Link Management14 min read

GDPR-Compliant URL Shortener: What to Check Before You Choose One

A buyer's checklist for choosing a GDPR-compliant URL shortener: what click tracking actually collects, where IP addresses and cookies create legal work, and the questions to put to a vendor before you sign.

UseClick TeamAuthor
GDPR-Compliant URL Shortener: What to Check Before You Choose One

Quick answer: No URL shortener is "GDPR compliant" on its own. What you can choose is one that keeps your compliance work small. Look for a shortener that does not store IP addresses, sets no cookies on the redirect, names every processor and where your data lives, signs a data processing agreement (Art. 28 GDPR), deletes click data on a fixed schedule, and lets you export or delete everything. If a vendor cannot answer those points in writing, treat that as your answer.

Key takeaways

  • Every click is a request from a person's device. If the shortener stores the IP or sets a cookie, it processes personal data, and you, as controller, need a legal basis. The shortener is your processor, so a DPA under Art. 28 GDPR is required.
  • Cookies or similar identifiers stored on the visitor's device fall under the ePrivacy rules (in Germany, § 25 TDDDG, formerly TTDSG). A redirect that sets a tracking cookie can need consent before it fires, which a redirect has no way to ask for.
  • "EU hosted" is only part of the question. Ask which companies touch the traffic (hosting, CDN, edge) and what covers any transfer outside the EU.
  • Ask for retention in days and whether deletion is automatic.
  • This is not legal advice. Use the checklist to narrow the field, then have your data protection officer or counsel confirm your setup.

A redirect like go.acme.com/offer is a server receiving a request from the visitor's browser, carrying an IP address, a user agent string, a language header and often a referrer. What the shortener does with those values decides how much GDPR work you have.

Three things turn a redirect into personal data processing:

  1. IP addresses. The Court of Justice of the EU held in Breyer (C-582/14, 2016) that a dynamic IP address can be personal data for a website operator. Most regulators treat stored IPs as personal data by default.
  2. Identifiers on the device. A cookie, local storage entry or similar identifier that follows the visitor across clicks is an online identifier under Recital 30 GDPR, and storing or reading it is covered by Art. 5(3) of the ePrivacy Directive.
  3. Profiles. If the tool links clicks from the same person across your links, or worse, across other customers' links, it builds a profile. That is the pattern the older post on the hidden privacy risks of traditional link shorteners describes.

Once personal data is involved, the usual GDPR machinery applies: a legal basis under Art. 6 (for click statistics this is often legitimate interests under Art. 6(1)(f), sometimes consent under Art. 6(1)(a)), information for the people concerned (Art. 13), a processing record (Art. 30), a contract with your processor (Art. 28) and rules for any transfer outside the EU (Art. 44 onwards).

The practical goal is to pick a shortener whose design keeps as much of that off your desk as possible.

A website can show a consent banner before analytics scripts run. A redirect has no page to show one on: it answers with a 302 or 301 in milliseconds. If that response carries a tracking Set-Cookie header, the identifier is stored before anyone could agree to it.

Under Art. 5(3) ePrivacy, and § 25 TDDDG in Germany, storing information on a device needs consent unless it is strictly necessary for a service the user asked for. A tracking cookie on a redirect is hard to argue as strictly necessary. So the cleanest answer is a shortener that sets no cookies at all on the redirect. We covered the general case for cookie-free click tracking in why you don't need cookies to track clicks, and the banner question for websites in do you need a cookie consent banner.

One caution: "no cookies" is not the whole test. The European Data Protection Board's Guidelines 2/2023 on the technical scope of Art. 5(3) read the rule broadly, including some fingerprinting and tracking techniques that do not use cookies. So also ask how a cookie-free tool counts unique visitors.

What a click can carry, and what it means for you

This table is the quickest way to read a vendor's documentation. For each field, ask whether the shortener stores it, derives something from it, or drops it.

Data point How it arrives GDPR relevance What a privacy-friendly shortener does
IP address Every request Personal data in most readings Uses it in memory for coarse location, never stores it
Tracking cookie Set by the redirect Online identifier, ePrivacy consent issue Sets none
Full user agent string Every request Adds to fingerprinting risk Parses browser, OS and device type, discards the string
Visitor hash Computed by the vendor Pseudonymous data, depends on inputs Documents inputs, uses it only for unique counts, deletes it with the click
Country, region, city Derived at the edge Coarse location, lower risk Stores coarse location only, no GPS, no coordinates tied to a person
Referrer Request header Can contain personal data in URLs Stores it for attribution, covered by retention
Language Request header Low risk alone Stores the value, e.g. "de-DE"

On the hash row: under Recital 26 GDPR, pseudonymised data is still personal data if it can reasonably be linked back to a person. A hash of a stored IP plus a fixed key links back far more easily than a hash of coarse browser characteristics. Ask what goes in.

