Is Opensend GDPR compliant?
Opensend typically loads marketing trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So Opensend can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads Opensend, not on Opensend itself.
- Consent required
- Yes, block it until the visitor opts in
- Consent category
- marketing
- Tracker domain
- opensend.com
Overview
Opensend operates in the visitor identification category — a highly invasive data practice in which scripts attempt to match anonymous website visitors to known email addresses without any prior user interaction. When an anonymous visitor lands on a page running Opensend, the script transmits browser signals (fingerprint components, local storage values, and behavioral patterns) to Opensend's identity graph, which attempts to resolve the visitor to an email address from its database. Matched identifiers are then passed to email marketing automations for outreach.
What This Script Does
The Opensend script performs the following during a visitor session:
- Signal collection: Collects browser attributes, local storage values, and session characteristics to construct a visitor fingerprint
- Identity resolution: Transmits collected signals to Opensend's servers, where they are compared against Opensend's proprietary identity graph of email addresses and browser fingerprints built from publisher network data
- Match transmission: When a match is found, the resolved email address is passed to configured email marketing platforms (Klaviyo, HubSpot, Mailchimp, etc.) to trigger automated outreach sequences
- Cookie setting: Sets cookies to track visitor sessions and suppress duplicate identity resolution calls
- No user interaction required: The entire identification flow occurs without any form submission or voluntary data disclosure by the visitor
Consent & Compliance
- Consent Category: Marketing
- GDPR/ePrivacy: Opensend's visitor identification mechanism is highly problematic under GDPR. Matching anonymous visitors to email addresses without their knowledge constitutes processing of personal data without a valid lawful basis. Legitimate interest cannot support this use case — the practice is fundamentally contrary to visitor expectations and privacy rights. Under ePrivacy, setting cookies and reading browser storage for cross-site identification requires prior opt-in consent.
- CCPA/CPRA: Opensend's practice of resolving visitor identities and sharing email addresses with email marketing platforms constitutes "sharing" of personal information for cross-context behavioral advertising purposes under CPRA, even without payment changing hands.
- Enforcement risk: Identity resolution without consent has been the subject of enforcement attention across European DPAs. Using Opensend on a site with EU visitors creates significant regulatory exposure.
Should You Block This Without Consent?
Yes. Opensend identifies anonymous visitors without consent and passes their personal data to marketing automations without their knowledge or interaction. This practice requires explicit opt-in consent under both GDPR and ePrivacy before any script execution. Given the high-risk nature of the data practice, loading this script without prior consent creates material GDPR enforcement exposure.
Consent Categories
Also Known As
Industries
Tracked Domains (1)
opensend.comMarketingopensend.com is a marketing domain operated by Opensend, used to serve ads, build audiences, and measure ad conversions.
Frequently Asked Questions
Related Vendors

Manage consent for Opensend
ConsentStack automatically detects and manages Opensend trackers so your site stays compliant with global privacy regulations.