GTM template with instructions video from Simo Ahava!
Server-side tracking won't make you GDPR compliant on its own. But it can give you far more direct control over your data flows than client-side tracking ever could. And once you have the control, you’re ready to build towards compliance.
It's a common misconception that once you switch to server-side tracking, you don’t need cookie banners anymore. Privacy officers, on the other hand, know that this is still an area that draws regulatory scrutiny.
The numbers offer some perspective: European regulators have issued €7.1 billion in GDPR fines since 2018, according to DLA Piper's GDPR Fines and Data Breach Survey, with €1.2 billion of that in 2025 alone, and website tracking is a frequent target.
This article covers what the regulation requires, the misconception often trips up marketing teams, and where server-side tracking can support.
Of course, none of what we say here is legal advice, so we also include some recommendations for what to take to legal, so you can get the correct professional guidance for your particular situation.
If you’re curious to see how Tracklution itself supports this process, from documentation to certifications and DPAs, that’s exactly what our compliance solutions page covers.
The General Data Protection Regulation, in force since 2018, governs how organizations process the personal data of people in the EU, wherever the organization is based.
The GDPR is built on several core principles, but there are a few that are most relevant for tracking:
If you operate globally, similar laws, such as the CCPA in California, layer their own requirements. This piece focuses on Europe, but the same principle applies in every market: always know what data you collect and stay in control of it.
The regulation applies to data processing wherever it happens. Both client-side tracking and server-side tracking fall under exactly the same rules, but this is rarely understood and appreciated. The confusion around GDPR and server-side usually comes from two places:
No. Consent requirements apply to all forms of personal data processing. Moving data collection to a server will change the mechanics of collection and processing, but it is processing nonetheless - and the legal obligations stay the same.
Regulators don’t hesitate when it comes to enforcing these obligations. In September 2025, France's CNIL fined Google €325 million. Google showed Gmail users ads without consent, and served an invalid cookie consent at account creation. This was Google's third French consent fine, after €100 million in 2020 and €150 million in 2021.
According to Anni Salo, CEO at Tracklution, the distinction is simple:
"Server-side tracking gives you the transparency and control that GDPR is built on, but it doesn't remove the need for lawful basis, and usually consent when we processing that personal data for marketing purposes. Those are separate things, and companies that mix them up are at risk of getting in trouble."
Even if Google had run everything server-side, the outcome would have been the same. Consent is a separate question, and no advanced tracking architecture can answer it for you.
EU tracking rules are based on two layers:
Server-side tracking can reduce your reliance on cookies. In practice, this means that less of the tracking process on your site falls under the ePrivacy Directive's device access rules specifically. It does not, however, touch the processing consent requirement if you handle any PII (personally identifiable information) data, and your consent management platform still needs to play its role.
Having control over your data is a prerequisite for GDPR compliance, and client-side tracking gives you very little of it. This is the main thing that server-side tracking changes when it comes to regulation.
When a third-party script runs in a visitor's browser, that vendor decides what data to collect. You can install the pixel, configure the events, and hope for the best, but you can't fully trace what the script captures on every page and every session.
Server-side tracking works differently: a lightweight first-party script captures the data and sends it to a tracking server first. From there, you decide what's forwarded to each platform.
With a managed platform like Tracklution, the infrastructure is run for you, but you have full control over what you collect and where you send it.
Practically, the change to server-side tracking looks like this:
For the mechanics in more depth, see how server-side tracking actually works.
What happens without the visibility and control?
In 2024, Sweden's data protection authority IMY fined two online pharmacies, Apoteket and Apohem, a combined 45 million SEK (about €4 million). According to IMY, both ran the Meta Pixel and enabled a sub-feature that sent sensitive data to Meta without their knowledge, including purchases of treatments for specific health conditions. It’s understandable that users wouldn’t want anyone having this information, let alone an ad platform. Neither pharmacy had procedures to detect it, and the data flowed until it was flagged by outsiders.
This is what the black box of client-side tracking looks like in practice. Nobody at either pharmacy chose to send health data to Meta, and nothing in their setup alerted them that there was an issue.