The first three decide whether the redirect itself creates consent problems. The rest decide how much paperwork you carry.

1. Are IP addresses stored?

The answer you want is "never", not "anonymised after 30 days" or "hidden in reports". A tool that stores full IPs and hides them in the dashboard still holds personal data on your behalf.

2. Does the redirect set any cookies or write to the device?

Test it: open your browser's network tab, click a short link and look for Set-Cookie on the redirect response. Also check for an intermediate page with scripts before the destination, which some free plans insert.

3. How are unique visitors counted?

Every tool that shows "unique clicks" recognises repeat visitors somehow. Ask what the identifier is built from, whether it is stored on the device, and whether it is linked across different customers' links.

4. What exactly is collected per click?

Ask for the field list. "Country, region, city, browser, OS, device type, language, referrer, timestamp" is an answer. "Standard analytics data" is not.

5. Does the vendor use click data for its own purposes?

Look for advertising, data sales or sharing with partners. A vendor that uses your audience's clicks for its own purposes is a controller for that part, and you have to tell your audience.

6. Where is data stored, and where does it travel?

"EU hosted" should mean the click database is in the EU. Traffic still passes through hosting, edge and CDN providers, often US companies. Transfers to the US can rely on the EU-US Data Privacy Framework (the Commission's adequacy decision of July 2023, Art. 45) or Standard Contractual Clauses (Art. 46). The vendor should name the mechanism for each provider.

7. Is there a complete processor list?

Art. 28(2) GDPR requires your authorisation for sub-processors, which in practice means a published list and notice of changes. Expect the database host, application host, CDN or edge network, and payment and email providers.

8. Will they sign a DPA?

Under Art. 28(3), the processor contract has to cover the subject matter, duration, purpose, types of data, confidentiality, security (Art. 32), sub-processors, assistance with data subject requests, and deletion at the end. In Germany this is the Auftragsverarbeitungsvertrag (AVV). Ask for it before you sign up for a paid plan, not after.

9. How long is click data kept?

Art. 5(1)(e) requires storage limitation. Ask for the number of days and whether deletion is automatic. "As long as your account exists" means you build the deletion routine yourself.

10. Can you export and delete?

You need CSV or API export for your records, deletion of single links with their data, and account deletion. If a visitor asks for access or erasure (Art. 15 and 17), the vendor must help you answer. With no stored IPs and no cookies, the honest answer is often that you cannot identify the person in the data, a situation Art. 11 GDPR addresses.

Questions to send a vendor before you buy

Copy these into an email. A good vendor answers quickly and in writing.

  1. Do you store visitor IP addresses anywhere, including logs? For how long?
  2. Does your redirect set cookies or use local storage? Does it ever show an intermediate page?
  3. How do you count unique visitors? What goes into the identifier, and where is it stored?
  4. Please list every field you store per click.
  5. Where is the click database located? Which providers process traffic or data outside the EU, and under which transfer mechanism?
  6. Where is your current sub-processor list, and how do you notify customers of changes?
  7. Can you send your DPA (AVV) for signature?
  8. What is the retention period for click data on the plan I am considering, and is deletion automatic?
  9. How do I export all click data, and how do I delete a link, its data and my account?
  10. Do you use my visitors' data for any purpose of your own?

How to read a shortener's privacy documentation

Read vendor privacy policies with two questions in mind.

Whose data is this sentence about? Many policies spend pages on account holders and one paragraph on the people who click. That paragraph is the one that matters for you.

Is it a design claim or a promise? "We anonymise IP addresses" can mean they are never stored, or truncated after storage, or hidden in the interface. "Industry-standard security" says nothing. Specific statements ("IP addresses are not stored", "click data is deleted after N days", "database hosted in Frankfurt") are the ones you can put in your records.

Also check that the policy, the DPA and the pricing page agree. Documents drift as products change; if two say different things, ask which is current, in writing.

For how GDPR and CCPA differ when your links reach both EU and US audiences, see the GDPR vs CCPA link tracking guide.

Is a US shortener automatically a problem?

