Short answer: GDPR tracking for SMEs isn't categorically prohibited, but many typical marketing setups are risky without effective consent. In practice, you usually need a proper consent setup as soon as you use non-essential tracking technologies, third-party providers, conversion tracking for advertising platforms, or remarketing. However, if you're only using limited, data-minimizing reach measurement or analyzing server logs for your own website, the situation requires a more nuanced assessment.
Especially with GDPR tracking in small businesses in South Tyrol, Austria, Germany, and the rest of the DACH region, I've been seeing the same pattern for years: too many tools, too little clarity, and ultimately, poor results. The problem is rarely a lack of tracking. The problem is almost always an unclear purpose, an incorrect legal basis, and a consent banner that promises more technically than it actually delivers.
- Requires consent These are mostly marketing tracking, remarketing, advertising platforms, many third-party embeds and cross-channel profiles.
- Perhaps to be examined more closely These are pure server logs, very reduced first-party measurement, and tightly configured audience measurement setups without additional profiles.
- Important: A consent banner doesn't measure anything. An analytics tool doesn't manage consent. And a tag manager isn't a legal basis.
For SMEs, the maximum amount of data is not crucial, but rather a clean, data-efficient setup with a few truly useful key performance indicators.
GDPR tracking for SMEs: What really needs to be separated legally
GDPR tracking often involves two levels being confused. The first level concerns access to the end device. The second level concerns the subsequent processing of personal data. For Germany, end device access is... Section 25 TTDSG or today TDDDG The regulation states: Storing or reading information on end devices is generally only permitted with prior consent, unless it is technically absolutely necessary.
For you as the operator, this means: A cookie or similar mechanism can become relevant even before the actual GDPR question arises. Only then does the second check follow: Which Legal basis Does it have further processing? Is it a consent necessary or comes up in tight cases legitimate interest Consider it? Many setups fail precisely at this point of separation.
What usually requires consent in SME setups
- google analytics 4 respectively GA4, when it is used classically for web analytics, advertising links or cross-channel evaluations.
- Conversion tracking for Google Ads, Meta or other advertising platforms.
- Remarketing and any form of re-engagement across platform boundaries.
- Many Third party providers-Embedded content such as maps, videos, external forms, chat tools or social plugins.
- Tracking via Tag Manager, if tags are triggered before consent is given.
What needs to be examined more closely and in a more differentiated manner
- server logs, insofar as they are necessary for operation, safety and fault analysis.
- Very reduced Audience Measurement-Setups for range measurement when configuration and purpose are narrowly limited.
- First-party tracking without additional profiles, without sharing with third parties and with clear data minimization.
- Cookieless trackingProvided that there is technically no access to end devices requiring consent and no profiling processing. This is stricter than many providers portray it in their marketing.
The data protection conference did not issue a blanket approval for audience measurement. Evaluation report on OH Telemedia It becomes clear: Measuring reach without consent is only possible with a precisely defined configuration and purpose. As soon as additional user data or further evaluation results are involved, the situation becomes significantly stricter.
Consent banner, consent management platform and analytics tool: three different roles
A common misconception regarding GDPR tracking in SMEs is: "We have a consent banner, so we're compliant." This is only true if the technical implementation is sound. Consent management solution A consent management platform manages decisions. The analytics tool measures behavior. The tag manager distributes scripts. You need to think about these three roles separately and connect them seamlessly.
- Consent banner: Displays options and solicits decisions.
- Consent Management Platform: It stores and manages consents in a traceable manner.
- Analysis tool: measures visits, events, conversion goals, or campaign paths.
- Tag Manager: Scripts are only loaded if the necessary permission is actually granted.
In practice, I often see banners that look perfectly fine, while Google Analytics (GA4), heatmaps, or external videos load on the very first page load. In that case, the banner isn't fulfilling its purpose. This is particularly frustrating for small businesses because it increases effort, risk, and data clutter simultaneously.
Matomo: privacy-friendly options are available, but not automatically consent-free.
