FlowConsent
ServicesBlogExtensionSolutionsPricingTry FlowConsent
FlowConsent

FlowConsent is a GDPR-compliant cookie consent management platform.

Product

  • Services
  • Extension
  • Extension support
  • Solutions
  • Pricing
  • FlowConsent App

Legal

  • Privacy Policy
  • Terms of Service
  • Legal notice

© 2026 FlowConsent by BeBranded. All rights reserved.

FrancaisDeutschEspanol

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Analytics
  4. CARTO Data Observatory
C

CARTO Data Observatory

AnalyticsWebsite

Related services

34SP.com

34SP.com is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 34SP.com supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 34SP.com enables informed decisions that improve experience and drive results.

Analytics
5

51.LA

51.LA is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. 51.LA supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, 51.LA enables informed decisions that improve experience and drive results.

Analytics

52Degrees

52Degrees is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. 52Degrees offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, 52Degrees empowers organizations to optimize strategy and maximize return on investment.

Analytics
A

a3 Lazy Load

a3 Lazy Load is a comprehensive e-commerce platform that provides businesses with all the tools needed to build, manage, and grow an online store. From product catalog management and secure payment processing to inventory tracking and order fulfillment, a3 Lazy Load delivers a complete commerce solution. It features responsive storefront themes, SEO-optimized product pages, and powerful marketing tools to help merchants increase visibility and drive sales across channels.

Analytics
A

Able CDP

Able CDP is a digital analytics solution that helps businesses measure and understand their online performance through comprehensive data collection and analysis. It provides visitor tracking, behavioral insights, and conversion metrics across websites and applications. Able CDP supports custom event tracking, audience segmentation, and automated reporting. With intuitive dashboards and visualization tools, Able CDP enables informed decisions that improve experience and drive results.

Analytics
A

Abralytics

Abralytics is an analytics and measurement platform providing deep insights into digital ecosystem performance. It tracks user interactions, measures campaign effectiveness, and identifies optimization opportunities across web and mobile. Abralytics offers customizable dashboards, automated alerts, and data export capabilities. By transforming raw data into actionable intelligence, Abralytics empowers organizations to optimize strategy and maximize return on investment.

Analytics
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does CARTO Data Observatory do?

The CARTO Data Observatory is a geospatial data marketplace and enrichment service built into the CARTO platform. It lets analysts subscribe to curated location datasets (demographics, points of interest, mobility, weather) and join them inside their cloud data warehouse via SQL.

What the Data Observatory does

The CARTO Data Observatory is a catalogue and delivery layer for geospatial datasets, embedded in the CARTO platform. Users browse hundreds of curated datasets covering demographics, points of interest, human mobility, real estate, weather, and administrative boundaries, then subscribe and run spatial joins directly inside their cloud data warehouse (BigQuery, Snowflake, Redshift, or Databricks). Data flows server side through CARTO APIs without leaving the customer warehouse perimeter, which makes it primarily a back office analytics tool rather than a website tracker. The CARTO marketing site and product UI are the only web surfaces that load classic cookies.

Cookies and data collected

On the CARTO website and platform UI, cookies are set for authentication (session, CSRF), for product analytics (Mixpanel or Amplitude), for support chat (Intercom), and for marketing on the public site (Google Analytics 4, HubSpot, LinkedIn Insight Tag). Inside the Data Observatory itself, the data exchanged is mostly aggregated statistical or geographic data, not personal data. Personal data appears only in account profiles, billing, support tickets, and audit logs of who subscribed to which dataset and when.

GDPR and ePrivacy implications

For paid customers, the lawful basis is contract performance under Article 6(1)(b) GDPR. Strictly necessary session cookies are exempt under Article 5(3) ePrivacy. All marketing, analytics, and support cookies on the carto.com website and on dashboards require prior, freely given, specific, informed, and unambiguous consent. CARTO acts as a processor for customer account data and as a controller for its own marketing site. Customers must sign the CARTO DPA and review the sub-processor list.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Datasets, licences, and personal data

Most datasets in the Data Observatory are aggregated to administrative units (NUTS regions, postal codes, hexagons, census blocks) and contain no directly identifiable personal data. Some mobility, telco, or geomarketing datasets may be derived from personal data and licensed under specific terms. Customers must read each dataset licence, identify whether the source is GDPR personal data, and document the lawful basis for combining it with their own data, especially when joining customer level identifiers.

International data transfers

CARTO operates from Spain and the United States and uses AWS and Google Cloud as infrastructure providers. EU customers can request EU only deployment for the platform tenant, but support and corporate functions involve US staff and tools. Transfers rely on Standard Contractual Clauses, the EU US Data Privacy Framework where the partner is certified, and supplementary measures (encryption, role based access). A Transfer Impact Assessment is required for the operational metadata flow.

