Privacy Battles
Simple Analytics
Privacy Score
94
%
⚔️
Plausible
Privacy Score
94
%

Designated DPO or GDPR correspondent

Compliant
Partially Compliant
Not Compliant

Simple Analytics doesn’t process personal data, therefore does not have to designate a DPO.

Simple has a privacy dedicated email contact available on the website: privacyquestions@simpleanalytics.com

Compliant
Partially Compliant
Not Compliant

Plausible doesn't mention having a DPO or GDPR correspondent but has a privacy dedicated email contact available on its website: privacy@plausible.io

Privacy Policy

Compliant
Partially Compliant
Not Compliant

Regarding cloud:
A Cloud Privacy Policy is not necessary as no personal data is processed in the Cloud.

Regarding website:
https://simpleanalytics.com/privacy-policy

Compliant
Partially Compliant
Not Compliant

Country & Type of Data storage

Compliant
Partially Compliant
Not Compliant

Company Headquarters:
The Netherlands 🇳🇱  (EU) 🇪🇺

Storage Facilities:
All analytics data is processed by Dutch cloud providers Worldstream and Leaseweb.

Compliant
Partially Compliant
Not Compliant

Company Headquarters:
Estonia 🇪🇪  (EU) 🇪🇺

Storage Facilities:
All analytics data is processed by German cloud provider Hetzner, in Germany.

Possibility to host Plausible Analytics on controller premises.

Data transfers outside the EU

Compliant
Partially Compliant
Not Compliant

Data is never transferred outside the EU.

Compliant
Partially Compliant
Not Compliant

Plausible doesn’t transfer analytics data outside the EU.

Legal tools for Subcontractors

Compliant
Partially Compliant
Not Compliant

Simple has only one subcontractor for CDN that is called BunnyCDN and is part of a company called BunnyWay, located in Slovenia (EU). They have concluded a written agreement protecting personal data processed on BunnyCDN's part.

Compliant
Partially Compliant
Not Compliant

For every subcontractor, Plausible assesses its commitment to privacy and signs a DPA including controller-processor Standard Contractual Clauses.

Plausible has made public its list of subprocessors: https://plausible.io/privacy

Data Breach Notification

Compliant
Partially Compliant
Not Compliant

Simple shares technical incidents on its website: https://status.simpleanalytics.com/?ref=simpleanalytics.com

Simple doesn’t process personal data and therefore a data breach cannot be materialized nor notified.

Compliant
Partially Compliant
Not Compliant

In case of data breach, Plausible will notify the controller without undue delay by email (not later than 48 hours after having become aware of it) and provide a description of the incident as well as periodic updates about the incident, including its impact.

Right Requests Process

Compliant
Partially Compliant
Not Compliant

Simple doesn’t process personal data therefore does not have to fulfill this GDPR obligation.

Compliant
Partially Compliant
Not Compliant

Data requests will be forwarded to the controller without delay.

Data Privacy Impact Assessment

Compliant
Partially Compliant
Not Compliant

Simple doesn’t process personal data therefore does not have to fulfill this GDPR obligation.

Compliant
Partially Compliant
Not Compliant

Plausible will provide assistance to the controller for DPIAs.

Employee Trainings

Compliant
Partially Compliant
Not Compliant

Simple doesn't process personal data and therefore is not obliged by the GDPR to have its employees subject to confidentiality obligations and trainings on personal data management.

Compliant
Partially Compliant
Not Compliant

Employees required to access analytics data are informed of the confidential nature of the data and comply with the GDPR obligations sets out in the DPA.

Security Policy

Compliant
Partially Compliant
Not Compliant

Simple doesn’t mention having a security policy.

Compliant
Partially Compliant
Not Compliant

Plausible doesn’t mention having a security policy.

Organizational and Technical Security Measures

Compliant
Partially Compliant
Not Compliant

Server security:
Cloud security relies on Worldstream and Leaseweb.

Other measures:
Anonymisation and pseudonymisation of data, password encryption, backups on external servers.

Compliant
Partially Compliant
Not Compliant

Plausible doesn’t mention having a security policy.

Data Encryption

Compliant
Partially Compliant
Not Compliant

Data is encrypted at rest.

Compliant
Partially Compliant
Not Compliant

Data is encrypted in transit (HTTPS) and at rest.

Restriction of access

Compliant
Partially Compliant
Not Compliant

Simple doesn’t process personal data therefore does not have to fulfill this GDPR obligation.

Compliant
Partially Compliant
Not Compliant

Plausible allows external access or processing of personal data to employees submitted to confidentiality clauses for IT support and maintenance.

Reuse of data

Compliant
Partially Compliant
Not Compliant

Swetrix doesn’t reuse personal data, nor sell it.

Compliant
Partially Compliant
Not Compliant

Plausible doesn’t reuse analytics data or share it with third-parties.

Exemption of cookie consent

Compliant
Partially Compliant
Not Compliant

YES, Simple doesn’t set any cookies.

Compliant
Partially Compliant
Not Compliant

Plausible doesn’t collect cookies.

Submission to Cloud Act/FISA

Compliant
Partially Compliant
Not Compliant

NO, data is stored in the EU and anonymized (therefore no more considered personal).

Compliant
Partially Compliant
Not Compliant

NO, data is stored in the EU by an European cloud provider.