TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Plausible and Fathom analytics are not GDPR compliant

5 pointsby ellinooraalmost 5 years ago

2 comments

dylzalmost 5 years ago
I agree wholeheartedly with this, and also toss simpleanalytics into the ring. They explicitly advertise the ability to bypass blockers and set up custom subdomains on their frontpage, which IMO _the person that is blocking it does not wish to send telemetry_, forcing them to do it is both a forced opt-in and rude as hell.<p>If you are going to try to turn a profit by yelling about how you&#x27;re so respectful and compliant, maybe not intentionally try to bypass end-users&#x27; explicit, human-set, consensual opt-out with your forced shady opt-in.<p>You are not being &quot;privacy friendly&quot;, you are refusing the user&#x27;s explicit &quot;no consent, please don&#x27;t do this&quot; and forcing yourself on them anyway.<p>--<p>An unrelated note on technical infrastructure: many of these projects are EU based and proudly tell everyone that they are EU based.<p>Unfortunately, for example - see <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;CLOUD_Act" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;CLOUD_Act</a>:<p>- Plausible hosts on DigitalOcean<p>- Plausible uses Cloudflare<p>- Simpleanalytics uses Cloudflare<p>- Fathom is on AWS
ellinooraalmost 5 years ago
Both Fathom [1] and Plausible [2] claim to be GDPR compliant, but they are not.<p>They use a technique called &quot;device fingerprinting&quot; by collecting online identifiers, such as IP addresses, and browser characteristics for identification. Thus user consent is needed.<p>1: <a href="https:&#x2F;&#x2F;usefathom.com&#x2F;gdpr-ccpa-pecr-compliant" rel="nofollow">https:&#x2F;&#x2F;usefathom.com&#x2F;gdpr-ccpa-pecr-compliant</a> 2: <a href="https:&#x2F;&#x2F;plausible.io&#x2F;data-policy" rel="nofollow">https:&#x2F;&#x2F;plausible.io&#x2F;data-policy</a>
评论 #24309926 未加载