Skip to main content
Pingdom logo
Performance Monitoring High complexity

Pingdom

by Pingdom

Sets cookies
No
Sends PII
No
Cross-site tracking
No

Overview

Pingdom is a website performance monitoring service owned by SolarWinds that provides uptime monitoring, page speed analysis, and real user monitoring (RUM). The Pingdom RUM JavaScript snippet collects performance metrics from actual visitor browsers, including page load times, resource timing, and geographic performance distribution. While synthetic monitoring (external probes) does not involve personal data, the RUM component executes in the user's browser and collects data that may be linked to individual visitors. Pingdom is commonly deployed on enterprise websites, e-commerce platforms, and public sector digital services where uptime and performance are business-critical.

Detection Capabilities

Signature count
1
Detection methods
network

Performance Impact

Performance Impact

Requests per page
1

Common Mistakes

  • 1 Assuming Pingdom RUM is purely technical and exempt from consent requirements, when the client-side script collects browser data that may constitute personal data under GDPR (IP addresses, user agent strings, geographic location)
  • 2 Deploying the RUM snippet without distinguishing it from synthetic monitoring in the privacy notice - only RUM involves processing visitor data
  • 3 Not reviewing SolarWinds' data processing terms following the SolarWinds supply chain attack (2020), which highlighted the importance of vendor security due diligence
  • 4 Failing to include Pingdom RUM in the cookie audit, as its cookies and local storage usage are often overlooked alongside more prominent analytics tags
  • 5 Loading the RUM snippet on all pages when performance monitoring on a representative sample would be sufficient and more proportionate

Compliance Considerations

Pingdom RUM executes JavaScript in the visitor's browser and collects performance metrics that may include IP addresses and browser fingerprint data, which constitute personal data under GDPR. The legal basis depends on implementation: if RUM data is fully anonymised and used solely for service performance, legitimate interest may apply; if it retains identifiable data or is combined with analytics, consent may be required. SolarWinds (Pingdom's parent company) processes data in the United States and is subject to the EU-US Data Privacy Framework. Organisations should assess whether the RUM implementation collects personal data, include it in their CMP if consent is required, and ensure vendor security due diligence reflects SolarWinds' post-incident security improvements.

Related Services

Need help governing Pingdom?

Our governance diagnostic identifies compliance gaps across your entire tag estate.

Start your Governance Diagnostic