US persons' communications. It is precisely this imbalance that led the Court of Justice of the European Union to invalidate two successive transfer frameworks.

Today a third framework exists, the Data Privacy Framework adopted in 2023, which lets certified American companies receive European data. But it is already challenged in court by the same people who brought down the previous two, and no serious observer bets on its durability. Building your measurement on that base means accepting to rebuild everything at the next ruling. To this a second, more technical flaw is added: fingerprinting. Some tools identify users by their browser's fingerprint to track them without cookies. The European Data Protection Board confirmed, in its guidelines 2/2023, that these techniques fall, like cookies, under the consent requirement of Article 5(3) of the ePrivacy Directive. Tracking without consent through fingerprinting is not a clever workaround, it is a violation.

The five criteria of compliant tracking, and their double benefit

Here is the standard. What is striking, laying it out, is that each criterion protects legally and strengthens measurement. That is the whole thesis of this article.

The first criterion is processing within the European Union. Your data does not leave the European legal framework, which removes the transfer risk, and it stays under a single, stable jurisdiction, which makes your measurement independent of transatlantic upheavals. The second is the hashing of personal data. Email, phone and name are normalized then hashed in SHA-256, never stored in clear text; the match between a lead and an ad is made on fingerprints, not on identities. Legally, a breach exposes only irreversible hashes. And it is exactly the same mechanism as Meta's advanced matching and Google's Enhanced Conversions: hashed data is also the data that attributes best in a post-cookie world.

The third criterion is respect for consent, passed to the platforms via Google Consent Mode v2, mandatory in the European Economic Area since March 2024 to keep measuring and remarketing. Consent is not just a legal box: correctly transmitted, it lets the platforms model the missing conversions rather than lose them. The fourth is limited retention with automatic purge and anonymization: you keep only what is needed, the rest is erased, which reduces both the risk surface and the noise in your analytics. The fifth is the absence of stealth fingerprinting: you measure with consent, not against it, which protects you from the violation and grounds data no one can contest.

The five criteria of GDPR-compliant tracking, each with what it protects legally and what it measures better: processing within the EU, SHA-256 hashing, consent + Consent Mode v2, limited retention and purge, no stealth fingerprinting.
Each compliance criterion protects legally AND strengthens measurement: compliance and performance converge.

The fault line in three collapses

To understand why building on a transfer to the United States is fragile, just look at recent history. Three legal frameworks have successively authorized these transfers, and two have already fallen, the third is under attack. This is not an accident, it is a pattern.

The fault line of EU-US data transfers in three frameworks: Safe Harbor (2000-2015, invalidated Schrems I), Privacy Shield (2016-2020, invalidated Schrems II), Data Privacy Framework (2023, challenged in court).
Three frameworks have authorized EU-US transfers; two have fallen, the third is under attack.

Each collapse forced thousands of companies to urgently revisit their legal basis, sometimes to cut data flows overnight. A tool designed to stay within the European Union does not know that risk, not because it found a trick, but because it never set foot on the ground that collapses.

Where Metrikia sits

Metrikia did not add compliance afterward, it made it a foundation. The entire infrastructure is hosted in the European Union, no data transits through American servers. Personal information, email, phone, name, is normalized then hashed in SHA-256 and never stored in clear text: the match between your leads and your ads is made on fingerprints, so a breach would expose only irreversible hashes. Retention is configurable, with automatic purge and anonymization, and Google Consent Mode v2 is natively supported.

But the point that matters for a media buyer is that none of this is paid for in performance. Hashed data is what best attributes your offline conversions to the platforms, well-transmitted consent is what recovers the sales classic tracking loses, and the reference revenue stays the CRM's actually-collected cash. The goal was never to make you compliant at the cost of your measurement, but to show you that, well designed, compliance is your most solid measurement.

Frequently asked questions

Is an American tracking tool illegal in Europe? Not automatically, but legally fragile. Transferring personal data to the United States has seen two successive legal frameworks invalidated by European courts, and the third, the 2023 Data Privacy Framework, is already challenged. Using a tool that stores your data on US servers exposes you to rebuilding everything at the next reversal, on top of the Cloud Act risk.

Does fingerprinting let you bypass consent? No. The European Data Protection Board confirmed, in its guidelines 2/2023, that fingerprinting falls, like cookies, under the consent requirement of Article 5(3) of the ePrivacy Directive. Tracking a user by their browser fingerprint without their consent is a violation, not a technical trick.

Does GDPR compliance cost measurement performance? Well designed, no, on the contrary. Hashed first-party data is exactly what Meta's advanced matching and Google's Enhanced Conversions use to attribute in a post-cookie world. Consent correctly transmitted via Consent Mode v2 lets the platforms model conversions rather than lose them. Compliance and measurement converge.

What is Google Consent Mode v2 and is it mandatory? It is the mechanism by which you pass Google the consent state of your users. It has been mandatory in the European Economic Area since March 2024 to keep using conversion measurement and remarketing on Google's advertising products with European users.

Does this article constitute legal advice? No. It describes technical criteria and the state of the law at its writing date, on a moving subject. For an assessment of your specific situation, consult a lawyer specialized in data protection.

References

Court of Justice of the European Union. (2020). Judgment C-311/18 (Schrems II). https://curia.europa.eu/juris/liste.jsf?num=C-311/18

European Data Protection Board (EDPB). (2023). Guidelines 2/2023 on the technical scope of Art. 5(3) of the ePrivacy Directive. https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-22023-technical-scope-art-53-eprivacy-directive_en

Google. (n.d.). Updates to consent mode for traffic in the EEA. Google Ads Help. https://support.google.com/google-ads/answer/13695607

CNIL. (2022). Cookies: sanctions against Google and Facebook. https://www.cnil.fr/en/cookies-cnil-fines-google-total-150-million-euros

Baptiste Noel, co-founder of Metrikia. MSc in Clinical Neuroscience and MSc in High Performance.

Ready to measure your true advertising ROI?

Connect your ad accounts and CRM in 5 minutes.