Back to blog
    Legal & Compliance14 September 2026 9 min

    Cookieless analytics: measuring your audience without losing half the data

    Few business owners still look at their traffic reports with real confidence. Between consent banners that most visitors decline, ad blockers that strip out tracking scripts and browsers that cap how long a cookie survives, the figures in a conventional dashboard describe only a slice of what actually happened. The irony is hard to miss: companies have never spent more on measurement, and never trusted it less.

    The starting point is legal. The GDPR and the ePrivacy directive require prior, freely given and explicit consent before any cookie that is not strictly necessary to deliver the service. Regulators across Europe have hardened their position, fined major platforms and made clear that loading a tracking script before the visitor has chosen is already a breach. In practice, a European site now sees somewhere between thirty and sixty per cent of visitors refuse. Half the traffic simply vanishes from the reports.

    That gap is not harmless, because it distorts decisions. An acquisition channel whose audience declines tracking more often looks weaker than it is. A service page with heavy mobile traffic behind a blocker looks irrelevant. Budgets then get reallocated on the basis of a biased sample, which costs far more than the analytics tool itself. The first benefit of going cookieless is not compliance; it is that the numbers start meaning something again.

    The technical idea is straightforward. Instead of identifying a person and following them over time, a cookieless tool counts aggregated events either server-side or through a lightweight script that writes nothing to the device: a page view, a referrer, a device category, a country. Nothing is stored on the visitor's browser, no persistent identifier is built, and no data leaves the European Union. Handled this way, the processing falls outside the mandatory consent regime, provided the published exemption conditions are respected.

    There is a genuine trade-off and it deserves to be stated plainly: you lose the individual view. No three-week user journey reconstructed step by step, no last-click multi-touch attribution, no granular retention cohorts. What you get in return is a complete, unsampled, stable dataset. For the overwhelming majority of the companies we work with, that exchange is clearly worth making. They need to know which pages generate enquiries, not to reconstruct each visitor's digital biography.

    The tooling has matured considerably. Several European solutions now offer hosting on the continent, auditable source code, a footprint of a few kilobytes and enough reporting to run a site properly: entry pages, traffic sources, engagement, declared conversions. Some appear on regulators' lists of tools exempt from consent, which makes the compliance assessment far shorter. This is the kind of setup we deploy by default on the sites we build, including our own.

    The performance gain is worth spelling out, because it is measurable. A conventional stack with a tag manager, advertising pixels and a session-recording tool routinely adds several hundred kilobytes of JavaScript and delays interactivity. A cookieless script usually weighs under two kilobytes. On mobile, over a constrained network, that difference shows up directly in Core Web Vitals, and therefore in the signals Google uses to rank pages.

    The practical question is how to steer the business without individual identifiers. Our answer involves three shifts. First, measure commercial events rather than micro-interactions: form submitted, appointment booked, quote requested. Second, reason by period and entry page rather than by unique user, which is enough to spot a trend or the effect of a publication. Third, triangulate with two reliable free sources: Search Console for search performance, and the CRM or inbox for what actually closed.

    That last point matters most and is skipped most often. The useful question is not how many visitors came this month, but where the enquiries you genuinely handled came from. Adding a source field to a form, logging how a caller found you, noting the first channel a prospect mentions in a meeting: this qualitative evidence is worth more than any sessions chart, and no consent banner can take it away.

    A word on advertising, since the objection always comes up. If you run paid acquisition, the platforms require their own pixels and consent becomes necessary again for that specific purpose. Nothing prevents the two logics from coexisting: cookieless analytics running for one hundred per cent of traffic as the internal reference, and advertising tags gated behind consent, used solely to optimise campaigns. It is a clean architecture, defensible under audit and easy for a team to understand.

    Across the markets we operate in, from Paris to Stockholm, this approach has become a selling point. Public buyers, large accounts and increasingly private clients look at what loads on a page. A site with no intrusive banner, no dozen third-party trackers and no data leaving Europe signals seriousness before a single word of copy is read. Compliance, long treated as a defensive cost, turns into a differentiator.

    At AKREA DIGITAL we build this in from the outset. Our design and development work excludes unnecessary third-party trackers as a matter of principle, our digital audit inventories every script loaded and its legal basis, and our SEO and digital performance team uses that complete dataset to prioritise editorial work instead of guessing.