Do I need consent to use RUMvision?
You do not necessarily need consent to use RUMvision.
RUMvision is designed so that core Real User Monitoring can be separated from functionality that may require consent or an additional privacy assessment.
This means you do not have to treat the entire RUMvision tracker as one all-or-nothing consent decision.
For a typical ecommerce website, the first question is which RUMvision features you actually want to use.
Core Real User Monitoring
Our core monitoring measures things such as Core Web Vitals, loading and responsiveness timings, page context, browser and device categories and limited technical visit information.
RUMvision has assessed this core processing under legitimate interest in our Legitimate Interests Assessment.
That assessment covers the GDPR legal basis for the processing. It does not automatically decide whether accessing information on a visitor's device requires consent under the ePrivacy rules that apply in your country.
For customers operating under Dutch law, the Dutch Telecommunications Act contains an exception for certain storage or access used to obtain information about the quality or effectiveness of an online service, where the impact on privacy is none or only minor.
Whether your implementation falls within that exception depends on the actual configuration you use.
What if I want to avoid persistent browser storage?
You can disable RUMvision's persistent browser storage:
- either via feature settings via "Privacy and Consent" for all users
- or at runtime to change this dynamically per user depending on consent status
Core RUM measurements can still be collected without a persistent Browser Identifier. You will lose some continuity-related insights, such as the ability to associate measurements with the same browser over a longer period, but you can still measure real-world website performance.
This can be a useful configuration if you want to keep your implementation as limited as possible.
What if persistent storage is enabled?
Persistent browser storage is enabled in the standard RUMvision property configuration.
When enabled, RUMvision may use localStorage for limited first-party state, including a randomly generated Browser Identifier.
The Browser Identifier:
- is randomly generated
- is specific to your website
- is not based on browser fingerprinting
- does not contain a name, email address or customer account identifier
- is not used to recognise visitors across unrelated websites
- has a maximum lifetime of 90 days
Persistent browser storage requires a separate assessment under the applicable rules for storing or accessing information on a visitor's device.
If you determine that prior consent is required, RUMvision allows you to keep storage disabled from the beginning of the page lifecycle and enable it only after consent has been obtained.
What happens before consent?
If your implementation requires prior consent for a particular RUMvision capability, that capability should remain disabled until consent has been given.
RUMvision supports this at different levels depending on the feature. Persistent storage can be disabled from the start, and several optional capabilities can be configured or activated separately.
It is important to understand that disabling browser storage does not automatically disable all RUMvision processing.
The consent_storage setting controls RUMvision-managed browser storage only. Core Web Vitals measurement, error monitoring, responsiveness diagnostics and other functionality have their own configuration.
What happens when consent is withdrawn?
If RUMvision-managed storage has been enabled and the storage consent state is later disabled, RUMvision removes the local and session storage controlled by that setting.
Any other capability that you operate on the basis of consent must also be disabled where required.
What about optional features?
Optional RUMvision features should be considered separately rather than assuming that one consent decision covers the entire platform.
For example, our Legitimate Interests Assessment distinguishes between:
- core RUM and Web Vitals measurements
- persistent browser storage
- JavaScript error monitoring
- responsiveness diagnostics
- Business Metrics
- additional browser and device signals
- more privacy-sensitive optional context such as interaction labels or URL query information
Some of these are covered by our standard assessment, some have additional conditions, and some require a separate assessment before they are enabled.
We explain those differences in our article on optional monitoring features.
So what should I do for my ecommerce website?
A practical approach is:
- Decide which RUMvision features you actually need.
- Decide whether you want persistent browser storage enabled.
- Review the RUMvision Legitimate Interests Assessment for the features you use.
- Assess the applicable cookie and ePrivacy rules for your country and implementation.
- If prior consent is required for a capability, configure it so that processing does not start before consent.
- Describe your actual use of RUMvision in your privacy and cookie information.
RUMvision provides a pre-assessed Legitimate Interests Assessment to make this process easier. You do not need to recreate our technical analysis. You review whether the assumptions match your own deployment and record your configuration in the Customer Deployment Record.
Why can't RUMvision simply say that consent is never required?
We can't say that consent is never required because that would not be accurate for the following reasons:
The GDPR legal basis for processing personal data and the rules for storing or accessing information on a visitor's device are separate legal questions. Those rules can also differ between countries and depend on the functionality you enable.
We prefer to give you controls and documentation that let you make the right decision for your implementation rather than make a blanket claim that cannot apply to every website.
