Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
TomTom Maps provides interactive maps, geocoding and routing through a JavaScript SDK and Maps API. Loading a map sends the visitor IP address to TomTom and may use local storage or cookies, while location features process the visitor position, so consent is generally required.
TomTom Maps is a mapping platform that lets websites embed interactive maps and use services such as geocoding, search and routing. Developers add the TomTom Maps SDK or call the Maps API, and the browser then loads map tiles and runs the SDK. It is a common alternative to other commercial map providers and is often chosen by EU businesses because TomTom is based in the Netherlands.
Whenever a map loads, the visitor browser contacts TomTom servers, which receive the IP address, the requested map area and technical request data. The SDK may store data in the browser local storage for caching and can set cookies. If you use geolocation features, the visitor approximate or precise position is processed as well. The IP address and any location data are personal data under the GDPR.
Storing or reading data on the visitor device through cookies or local storage that is not strictly necessary triggers Article 5(3) of the ePrivacy Directive and the need for consent. Processing the IP address and any geolocation is governed by the GDPR. Because an embedded map is rarely strictly necessary, you should treat it as a non essential feature that requires a lawful basis before it loads.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Use of precise geolocation always requires explicit consent, and the browser itself will prompt the visitor before sharing the position. For the map embed, the safest approach is to load it only after the visitor accepts, or to use a click to load placeholder so that no data goes to TomTom until the visitor chooses to view the map. Consent must be recorded and revocable.
TomTom is a Netherlands based company, which keeps a large part of processing within the EU and is generally favourable for European users. Even so, tile and API delivery can run through a global content delivery network, so some edge processing may occur outside the EEA. Review your TomTom agreement to confirm the data location and the safeguards that apply, and disclose any transfer in your privacy notice.
Place the map behind your consent management platform or a click to load wrapper, request geolocation only when the visitor asks for it, and sign a data processing agreement with TomTom. List the map cookies and local storage in your cookie policy, explain the purpose of any location processing, and keep a record of consent. Review the transfer position periodically as the service evolves.
Websites using TomTom Maps must obtain user consent under GDPR regulations.
DPIA considerations
A DPIA is advisable where precise geolocation is used at scale or where map interactions are combined with other profiling, as location is sensitive context data. For a simple embedded map a documented assessment of the IP processing, the use of geolocation and the delivery network is usually sufficient. The EU base of TomTom reduces, but does not remove, the transfer risk.
Sample consent text
This page can display an interactive TomTom map. Loading it sends your IP address to TomTom and may use your location. Do you consent to load the map and, where used, share your location?
Third-party domains contacted
api.tomtom.comkr1.api.tomtom.comwww.tomtom.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| TomTom SDK local storage | Functional | Persistent until cleared | The Maps SDK stores tile and configuration data in browser local storage to cache map content and improve loading performance. |
| tomtom_session | Functional | Session | May be set to associate map and API requests within a single session for rate limiting and service operation. |
TomTom Maps uses cookies for user preferences — inform visitors with a consent banner.
The Maps SDK mainly uses browser local storage to cache tiles and configuration, and it may set functional cookies for session handling and rate limiting. These are not strictly necessary for your site, so they generally require consent.
Yes, in most cases. Loading the map sends the visitor IP to TomTom and uses non essential storage, and any precise geolocation needs explicit consent, so you should load the map only after the visitor agrees.
The legal basis is consent under Article 6(1)(a) GDPR for precise location and for non essential storage, with Article 5(3) ePrivacy governing the cookies and local storage placed on the device.
TomTom is based in the Netherlands and keeps much processing in the EU, which is favourable. However tiles and API responses can be served through a global delivery network, so some edge processing may occur outside the EEA. Confirm the data location in your TomTom agreement.
A DPIA is advisable when precise geolocation is used at scale or combined with other profiling. For a simple embedded map a documented assessment of IP processing, location use and delivery is usually enough.
Use a click to load placeholder or block the map behind consent, request geolocation only on user action, sign a data processing agreement, and list the cookies and local storage in your cookie policy with a clear purpose.
Yes. OpenLayers or Leaflet with self hosted or OpenStreetMap tiles can reduce third party data sharing, and other EU based map providers exist. The right choice depends on your need for routing, search and styling.
State that the page embeds TomTom Maps, list the local storage and cookies it uses with their purpose, name TomTom as the recipient, and explain that loading the map sends your IP and that location may be processed with consent.