What information can a website legally collect?
Technically, a website receives a network address, the page requested, the referring page and the browser's own description of itself, before anyone installs anything. What you may lawfully store, for how long, and whether you need permission first is a different question, and it depends on where your visitors live rather than where you are.
This is not legal advice, and we sell a product in this area, so read it with that in mind. Rules differ by jurisdiction, they change, and the penalties for getting consent wrong are real. Anything below is background for a conversation with someone qualified, not a substitute for one.
What arrives automatically
Some information is inherent to how the web works. A browser has to say what it wants and where to send it, so a server necessarily receives:
- • The network address the request came from, which resolves to an approximate location.
- • Which page was requested, and often which page linked to it.
- • A user-agent string describing the browser and operating system.
- • The language the browser prefers.
What tools add on top
Analytics scripts go further: how long someone stayed, what they clicked, which pages they moved between, and whether this browser has been before. That last one usually requires storing something on the device, which is where cookie and consent rules start to apply.
There is a meaningful difference between reading what the browser sent anyway and storing an identifier to recognise someone later. Several regimes treat those differently, and it is worth knowing which side of the line your tools sit on.
Why the answer depends on your visitors
The obligations generally follow the person, not the business. A company in the United States with customers in Germany is dealing with European rules for those visitors, and the EU and UK regimes are considerably stricter than most US state laws about what may happen before consent.
This is the single most common misunderstanding on this topic: that being based somewhere permissive settles it. It does not.
The questions worth asking
If you take one thing to an adviser, take these:
- • Where do my visitors actually live, and which rules follow from that?
- • Does anything I use store an identifier on a visitor's device, and does that need consent before it loads?
- • How long is data kept, by me and by every third party processing it on my behalf?
- • Who else receives it, and where are their servers?
- • What would I have to do if a visitor asked me to delete what I hold about them?
What to do in the meantime
Collect less than you can. The safest data is the data you never stored, and most small businesses need far less than their tools collect by default.
Say plainly in your privacy notice what you collect and why. That is expected everywhere, costs nothing, and is the part most sites do worst.
Find what is costing you search clicks, then watch the fix work.
VisitorPing reads your own Search Console data for the pages losing clicks, then rings your phone the moment someone lands on your website.