GDPR sets rules for processing personal data, including lawful bases, special-category data, individual rights, security, and breach notification. An organization should identify whether it acts as a controller or processor, document why each data field is necessary, set retention limits, and honor access, correction, deletion, and objection requests where they apply. Processor relationships can require a Data Processing Agreement, while higher-risk processing may need a Data Protection Impact Assessment. Web analytics can also fall under national ePrivacy rules governing storage or access on a user's device. Avoiding analytics cookies reduces one technical category of storage, but it does not automatically establish legitimate interests or remove every consent obligation. IP-derived hashes and other pseudonymised values can remain personal data. A privacy notice should describe the actual data flow rather than repeat a generic compliance claim. The correct assessment depends on purpose, implementation, other technology, contractual roles, data transfers, and jurisdiction. Technical minimization helps, but legal conclusions should be reviewed against the live deployment and current regulator guidance.