Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
FirstHive is a customer data platform that unifies first party customer data across web, email, mobile and offline sources, resolves identities and powers marketing automation. It ingests directly identifying data such as emails and phone numbers and builds persistent profiles, which makes it large scale profiling under the GDPR. It uses first party and third party cookies and requires prior consent and a solid legal basis. Because it is hosted in India, with no EU adequacy decision, transfers depend on Standard Contractual Clauses and a transfer impact assessment, and a DPIA is normally required.
FirstHive is a customer data platform headquartered in India that unifies first party customer data from web, email, mobile and offline channels into a single view. It performs identity resolution to stitch together the different touchpoints of the same person and then powers segmentation, marketing automation and personalised campaigns. Because it deliberately joins data across channels and builds persistent profiles, it sits at the heart of an organisation marketing operation. For European deployments this means the platform processes the personal data of large numbers of customers and prospects on an ongoing basis.
FirstHive ingests directly identifying data such as email addresses and phone numbers, alongside behavioural events from the website, email engagement and mobile activity. On the web it relies on first party and third party cookies, including a persistent visitor identifier such as fhive_uid, a session cookie such as fhive_session and tracking helpers such as fh_track. These identifiers are linked to known customer records, so the resulting profiles are rich and directly attributable to individuals. None of this is necessary to deliver the website itself, which places the tracking firmly in the non essential category that demands consent.
Under the GDPR, building unified profiles through identity resolution is profiling, and doing it at scale on directly identifying data is treated as a high risk activity. Article 5(3) of the ePrivacy Directive separately requires prior consent for the cookies and identifiers placed on the user device. FirstHive normally acts as a processor on behalf of the controller, so a data processing agreement under article 28 is essential, together with clear documentation of purposes, retention and the international element. The combination of cross channel tracking and identifiable profiles raises the regulatory stakes considerably.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent is the appropriate basis for the cookies and for the profiling that FirstHive performs, because legitimate interest is very hard to sustain for cross channel profiling of identifiable people. That consent must be obtained before any identifier is set, must be specific to the profiling and marketing purposes, and must be as easy to withdraw as to give. In practice you should block the FirstHive tag behind a consent management platform, pass the consent signal through to the platform, and stop building or enriching profiles for users who decline or later withdraw.
FirstHive is based in India and typically hosts data on AWS in India or in a region chosen by the customer. India does not benefit from a European Commission adequacy decision, so transfers cannot rely on adequacy and instead require the EU Standard Contractual Clauses backed by a transfer impact assessment that considers local access to data. The India DPDP Act 2023 also governs the processing in India and should be reflected in your documentation. Where possible, choosing an EU hosting region and applying strong supplementary measures will reduce the transfer risk.
Sign a robust data processing agreement, complete a data protection impact assessment and put the Standard Contractual Clauses and a transfer impact assessment in place before launch. Route the FirstHive tag through your consent management platform so no identifier is set without consent, and synchronise consent withdrawals so profiles stop being enriched. Apply data minimisation, set clear retention limits on profiles and identifiers, and update your privacy notice and cookie policy to name FirstHive, describe the profiling and explain the transfer to India. Review the arrangement regularly and keep the supporting records to demonstrate accountability.
Websites using FirstHive must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is normally required for FirstHive because it carries out large scale profiling and cross channel identity resolution on directly identifying data. Map every source feeding the platform, the identifiers used, the profiles built and the retention applied. Assess the transfer to India under the Standard Contractual Clauses, the supplementary measures and the India DPDP Act 2023. Evaluate the risks of profiling to individuals and document mitigations such as consent gating, data minimisation and limited retention before going live.
Sample consent text
We use FirstHive to recognise you across our website, email and apps and to build a unified profile so we can personalise our marketing. This relies on cookies and identifiers and only happens after you accept, and it may transfer your data to FirstHive on infrastructure in India under EU approved safeguards. You can refuse or withdraw your consent at any time without losing access to the site.
Third-party domains contacted
firsthive.comapp.firsthive.comcdn.firsthive.comtrack.firsthive.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| fhive_uid | analytics | persistent (up to 1 year) | Persistent visitor identifier used for cross channel identity resolution and to link behaviour to a unified customer profile. |
| fhive_session | functional | session | Maintains the visitor session so events can be grouped within a single visit. |
| fh_track | analytics | persistent (up to 1 year) | Tracks on site behaviour and engagement events that feed segmentation and marketing automation. |
FirstHive collects user analytics data — you legally need a consent banner. Try FlowConsent free.
FirstHive uses first party and third party cookies, including a persistent visitor identifier such as fhive_uid, a session cookie such as fhive_session and tracking helpers such as fh_track. These are linked to known customer records and feed identity resolution and profiling, so they are not strictly necessary and require consent.
Yes. The cookies and the profiling are not strictly necessary, so you must obtain prior, specific and freely given consent before any identifier is set. The tag should stay blocked until the visitor opts in, and profiles should not be built for those who decline.
The appropriate basis is consent under GDPR article 6(1)(a) for the profiling and marketing identifiers, combined with the prior consent required by article 5(3) ePrivacy for the cookies. Legitimate interest is very difficult to sustain for cross channel profiling of identifiable people.
Yes. FirstHive is based in India and typically hosts data on AWS in India or a customer chosen region. India has no EU adequacy decision, so transfers rely on the EU Standard Contractual Clauses plus a transfer impact assessment, and the India DPDP Act 2023 also applies.
Yes, a DPIA is normally required. FirstHive carries out large scale profiling and identity resolution on directly identifying data, which is high risk under GDPR article 35. Document the sources, identifiers, profiles, retention and the transfer to India, and record your mitigations before going live.
Sign a data processing agreement, complete a DPIA and put Standard Contractual Clauses and a transfer impact assessment in place first. Gate the tag behind a consent management platform, pass the consent signal to FirstHive, apply data minimisation and clear retention, and synchronise consent withdrawals so profiles stop being enriched.
Other customer data platforms offer EU hosting or stronger transfer guarantees, which can simplify the compliance picture. If full cross channel identity resolution is not essential, lighter first party analytics with a cookieless option may reduce risk. Whichever tool you choose, consent gating and a DPIA remain necessary for profiling.
List each FirstHive cookie with its purpose and duration, explain that the platform builds unified profiles through identity resolution, and disclose the transfer to India under the Standard Contractual Clauses. Link to your consent settings and review the entry whenever the configuration or hosting region changes.