Skip to content
Back to blog
GDPR|Growth Hackers

Server-Side Tracking: Is It Worth It for Swedish Companies?

Server-Side Tracking: Is It Worth It for Swedish Companies?

Server-side tracking is usually sold as a performance fix. In Sweden, after IMY's enforcement cases against Tele2 and CDON, it's just as much a GDPR question. Here's an honest breakdown of when it's worth the investment β€” with a real client case.

Free analysis

Unsure if server-side tracking is right for you?

We review your current measurement setup free of charge and give you an honest answer on what actually needs prioritizing.

Book a free consultation

Server-side tracking is usually marketed as a way around ad blockers and Safari's Intelligent Tracking Prevention. That's true, but it's no longer the main reason Swedish companies should care. After IMY's enforcement cases against Tele2 and CDON in summer 2023, server-side tracking became a central part of how Swedish companies can actually comply with GDPR when using Google Analytics.

This article is an honest breakdown: what server-side tracking actually solves, what it doesn't, and a real example of when the investment paid off.

Client-side vs. server-side: what's the difference?

In a classic client-side setup, Google Tag Manager runs directly in the visitor's browser. Every tag β€” Google Analytics, Google Ads, Meta Pixel β€” sends data straight from the visitor's device to each platform. The browser sees and can block every individual call, which is exactly what ad blockers and browser tracking protections do.

In a server-side setup, the website instead sends data to a server you control, which then forwards it to Google, Meta, and other platforms. The visitor's browser only talks to your own server β€” which is both harder to block and gives you a control point over what actually gets forwarded, and where.

Why it became a GDPR question, not just a performance one

That control point is exactly what made the difference in IMY's enforcement cases. We cover the full regulatory picture and all four companies involved in our guide to Consent Mode v2 for Swedish companies β€” but the short version: Tele2 and CDON were fined because personal data via Google Analytics was sent to the US uncontrolled. Dagens Industri and Coop avoided fines by implementing server-side Google Tag Manager on an EU-based host, with IP anonymization and cookie ID hashing before data left the server.

The point isn't that server-side tracking automatically makes you GDPR-compliant. The point is that it gives you a place to actually do something about the third-country transfer β€” anonymize, filter, hash β€” before data leaves the EU. Without that control point, everything passes straight through, uncontrolled, directly from the visitor's browser.

A real example: Aleris

Aleris, a healthcare provider, needed a GDPR-compliant measurement setup that worked consistently across multiple business units and products β€” an industry where the requirements for handling personal data are especially strict. We implemented GA4 with server-side tracking, real-time user journey tracking, and an automated reporting structure.

The result: real-time monitoring implemented, all business areas covered by the same measurement framework, and automated reporting that replaced manually pulling data together from multiple systems. Server-side tracking was a requirement for handling personal data correctly given the industry's sensitivity β€” not a marginal optimization. Read the full case: Aleris.

When is it worth the investment β€” and when isn't it?

Server-side tracking requires server infrastructure of your own (or a managed service), ongoing maintenance of the tag configuration, and usually developer support to set up correctly. It's not free, and it isn't always the right first step.

It's probably worth it if: you handle sensitive personal data (health, finance, HR), you have significant ad spend where data loss from ad blockers already shows up in your conversion numbers, or you've already received a query or complaint from IMY or a data subject.

It's probably not the first priority if: your current Consent Mode implementation isn't even in place β€” that's where you should start, not in server infrastructure β€” or your data volume is too small to justify the added complexity. An empty or misconfigured Consent Mode setup running server-side is still a misconfigured setup, just a more expensive one to maintain.

Basic requirements to get started

  • A server-side GTM container, either self-hosted on Google Cloud, AWS, or an EU-based provider, or through a managed service.
  • A dedicated subdomain (e.g. data.yourdomain.com) pointing to the server container, so first-party cookies can be set correctly.
  • A review of which tags actually need to move server-side β€” not everything does, and moving unnecessarily just increases the maintenance burden.
  • A correctly maintained Consent Mode implementation. Server-side tracking doesn't replace consent handling; it's a complement, not a shortcut.

Frequently Asked Questions

Does server-side tracking replace the need for Consent Mode?

No. They solve different problems. Consent Mode governs whether data can be collected based on the visitor's consent. Server-side tracking governs how and where the collected data is processed before it reaches a third party. You need both for a complete, GDPR-aligned measurement setup.

Is server-side tracking only for large companies?

No, but the complexity and cost mean it's usually most relevant for companies with significant ad spend, sensitive data categories (such as healthcare or finance), or both. Smaller companies with simpler data handling should usually prioritize a correct Consent Mode implementation first.

How long does a server-side tracking implementation take?

It depends on how many tags need to move and how complex your current GTM setup is. A basic implementation with GA4 and a handful of ad platforms typically takes a few weeks, including testing and data quality verification before going fully live.

Do we have to host the server ourselves?

No. Most companies choose a managed solution or set up the container on Google Cloud or an equivalent. What matters from a GDPR standpoint is where the server is physically located and which company is legally responsible for processing the data, not whether you handle the operations yourself.

Wondering whether server-side tracking is the right investment for you? Learn more about our measurement service or book a free call β€” we'll review your current setup and give you an honest answer, even if that answer is that you don't need it yet.

Free analysis

Want to build a GDPR-compliant measurement setup?

Growth Hackers has implemented server-side tracking and GDPR-compliant measurement for Swedish companies, including in healthcare.

Learn more about our measurement service