Collecting and analysing visitor behaviour on the company website using analytics tools and cookies.

Data Details
Data Subjects
Website VisitorsProspects
Data Volume
100,000+ sessions/month
Data Categories
IP AddressBrowser DataPage ViewsClick BehaviourSession DurationDevice Type
Processing Type
Analysis
Automated Decision-Making
No
Legal Basis
Legal Basis
Consent
Consent Mechanism
Cookie Consent Banner (OneTrust)
Purpose
Improving website user experience and measuring marketing campaign effectiveness.
Legal Basis Detail
Cookie consent banner with granular consent options for analytics cookies.
Recipients & Transfers
Cross-Border
Internal Recipients
MarketingProduct Team
External Recipients
Google Analytics (US)Hotjar (IE)
Transfer Countries
USIE
Transfer Safeguards
Google Analytics data processing addendum. Hotjar DPA. Both under SCCs.
Retention & Security
Retention Period
26 months (Google Analytics default)
Retention Justification
Security Measures
✓ IP Anonymization✓ Cookie Consent Platform✓ Data Minimization✓ Opt-Out Mechanism
PDPL Compliance Assessment
Update →
D1 Data Subject Rights & Consent
82%
Compliant

All requirements for Data Subject Rights & Consent are met. Documentation is complete and up to date.

D2 Processing Principles & Lawful Basis
75%
Partial

Most requirements for Processing Principles & Lawful Basis are addressed. Some gaps identified in documentation or proce…

D3 Data Protection & Security
72%
Partial

Most requirements for Data Protection & Security are addressed. Some gaps identified in documentation or process.

D4 Organizational Requirements & Governance
65%
Partial

Most requirements for Organizational Requirements & Governance are addressed. Some gaps identified in documentation or p…

D5 Cross-Border Data Transfer
48%
Non-Compliant

Significant gaps identified in Cross-Border Data Transfer. Immediate remediation required.

D6 Compliance & Accountability
70%
Partial

Most requirements for Compliance & Accountability are addressed. Some gaps identified in documentation or process.

Associated Risks
1
High Analytics DPIA overdue - enforcement risk… Open
Edit Activity Add Risk