> We did all the tracking on the backend
Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.
> We did all the tracking on the backend
Just checking, you do know that still counts as tracking and may fall under GDPR rules? GDPR was never just about cookies.
I do but we shouldn’t be talking about cookies in our cookie banner then.
That's why the usual phrasing is some variation of "Are we allowed to track you? We use cookies for that".
It was never about the cookies themselves. That just happened to be the most common form of tracking in use when the GDPR was originally written. Cookie-less tracking still requires a consent prompt, tracking-less cookies never required one.