Matomo This is a sensible option for many SMEs if you primarily want to understand your own offering and don't need the logic of an advertising platform. The advantage often lies in its close alignment with actual needs: less platform dependency, more control, often genuine first-party tracking, and greater data efficiency.
However, it's important to be realistic: Matomo is not automatically permissible. Matomo itself describes this in its official FAQthat use without a consent banner is only conceivable with a strict, data protection-focused configuration, for example without Cookies, anonymized and without browser feature detection. Therefore, the crucial factor is not the brand name of the tool, but its specific implementation.
If you want to set up Matomo in a clean and streamlined way, pay particular attention to these points:
- Become Cookies Set or not.
- Is the measurement pure First-party tracking Or are other services connected to it?
- Is only one website being measured, or are users connected across multiple sites?
- Is IP anonymization Are they active and are additional identifiers avoided?
- Do you use features like heatmaps, session recordings, user IDs, or e-commerce data?
- Is there a clean Data processing with hosting and technology partners, if necessary?
I usually advise small businesses to ask themselves a straightforward question: Do you really need cross-channel attribution and marketing automation, or do you primarily want to know which content performs well, which pages generate inquiries, and where users drop off? For many SMEs, the second option is perfectly sufficient. In that case, Matomo is often closer to their actual needs than a complex tool stack.
GA4 and data protection: useful for marketing, but only with proper consent
google analytics 4 It's functionally powerful, especially if you want to tightly integrate Google Ads, cross-channel campaigns, conversion tracking, and ad analytics. For some companies, this makes economic sense. For many small businesses, however, it adds more complexity than it provides.
From a data protection perspective, Google Analytics was particularly controversial in Europe. EDPB on the 101 NOYB complaints It notes that several supervisory authorities have ordered website operators to comply with GDPR requirements or to cease data transfers to the US. For SMEs, this does not automatically mean that GA4 is generally inadmissible. However, it clearly states for SMEs: The current classification must always be reviewed in light of the legal and data transfer situation after 2023, and not based on outdated practical experience.
My practical advice is therefore simple:
- If you GA4 If you need it, then use clear consent logic and technically clean blocked tags.
- If you've only installed GA4 out of habit, the effort is often greater than the benefit.
- If you are not actively using Google Ads or complex attribution, reduced GDPR tracking is often the better decision.
Especially in small teams, I often see that while Google Analytics 4 (GA4) is implemented, nobody can really read the reports with confidence. This leads to more risk, more complexity, and still no better decision. A few reliable figures are better than a dashboard full of half-understood metrics.
IP anonymization, cookieless tracking, and legitimate interest: the three most common misunderstandings
First misunderstanding: IP anonymization solves everything. That's not true. The Data Protection Conference has stated in its Information about Google Analytics It has been clarified that shortening the IP address is only an additional security measure. This does not automatically make data processing anonymous, nor does it automatically eliminate the need for consent.
Second misunderstanding: Tracking without cookies is always permissible. That's also not true. The absence of a cookie alone does not answer the question of whether consent is required for access to the end device or for the processing of personal data.
Third misunderstanding: Legitimate interest is not a simple solution. For very specific, data-minimizing measurements, legitimate interest can be part of the assessment. However, for many marketing setups, profiling, advertising functions, and third-party integrations, this legal basis does not automatically apply.
A pragmatic minimal setup for GDPR tracking in small businesses
When I work with SMEs, I always try to scale down GDPR tracking first, not scale it up. In reality, a lean setup often leads to better decisions. A typical example from my experience: A company starts with ten integrated services, two tracking pixels, a consent banner, and still unclear data. After reducing it to three actual goals, the picture often improves significantly: more clarity, less banner clutter, less risk.
A robust minimum setup for many small businesses looks like this:
- Define a maximum of three business objectives. For example, a quote request, a phone call, and a qualified form submission.
- Separate baseline measurement from marketing measurement. Reach is something different than conversion tracking or remarketing.
- Document the legal basis for each purpose. Not a flat rate per tool, but per processing operation.
