Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
OneAPM is a Chinese application performance monitoring (APM) vendor that provides a JavaScript-based Real User Monitoring (RUM) agent. When embedded on a website, it collects page load timings, JavaScript errors, device and network data, and may set persistent identifiers. Data is processed on servers located in China, a jurisdiction without an EU adequacy decision, making this a high-risk service requiring explicit user consent and appropriate transfer safeguards.
OneAPM is an application performance monitoring (APM) platform developed by OneAPM Co., Ltd., a Chinese technology company. Its Browser Insight product is a JavaScript-based Real User Monitoring (RUM) agent designed to be embedded into web pages. Once loaded, it measures actual end-user experience including page load times, resource timings, JavaScript errors, and network conditions. The company also operates under the Tingyun brand and collects data via the domains oneapm.com and tingyun.com.
The OneAPM RUM JavaScript agent collects performance metrics, browser and device information, and may set or read cookies and local storage identifiers to correlate sessions and page views. Collected data typically includes page load duration, network timing, browser version, operating system, and viewport dimensions. Because identifiers are used to track individual sessions, the processing falls within the scope of the ePrivacy Directive and requires informed prior consent from EU visitors.
Under the GDPR, processing EU personal data requires a lawful basis. Because OneAPM places identifiers on end-user devices and links them to behavioural data, consent under Article 6(1)(a) is the appropriate legal basis. The ePrivacy Directive Article 5(3) independently requires opt-in consent before any non-essential storage or access on a user''s terminal equipment. Legitimate interests cannot override this requirement for the cookie/identifier layer. Your privacy policy and cookie notice must accurately describe OneAPM''s processing, including the China data transfer.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
China has no EU adequacy decision under Article 45 GDPR. Any transfer of EU personal data to China must therefore be covered by appropriate safeguards, most commonly Standard Contractual Clauses (SCCs) under Article 46(2)(c). Crucially, the EDPB Recommendations 01/2020 require organisations to conduct a Transfer Impact Assessment (TIA) to evaluate whether Chinese surveillance legislation (including the National Intelligence Law and the Cybersecurity Law) prevents the SCCs from being effective in practice. Given these laws, the risk that EU data could be accessed by Chinese authorities without EU-equivalent protections is real and must be documented.
A Data Protection Impact Assessment (DPIA) under Article 35 GDPR is strongly recommended before deploying OneAPM on an EU-facing website. The combination of systematic monitoring of website visitors, use of identifiers, and transfer to a high-risk third country (China) meets multiple criteria from the EDPB''s list of processing types likely to result in high risk. The DPIA should assess the necessity and proportionality of the monitoring, the transfer safeguards in place, and supplementary technical measures such as anonymisation or proxying data through an EU intermediary.
To use OneAPM compliantly on an EU website: block the RUM script until the user gives explicit consent via a GDPR-compliant cookie banner; obtain and document SCCs with OneAPM and complete a TIA; update your privacy policy to disclose the China transfer and the associated risks; consider whether a European-hosted APM alternative would achieve the same objective with lower risk; and review your processing records (Article 30 GDPR) to include OneAPM as a sub-processor or independent controller.
Websites using OneAPM must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is strongly recommended given the transfer of EU visitor data to China (no adequacy decision), the collection of device fingerprint and performance data, and the use of persistent identifiers. Assess: legal basis for transfer (SCCs), transfer impact assessment (TIA) under EDPB Recommendations 01/2020, data minimisation options, and whether Chinese national security laws could compel access to EU personal data.
Sample consent text
We use OneAPM to monitor the performance of our website and detect errors in real time. This service sets identifiers and sends technical data about your browser, device and connection to servers located in China. Please accept to enable performance monitoring.
Third-party domains contacted
oneapm.comtingyun.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| RUM Session Identifier | persistent | Session to 1 year (varies by configuration) | Identifies and correlates end-user browser sessions for real-user monitoring. Used by the OneAPM Browser Insight agent to attribute page performance metrics and JavaScript errors to individual sessions. Non-essential; requires prior consent from EU visitors. |
| RUM Visitor Identifier | persistent | Up to 1 year | Distinguishes returning visitors from new visitors to aggregate performance trends. Set by the OneAPM RUM JavaScript agent. Non-essential tracking identifier; requires prior consent from EU visitors. |
OneAPM collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Yes. The OneAPM Browser Insight RUM agent is designed to set and read identifiers (cookies and local storage) on end-user devices in order to correlate page views and sessions. These identifiers are used for tracking purposes and are therefore non-essential, meaning prior informed consent is required from visitors in the EU before they are set.
Yes, consent is required. Because the OneAPM RUM script sets identifiers on user devices and sends personal data (including device and network information) to servers in China, it falls under both Article 5(3) of the ePrivacy Directive and the GDPR. You must block the script from loading until the user has actively consented via a compliant cookie banner.
The applicable legal basis is consent under Article 6(1)(a) GDPR. Because the RUM agent places non-essential identifiers on visitor devices, legitimate interests cannot serve as an alternative basis for the cookie layer. Consent must be freely given, specific, informed and unambiguous, and users must be able to withdraw it as easily as they gave it.
Yes. OneAPM is a Chinese company and processes data on infrastructure located in China. China has no EU adequacy decision under Article 45 GDPR. Any transfer therefore requires appropriate safeguards: Standard Contractual Clauses (SCCs) and a Transfer Impact Assessment (TIA) evaluating whether Chinese surveillance laws (including the National Intelligence Law) undermine the effectiveness of those SCCs in practice.
A Data Protection Impact Assessment (DPIA) under Article 35 GDPR is strongly recommended. The combination of systematic end-user monitoring, persistent identifiers, and transfer to China satisfies multiple criteria on the EDPB list of high-risk processing types. The DPIA must assess necessity, proportionality, transfer safeguards, and any supplementary technical or contractual measures.
Block the OneAPM script via your tag manager or CMP until valid consent is obtained. Obtain SCCs from OneAPM and complete a Transfer Impact Assessment. Update your privacy policy and cookie notice to disclose the service, its purpose, and the China transfer. Maintain records of processing under Article 30 GDPR. Consider whether a European-hosted APM alternative could meet your monitoring needs with lower regulatory risk.
Yes. Several European APM and RUM vendors offer comparable functionality while keeping data within the EU: for example Elastic APM (self-hosted or EU SaaS), Dynatrace, Datadog (EU region), or open-source options like Sentry (self-hosted). These alternatives avoid the China transfer risk and can significantly reduce consent and compliance obligations.
Your cookie policy should list OneAPM as a third-party analytics and monitoring service, identify its purpose (real-user performance monitoring and error detection), state that data is transferred to China under Standard Contractual Clauses, and link to the OneAPM privacy policy. Update your policy whenever the service, its cookies, or the transfer mechanism changes. Include OneAPM in the consent management platform so users can opt in or out.