Does your website use third-party services? Get GDPR compliant in minutes.
Try FlowConsentFree plan · 10-min setup
IBM Instana is an observability and application performance monitoring platform. Its core tracing is server side, but the optional End User Monitoring (EUM) feature injects a JavaScript beacon that captures page performance, user agent, IP address and session data. When EUM is enabled it should be treated like real user monitoring, with consent and transfer obligations in the EU.
IBM Instana is an observability and application performance monitoring platform that automatically traces requests, maps service dependencies and detects issues across applications and infrastructure. Most monitoring is server side through agents, but Instana also offers End User Monitoring, which observes the real browser experience of website visitors.
Server side tracing collects technical telemetry and does not touch the visitor browser. The End User Monitoring beacon is different, it injects JavaScript that captures page load timing, errors, the user agent, the visitor IP address and a session identifier, and it may store that identifier in local storage or a cookie. This browser data can identify individuals and is personal data under the GDPR.
If only server side tracing is used, you can usually rely on legitimate interest for operational monitoring. Once End User Monitoring is enabled and stores an identifier on the device or processes IP and session data tied to individuals, the ePrivacy Directive requires prior consent for that storage, and the processing must have a valid GDPR basis and be disclosed.
Get GDPR compliant in 10 minutes
Free plan available · No credit card required
Where End User Monitoring is active, load the beacon only after the visitor consents to performance or analytics tracking, and block it behind your consent manager until then. If you run server side tracing only, no browser consent is needed because nothing is stored on the visitor device, though you still document the processing.
Instana is an IBM product offered as SaaS in several regions. When End User Monitoring data including IP addresses is sent to a backend outside the EEA, such as the United States, you need a transfer mechanism such as the Data Privacy Framework or Standard Contractual Clauses. Selecting an EU backend can keep server side and EUM data within the EEA.
Decide whether you need End User Monitoring, gate it behind consent if you do, consider IP truncation and shorter retention, sign a data processing agreement with IBM, choose an EU backend where possible, list any EUM identifiers in your cookie policy and document the lawful basis for server side tracing.
Websites using Instana must obtain user consent under GDPR regulations.
DPIA considerations
Server side tracing alone is low risk and a DPIA is rarely required. When End User Monitoring is enabled, assess the risk of systematic collection of IP addresses, user agents and session identifiers across many visitors and document the processing, since combined monitoring can raise the risk profile.
Sample consent text
We use IBM Instana End User Monitoring to measure page performance. This processes your IP address and session data and may transfer it to IBM outside the EU. Do you accept performance monitoring?
Third-party domains contacted
instana.ioeum.instana.ioibm.comCookies placed
| Name | Type | Duration | Purpose |
|---|---|---|---|
| instana session identifier | Performance / EUM | Session | Identifies a browser session for End User Monitoring correlation, often stored in local storage |
| instana user identifier | Performance / EUM | Persistent | Recognises a returning end user across visits when End User Monitoring is enabled |
Instana collects user analytics data — you legally need a consent banner. Try FlowConsent free.
Server side tracing sets nothing in the browser. When End User Monitoring is enabled, Instana may store a session or user identifier in a cookie or in local storage to correlate browser performance beacons.
It depends on the mode. Pure server side tracing needs no browser consent. If End User Monitoring stores an identifier on the device or processes browser data tied to individuals, prior consent is required under the ePrivacy Directive.
Server side tracing can rely on legitimate interest under Article 6(1)(f) GDPR. End User Monitoring that stores identifiers and processes IP and session data needs consent under Article 6(1)(a).
It can. Instana is an IBM SaaS product offered in several regions. If you use a US backend, or if EUM data including IP addresses is sent there, you need a transfer mechanism such as the Data Privacy Framework or Standard Contractual Clauses.
Server side tracing rarely needs a DPIA. With End User Monitoring enabled, assess the risk of systematic collection of IP, user agent and session data across many visitors and carry out a DPIA if the risk is high.
Decide if you need End User Monitoring, gate it behind consent if you do, consider IP truncation, sign a data processing agreement with IBM, choose an EU backend where possible and disclose any EUM identifiers and the server side basis.
Alternatives include other observability tools, server side only tracing stacks, or EU hosted monitoring platforms. Running tracing without End User Monitoring avoids storing identifiers on the visitor device.
If End User Monitoring is enabled, list the Instana identifiers with their purpose and duration, name IBM as a recipient, explain possible US transfers and describe how visitors withdraw consent. Server side only setups need no cookie entry.