GDPR and link analytics: what you can collect and how
IP addresses are personal data. Here is how click analytics stays useful and lawful at the same time.
By ShortFreeURL Team · 8 July 2026
IP addresses are personal data
Under GDPR an IP address is personal data because it can identify an individual when combined with other information. That does not mean you cannot process it — it means you need a lawful basis and appropriate safeguards.
Lawful basis
Most click analytics runs on legitimate interests: you need to know whether your campaigns work, and the privacy impact is low if you handle the data properly. Document the assessment. If you are combining click data with personal profiles for targeting, consent is the safer basis.
Minimise at collection
Turning on IP hiding means the address is used to derive country and city and then discarded rather than stored. You keep the geography that is actually useful in a report and stop holding the identifier that creates the risk.
Retention
Keep raw per-click logs only as long as you have a reason to. Aggregates can be kept much longer with far less risk, because they are not personal data. Set the retention period deliberately rather than defaulting to forever.
Processor obligations
Your link platform is a processor. You need a data processing agreement, a list of sub-processors, clarity on where data is stored, and a route to export or delete data on request. Ask for all four before you sign.
Cookies
Redirect analytics generally does not need a cookie at all. A/B stickiness does, and password gates do. Those are arguably strictly necessary for the function requested — but if you are unsure, disclose them in your cookie notice.

