Back
Use Matomo Tag Manager GDPR compliant. Follow these instructions:
Services & integrations
Back
The GDPR compliant use of Matomo Tag Manager
First of all, we have to clarify whether consent is required in order to integrate Matomo Tag Manager GDPR compliant.
The documents contained on https://matomo.org/matomo-cloud-dpa/ must be checked to ensure that all the criteria of Art. 28 GDPR are met and that the technical and organizational measures specified by the service provider represent protection appropriate to the risk.
The documents must be archived so that they can be proven to the supervisory authority if necessary.
1. Mention Matomo Tag Manager in the privacy policy completely, simply and transparently
The privacy policy on your website must be comprehensive, transparent and accurate. It should be readable and understandable by anyone, even without legal training. It is important to include a section on Matomo Tag Manager that clearly describes what data is collected, for what purpose it is used and who is responsible for it, as well as whether data is shared and what legal basis applies.
Privacy Statement for the Service Matomo Tag ManagerBeim Zugriff auf manche Teildienste unserer Website werden zusätzliche personenbezogene Daten verarbeitet. Dabei verarbeitete Datenkategorien: technische Verbindungsdaten des Serverzugriffs (IP-Adresse, Datum, Uhrzeit, abgefragte Seite, Browser-Informationen). Zweck der Verarbeitung: Auslösung, Steuerung und Verwaltung weiterer Dienste unserer Website. Die Rechtsgrundlage für die Verarbeitung: Ihre Einwilligung nach Art. 6 (1) a DSGVO. Eine Übermittlung von Daten erfolgt: an den Auftragsverarbeiter InnoCraft Ltd., 150 Willis St, 6011 Wellington, Neuseelandvertreten durch ePrivacy Holding GmbH, Prof. Dr. Christoph Bauer, Burchardstraße 14, 20095 Hamburg, Deutschland, [email protected]. Dies kann auch eine Übermittlung von personenbezogenen Daten in ein Land außerhalb der Europäischen Union bedeuten. Die Übermittlung der Daten nach Neuseeland erfolgt aufgrund Art. 45 DSGVO iVm der Angemessenheitsentscheidung 2013/65/EU der Europäischen Kommission.
2. Additional Information for Matomo Tag Manager and GDPR
In addition to the above information, the data protection information must also contain the mandatory information from Art. 13 or 14 GDPR: Name and contact details of the controller, if necessary the contact details of the data protection officer, the purposes for which the personal data are to be processed, the legitimate interests, if the processing is based on Article 6 (1) f GDPR, the duration of the processing, information on the rights of the data subjects including the right to lodge a complaint with a supervisory authority, the possibility of simply revoking consent given, and information as to whether the Provision of the data is required by law or contract or what the possible consequences of non-provision would be. In the event that the data is used for automated decision-making, including profiling, meaningful information about the logic involved and the scope and impact on the data subject must be provided. The processing of the data must also be documented in the list of processing activities in accordance with Art. 30 GDPR. The information required for this can already be found in the privacy statement, which can be created from the previous information.
3. Use a Consent Management Provider CMP (cookie banner/cookie popup/cookie bar)
Different names, but usually the same purpose. CMP supports you with consent (opt-in and opt-out, data protection declaration and other GDPR topics. Technical support is recommended with regard to the GDPR and consent management in order to avoid errors.
Preconfigured services & integrations
Individually expandable