Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
CARTO Analytics is a location intelligence platform that runs spatial analytics on maps and can process visitor location and behavioural data.
CARTO Analytics is a location intelligence and geospatial analytics platform with roots in Spain and the United States. It lets organisations visualise and analyse spatial data on interactive maps, combining business data with geographic context. Companies use it to understand where customers are, how they move and which locations perform best.
When embedded in a public facing site or app, CARTO can process location data such as coordinates, IP based geolocation and movement patterns, alongside behavioural events tied to map interactions. It may set functional cookies to keep map sessions and preferences, and it loads tiles and API resources from its own domains. Location data is particularly sensitive because it can reveal home, work and routine.
Location and behavioural analytics fall squarely within the GDPR, and precise location is treated as high risk personal data. The ePrivacy Directive also requires prior consent before non essential cookies or trackers are placed on a visitor device. Because spatial data can single out individuals, you must apply data minimisation and clear transparency about what is collected and why.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
For behavioural and location analytics you should obtain freely given, specific, informed and unambiguous consent before CARTO begins processing visitor data. Load the analytics layer only after the visitor opts in through your consent banner, and provide an equally easy way to withdraw. Aggregated, non identifying spatial analysis may rely on legitimate interest, but only after a documented balancing test.
CARTO can be deployed in European Union regions, but data may also be processed in the United States depending on your configuration. Transfers to the United States should rely on the EU US Data Privacy Framework where the vendor is certified, or on Standard Contractual Clauses with supplementary measures. Confirm your hosting region in the contract and keep the data processing agreement on file.
Map every CARTO data flow, choose an EU region where possible and reduce location precision to the minimum you need. Gate the analytics layer behind consent, document a legitimate interest assessment for any aggregated use and complete a data protection impact assessment. Finally, list CARTO in your privacy policy and cookie notice, and record the signed data processing agreement.
Websites using CARTO Analytics must obtain user consent under GDPR regulations.
DPIA considerations
A data protection impact assessment is strongly recommended because CARTO can process precise location data, which is considered sensitive and high risk. Assess the granularity of location collection, the potential for re identification and any transfers to the United States.
Sample consent text
We use CARTO Analytics to analyse location and usage data on interactive maps so we can improve our services. These insights may involve processing in the United States. Do you consent?
Third-party domains contacted
carto.comapi.carto.comgateway.carto.comtiles.carto.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| carto_session | Functional | Session | Maintains the interactive map session and viewport state while the visitor browses. |
| carto_prefs | Functional | 1 year | Stores map display and layer preferences so the view is remembered on return. |
This service may collect user data. Ensure GDPR compliance with FlowConsent.
When embedded in a public site, CARTO can set functional cookies to keep map sessions and user preferences, and it may process IP based geolocation. The exact cookies depend on your configuration, so run a cookie scan before publishing.
Yes. For behavioural and location analytics you need prior, freely given consent before CARTO processes visitor data. Load the analytics layer only after the visitor opts in through your consent banner.
The primary legal basis is consent under Article 6(1)(a) GDPR. Aggregated, non identifying spatial analysis may rely on legitimate interest under Article 6(1)(f), but only after a documented balancing test.
It can, depending on the deployment region you choose. Where data reaches the United States, rely on the EU US Data Privacy Framework if the vendor is certified, or on Standard Contractual Clauses with supplementary measures.
A data protection impact assessment is strongly recommended because precise location data is high risk. Assess the granularity of collection, the risk of re identification and any transfers outside the European Union.
Choose an EU region where possible, minimise location precision, gate the analytics layer behind consent and document a legitimate interest assessment for aggregated use. Keep the signed data processing agreement and list CARTO in your privacy and cookie notices.
EU hosted geospatial and analytics tools such as privacy focused mapping platforms can reduce transfer risk. Whichever you choose, apply the same consent, minimisation and documentation principles.
Add CARTO to the analytics or location category in your cookie notice, describe the data it processes, state the retention period and disclose any United States processing. Update the notice whenever your configuration changes.