Your tracking works. Before you start using your data, take a few minutes to review your essential privacy settings.
You don’t need to configure every privacy option now. For this Getting Started guide, focus on three things: what you collect, how you handle consent, and how long you keep your data.
⚠️ Important
This page helps you set sensible defaults. It is not legal advice. Your exact obligations depend on your country, applicable laws, your data, and how you use Matomo. When in doubt, check with your legal team or Data Protection Officer (DPO).
Step 1 Review what data you collect
Start with a simple principle: only collect the data you actually need.
Matomo provides privacy settings to reduce the amount of personal data you collect. For your initial setup, review:
- IP addresses: check your IP masking/anonymisation setting.
- User IDs: only collect them if you need them and if your privacy setup allows it.
- URLs and custom tracking: make sure you are not accidentally sending personal or sensitive information to Matomo.
You can find the main controls under Administration > Privacy.
📚 Learn more
• Configure Privacy Settings in Matomo
• Privacy – Anonymise Data
Step 2 Choose your cookie and consent approach
Do you need consent? This depends on where your visitors are, the laws that apply to you, and how you’ve configured Matomo.
There are three common approaches:
- Ask for consent. If your setup requires consent, Matomo can wait until a visitor gives permission before tracking. You can also integrate Matomo with common Consent Management Platforms (CMP).
- Cookieless tracking. Matomo can track without analytics cookies. This can reduce the amount of information stored on visitors’ devices, but cookieless does not automatically mean consent-free.
- Consent-exempt analytics. Some jurisdictions allow limited analytics without consent when specific requirements are met. For example, Matomo provides a dedicated configuration for the French CNIL audience-measurement exemption.
💡 Tips
Not sure which applies to you? Check with your privacy or legal team before choosing. Matomo’s privacy guides can help them review your setup.
Step 3 Decide how long to keep your data (data retention)
Analytics data does not necessarily need to be stored forever. Keep only what you need.
Matomo lets you configure retention and deletion settings for data you no longer need. Choose a retention period based on:
- what you actually need to analyse
- your organisation’s retention policy
- the privacy requirements that apply to you
If your organisation already has a data retention policy, use that as your starting point.
📚 Learn more
Quick Privacy Checklist
Before continuing, check:
Quick Privacy Check
☐ I reviewed and know what personal data Matomo collects.
☐ I know which consent approach applies to my setup.
☐ My consent setup is connected, if required.
☐ I reviewed how long detailed analytics data is kept.
☐ My privacy or legal team has reviewed the setup, if needed.
That’s enough for now.
Matomo has more privacy controls available, but you don’t need to configure everything before learning how to use your reports.
You can always come back and refine them as your tracking evolves. You don’t need the same configuration as every other Matomo user. You need the configuration that fits your organisation and use case.
Good to know
- Your data stays yours. On Matomo Cloud, your data is hosted in the EU, you own it, and a data processing agreement is available for your records.
- Visitor rights are built in. When you need them: an opt-out for visitors, tools to find, export, or delete one person’s data. You can read this How to respect GDPR data subjects’ rights in Matomo if needed.
- Share with your stakeholders. Send your DPO or legal team Matomo’s trust center and privacy page as a reference: Matomo and privacy
Go deeper
📚 More resources (only if you need it):
• Configure Privacy Settings in Matomo
• Can I use Matomo Analytics without asking for consent or using a cookie banner?
• What is GDPR?
• Matomo – InnoCraft’s Trust Center