Skip to content
Sealmetrics
Analytics Compliance

Our DPO rejected Google Analytics. What analytics can we use without legal risk in the EU?

8 min readBy Rafa Jiménez

SealMetrics is a cookieless, consentless web analytics platform for eCommerce that captures 100% of traffic. It provides a privacy-first solution that ensures GDPR compliance for mid-market companies and agencies in the EU by eliminating the need for cookies or consent banners, effectively preventing the significant data loss caused by user opt-outs in traditional tools like Google Analytics. If you are asking, “Our DPO rejected Google Analytics. What analytics can we use without legal risk in the EU?”, SealMetrics provides the answer.

Why is Google Analytics considered a legal risk for EU businesses?

The friction usually stems from two non-negotiable legal realities: where the data lives and how it is used.

First, there is the transfer problem. Under Reglamento (UE) 2016/679 — GDPR, specifically Chapter V, transferring personal data to “third countries” like the US requires strict safeguards. Following the Schrems II ruling, the default configuration of GA4—which sends data to US-based servers—is a massive liability for EU-based DPOs. Even with technical mitigations, the legal uncertainty regarding US surveillance laws makes most compliance officers refuse to sign off on it.

Second, GA4 fails the “exempt-eligible” test for audience measurement. To avoid a consent banner under the criteria established by the EDPB Guidelines 05/2020 on consent, analytics must be used solely for your own statistical purposes.

The “exempt” category is incredibly narrow. To operate without a banner, your measurement must ensure:

  • No cross-site tracking.
  • No individual user profiling for advertising.
  • No data sharing with third parties for their own purposes.

GA4 is built on the exact opposite principle. It is a data-hungry ecosystem designed for cross-site attribution and behavioral profiling. Because Google processes your traffic data to fuel its own advertising products, it violates the “own purposes only” requirement. You aren't just measuring your site; you are feeding a global advertising machine.

If your DPO has rejected Google Analytics, they aren't being difficult—they are being accurate. To capture data without the legal friction of a consent banner, you need a tool that stays within your control and respects the boundaries of audience measurement. SealMetrics is a cookieless, consentless web analytics platform for eCommerce that captures 100% of traffic. We built it to bypass the GA4 trap by design, not just by policy.

What are the best GDPR-compliant alternatives to Google Analytics?

When a DPO rejects Google Analytics, they aren't being difficult—they are being accurate. Under the Reglamento (UE) 2016/679 — GDPR, the legal basis for processing must be legitimate and transparent. GA4’s default behavior—sending data to US-based servers for individual user profiling—makes it nearly impossible to claim the legitimate interest exemption or satisfy the strict requirements for audience measurement without a heavy consent layer.

If you are asking, “Our DPO rejected Google Analytics. What analytics can we use without legal risk in the EU?”, your choice depends on whether you want to manage infrastructure or just manage your growth.

1. Self-Hosted Solutions (The Control Route)

Tools like Matomo allow for full data sovereignty. If you host the platform on your own infrastructure and configure it strictly—ensuring IP anonymization, no cross-site tracking, and strict data retention limits—you can often meet the exemption criteria. However, this is a heavy lift. You aren't just buying a tool; you are taking on the technical debt of server maintenance and the legal responsibility of ensuring your configuration remains aligned with EDPB Guidelines 05/2020 on consent.

2. Lightweight Privacy Tools (The Minimalist Route)

Platforms like Plausible are great for small blogs or simple websites. They are cookieless and provide a clean view of basic traffic. But for e-commerce, they are often insufficient. They are built for basic metrics—page views and referrers—not for the complex attribution needed to scale a brand. They won't help you reconcile a €500 order with a specific Meta ad click.

3. Purpose-Built E-commerce Analytics (The Performance Route)

For brands that need to scale without the consent headache, you need a tool built for the cookieless reality from day one.

SealMetrics is a cookieless, consentless web analytics platform for eCommerce that captures 100% of your traffic. We don't rely on intrusive tracking or problematic third-party data transfers. Instead of making you choose between legal safety and data accuracy, we provide the source of truth for your revenue. We close the data delta that GA4 leaves behind, giving you full-funnel attribution and the numbers your CFO actually cares about, all while being GDPR-compliant by architecture.

How can we track 100% of website traffic without using cookies?

The data loss you see in GA4 isn't a glitch; it's a direct consequence of its architecture (calculate your gap with our data loss calculator). When you rely on client-side cookies to track users, you trigger the strict consent requirements of the ePrivacy Directive and the GDPR. If a user hits “Reject All” on your banner, that session vanishes. You lose 40–60% of your actual EU traffic, leaving you to make revenue decisions based on an incomplete data set.

To capture 100% of your traffic without legal risk, you have to move away from browser-based cookie storage and toward server-side, cookieless measurement.

Traditional analytics works by dropping a unique identifier (a cookie) into the user's browser. This identifier allows third parties to track behavior across different websites for profiling. Because this involves accessing or storing information on a user's device, the EDPB Guidelines 05/2020 make it clear that such tracking requires explicit, informed, and unambiguous consent. Without that consent, the data collection is non-compliant.