- Only use the integrations that you actually evaluate. No pixel should be allowed to run "maybe later".
- Keep events data-efficient. No unnecessary parameters, no sensitive content, no overloaded custom events.
- Block all unnecessary tags until they are released. This also applies to embedded content from third-party providers.
- Review contracts and roles. Order processing, hosting, CMP, form service, newsletter and analysis must be properly documented.
- Test the cancellation. Consent must be just as easy to withdraw as it was to give.
If you want to delve deeper into measurement plans, key performance indicators (KPIs), and prioritization, our article on [topic] will also help you. Data analysis in marketing for SMEsBecause good GDPR tracking doesn't start with a script, but with a good question.
Typical mistakes I see time and again in SMEs
- GA4 loads even before consent is given. The consent banner is visible, but technically ineffective.
- Matomo is generally presented as always requiring no consent. It all depends on the configuration, purpose, and data flow.
- The banner only considers analytics. YouTube, maps, fonts, external forms or chat tools are forgotten.
- A tag manager is often confused with a compliance officer. He can control things cleanly, but he can also trigger them incorrectly.
- Too much data is being collected. More data does not automatically mean better decisions.
- The connection to the website strategy is missing. Tracking without a goal primarily generates data noise.
That's precisely why this topic doesn't belong in isolation within the technical realm. Tracking is part of the website architecture, the content, and the business logic. When we design websites, we consider this from the very beginning, whether in the technical website implementation or in an upstream setting strategic consulting.
FAQ: The most important questions about tracking in everyday SME life
Do I automatically need a consent banner for every tracking activity?
No. A consent banner is primarily necessary if you use technologies or processing activities that require consent. Pure server logs or very specific, technically necessary processes need to be reviewed differently, but you must clearly document this distinction.
Is Matomo realistic without consent?
Under strict conditions, this can be realistic, but only with a very data-efficient configuration. As soon as CookiesThe addition of further identifiers, multiple websites, heatmaps, user IDs or other advanced features quickly changes the rating.
Is GA4 prohibited under the GDPR?
I wouldn't put it so generally. In practical terms, however, GA4 means for SMEs: only work with clear consent, transparent technical controls, and up-to-date review of the data protection framework.
Is IP anonymization sufficient as a protective measure?
No. IP anonymization is useful, but it's not a free pass. If other usage data, identifiers, or links are also processed, the data protection review remains fully valid.
Does a Google Tag Manager itself require consent?
The Google Tag Manager is primarily a technical control tool. The crucial factor is what is loaded via the Tag Manager and whether these scripts are activated before consent is given. In many faulty setups, this is precisely where the problem lies.
What about YouTube, Maps, external forms, or other third-party content?
This content is often overlooked in banner ads, even though it can be just as legally and technically relevant as analytics. Examine each integration individually: Who loads what, when, from which third-party provider, and on what legal basis?
When is legitimate interest a viable alternative to consent?
For very precise, data-saving measurements for your own offering, a legitimate interest may be part of the review. For advertising platforms, remarketing, extensive conversion tracking, or profiling, this justification is usually much weaker.
My conclusion after over 20 years of experience: Small businesses rarely need more tracking. Small businesses need better decisions. If you're building your website as its own system, accurate measurement is a tool for clarity, not surveillance. This article is intended as a decision-making aid, not legal advice. As soon as sensitive data, health information, HR data, or other particularly confidential areas are involved, you should also seek legal review.
Sources
- Law on Data Protection and the Protection of Privacy in Telecommunications and Telemedia — gesetze-im-internet.de (2021)
- Data Protection Conference / Media Working Group – Evaluation Report on the Consultation of the OH Telemedia — datenschutzkonferenz-online.de (2022)
- European Data Protection Board — edpb.europa.eu (2023)
- Matomo FAQ: Can I use Matomo Analytics without asking for consent or using a cookie banner? — matomo.org (n.d.)
- Data Protection Conference – Guidelines for the use of Google Analytics in the non-public sector — datenschutzkonferenz-online.de (2020)