DuckDuckGo built its entire brand on one sentence: “We don’t track you.” That claim holds up better than most privacy marketing does, but it’s not the same thing as GDPR compliance, and the gap between the two is very interesting to look at.
DuckDuckGo still needs an Article 27 representative, still had to work through a real vendor-tracking controversy in 2022, and still makes deliberate architectural choices that map directly onto GDPR’s data minimisation and privacy-by-design principles.
For any organisation building or buying data-handling systems, DuckDuckGo’s approach, warts included, is a useful case study.
• DuckDuckGo doesn’t create user sessions, store identifying cookies, or log IP addresses against searches, a practical example of the data minimisation Article 5(1)(c) GDPR requires.
• Privacy branding doesn’t remove statutory obligations: DuckDuckGo still appoints an Article 27 representative for the EU (IT Governance Europe Limited) and a separate one for the UK (GRCI Law Limited).
• In 2022, DuckDuckGo’s browser was found allowing Microsoft-linked trackers on Bing and LinkedIn domains, a gap between its privacy claims and its ad-syndication contract that took months to close.
• DuckDuckGo’s search ads are matched to the page you’re viewing rather than a profile built from your history, showing that contextual targeting is a working alternative to behavioural tracking.
• Optional features such as Email Protection and Sync & Backup only request the specific data needed to run, and disclose that need before you opt in, which is Article 13’s transparency requirement applied at the feature level rather than buried in one long privacy policy.
DuckDuckGo’s privacy policy describes a search engine built to be stateless by design. It doesn’t save IP addresses alongside search queries, doesn’t log unique identifiers that could tie a search back to a person, and doesn’t build session histories the way most search engines do. Device information such as IP address and browser type gets used briefly to deliver results and block bots, then isn’t retained in a form connected to what was searched.
The company states it has never sold personal information, and that it can’t hand over search or browsing histories in response to legal requests because it doesn’t hold them in the first place. That’s a meaningfully different position from a company that holds the data and chooses not to share it: DuckDuckGo’s architecture removes the data from the equation before the legal question even arises.
DuckDuckGo’s stateless design lines up with two GDPR principles most organisations struggle to operationalise. Data minimisation, set out in Article 5(1)(c), requires that personal data collected be adequate, relevant, and limited to what a specific purpose needs, nothing gathered “just in case” it becomes useful later. Not logging IP addresses against search queries is minimisation applied at the architecture level rather than the policy level.
The second principle is privacy by design and by default under Article 25, which asks organisations to build data protection into a system from the outset rather than bolting it on afterwards. DuckDuckGo’s anonymous cookies for settings, random near-location for local search results, and end-to-end encrypted delivery of content are all technical choices built into the system before a user ever interacts with the product.
Yes, and this is the part businesses tend to miss. Article 27 GDPR requires organisations outside the EU that process EU residents’ personal data to appoint a local representative, regardless of how little data they collect or how privacy-focused their business model is. DuckDuckGo, a US company, appoints IT Governance Europe Limited as its EU representative and GRCI Law Limited as its separate UK representative.
The lesson for other businesses is direct: “we barely collect any data” is not a basis for skipping Article 27. The obligation is triggered by offering goods or services to, or monitoring, people in the EU or UK, not by data volume. Any non-EU organisation building a minimal-data product still needs to work through the same representative appointment that a large-scale data processor does. Our guide to EU and UK representative requirements covers how to appoint one.
In May 2022, security researcher Zach Edwards found that DuckDuckGo’s mobile browser and browser extension let tracking scripts from Microsoft-linked domains, including Bing and LinkedIn, run even while blocking third-party trackers from everyone else. That directly contradicted the “we block trackers” promise DuckDuckGo had built its reputation on.
Founder Gabriel Weinberg explained the exception came from a search syndication agreement with Microsoft, DuckDuckGo’s ad partner, that restricted what its browser could block on Microsoft-related domains without breaking the underlying business relationship. It took until August 2022 for DuckDuckGo to renegotiate those terms and remove the carve-out entirely.
For businesses, the useful lesson here is about vendor contracts: they can quietly override a privacy commitment that looks solid on paper, and the gap only surfaces when someone independently tests what the product actually does rather than what its policy says. A signed Data Processing Agreement with a vendor documents an intention. Confirming that the vendor’s technical behaviour actually matches it takes separate testing.
• Contextual advertising, matching ads to the content on the page rather than a profile built from behaviour, can replace behavioural tracking as a revenue model without needing the underlying personal data at all.
• Statelessness reduces breach exposure directly: data that was never logged can’t be exposed in an incident, which changes the risk profile of a breach notification under Article 33 before one even happens.
• Optional features should request only the specific data each feature needs, disclosed at the point the person opts in, rather than relying on one general-purpose privacy policy to cover everything.
• Vendor relationships need periodic technical verification alongside the signed contract. Testing what your product actually sends to a partner’s domains catches gaps that a paper DPA review won’t.
DuckDuckGo’s stateless architecture is a genuine, working example of data minimisation and privacy by design. Its Article 27 representative appointments show that even a company selling privacy still has to meet the same statutory obligations as everyone else, and its 2022 Microsoft tracker exception shows that a vendor contract can undercut a privacy promise if nobody checks the actual technical behaviour against it. Auditing your own product’s data flows against what your privacy policy claims, the way outside researchers did to DuckDuckGo, is the practical exercise worth borrowing.
DuckDuckGo’s stated practices – not logging IP addresses against searches, not creating user profiles, and appointing EU and UK Article 27 representatives – are consistent with GDPR’s data minimisation and representative requirements. Compliance ultimately depends on ongoing practice matching policy, which the 2022 Microsoft tracker exception shows isn’t automatic even for a privacy-focused company.
Article 27 GDPR is triggered by offering goods or services to, or monitoring, individuals in the EU or UK. How much data an organisation actually collects doesn’t change that. A low-data business model reduces risk but doesn’t remove the statutory requirement to appoint a representative.
In 2022, researchers found DuckDuckGo’s browser exempted Microsoft-linked tracking scripts on domains like Bing and LinkedIn from its tracker-blocking protections, due to terms in its search advertising agreement with Microsoft. DuckDuckGo renegotiated those terms and closed the exception in August 2022.
DuckDuckGo earns most of its revenue from search ads matched to the search results page a person is viewing, rather than a profile built from search or browsing history. Ad clicks are handled through Microsoft’s ad network under terms that restrict associating clicks with an individual profile.
Disclaimer: This blog post is intended solely for informational purposes. It does not offer legal advice or opinions. This article is not a guide for resolving legal issues or managing litigation on your own. It should not be considered a replacement for professional legal counsel and does not provide legal advice for any specific situation or employer.
About the Author
Zlatko Delev
Country Manager & Head of Commercial — GDPRLocal
Zlatko specialises in data protection compliance, ISMS strategy, and AI law. With a legal background and hands-on experience supporting organisations globally, he helps businesses navigate GDPR, the EU AI Act, and international privacy frameworks.