No. Many people search for a "Bitly alternative for GDPR", but US-based services can be used lawfully in the EU: the Data Privacy Framework and SCCs give transfers a legal basis, and the same ten questions apply.

What differs is documentation and your organisation's risk appetite. Some German companies and public bodies want personal data to stay in the EU, and some data protection officers ask about US authorities' access to data held by US companies. There, a tool that stores little personal data in the first place shrinks the question.

The terms map directly: DSGVO is the GDPR, the AVV is the Art. 28 DPA, and the device storage rule is § 25 TDDDG (called TTDSG until 2024). German authorities are strict about consent for tracking cookies, so the redirect cookie check matters even more, and you will want the processor list for your Verzeichnis von Verarbeitungstätigkeiten (Art. 30 record).

How useClick handles this

Here is how useClick answers the checklist today:

  • No IP addresses stored. The IP is only used at request time to derive coarse location.
  • No cookies on the redirect. Click tracking happens server-side during the redirect. The only cookies useClick sets are login cookies for account holders in the dashboard.
  • Unique visitors are counted with a SHA-256 hash of coarse browser characteristics (a shortened user agent, language and time zone). No IP address goes into it, and nothing is stored on the visitor's device.
  • What is stored per click: country, region and city, browser, OS, device type, language, referrer and time. No full user agent, no GPS.
  • Location and providers: our privacy policy names Supabase (database hosted in Frankfurt, Germany), Vercel (application hosting, a US company, with the Data Privacy Framework and SCCs named as the transfer basis), Cloudflare (CDN and edge) and Stripe (payments).
  • Retention by plan, deleted automatically by a daily job: 30 days on Free, 12 months on Starter, 24 months on Growth and 3 years on Pro and Business. The details are in plans and limits.
  • Export and deletion: API access on every plan, CSV export from Starter, and self-service account deletion.
  • Custom domains on every plan, including Free, so your links live on go.yourcompany.com and you can move vendors later without breaking them.

More on the design is on the privacy-first analytics page. Whichever vendor you pick, us included, get the DPA and current processor list in writing for your records.

Frequently asked questions

Is there a GDPR-compliant URL shortener?

A shortener cannot be compliant for you, because compliance depends on how you use it. But some are designed to process very little personal data: no stored IPs, no cookies on the redirect, EU data storage, a DPA and automatic deletion. That makes your own work much smaller.

Only if the shortener stores or reads information on the visitor's device for a purpose that is not strictly necessary, such as a tracking cookie. A redirect that sets no cookies and uses no device identifiers generally does not trigger the ePrivacy consent rule. Check the redirect response yourself for Set-Cookie headers.

Is Bitly GDPR compliant?

That depends on your configuration, your contract and your own assessment, not on a label. Bitly is a US company, so you would rely on the Data Privacy Framework or SCCs for transfers. Ask Bitly, and any alternative, the ten questions above and compare the written answers.

If the shortener processes personal data of your link visitors on your behalf, yes. Art. 28 GDPR requires a written contract with every processor. Even a tool that stores little personal data still receives IP addresses in requests, so most data protection officers will want the DPA on file.

One whose click database is stored in the EU. Check that the claim covers the analytics data, not only the marketing site, and ask which non-EU providers still handle traffic, such as a CDN or application host, and under which transfer mechanism.

Only as long as you need it for the purpose, which is the storage limitation principle in Art. 5(1)(e). For campaign reporting, one to three years covers most annual comparisons. What matters most is that there is a fixed period and that deletion is automatic.

The decision in one paragraph

Pick the shortener that gives short, specific, written answers: no stored IPs, no cookies on the redirect, a documented unique-visitor method, a named database location and processor list, a signable DPA, retention in days, and self-service export and deletion. Each removes work from your side. Then run the setup past your data protection officer or counsel, because your legal basis and notices are still yours to get right. If you want to see what that looks like in a working product, start free on useClick with your own domain.

Try UseClick.io

A privacy-first platform for sharing links, building bio pages, and understanding your traffic.

Short Links Analytics, Link in Bio Pages, and Website Analytics

  • Branded short links with analytics for campaigns, destinations, and every click you share.
  • Link in Bio pages that bring your most important links together in one branded place.
  • Website analytics to understand traffic sources, top pages, and on-site performance.
Start for Free

No credit card required.

Ready to track smarter?

UseClick.io makes link management effortless. Create branded short links that are clean, memorable, and built to strengthen your brand identity.