> Rather than count unique IP addresses (requiring storing state about each visitor), we simply count page views that originate from a distinct referral or navigation event, avoiding the need to store information that might be considered personal data.
They don't store IP addresses (but other referral ids that identify users in a different way) ; and they exclude EU visitors by default.
You do your opinion
Just saw that in the dashboard: "Enable globally", "Exclude EU". Kinda funny (in a bad way)
> they exclude EU visitors
GDPR is applicable on EU citizens, disregarding where they browse from. So either they have to track whether you're an EU citizen/EU visitor or they track EU visitors when browsing from outside of EU. This makes it not GDPR compliant.
The main issue is that your privacy policy is most likely not mentioning this third-party tracking because you were not even aware of it. Who is going to be responsible? Who is going to be fined for not mentioning this tracking in _your_ privacy policy? You. (Your company)