Privacy Mode B — privacy posture & DPIA guidance
⚠️ DRAFT — pending external counsel review. This page is the companion to the A→B upgrade step in your site’s Settings → Privacy & data. The wording and the cookie-banner recommendation below are our interim position and may change after our external data-protection counsel completes their review. Nothing here is legal advice; confirm your own DPIA with your data-protection adviser.
What Mode B is
Mode B (Balanced) gives you unique visitors, sessions, and bounce rate without a
cookie banner. It derives a per-visitor identifier on our servers from a daily
rotating salt that is destroyed within 48 hours. There is no cookie, no
localStorage, no device fingerprint — nothing is stored on or read from the
visitor’s device.
Our interim, conservative wording for what Mode B is:
Pseudonymous while the daily salt lives, anonymous after destruction; processed under legitimate interest (Art 6(1)(f)); no cookie banner required because no information is stored on or read from the user’s device (ePrivacy Art 5(3) is not engaged).
We deliberately do not claim, unqualified: “collects no personal data,” “fully anonymous,” “GDPR compliant,” or “exempt from [specific DPA] requirements.”
Do I need a cookie banner?
Because Mode B stores nothing on the device, the ePrivacy Art 5(3) consent requirement (the “cookie banner”) is not engaged, and the processing runs under legitimate interest (GDPR Art 6(1)(f)). So in the general case: no banner is required.
The upgrade dialog shows a region-aware note based on your site’s recent traffic:
| Your EU/EEA traffic share | What we recommend |
|---|---|
| Below 50% | Standard: no cookie banner required under legitimate interest. |
| 50% or more | Same legal basis, but confirm the legitimate-interest assessment fits your DPIA, given your majority-EU/EEA audience. |
Open items for counsel (tracked, may change this page): the exact 50% threshold, which countries count as “EU/EEA” (we currently use EU-27 + Iceland, Liechtenstein, Norway; GB / UK is handled separately under UK GDPR), and whether the wording above is defensible as written.
What changes when you upgrade a region A → B
- New events for visitors in that region get a server-derived
visitor_idandsession_id; your dashboard’s Unique Visitors, Bounce Rate, Avg Session Duration, Entry Pages, and per-page metrics light up for that traffic. - History is untouched — there is no backfill (past daily salts are already destroyed, so prior events cannot be re-identified).
user_idstays null (that’s Mode C, a separate, consent-gated mode).
Switching back (B → A)
Downgrading is self-serve and non-destructive: it simply stops deriving identifiers for that region’s future visitors. Existing Mode B rows are unaffected — their identifiers are already anonymous once the daily salt is destroyed.