Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
Monsido, part of Acquia, is a web governance platform covering accessibility, quality assurance, SEO, and data privacy and consent scanning. To monitor how a website is used, it sets first-party analytics cookies on visitor devices. While it helps organisations improve compliance, its own analytics cookies still require user consent in the European Union.
Monsido is a web governance platform from Acquia that helps organisations manage accessibility, quality assurance, search engine optimisation, and data privacy. It includes consent and privacy scanning that can detect cookies and trackers across a website. Because part of its value comes from understanding how visitors use a site, it also collects first party analytics.
Monsido sets first party analytics cookies that record page views, sessions, and navigation patterns, along with a functional cookie for an accessibility colour blindness mode. These cookies store a visitor identifier and usage information tied to the website operator. The analytics data is personal data under the GDPR because it can be linked to an individual visitor.
Even though Monsido is itself a privacy and accessibility tool, its analytics cookies are not strictly necessary, so Article 5(3) of the ePrivacy Directive requires prior consent. The processing then needs a GDPR legal basis, which for analytics is consent under Article 6(1)(a). Governance scanning of the operator own content can rest on legitimate interest, but visitor analytics should not be bundled into that basis.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
The Monsido analytics script should be loaded only after the visitor has accepted analytics cookies through your consent banner. The functional accessibility cookie can usually be treated as necessary because it stores a user preference. Configure your consent management platform so the analytics and functional categories are handled separately and respected consistently.
Monsido is operated by a United States company, and usage data may be processed in the United States unless European Union hosting is selected. Where data leaves the European Economic Area, transfers rely on Standard Contractual Clauses supported by a transfer impact assessment. Choosing EU hosting where available can reduce the complexity of these transfers.
Gate the Monsido analytics cookies behind consent, document them in your cookie policy, and select EU hosting if your data residency requirements call for it. Keep a record of consent and offer an easy way to withdraw it, and confirm the transfer safeguards in your data processing agreement. Review the configuration periodically so the live behaviour matches your disclosures.
Websites using Monsido must obtain user consent under GDPR regulations.
DPIA considerations
Monsido is a moderate risk tool because it collects first party analytics about website visitors, even though it is itself a privacy and accessibility platform. Key considerations are (1) the nature of the data, which is usage and navigation information linked to a visitor identifier; (2) the legal basis, which for analytics cookies must be consent collected before the script loads, while governance scanning of the operator own content can rely on legitimate interest; (3) transparency, clearly distinguishing the analytics collection from the compliance scanning features; (4) international transfers, since data may be processed in the United States unless EU hosting is chosen, with Standard Contractual Clauses and a transfer impact assessment; and (5) data subject rights, including a simple way to withdraw consent. A full data protection impact assessment may not be mandatory but is good practice where analytics are deployed at scale.
Sample consent text
We use Monsido analytics cookies to understand how visitors use our website and to improve it. Click Accept to allow analytics or Reject to decline.
Third-party domains contacted
monsido.comapp.monsido.comcdn.monsido.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| monsido | Analytics | 1 year | First party analytics cookie that records how visitors navigate and use the website. |
| Monsido_UID | Analytics | 1 year | Stores a unique analytics identifier used to distinguish visitors for usage statistics. |
| MonsidoColorBlindMode | Functional | 1 year | Remembers the colour blindness accessibility mode preference selected by the visitor. |
| monsido_session | Analytics | Session | Tracks a single browsing session to attribute page views and navigation to the same visit. |
Monsido is an essential service, but transparency matters. Manage all your consent with FlowConsent.
Monsido sets first party analytics cookies that record how visitors use a website, including a usage cookie and an analytics identifier cookie. It also sets a functional cookie that remembers a colour blindness accessibility mode. The analytics cookies are non essential and require consent, while the accessibility cookie can usually be treated as necessary.
Yes, for its analytics cookies. Although Monsido is a privacy and accessibility tool, its analytics cookies are not strictly necessary, so Article 5(3) of the ePrivacy Directive requires prior consent. The functional accessibility cookie can usually rely on the necessity exemption because it stores a user preference.
For the analytics cookies the legal basis is consent under Article 6(1)(a) of the GDPR, with prior consent required by Article 5(3) of the ePrivacy Directive. Governance and compliance scanning of the operator own content can rely on legitimate interest under Article 6(1)(f). Visitor analytics should not be bundled under legitimate interest.
It can. Monsido is operated by a United States company, and usage data may be processed in the United States unless EU hosting is selected. Where data leaves the European Economic Area, transfers rely on Standard Contractual Clauses with a transfer impact assessment. Choosing the available EU hosting option reduces this exposure.
A full data protection impact assessment is not always mandatory for Monsido, but it is good practice where visitor analytics are deployed at scale. The assessment should cover the legal basis for analytics, transparency, retention, and international transfers. Documenting the separation between analytics and governance scanning is also helpful.
Load the Monsido analytics script only after the visitor accepts analytics cookies through your consent banner, and treat the accessibility cookie as a functional preference. Document the cookies in your cookie policy, keep records of consent, and offer an easy way to withdraw it. Select EU hosting if your data residency needs require it and confirm the transfer safeguards in your contract.
Alternatives include other web governance and accessibility platforms, dedicated accessibility checkers, and privacy focused analytics tools that minimise or anonymise data. Some analytics tools can run without consent if they avoid personal identifiers, though feature sets differ. The right choice depends on your governance needs and your consent strategy.
List the Monsido cookies by name, type, duration, and purpose, distinguishing the analytics cookies from the functional accessibility cookie. Explain that the analytics cookies monitor site usage and require consent, and note that data may be processed in the United States unless EU hosting is selected. Tell users how to manage or withdraw consent through your banner.