Privacy & compliance

GDPR and BobRay

BobRay was designed so that using it does not create the GDPR obligations traditional analytics do. Here is the reasoning your DPO will want to see.

6 min read Updated June 2026 Privacy & compliance
NO COOKIES · NO IDs

The core position

GDPR governs personal data. BobRay's analytics dataset contains none: no identifiers, no IP addresses at rest, no cookies, and tokens that cannot single out a person across days or sites. Aggregated, anonymous statistics fall outside personal-data processing, which is why no consent banner is required for the measurement itself.

Roles, for the paperwork

For visitor analytics, our customers are controllers of their websites and BobRay acts as a processor of the transient technical data used to produce anonymous aggregates; a signed Data Processing Agreement is available on Scale and Enterprise. For your own account data (name, email, billing), BobRay LLC is the controller, covered in the privacy policy.

ePrivacy / PECR too

Because nothing is stored on or read from the visitor's device, the ePrivacy rules that force cookie banners simply are not triggered. That is the honest reason the banner can go, not a loophole, an architecture.

What you should still do

Common pitfalls

The mistakes we see most often on this topic, so you can skip them entirely.

Quick reference

Consent neededNo, for the analytics
DPAScale/Enterprise, on request
SCCsIncorporated where relevant
Data locationEU only (NL + DE)
Did this solve it? If not, write to support with your site ID, a real person replies within one business day.