Is document tracking GDPR compliant, and what should it record?
Document tracking can be GDPR compliant. It takes five things from the sender: a lawful basis for tracking, a notice telling recipients that viewing is tracked, only the data the follow-up needs, a set retention period, and a vendor that processes the data under a data processing agreement. GDPR-compliant document tracking rests on those five decisions, and a good tool makes each one easy to get right.
This page is for sales, marketing and investor relations teams who send decks through tracked links to people in the EU, and for the privacy and security reviewers who approve the tool. It covers what counts as personal data in document tracking, who is responsible for it, what recipients should be told, and the questions to put to any vendor. It is general information, not legal advice. Your data protection officer or counsel makes the final call.
Is document tracking GDPR compliant?
Document tracking is GDPR compliant when it is run within the regulation's principles: a lawful basis, transparency, data minimization, limited retention and security. GDPR does not ban tracking who opens a document. It governs how the personal data that tracking produces is collected, used and kept.
Document tracking produces personal data as soon as a view can be tied to a person. A deck sent to a named contact at a prospect, opened through a link that recorded their email address, is a record about that contact. The slide-level detail, which slides they read and for how long, is personal data too, because it describes that person's behavior.
The practical answer for most teams is that GDPR-compliant document tracking is achievable and routine, provided the five decisions in the opening paragraph are made on purpose. The compliance gaps teams do run into sit around the tracking: no notice to recipients, no stated retention period, no agreement with the vendor.
What counts as personal data in document tracking?
Listed below are the 7 kinds of data a document tracking tool can capture that may count as personal data under GDPR, depending on whether they can be linked to an identifiable person.
- Email address and name: captured when a link asks the viewer to identify themselves. Always personal data.
- IP address: sent by every browser. Personal data when it can be linked to a person, which is why storage method matters.
- Location: derived from the IP address. A country is coarse, a city is finer and a precise location is finer still.
- Device and browser details: from a device class to a full browser fingerprint. The more detail, the more identifying.
- Timestamps: when the link was opened and when the visit ended.
- Engagement: time on each slide or page, clicks, and links followed inside the document.
- Downloads: which file was downloaded and when.
Data minimization, one of GDPR's principles, asks whether each item serves the purpose. A sales team following up on a proposal needs to know that the deck was opened and which slides held attention. It rarely needs a city or a browser version.
Who is responsible for GDPR in document tracking?
The sender's organization is responsible for GDPR in document tracking as the data controller, and the tracking vendor acts as its data processor. The controller decides why the data is collected and what it is used for. The processor stores and processes it on the controller's instructions.
The relationship needs a data processing agreement, which GDPR requires between a controller and a processor. The agreement sets out what the vendor may do with the data, its security obligations, the sub-processors it uses and what happens to the data at the end of the contract. Reviewers also check where the data is hosted, because a transfer outside the EU and EEA needs its own safeguards.
The individual sender carries part of it in practice. The rep who turns off the email gate, or leaves tracking on for a personal contact, is making a controller's decision on the organization's behalf. Company-wide settings that fix those choices centrally take the decision off each rep.
What lawful basis does document tracking use?
Document tracking usually relies on legitimate interests or on consent, the two lawful bases that fit a sender following up on a document they chose to share. The sender picks one, records the reasoning, and names it in the privacy notice.
Legitimate interests fits many business-to-business sends: a proposal to a contact who asked for it, a deck after a meeting, an investor update to an existing investor. It requires a balancing test that weighs the sender's interest in knowing the deck was read against what the recipient would reasonably expect. Slide-level tracking of a deck a prospect requested is easier to justify than detailed tracking of a cold send.
Consent fits sends where the recipient has no existing relationship with the sender, or where the organization prefers an explicit opt-in. Consent under GDPR has to be freely given, specific and as easy to withdraw as to give.
Rules on cookies and similar technologies can apply alongside GDPR in the EU, because a viewer that stores information in the recipient's browser raises its own question. Ask the vendor what the viewer stores and why, and put the answer in front of the person who owns the privacy notice.
What should recipients be told about document tracking?
Recipients should be told that viewing the document is tracked, who is tracking it, what is recorded and where to read more. GDPR's transparency principle requires that information when personal data is collected, in plain language.
Two places carry it. The first is the viewer itself: a visible notice on the screen the recipient sees before or while opening the document, linking to the sender's privacy notice. The second is the privacy notice, which should name document tracking as a purpose, the lawful basis, the retention period and the recipient's rights to access and erasure.
A notice in the viewer also changes how tracking reads to the recipient. A professional who sees that the sender tracks engagement reads it as ordinary business practice. One who finds out later reads it as surveillance.
What should you ask a document tracking vendor about GDPR?
Listed below are 8 questions to ask any document tracking vendor during a GDPR review, with the answer that makes the review straightforward.
- Where is the data hosted? Look for a named region inside the EU, and a list of sub-processors with their locations.