Anni, our CEO, has a standing answer for this failure mode:
"We remove the black box. You see exactly what data is collected, how it's processed, and where it's sent. Those are the core grounds of GDPR compliance."
– Anni Salo, CEO at Tracklution
For companies in privacy-sensitive markets, this control is becoming more and more of a deciding factor. Aava & Bang, a Finnish B2B marketing agency, standardized server-side tracking with Tracklution across their clients after witnessing how data privacy regulations and browser restrictions undermine data quality and attribution. This resulted in roughly 30% more tracked conversions per client, and a setup that’s adequately transparent and controllable to help meet regulatory requirements..
"The way success is measured has changed for good with GDPR and tightening regulations. How can we prove that we're doing the right things?"
– Sampo Soininen, Digital Strategist at Aava & Bang
The answer is that you can prove it by being able to show it, which is what the whole visibility argument ultimately comes down to.
Read the full Aava & Bang case study.
None of this is purely about staying out of trouble. Cisco's 2026 Data and Privacy Benchmark Study of 5,200 privacy professionals found 99% of organizations report tangible benefits from privacy investment, with reduced sales friction among the most cited.
Of course, having the right tool doesn’t take care of everything automatically. The setup still needs to be done right, and getting it wrong could mean exposing the data you were meant to protect.
Consent mode is Google's mechanism for communicating user consent choices to its tags. It works with both client-side and server-side setups, whether that's a dedicated server-side tracking platform or server-side Google Tag Manager (sGTM).
In basic mode, according to Google's documentation, tags stay blocked until the user consents, and if they don’t, nothing is sent to Google at all, not even the consent status. In advanced mode, tags load right away, and while consent is denied, they send only cookieless pings. When consent is granted, the full measurement data goes through. Google Analytics 4 and Google Ads use those pings to model the missing conversions.
Microsoft and Meta run similar mechanisms. And since the EU's Digital Markets Act, Google requires proof of consent on every conversion from European users. Advertisers running Google Ads in the EU can no longer skip this requirement.
Basic mode is the safer legal call, but it comes with less conversion data to work with. Advanced mode gets the data back through modeling, but there's no definitive ruling yet on whether its cookieless pings are compliant, and interpretations vary by country and industry.
Ultimately, this is a business decision that belongs with your legal team.
The element that server-side tracking adds is simple universal enforcement of your decision. The user's consent status travels with each event into the tracking server, so your Google Tag Manager setup or tracking platform respects it across every destination, and you can easily verify that it does.
If you're unsure what your current tags are forwarding before consent is given, auditing your pipeline is a good place to start.
Run a free Tracklution audit to map exactly what data your site collects and where it goes. It's a concrete starting point for your next compliance review.
The physical location of your tracking infrastructure holds more weight than simply helping you be legally compliant.
Where you host your data can be a deciding factor in security reviews, campaign launches, and can even make or break your sales deals. Transferring data outside the EU can trigger extra legal requirements. EU-US data transfers in particular have a messy legal track record, so many companies choose to keep the data in the EU and avoid the complications altogether.
But doing so is harder than it sounds. Many server-side tagging setups run on Google Cloud by default, and plenty of tools route data through US infrastructure without making it particularly obvious. For privacy-conscious organizations, especially in Germany and the Nordics, EU residency is a hard requirement.
Tracklution was built and is hosted in the EU. For EU customers, data is processed on AWS in Stockholm and never leaves the EU. Customers elsewhere can choose US or Oceania hosting, and enterprise plans support custom locations. The platform isn't built on Google Cloud, which some privacy-focused teams count as a point in its favor.
Not every provider clears that bar. Anni's advice for telling them apart is pretty clear:
"Be aware that you use a proper server-side tracking solution, not some random gateway that's transferring data from one place to another without proper security certifications and proper systems in place."
– Anni Salo, CEO at Tracklution
If a vendor can't tell you where your data is processed, or show certifications like SOC 2 and ISO 27001 behind their data security claims, the path forward becomes clear.
