English
consentglass · GDPR scanner for websites

HomeGuides › Service

Using Matomo in compliance with the GDPR

Matomo can be self-hosted or used as Matomo Cloud (servers in Germany). Whether consent is required depends on cookies, IP handling and hosting — not on the name of the tool.

Is this a risk?

If Matomo sets cookies or reads other identifiers from the device, § 25 (1) TDDDG applies and prior consent is required. Some supervisory authorities consider a cookieless setup with immediate IP truncation and no cross-device merging defensible without consent, others are more cautious — there is no nationwide uniform clearance. With Matomo Cloud, a data processing agreement with InnoCraft is also needed.

What you can do

How consentglass helps

The free scan checks the delivered HTML and shows which services are embedded, whether a cookie banner is detected and whether privacy-policy and legal-notice links are present — with context for each finding. It is not a substitute for legal advice.

Read on

This text is general information to the best of our knowledge, not legal advice. For an individual case, consult a law firm specialising in IT law.