Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Prisme is a privacy first, cookieless web analytics product made and hosted in the European Union, which means it can usually run without a cookie banner or prior consent.
Prisme is a privacy first web analytics platform from a French team, offered both as a managed service and as open source software. It gives website owners the usual metrics such as visits, page views, referrers and basic device categories, while avoiding the invasive tracking associated with mainstream analytics. The script is very small, around one kilobyte, which keeps pages fast. It is positioned as a respectful alternative to tools that rely on cookies and cross site identifiers.
Prisme is cookieless and does not set cookies or store persistent identifiers in the browser. Instead of following individuals, it records aggregate events such as a page view together with coarse, non identifying context like the referrer, the page and a broad device or country category. It is designed to avoid collecting data that singles out a specific person, and it does not build cross site profiles. This data minimisation is the core of its privacy first design.
Because Prisme does not store or read information on the user device beyond what is strictly necessary, the consent rule in Art. 5(3) of the ePrivacy Directive is generally not triggered. Under the GDPR any data that could still relate to a person is processed on the basis of legitimate interest, supported by strong minimisation and the absence of profiling. Hosting in the European Union means the usual third country transfer concerns do not arise. This combination is what allows many sites to run Prisme without a cookie banner.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
For a standard cookieless deployment, prior consent is generally not required, which is consistent with guidance from European authorities such as the French CNIL on privacy preserving analytics. You should still be transparent in your privacy notice and offer a simple way to object to the processing. If you extend Prisme with custom events that capture identifying details, reassess whether consent becomes necessary. Keep your configuration aligned with the cookieless, aggregate model to stay within the no consent position.
Prisme is made and hosted in the European Union, so in its managed form there is no transfer of personal data to the United States or other third countries. If you self host the open source version, you control the hosting location and can keep everything within the European Economic Area. This avoids the need for Standard Contractual Clauses and transfer impact assessments that burden non European tools. It is a meaningful advantage for organisations focused on data residency.
Add Prisme to your privacy notice as your analytics provider, describing the cookieless, aggregate nature of the measurement and the legitimate interest basis. Document a brief legitimate interest assessment and confirm that no personal identifiers are placed on the device. If you use the managed service, verify the European hosting in your records, and if you self host, keep the deployment within the European Economic Area. Review any custom events you add to ensure they remain privacy preserving.
Websites using Prisme must obtain user consent under GDPR regulations.
DPIA considerations
A full data protection impact assessment is generally not required for a standard Prisme deployment. The tool is cookieless, collects aggregate measurement rather than identifying individuals, and is hosted in the European Union without third country transfers, which keeps the risk to data subjects low. You should still record a short assessment of the data collected, confirm that no personal identifiers are stored on the device and document the legitimate interest balancing test.
Sample consent text
This site uses Prisme, a privacy first analytics tool that measures visits without cookies and without tracking you across sites. No personal identifiers are stored on your device and the data stays in the European Union. Because the measurement is aggregate and privacy preserving, it relies on our legitimate interest rather than your consent, and you can object at any time.
Third-party domains contacted
prismeanalytics.comapp.prismeanalytics.comapi.prismeanalytics.comPrisme collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Prisme is cookieless and does not set any cookies in the browser. It also avoids persistent identifiers in local storage, so there is nothing on the device to track a returning visitor. This is a deliberate part of its privacy first design. As a result you do not need a cookie banner for Prisme itself.
For a standard cookieless deployment, prior consent is generally not required. Because the script does not store or read information on the device beyond what is strictly necessary, the ePrivacy consent rule is not triggered, and the aggregate data relies on legitimate interest. You should still inform visitors in your privacy notice and let them object. Reassess only if you add custom events that capture identifying details.
Any data that could relate to a person is processed under legitimate interest in Art. 6(1)(f) GDPR, supported by strong data minimisation and no profiling. There is no separate ePrivacy consent requirement because the tool does not place identifiers on the device. Document a short legitimate interest assessment to evidence the balance. This keeps the processing lawful without a consent banner.
No. Prisme is made and hosted in the European Union, so the managed service does not transfer personal data to the United States or other third countries. If you self host the open source version, you choose the location and can keep everything in the European Economic Area. This avoids Standard Contractual Clauses and transfer impact assessments. Data residency in Europe is one of its main selling points.
Generally no. A cookieless, aggregate analytics tool hosted in the European Union with no profiling and no third country transfers presents a low risk to data subjects. A full data protection impact assessment is usually not triggered. A short record of the data collected and the legitimate interest balance is sufficient for most deployments.
Install the script, then add Prisme to your privacy notice describing the cookieless, aggregate measurement and the legitimate interest basis. Offer a simple way to object, and keep the configuration aligned with the privacy first model. If self hosting, keep the deployment within the European Economic Area. Review any custom events to ensure they do not introduce identifiers.
Yes. Other privacy first, cookieless analytics tools follow a similar model and can also run without consent when configured carefully. Cookie based analytics such as the mainstream platforms generally do require consent and often involve US transfers. If your priority is European hosting and a banner free setup, Prisme and similar tools are a strong fit. Choose based on hosting, features and openness.
Because Prisme sets no cookies, your cookie policy can state that the analytics provider operates without cookies and without persistent device identifiers. In your privacy notice, describe the aggregate data collected, the legitimate interest basis and the European hosting, and explain the right to object. Keep the wording accurate so visitors understand no tracking cookies are involved. Update it if you later add features that change this.