Practical compliance steps

Sign the CARTO DPA, attach the SCC and DPF documentation, and pick the EU region for sensitive deployments. Configure SSO, role based access, and audit logging. Enforce a cookie banner on your CARTO dashboards if exposed to end users, and treat the carto.com marketing site cookies as opt in. Read each Data Observatory dataset licence, document the lawful basis for any join with personal data, and align retention with internal policies.

GDPR consent category

Analytics

Websites using CARTO Data Observatory must obtain user consent under GDPR regulations.

Legal basisArticle 6(1)(b) GDPR contract performance for paid CARTO subscriptions, Article 6(1)(f) legitimate interest for security logs, and Article 6(1)(a) consent for non essential cookies on the marketing site under Article 5(3) ePrivacy.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive, EU US Data Privacy Framework, UK GDPR, LOPDGDD (Spain), Loi Informatique et Libertés, BDSG/TTDSG, Codice Privacy, plus dataset specific terms (e.g. Eurostat, INE, OpenStreetMap licences).

DPIA considerations

A full DPIA is generally not required because the Data Observatory mainly delivers aggregated geospatial datasets server side. A DPIA becomes necessary if customers join the data with personal data of EU individuals at scale, especially mobility, telco, or sociodemographic feeds. The AEPD and EDPB consider large scale geolocation analytics as DPIA prone activities. Document data flows, sub-processors, retention, and a Transfer Impact Assessment.

Sample consent text

We use CARTO and the CARTO Data Observatory to enrich our analytics with curated geospatial data. Strictly necessary cookies keep your session secure. Analytics, marketing, and chat cookies are only set with your consent and you can change your preferences at any time.

Technical details

Tracking methodServer-side geospatial data marketplace and enrichment API integrated with cloud data warehouses (BigQuery, Snowflake, Redshift, Databricks). Customer SQL workloads call CARTO endpoints to subscribe to or join curated geospatial datasets. The CARTO website itself loads marketing analytics, support widgets, and product cookies on authenticated dashboards.
Server locationSpain (Madrid) and the United States (AWS us-east-1, Google Cloud us-central1) operated by CARTO. European customers can opt for an EU region for the platform tenant.
Data transferred outside the EUAccount metadata, dashboard usage, and dataset subscription logs may be processed in the United States. Geospatial datasets themselves are typically aggregate or anonymous. Transfers rely on Standard Contractual Clauses and the EU US Data Privacy Framework certification of CARTO sub-processors.

Third-party domains contacted

carto.comapp.carto.comauth.carto.comdata.carto.comgoogleapis.comamazonaws.com

Cookies placed

NameTypeDurationPurpose
carto_sessionfirst_partySessionAuthenticated session cookie for the CARTO platform UI.
carto_csrffirst_partySessionCross site request forgery protection token for the CARTO web application.
_gathird_party2 yearsGoogle Analytics 4 measurement on the CARTO marketing website (loaded only after consent).
intercom-idthird_party9 monthsIdentifies returning users in the Intercom support widget on the CARTO website.

CARTO Data Observatory collects user analytics data — you legally need a consent banner. Try FlowConsent free.

Get started freeScan your site

Frequently asked questions

Does the Data Observatory set cookies on my visitors?

No. The Data Observatory is a server side data delivery service that runs inside your cloud data warehouse. Cookies are only set on the CARTO marketing site and on the CARTO platform UI used by your analysts.

Is consent required to query datasets?

Authenticated session cookies on the CARTO platform are strictly necessary. Analytics, marketing, and support cookies on the marketing site or in dashboards require prior consent under Article 5(3) ePrivacy.

What is the GDPR lawful basis?

Contract performance under Article 6(1)(b) for the paid subscription, legitimate interest under 6(1)(f) for security logs, and consent under 6(1)(a) for non essential cookies on the marketing site.

Are there transfers to the United States?

Yes. Account metadata and support data may be processed in the US. Transfers rely on Standard Contractual Clauses and the EU US Data Privacy Framework certification of CARTO sub-processors. Sensitive deployments can be pinned to an EU region.

Do I need a DPIA?

A DPIA is generally not required for aggregated geospatial datasets but becomes recommended when joining mobility, telco, or fine grained sociodemographic data with personal data of EU residents at scale.

How should I deploy CARTO securely?

Enforce SSO, MFA, role based access, and audit logging. Pick the EU region for the platform tenant when possible, encrypt warehouse credentials, and review CARTO SOC 2 / ISO 27001 documentation annually.

Are there alternatives that keep data in the EU?

Yes. The CARTO platform itself can be deployed in EU regions. Alternatives include Mapbox (with EU options), HERE Technologies, or open source stacks (Geoserver, PostGIS) hosted in the EU, although dataset breadth is generally smaller.

How should the privacy notice describe the Data Observatory?

List CARTO as a processor, describe the platform UI, the dataset catalogue, the cloud warehouse delivery model, the EU US transfers, and the safeguards (SCCs, DPF, EU region option, encryption). Link to the CARTO privacy policy and DPA.