Compliance-artikelen
Korte links bevatten persoonsgegevens: IP-adressen, apparaatsignalen, soms campagne-identifiers die aan een persoon zijn gekoppeld. Deze handleidingen behandelen GDPR-conforme linktracking, EU-gegevensopslag, cookieloze analyses, verwerkersovereenkomsten, en wat je elke leverancier moet vragen voordat je klantkliks via hen laat lopen. Geschreven voor marketeers en FG's die praktische antwoorden nodig hebben, met de juridische bronnen erbij vermeld. EU-first is Elido's thuisterrein, en in deze categorie laten we het huiswerk zien.
- Compliance
Homograafaanval: hoe een lookalike-domein je voor de gek houdt
Een homograafaanval verbergt een vervalst domein achter de xn---codering van punycode en lookalike-tekens. Hoe het trucje werkt en hoe je een link eerst controleert.
9 min leestijdhomograph attack · punycode · idn homograph attack - Compliance
Toegankelijkheid van QR-codes: WCAG, contrast en alternatieven
Een QR-code is een afbeelding zonder tekstalternatief en een doel waar niemand naartoe kan tabben. Wat toegankelijkheidsregels verwachten, en de geprinte terugvaloptie die het meeste oplost.
6 min leestijdqr code accessibility · wcag · european accessibility act - Compliance
Bewaartermijn van clickdata: hoe lang bewaar je analyticslogs
De GDPR geeft geen getal voor clickdata. Hoe je verdedigbare bewaartermijnen per gegevenscategorie vaststelt, ze documenteert, en verwijdert zonder je rapportage te verliezen.
7 min leestijdclick data retention · storage limitation · gdpr retention period - Compliance
QR Codes and GDPR: What a Scan Collects and What You Owe
The printed code collects nothing. The redirect behind it processes an IP address, which is personal data. What that means for lawful basis and retention.
5 min leestijdqr codes and gdpr · qr code privacy · is a qr scan personal data - Compliance
Digital Product Passport QR Codes: The EU ESPR Rules
The EU Digital Product Passport puts a QR code on your products by law. What the ESPR requires, the 2027 battery and textile deadlines, and how to comply.
5 min leestijddigital product passport qr code · digital product passport · espr qr code - Compliance
Cookie Consent for Short Links: What the EU Requires
Do short links need a cookie banner? A DPO explains when redirect tracking triggers ePrivacy consent, and when a cookieless, EU-resident setup avoids it.
7 min leestijdcookie consent for short links · do short links need cookie consent · url shortener cookie consent - Compliance
Is Google Analytics GDPR Compliant? EU Answer
Google Analytics is not banned, but EU regulators ruled it broke GDPR by sending data to the US. What the Data Privacy Framework changed, plus EU alternatives.
5 min leestijdis google analytics gdpr compliant · google analytics gdpr · google analytics eu - Compliance
Is Bitly GDPR Compliant? A DPO's Honest Answer
Bitly has a DPA, standard contractual clauses, and Data Privacy Framework certification. Compliant, yes - but not the same as EU-only data residency.
7 min leestijdis bitly gdpr compliant · bitly gdpr · bitly data processing agreement - Compliance
EU Alternatives to US SaaS: A Sovereignty Guide
Why EU teams are replacing US SaaS with European alternatives, the CLOUD Act vs GDPR conflict, and how to pick tools that keep data under EU jurisdiction.
6 min leestijdeu alternatives to us saas · european saas alternatives · digital sovereignty - Compliance
Are QR Codes Safe? Quishing and How to Stay Protected
QR codes are safe to scan - the risk is where they lead. How quishing works, how to spot a malicious QR code, and what to do if you scanned a fake one.
7 min leestijdare qr codes safe · quishing · qr code phishing - Compliance
Are URL Shorteners Safe? A Balanced Answer for 2026
Reputable URL shorteners are safe; the real risk is opaque destinations and abuse, both manageable. How to check a short link and choose a safe provider
10 min leestijdare url shorteners safe · url shortener safety · are short links safe - KernartikelCompliance
GDPR for URL shorteners: what your DPO actually wants to see
A working DPO's read on the GDPR articles that apply to URL shorteners - Articles 3, 6, 28, 30, 32, 35, sub-processor disclosure, and the DPA clauses
14 min leestijdgdpr url shortener · url shortener data residency · link tracking gdpr - Compliance
SOC 2 and HIPAA for link tracking: a procurement answer
What enterprise security questionnaires actually ask about a URL shortener: SOC 2 controls mapped to link infrastructure and where HIPAA stops applying
12 min leestijdsoc 2 url shortener · hipaa url shortener · link tracking compliance - Compliance
Consent Mode v2 for link tracking: what the DMA changed
Consent Mode v2 and the Digital Markets Act rewrote short-link analytics: what the four signals mean, how server-side recovery works, and what EDPB and CJEU say
11 min leestijdconsent mode v2 · google consent mode · digital markets act - Compliance
Schrems II and tracking pixels: where the DPF leaves you in 2026
Schrems II invalidated Privacy Shield. The EU-US Data Privacy Framework restored adequacy in 2023. What this actually means for marketing pixels under GDPR Article 44+
12 min leestijdschrems ii tracking · schrems ii pixels · eu us data transfer - KernartikelCompliance
EU data residency for marketing tools: what your DPO actually asks
What 'EU data residency' means under GDPR Article 3 + Schrems II - where marketing tools leak, the server-side fix, and a procurement checklist
13 min leestijdeu data residency · eu hosted analytics · gdpr analytics - Compliance
Cookieless attribution explained: what still works in 2026
Two attribution paths survive third-party cookie sunset - server-side identifiers and first-party redirects. A pragmatic stack for marketers who need real numbers
13 min leestijdcookieless attribution · cookieless tracking · server side attribution - Compliance
Safari ITP and click attribution in 2026: what still works
Every ITP version broke another tracking workaround. The full timeline, what each change killed, and the server-side redirect pattern that survives them all.
11 min leestijdsafari itp tracking · itp 2.3 · attribution after itp - Compliance
URL shortener security checklist: 9 things to verify first
A concrete checklist for vetting any URL shortener: malware scanning, webhook signing, API key storage, rate limits, bot filtering, audit logs, and takedowns.
13 min leestijdurl shortener security · url shortener api key · webhook security - Compliance
GDPR-friendly URL shorteners - what to look for in 2026
A practical checklist for evaluating URL shorteners under GDPR: EU data residency, IP truncation, DPA availability, right to erasure, and US-tool traps.
16 min leestijdgdpr url shortener · gdpr friendly url shortener · url shortener data residency