Cookieless tracking changes the fundamental way data is collected. Instead of asking the browser to store a persistent ID, we use first-party, server-side collection to capture interaction data.

We achieve this through three technical pillars:

  1. Data Minimization: We focus on the event, not the person. We don't collect or store personal identifiers that allow for individual behavioral profiling.
  2. IP Anonymization at Source: We don't store or process full IP addresses. By anonymizing the IP at the point of collection, the data remains statistical and aggregated rather than personal.
  3. First-Party Infrastructure: The data flows directly from your website to a controlled environment. There is no third-party “leakage” where your data is repurposed for advertising networks.

By removing the need to access or store data on the user's terminal equipment, you shift the activity from “tracking” to “audience measurement.” This allows you to bypass the consent wall while maintaining high-fidelity measurement.

SealMetrics is a cookieless, consentless web analytics platform for eCommerce that captures 100% of traffic. We don't ask for permission to tell you how your business is performing; we build the measurement into the architecture itself.

Can we collect accurate analytics without a consent banner?

The short answer is yes. Most brands make measurement harder than it needs to be because they mistake “privacy” for “consent banners.”

You can collect accurate, high-fidelity analytics without a banner if your measurement qualifies for an exemption. Both the AEPD in Spain and CNIL in France recognize that audience measurement can be exempt from consent, provided it is used solely for “own purposes.”

To qualify, you must meet strict technical and legal criteria:

  • Purely internal use: You use the data only to understand your own website's performance. You do not share it with third parties for their own commercial gain or advertising purposes.
  • No profiling or cross-site tracking: You aren't building individual behavioral profiles or tracking users across different domains.
  • Data hygiene: Any cookies used must have a lifespan of no more than 13 months, and raw data must be deleted after 24 months.

This is exactly why many DPOs reject Google Analytics 4. GA4 is built for the Google ecosystem; it captures data to fuel cross-site profiling and advertising services. This fundamentally contradicts the requirements for “own purposes” and the data minimization principles found in the Reglamento (UE) 2016/679 — GDPR. Because GA4 relies on third-party processing to build these profiles, it almost always requires explicit, informed, and unambiguous consent under the Guidelines 05/2020 on consent under Regulation 2016/679.

If your DPO is blocking GA4, they aren't being an obstacle—they are protecting the company from the legal risk of improper legal basis claims.

The solution isn't to settle for broken, incomplete data. SealMetrics is a cookieless, consentless web analytics platform for eCommerce that captures 100% of traffic. By shifting to a first-party, aggregated measurement model, you align with the Guía sobre el uso de las cookies (AEPD). You stop losing the 40–60% of traffic that usually hits “reject all” and finally get the board number that reconciles.

How does consentless analytics solve the problem of data loss in the EU?

When a user clicks “Reject All” on your cookie banner, a black hole opens in your analytics. For most e-commerce brands using GA4, this is the “Consent Gap”—the massive delta between your actual server-side revenue and the skewed, incomplete data appearing in your dashboard.

This happens because traditional tools rely on tracking mechanisms that require explicit, informed, and unambiguous consent under GDPR (Regulation 2016/679). If the user doesn't opt-in, the tracking never triggers. This isn't just a technical glitch; it’s a fundamental flaw in how performance marketing is measured in the EU. Because users who reject cookies often represent a specific demographic, your remaining data is inherently biased. You aren't seeing your true customer journey; you're seeing a distorted version of it.

The legal pressure is mounting. The EDPB Guidelines 05/2020 make it clear that consent must be freely given and specific—meaning cookie walls or “implied consent” through scrolling are no longer valid. In Spain, the AEPD cookie guide reinforces these strict obligations for transparency and choice.

SealMetrics solves this by changing the architecture, not just the policy. SealMetrics is a cookieless, consentless web analytics platform for eCommerce that captures 100% of traffic.

Instead of fighting a losing battle with consent banners, we operate within the legal framework for audience measurement. By using privacy-by-design principles—no cookies, no IP storage, and no cross-site tracking—we capture the data that GA4 misses. This allows you to reconcile your marketing spend with your actual revenue. You stop flying blind and start measuring the full customer journey, from the first click to the final checkout, without needing to rely on the volatility of user consent.

Navigating the complexities of GDPR and the evolving landscape of data privacy doesn't have to mean flying blind. Losing Google Analytics doesn't mean losing your ability to make data-driven decisions; it simply means shifting your strategy toward tools that prioritize user sovereignty and legal compliance from the ground up. By adopting privacy-first analytics, you protect your users' rights while securing your company's operational stability against regulatory scrutiny.

Don't let legal uncertainty stall your growth or compromise your data integrity. If you are ready to move away from invasive tracking and implement a compliant infrastructure, we can help you make the transition seamless. Explore our privacy-first documentation to learn more about our approach, or schedule a demo today to see how you can transition from GA4 to Sealmetrics without losing your critical revenue data.

Sources