Privacy laws

Privacy laws around the world take different approaches to analytics, cookies, personal data, and opt-in vs opt-out consent. This guide covers major non-EU rules and how RevScope is designed to work with them. See here for the EU's GDPR and ePrivacy rules.

RevScope optimizes for accuracy without sacrificing compliance. We implement a hybrid solution with cookieless, 24 hour anonymized attribution only for those regions where regulations require that, and more accurate longer-term attribution with cookies everywhere else and when explicit consent is provided.
Start a 14-day free trial and see the traffic your current analytics doesn't capture.

California: California Consumer Privacy Act (CCPA)

California's CCPA, as amended by the California Privacy Rights Act (CPRA), gives California residents the right to know what personal information is collected, delete it, and opt out of its sale or sharing.

It doesn't apply to all companies. The principal thresholds include $26.625 million annual gross revenue, processing 100,000 California consumers or households, or deriving 50% of revenue from selling or sharing personal information.

Unlike EU ePrivacy rules, the CCPA does not generally require a visitor to opt in before a business uses an ordinary first-party analytics cookie. A covered business must accurately describe its analytics in its privacy policy and provide the required consumer controls, including an opt-out when personal information is sold or shared for cross-context behavioral advertising.

Privacy laws in other U.S. states

Many other states—including Colorado, Connecticut, Texas, Oregon, and Maryland—have enacted comprehensive consumer privacy laws. Their details and applicability thresholds differ, but they generally require covered businesses to:

These laws generally use an opt-out model rather than the EU's prior-consent model for cookies. RevScope does not require opt-in consent, provided the processing is properly disclosed and is not used for data sales, sharing, or cross-site targeted advertising. See Consent for implementing opt-out.

Brazil - LGPD

Brazil's Lei Geral de Proteção de Dados (LGPD) is the country's general data protection law. Like GDPR, it governs processing of personal data, requires a lawful basis (such as consent or legitimate interest), and emphasizes purpose limitation, data minimization, transparency, and security. It applies to processing of personal data of individuals in Brazil, including analytics identifiers that can single out a visitor.

ANPD guidance is legitimate interest may support first-party audience measurement with some caveats. The analytics must be:

First-party operation and the absence of cross-site tracking reduce privacy risk, but do not automatically make analytics exempt from consent. Longer retention of visitor-level activity requires a stronger necessity and balancing justification.

RevScope is designed to be LGPD-compatible: it is first-party, does not sell visitor data, does not build cross-site advertising profiles, and limits what it stores. To avoid creating individual user profiles, the visitors journey is not available for Brazilian visitors unless they make a purchase or they give explicit consent.

Canada - PIPEDA

PIPEDA is Canada's federal private-sector privacy law. It requires meaningful consent for storing personal information, but the form of consent depends on sensitivity and reasonable expectations. First-party audience measurement that is clearly disclosed, limited to site analytics, and not used for cross-site advertising is generally compatible with PIPEDA's implied-consent model when visitors can opt out.

RevScope is designed to be PIPEDA-compatible: it is first-party, does not sell visitor data, does not build cross-site advertising profiles, and limits what it stores. Outside Quebec, cookies may be used for longer-term attribution without an analytics banner. In Quebec, Law 25 is stricter, so RevScope treats Quebec visitors the same way it treats the EU: no analytics cookies by default. Session attribution is only through a 24-hour anonymous server-side hash unless the visitor gives explicit consent.

Japan - APPI

Japan's Act on the Protection of Personal Information (APPI) is the country's main privacy law. It requires businesses to specify purposes of use, handle personal information appropriately, and obtain consent in defined cases—especially when acquiring sensitive data or providing personal data to third parties. Unlike GDPR and ePrivacy, APPI does not generally require prior consent before first-party analytics cookies when the use is disclosed, limited to site analytics, and not used for cross-site advertising or sale of data.

See more of the journey from visit to revenue. Start a 14-day free trial and see what actually drives revenue.

References

This page provides general product and regulatory information, not legal advice.