Consent, Cookies and Tracked Links: What GDPR Actually Applies
This article is not legal advice and cannot be. It names the instruments, describes the shape of the obligations they create, and stops there. Whether any of it applies to you, and what you must do about it, is a question for a lawyer who knows your business and your jurisdiction.
With that said: most of what freelancers and small teams believe about this is wrong in a specific and fixable way. They think there is one law. There are at least two, they govern different things, and confusing them is why people either panic or ignore the whole subject.
Two laws, two different objects
The ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC) governs the act of storing something on, or reading something from, a person’s device. Article 5(3) is the famous one — the "cookie rule". It requires informed consent for storage or access, with a narrow exemption for what is strictly necessary to provide a service the user explicitly requested. In the UK the same rule lives in the Privacy and Electronic Communications Regulations 2003, regulation 6.
The GDPR (Regulation (EU) 2016/679) governs what you then do with personal data. It is what decides whether you may keep it, for how long, on what basis, and what you owe the person it describes.
The cookie rule bites at the moment the cookie is set, regardless of whether the data is personal. The GDPR bites afterwards, and only if the data identifies somebody — which, per Recital 30 and Article 4(1), online identifiers and IP addresses generally can.
Are you the controller? Almost certainly yes
This surprises people. If you send a tracked link to a client, you decide why the reading is measured and what you do with the result. Under Article 4(7) that makes you the controller of that data. The tool you used is your processor.
The practical consequence is that the obligations land on you, not on your vendor, and they land on you even if you are one person with a laptop. Article 3 gives GDPR its reach: if you are established in the EU, or you are offering goods or services to people in the EU, it is in scope regardless of where you are sitting.
Article 28 then requires the arrangement with your processor to be in a written contract with specified terms. If you are handling EU or UK client data through any tool of this kind, asking the vendor for that agreement in writing is a reasonable thing to do and a bad answer is informative.
Consent or legitimate interests?
The GDPR side needs a lawful basis from Article 6(1). Two are realistically in play for read data.
- Legitimate interests, Article 6(1)(f). The one most B2B senders rely on: you have a real interest in knowing whether the proposal you were asked for was read, and the reader would not be surprised by it. It is not a free pass — it requires you to have actually balanced your interest against the reader’s rights, and Recital 47 makes reasonable expectations the pivot. Written down, that balancing is a legitimate interests assessment; a page of it is enough for a one-person business, and having none is the failure mode.
- Consent, Article 6(1)(a). Stricter, and harder than it looks, because Article 4(11) and Article 7 require it to be freely given, specific, informed and as easy to withdraw as to give. A notice at the foot of a screen is not consent. If you need consent, you need a mechanism.
And here is the part that trips everyone: the lawful basis you pick for the GDPR side does nothing about the ePrivacy side. If Article 5(3) requires consent for the cookie, having legitimate interests for the data does not rescue you.
The cookie question, answered honestly
A tracked document link sets a first-party cookie holding a random identifier, so that a return visit can be told apart from a new reader. Under Article 5(3) the question is whether that is "strictly necessary" for a service the reader explicitly requested.
Analytics cookies are conventionally treated by European regulators as outside that exemption — the reader asked to see the document, not to be counted. Some national authorities have carved out narrow room for strictly first-party, non-shared audience measurement; the CNIL’s guidance on audience measurement exemptions is the most-cited example, and it comes with conditions rather than being a blanket permission. Whether your use fits is exactly the kind of question that needs a lawyer rather than a blog.
What Quixli does, plainly, so you can put it into that assessment yourself: a shared document sets one first-party cookie with a random value and a one-year lifetime, displays a permanent notice telling the reader that the author can see view statistics, and does not present a consent banner. That is a deliberate design choice about a document a named person was sent, not a legal conclusion about your situation, and if your compliance position requires consent before any non-essential storage then it is a gap you need to close on your side.
The four obligations that actually generate work
- Transparency — Articles 13 and 14. The person has to be told who is processing their data and why. Article 14 covers the case where you did not get the data from them directly, which is most of this. In practice: your privacy notice should say that you use read tracking on documents you send, and one line in it is worth more than a paragraph nobody finds.
- Minimisation — Article 5(1)(c). Adequate, relevant and limited to what is necessary. This is a real constraint on feature choice, not a slogan: it is the argument for not having a scroll heatmap you would never act on.
- Storage limitation — Article 5(1)(e). Kept no longer than necessary for the purpose. Read data has a short useful life and a long liability tail, which is the whole subject of how long you should keep read data.
- Individual rights — Articles 15 and 17. A reader can ask you what you hold about them and can ask you to erase it. If you are the controller, that request comes to you and you have to be able to act on it. Being able to delete every tracking row for one document in one action is the difference between a manageable request and an embarrassing one.
California and the rest
The CCPA as amended by the CPRA works differently and it is a mistake to reason about it by analogy. Read data of an identifiable person is personal information under Cal. Civ. Code § 1798.140; § 1798.100 requires notice at or before collection; § 1798.105 is the deletion right; § 1798.120 is the opt-out of sale or sharing, where "sharing" has a specific meaning tied to cross-context behavioural advertising. Simply measuring your own document is a long way from that, but the notice obligation is not conditional on it.
One honest disclosure belongs here. California’s regulations at 11 CCR § 7025 treat an opt-out preference signal such as Global Privacy Control as a valid request where it applies. Quixli does not currently detect or act on Global Privacy Control or Do Not Track headers on shared documents. If honouring those signals is part of your compliance posture, that is a gap you should know about before you send anything.
What a small sender should actually do
- Have a privacy notice, and put one sentence in it about read tracking on documents you send.
- Write down, once, why you measure and why it is proportionate. A page. Keep it.
- Ask your vendor for the Article 28 processing terms in writing before you rely on the tool for client work.
- Set yourself a retention habit and keep it, rather than accumulating by default.
- Be able to answer, in one email, what you hold and to delete it. Test that you can, before somebody asks.
- Take advice if your clients are consumers, if you are in a regulated sector, or if you would be relying on consent rather than legitimate interests.
None of the above is a legal opinion and none of it is a substitute for one. It is a description of what the instruments say, which is the part most articles on this subject skip in favour of reassurance.
For what is actually in the database that these rules attach to, what a tracked link collects and what it does not is the inventory. The controls on each share — expiry, revocation, the gate — are documented in full.