Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Treasure Data is an enterprise Customer Data Platform that unifies first party data from many sources into persistent customer profiles. Its JavaScript SDK sets cookies and captures events and identifiers for identity resolution and large scale profiling. Because of non essential cookies and extensive profiling, it requires consent under GDPR and ePrivacy and a DPIA is likely.
Treasure Data is an enterprise Customer Data Platform, a CDP. It collects first party data from websites, apps, and back end systems and unifies it into a single persistent profile for each customer. Through identity resolution it links events and identifiers from many sources, so the platform can power segmentation, personalization and activation across marketing channels. It operates at large scale and its core purpose is building and enriching unified customer profiles.
The Treasure Data JavaScript SDK, known as td-js-sdk, sets first party cookies prefixed with td such as _td and _td_global, and captures page views, events, and identifiers. These cookies store a persistent identifier that is used to stitch behaviour to a unified profile, which may also include data ingested from other systems. Because the profile relates to identifiable individuals and uses persistent identifiers, it is personal data under the GDPR.
The cookies the SDK sets are not strictly necessary, so Article 5(3) of the ePrivacy Directive requires consent before they are stored or read. The unification and profiling also need a lawful basis under the GDPR, and for marketing personalization the appropriate basis is consent under Article 6(1)(a). Because the CDP combines data and profiles at scale, transparency and purpose limitation are especially important, and individuals must be able to exercise their rights across the unified profile.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Consent must be freely given, specific, informed and unambiguous, and the SDK should only collect non essential data after acceptance. Treasure Data runs on global infrastructure, with processing possible in the United States, Japan and other regions depending on the instance. These transfers require safeguards such as Standard Contractual Clauses or the EU US Data Privacy Framework, supported by a transfer risk assessment.
Configure the SDK to collect only after consent through a consent management platform, propagate consent signals into the CDP so downstream activation respects choices, and document the cookies in your cookie policy. Sign a data processing agreement, map data sources and retention, verify the processing regions and transfer safeguards, and carry out a Data Protection Impact Assessment given the large scale profiling and identity resolution.
Websites using Treasure Data must obtain user consent under GDPR regulations.
DPIA considerations
Treasure Data unifies data from many sources and performs large scale identity resolution and profiling, which is precisely the kind of processing that triggers a Data Protection Impact Assessment. Assess the scale of profiling, the combining of online and offline data, the use of persistent identifiers, transfers to the United States and Japan, and the rights of individuals across the unified profile.
Sample consent text
We use Treasure Data, a customer data platform, to combine information about your interactions into a unified profile and to personalize our services. This involves cookies and profiling. Do you consent to this processing?
Third-party domains contacted
treasuredata.comin.treasuredata.comcdn.treasuredata.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| _td | HTTP cookie | Persistent (up to 1 year) | Stores a persistent visitor identifier used by the SDK to capture events and stitch behaviour to a unified customer profile. |
| _td_global | HTTP cookie | Persistent (up to 1 year) | Stores a global identifier shared across properties to support cross site identity resolution in the CDP. |
| _td_ssc | HTTP cookie | Persistent | Supports server side cookie linking for identity resolution and event collection. |
Treasure Data collects user analytics data — you legally need a consent banner. Try FlowConsent free.
The Treasure Data JavaScript SDK, td-js-sdk, sets first party cookies prefixed with td such as _td and _td_global. They store a persistent identifier used to capture events and page views and stitch behaviour to a unified customer profile in the CDP.
Yes. The SDK cookies are not strictly necessary and the platform performs large scale profiling, so under Article 5(3) ePrivacy and Article 6(1)(a) GDPR you must obtain prior, freely given and informed consent before collection begins.
The appropriate basis is consent under Article 6(1)(a) GDPR, combined with consent for cookie storage under Article 5(3) ePrivacy. Given the scale of profiling and identity resolution, consent is generally required for the marketing personalization use cases.
Treasure Data runs on global infrastructure, with processing possible in the United States, Japan and other regions depending on the instance. Transfers require Standard Contractual Clauses or the EU US Data Privacy Framework plus a transfer risk assessment.
Yes, a Data Protection Impact Assessment is likely required. Treasure Data unifies data from many sources and performs large scale profiling and identity resolution, which is the kind of high risk processing that triggers a mandatory DPIA.
Collect only after consent through a consent management platform, propagate consent signals into the CDP so activation respects choices, document the cookies, sign a data processing agreement, map sources and retention, verify transfer safeguards and complete a DPIA.
Alternatives include other enterprise customer data platforms and lighter first party data approaches that minimise profiling. Any CDP that unifies and profiles at scale raises the same consent, governance, transfer and DPIA questions, so assess data location and minimisation.
List the td prefixed cookies set by the SDK, describe their purpose of building a unified profile, state their duration, name Treasure Data as a processor, and disclose transfers to the United States, Japan and other regions with the safeguards used.