The GDPR (General Data Protection Regulation) entered into force on May 25, 2018. It is Europe’s digital privacy regulation. It states that companies have to obtain the consent of Data subject s to store and process users’ personal data.

The European Commission prepared the GDPR, which replaced the outdated 1995 European Data Protection Directive. The idea behind GDPR is to provide individuals with full control over their personal data. It aims to strengthen and unify the rules of data collection from individuals within the European Union.

In the GDPR era, Personal data is not only name, photo, address, phone number or email address. It also includes the following data:

  • Biometric and genetic data
  • Economic status
  • Cultural and social identity
  • IP address and geolocation
  • Device ID
  • Cookies
  • Pseudonymous data

Read more about Data controller s, Data processor s or Data processing agreement s.

Visit the Piwik PRO blog to dive deeper into GDPR-related articles.


  • What is considered protected health information (PHI) under HIPAA? A guide for healthcare marketers

    Quick summary What PHI is: Any individually identifiable health information created, received, maintained, or transmitted by a covered entity or its business associates Who it applies to: Healthcare providers, health plans, healthcare clearinghouses, and their business associates Why it matters for marketing: Marketing tools that collect or transmit PHI without a BAA create HIPAA compliance…

  • We checked 59 hospital websites. 73% kept tracking visitors after opt-out.

    A new study by Piwik PRO and Verified Data scanned 59 major US hospital and clinic websites for tracking and data compliance. The findings show just how common it is for major US healthcare websites to run marketing tools that weren’t built for a regulated environment. What we actually found Across the 59 scanned sites,…