Nothing in this article is legal advice. Rather, it’s a working agenda for the conversation between marketing, ops, and legal.
In multi-brand setups, standardizing your tracking matters even more. The Platform Group, one of Germany's larger eCommerce groups with 30+ online marketplaces, replaced a patchwork of Shopify plugins, GTM server containers, and assorted tools with one unified Tracklution setup. This left them with just one thing to document, one thing to audit, and one consistent place to point to when anyone asks how their tracking works.
"While others are still debating whether to modernise, we've already built the foundation for the next decade of advertising."
– Shaan Raja, Teamlead SEO & Integration Analyst at The Platform Group
Read the full Platform Group case study.
While related, server-side tracking and GDPR compliance are separate questions. The regulation applies wherever tracking happens, and consent requirements don't just disappear server-side. No tracking tool makes you compliant by itself.
What changes is what you're able to do with a full server-side setup. Instead of hoping third-party scripts behave, you control and document exactly what goes where.
And it's quite clear where enforcement is heading. In April 2026, the CNIL extended cookie-consent logic to email tracking pixels, and Italy's regulator did the same only weeks later. Tools will keep changing, and enforcement will keep expanding. The only bulletproof defense is knowing what data you take in and where it goes, and having the proof on hand.
Once you have the control in place, you can build compliance on top of it.
Does server-side tracking make you GDPR compliant?
No. It gives you the control and visibility a compliant setup requires, but compliance depends on your lawful basis, consent management, transparency, and retention. While Tracklution is GDPR compliant as a company and product, and it enables your compliance, it can't take legal responsibility for your configuration.
Do you still need a cookie banner with server-side tracking? Most often, yes. Consent requirements come from the regulation's data processing rules and the ePrivacy Directive's device access rules. Neither disappears when tracking moves server-side.
Is server-side tracking legal in the EU? Yes. It's a data collection method, fully legal with a valid lawful basis, proper consent management, and transparent handling. Your legal exposure comes from what you collect and what you do with it, regardless of the method.
What is consent mode and how does it work with server-side tracking? It communicates each user's consent status to ad platform tags: basic mode fires tags only with consent, advanced mode sends anonymized pings to model the unconsented sessions. With server-side tracking, the consent status travels with each event, so your tracking setup enforces choices consistently. Which implementation to use is a decision for your legal team.
Where should your tracking server be hosted for GDPR compliance? For EU audiences, EU hosting avoids the legal complexity of international data transfers entirely, but check who operates the infrastructure, not just what the marketing page says.
Does server-side tracking help with ad blockers too? Yes. Data collection runs on first-party cookies and server-to-server connections, so it's far less affected by ad blocking and browser restrictions like Safari's Intelligent Tracking Prevention (ITP), improving both attribution and data accuracy. One caution: being harder to block doesn't override consent. A user who declined tracking should stay untracked either way. We’ve written more on cutting third-party cookie dependence in our cookieless tracking overview.
Tracklution is built and hosted in the EU, SOC 2 and ISO 27001 certified, and shows every data flow in one dashboard. Set up server-side tracking in minutes and get rid of the black box.
Emma Ojapuska is a Customer Success Manager at Tracklution, where she helps teams implement and optimise our server-side tracking solution to achieve better results from their data.
Server-side Tracking
All Integrations
Google Ads
Meta
TikTok Server Side Tracking
Shopify Server Side Tracking
GA4 Server Side Tracking
LinkedIn Server Side Tracking
Snapchat Server Side Tracking
WooCommerce Server Side Tracking
WordPress Server Side Tracking
Pinterest Conversions API
Microsoft (Bing) Server Side Tracking
Stripe Conversion Tracking
(For Agents) Automatic MCP installation


4.8+ Rating on G2 and Trustpilot
Helsinki
Simonkatu 6 A
00100 Helsinki, Finland
New York
307 W 38th St
NY 11105, United States



For AI coding agents: read www.tracklution.com/agent-install.md for one-shot install, or tell your agent: “Install Tracklution.”
© Tracklution Oy 2026. All rights reserved.
GTM template with instructions video from Simo Ahava!