- Is there a data processing agreement? It should be available before signature, not negotiated after it.
- Is the IP address stored? The best answer is that it is not stored in readable form, or not stored at all.
- How precise is location? Country level covers most follow-up needs.
- What does the viewer store in the browser? A session cookie for access state is the minimum. Ask about anything beyond it.
- Can tracking be switched off? Per link, and company-wide, so a policy can be enforced.
- Can the email gate be controlled centrally? The organization, not each rep, should decide when viewers are asked for their email.
- How long is engagement data kept? A fixed period with automatic deletion is easier to defend than indefinite storage.
Security certifications answer a different question from GDPR, whether the vendor protects the data it holds. SOC 2 Type II is the audit most reviewers ask for. The wider set of link controls, passwords, expiry and download permissions, is covered in the guide to sharing documents securely.
How does GDPR-compliant document tracking compare across data points?
GDPR-compliant document tracking records the data points a follow-up needs and leaves out the rest. The table below sets out the common data points, what each one tells the sender, and the minimisation question each one raises.
| Data point | What it tells the sender | Minimisation question | Lighter option |
|---|---|---|---|
| Viewer identity | Who opened the document | Does this send need a named viewer, or is an open enough? | Ask for an email only on links where follow-up depends on it |
| IP address | Distinguishes one visitor from another | Does anyone need to read the address? | Store a one-way hash, never the address |
| Location | Where the viewer was | Does the follow-up need more than a country? | Country code only |
| Device | How the document was read | Does the team need the browser and operating system? | Desktop, mobile or tablet only |
| Slide engagement | Which content held attention | How long does the team use it after the deal? | Automatic deletion after a fixed period |
The lighter option in each row still answers the follow-up question. The category of tool, and the analytics depth each one offers, is set out in the overview of document tracking tools.
How does SlideHub handle GDPR for document tracking?
SlideHub handles GDPR for document tracking by recording a short, fixed list of data points per visit and giving the organization central control over when tracking and identification happen. SlideHub records, per visit, when the visit started and ended, the country as a two-letter code, the device type as desktop, mobile or tablet, the time spent on each slide and the clicks on it, which files were downloaded, and which links in the deck were followed. It records the viewer's name and email only when the link asks for them.
SlideHub does not store the viewer's IP address in readable form, only as a one-way hash salted per link, and it does not record the city, the browser, the operating system or the user-agent string. The viewer keeps its state in a session cookie that remembers the password unlock and the email step. When tracking is on, the viewer's entry screens carry a notice that the content is tracked, with a link to more detail.
Administrators set the rules company-wide. Tracking can be left to each link or forced on or off for every link, the email gate can be disabled, optional or mandatory, and link statistics can stay private to the sender. Visit, slide engagement, download and link-click records older than two years are deleted automatically. Customer data is hosted in AWS Ireland, SlideHub is SOC 2 Type II certified, and the data processing agreement and the security overview are published for review. The send-and-track feature sits in the same library the deck came from, so the tracked version is the approved version.
More than 500 organizations use SlideHub each month, including KPMG, Netcompany and Bech-Bruun, and the platform is rated 4.9/5 on G2. Teams can compare plans on the pricing page or book a demo and bring their privacy reviewer's questions.
Frequently asked questions about GDPR and document tracking
Is document tracking legal under GDPR?
Document tracking can be run lawfully under GDPR. The sender needs a lawful basis for processing the recipient's data, has to tell the recipient that viewing is tracked, should collect only what the follow-up needs, and should keep it for a set period. The tracking vendor processes the data on the sender's behalf under a data processing agreement. This is general information, not legal advice.
Do I need consent to track who opens a document I send?
Not always. Many senders rely on legitimate interests for tracking a deck sent to a business contact, after weighing their interest against the recipient's expectations, while others ask for consent. Rules on cookies and similar technologies can apply on top of GDPR. The choice of basis belongs to the sender and its data protection officer.
Is an IP address personal data under GDPR?
An IP address can be personal data when it can be linked to a person, which is why a tracking tool should say whether it stores the address, how, and for how long. Storing only a one-way hash of the address, or deriving a country from it without keeping it, reduces what the tool holds about each viewer.
How long should document tracking data be kept?
GDPR sets no fixed period. It asks that personal data be kept no longer than the purpose needs. For deal follow-up, that is often the length of a sales cycle plus a margin for reporting. Pick a period, write it into the privacy notice, and choose a tool that deletes engagement records automatically when they age out.
What is the difference between document tracking and email tracking?
Email tracking loads a hidden pixel when an email is opened, often without the recipient noticing. Document tracking records what happens after the recipient chooses to open a shared link, such as which slides they viewed and for how long. The two raise different questions under GDPR and the ePrivacy rules, so assess them separately.
See how it works
Book a personalized demo to see how SlideHub could help in your organization