GDPR and BobRay
BobRay was designed so that using it does not create the GDPR obligations traditional analytics do. Here is the reasoning your DPO will want to see.
- Key takeaways
- No personal data in the analytics dataset → no consent banner required for it.
- Roles: you're controller of your site; BobRay processes transient technical data; DPA available.
- ePrivacy/PECR isn't triggered because nothing is stored on visitors' devices.
The core position
GDPR governs personal data. BobRay's analytics dataset contains none: no identifiers, no IP addresses at rest, no cookies, and tokens that cannot single out a person across days or sites. Aggregated, anonymous statistics fall outside personal-data processing, which is why no consent banner is required for the measurement itself.
Roles, for the paperwork
For visitor analytics, our customers are controllers of their websites and BobRay acts as a processor of the transient technical data used to produce anonymous aggregates; a signed Data Processing Agreement is available on Scale and Enterprise. For your own account data (name, email, billing), BobRay LLC is the controller, covered in the privacy policy.
ePrivacy / PECR too
Because nothing is stored on or read from the visitor's device, the ePrivacy rules that force cookie banners simply are not triggered. That is the honest reason the banner can go, not a loophole, an architecture.
What you should still do
- Mention your use of privacy-preserving analytics in your privacy policy, we provide suggested wording.
- Sign the DPA if your review process expects one.
- Route any visitor rights request our way per Handling visitor rights requests, spoiler: there is rarely anything to find.
Common pitfalls
The mistakes we see most often on this topic, so you can skip them entirely.
- Wrapping the snippet in a consent manager anyway, you lose decliners for nothing.
- Citing 'legitimate interest' for BobRay in your policy; simpler: no personal data processed.
- Forgetting your own account data is personal data with full GDPR rights.
Quick reference
| Consent needed | No, for the analytics |
| DPA | Scale/Enterprise, on request |
| SCCs | Incorporated where relevant |
| Data location | EU only (NL + DE) |