Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Zeotap is a Customer Data Platform built in Europe that unifies, enriches and activates customer data for marketing and customer intelligence. It performs identity resolution, audience building and profiling using first party identifiers, hashed contact data and universal IDs. Because it processes personal data for profiling and audience activation, it relies on user consent and carries significant privacy obligations.
Zeotap is a Customer Data Platform that was built in Europe with privacy compliance as a core design goal. It helps brands collect, unify, enrich and activate customer data so that marketing teams can build audiences and improve customer intelligence. The platform resolves identities by matching first party identifiers, hashed email addresses, hashed phone numbers and mobile advertising IDs into a single customer view. It then activates those audiences across advertising and marketing channels while supporting cookieless universal identifiers. Because it centralises and enriches personal data at scale, it sits at the heart of a controller marketing stack and brings substantial data protection responsibilities.
When deployed through a website tag, Zeotap can write a first party ID+ cookie that is unique to the browser, website and device, and it may use local storage to persist identifiers. The data collected typically includes online identifiers, hashed contact details, device and browser information, and behavioural events that describe how a visitor interacts with the site. These signals are used for identity resolution, audience building and profiling rather than for purely technical operation of the website. Zeotap also supports universal identifiers such as Zeotap ID+, ID5 and EUID, which can operate without third party cookies. Operators should document every identifier and storage item in their cookie inventory so that the real scope of collection is transparent.
Under the GDPR the data that Zeotap processes is personal data, and the matching of identifiers amounts to profiling. The ePrivacy Directive, transposed nationally through laws such as the German TTDSG and French CNIL guidance, requires consent before non essential identifiers are read from or written to a visitor device. Because audience building and identity resolution are not strictly necessary to deliver the website, they cannot rely on a technical exemption. The website operator usually acts as the data controller while Zeotap acts as a processor or as a joint controller depending on the activation use case. Clear roles, a data processing agreement and a lawful basis must be established before any collection begins.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Valid consent must be obtained before Zeotap sets identifiers or builds profiles, and that consent has to be freely given, specific, informed and as easy to withdraw as it is to give. A consent management platform should gate the Zeotap tag so that nothing fires until the visitor opts in to marketing or profiling purposes. Zeotap supports the IAB Europe Transparency and Consent Framework, which lets a compliant consent signal flow to the platform and downstream partners. Operators should map Zeotap to the correct purpose category and confirm that withdrawing consent stops collection and propagates a signal to delete or stop using the data. Regular testing ensures that the tag genuinely respects the consent state rather than firing on page load.
Zeotap stores user data in data centres located in Germany, Belgium and the United Kingdom, which keeps core processing inside the EU and EEA. However, data may be shared with recipients or sub processors located outside the EEA, and such sharing can constitute a transfer to a third country. Zeotap enters into EU Standard Contractual Clauses with those recipients and applies supplementary safeguards to maintain an equivalent level of protection. Where personal data reaches the United States, operators should confirm whether a recipient relies on the EU US Data Privacy Framework or on Standard Contractual Clauses together with a transfer impact assessment. These transfer mechanisms should be recorded in the record of processing activities.
Start by completing a Data Protection Impact Assessment because the profiling and identity resolution carried out by Zeotap usually meet the threshold for a mandatory assessment. Sign a data processing agreement, confirm the controller and processor roles, and record the transfer mechanisms that apply to non EEA recipients. Configure the consent management platform so the Zeotap tag is blocked until the visitor grants consent for marketing and profiling, and verify this with browser testing. Update the privacy notice and cookie policy to describe the first party identifier, the universal IDs and the enrichment activities in plain language. Finally, establish processes to honour access, objection and erasure requests, and review the configuration whenever new audiences or activation channels are added.
Websites using Zeotap must obtain user consent under GDPR regulations.
DPIA considerations
A Data Protection Impact Assessment is strongly recommended and often mandatory. Zeotap performs large scale profiling, identity resolution and audience building that can be considered systematic monitoring and evaluation of personal aspects. The assessment should document data sources, the matching of hashed emails and phone numbers, retention periods, automated decision making, and the safeguards for transfers outside the EEA. Particular attention is needed to special category data exclusion and to the rights of data subjects to object to profiling.
Sample consent text
We use Zeotap to unify and enrich your data and to build marketing audiences. With your consent we set a first party identifier and combine it with hashed contact data and universal IDs to personalise marketing. You can withdraw your consent at any time in our cookie settings.
Third-party domains contacted
zeotap.comspl.zeotap.comid5-sync.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| ID+ | first party cookie | up to 1 year | Stores a first party Zeotap ID+ identifier that is unique to the browser, website and device for identity resolution and audience activation. |
| Zeotap local storage identifier | localStorage | persistent until cleared | Persists Zeotap identifiers in browser local storage to support identity resolution and audience building across visits. |
Zeotap collects user analytics data — you legally need a consent banner. Try FlowConsent free.
When deployed through a website tag, Zeotap can write a first party ID+ cookie that is unique to the browser, website and device, and it may use local storage to keep identifiers. It also supports universal IDs such as Zeotap ID+, ID5 and EUID that can work without third party cookies. The exact items depend on your configuration, so document them in your cookie inventory.
Yes. Because Zeotap performs identity resolution, audience building and profiling, it is not strictly necessary for the website and requires prior consent under the ePrivacy rules and the GDPR. The tag should be blocked until the visitor opts in to marketing and profiling purposes.
The appropriate legal basis is consent under GDPR Article 6(1)(a) for profiling, audience building and the use of identifiers. Legitimate interest under Article 6(1)(f) may only support strictly necessary, non profiling operations and requires a documented balancing test. Consent remains the safe basis for marketing activation.
Core storage takes place in the EU and EEA, in data centres in Germany, Belgium and the United Kingdom. However, data may be shared with recipients or sub processors outside the EEA, including the United States, which is treated as a third country transfer. Such transfers rely on EU Standard Contractual Clauses, the EU US Data Privacy Framework where applicable, and supplementary safeguards.
In most cases yes. Zeotap carries out large scale profiling and identity resolution that can amount to systematic evaluation of personal aspects, which usually triggers a mandatory Data Protection Impact Assessment. The assessment should cover data sources, matching of hashed identifiers, retention and transfer safeguards.
Sign a data processing agreement, confirm controller and processor roles, and complete a DPIA before launch. Gate the Zeotap tag behind your consent management platform so it only fires after opt in, and pass a valid consent signal through the Transparency and Consent Framework. Update your privacy notice and cookie policy and test that withdrawing consent stops collection.
Other customer data platforms and identity solutions include Segment, Tealium AudienceStream, Salesforce Data Cloud and open source options that can be self hosted. The most privacy protective approach favours EU data residency, server side collection and consent first design. The right choice depends on your data residency needs and your appetite for profiling.
List the first party ID+ cookie, any local storage items and the universal IDs, with their purpose and duration. Explain that data is unified, enriched and used to build marketing audiences, and describe the EU storage locations and international transfer safeguards. Review the policy whenever you add new audiences or activation channels.