Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Able CDP is a customer data platform focused on server side conversion tracking and first party data collection for advertising platforms, operating from the United Kingdom. It captures conversions and customer events, resolves identity, and forwards events server side to platforms such as Google Ads and Meta. It favours first party and server side collection but still relies on identifiers that link activity to a person.
Able CDP is a customer data platform that focuses on server side conversion tracking and first party data collection for advertising platforms. It operates from the United Kingdom and captures conversions and customer events, resolves identity across touchpoints and forwards the resulting events server side to platforms such as Google Ads and Meta. The aim is to keep measurement accurate even when browser based tracking is restricted, while collecting data from a first party context.
Able CDP processes personal data such as conversion events, contact details used to match a customer and the identifiers that tie an event to a person. Although it favours first party and server side collection, it still relies on identifiers, including a first party cookie, so it is not a tracking free solution. Because that identifier is stored and read on the user device, it falls within the ePrivacy rules, and the matching of customer details supports identity resolution under the GDPR.
Under the GDPR, the website operator is normally the controller and Able CDP acts as a processor for the conversion tracking it performs on your behalf, while advertising platforms often act as separate or joint controllers for their own purposes. The conversion identifiers are not strictly necessary to deliver the website, so under article 5(3) of the ePrivacy Directive they require consent before being stored or read. Moving the tracking to the server does not remove this requirement, because the same personal data is still collected.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent should be obtained through a compliant consent banner before the conversion identifier is set and before events are forwarded to advertising platforms. The consent must be freely given, specific, informed and easy to withdraw, and the choice should genuinely control whether data is sent server side. A common approach is to pass the consent signal to Able CDP so that forwarding only happens for users who agreed. Keep records of how and when consent was collected.
Able CDP operates from the United Kingdom, which benefits from a European Commission adequacy decision, so the transfer to Able CDP itself is generally straightforward. However, it forwards conversion data to advertising platforms in the United States, and those onward transfers rely on the EU US Data Privacy Framework or on the EU Standard Contractual Clauses with a transfer impact assessment. You remain responsible for the lawfulness of the data you send to those platforms.
In practice, connect Able CDP to your consent management platform so that the conversion identifier and the server side forwarding only run with consent. Describe the conversion tracking and the sharing with advertising platforms in your privacy policy. Sign a data processing agreement with Able CDP, confirm the basis for each platform you forward to, set a sensible retention period and apply data minimisation to the fields you match. Review the setup whenever you add a new advertising destination.
Websites using Able CDP must obtain user consent under GDPR regulations.
DPIA considerations
Able CDP resolves identity and forwards conversion data to advertising platforms, so it can build a detailed view of customers and support advertising profiling. A data protection impact assessment is advisable. Assess the lawful basis for the conversion identifiers, the identity resolution logic, retention, and the onward transfers to platforms in the United States, since server side forwarding does not remove these obligations.
Sample consent text
We use Able CDP to measure conversions and to share marketing events with advertising platforms. With your consent, Able CDP sets a first party identifier and forwards conversion data server side to partners such as Google Ads and Meta. You can refuse or withdraw consent at any time.
Third-party domains contacted
able-cdp.comapi.able-cdp.comcdn.able-cdp.comtrack.able-cdp.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _able_uid | first party | persistent, up to 1 year | Conversion tracking identifier that links a visit to a later conversion |
| able_session | first party | session | Maintains the visitor session during conversion capture |
| _able_evt | first party | persistent, up to 90 days | Stores recent event data used for server side forwarding to advertising platforms |
Able CDP collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Yes. Even though Able CDP favours first party and server side collection, it still relies on identifiers, including a first party cookie that links conversions to a visitor. It may also use a short lived session identifier. Because these are not strictly necessary, they require consent before being stored or read.
Yes. The conversion identifiers need consent under article 5(3) of the ePrivacy Directive, and forwarding the data to advertising platforms needs a lawful basis under the GDPR. Moving the tracking to the server does not remove this, since the same personal data is collected. You should obtain consent before the identifier is set or events are forwarded.
The most appropriate basis is consent under article 6(1)(a) of the GDPR, paired with ePrivacy consent for the conversion identifiers. Because the data is shared with advertising platforms for marketing, consent is generally the safest basis. Record it in your records of processing and make sure the consent signal actually controls the forwarding.
Able CDP itself operates from the United Kingdom, which has a European Commission adequacy decision, so that transfer is generally straightforward. However it forwards conversion data to advertising platforms in the United States, and those onward transfers rely on the EU US Data Privacy Framework or the EU Standard Contractual Clauses with a transfer impact assessment.
A data protection impact assessment is advisable because Able CDP resolves identity and forwards data to advertising platforms, which supports profiling. The assessment should examine the lawful basis, the identity resolution logic, the fields you match, retention and the onward transfers to the United States.
Connect Able CDP to your consent management platform so the conversion identifier and the server side forwarding only run with consent. Describe the conversion tracking and the sharing with advertising platforms in your privacy policy. Sign a data processing agreement, minimise the fields you match and confirm the basis for each destination.
Some measurement tools keep data within the European Union and avoid forwarding to advertising platforms, which reduces transfer risk. Aggregated or consent based modelling can also lower the amount of personal data shared. The right choice depends on how much you depend on platform conversion data and where you want it stored.
List the Able CDP first party conversion cookie with its purpose and duration and explain the server side forwarding. State which advertising platforms receive data and that some forwarding involves transfers to the United States. Keep the policy aligned with what your consent banner actually controls.