Analytics without consent banners. Lawful by architecture, not by paperwork.
Updated · By Rafa Jiménez, Founder, Sealmetrics
Consent requirements depend on the processing and the applicable rules. Review the technical configuration alongside official guidance to understand when measurement can operate without a consent dialog, and what conditions still apply.
Review the scope and conditions in the CNIL's analytics exemption criteria.
Why cookie banners stopped working
Consent banners were never a measurement strategy — they were a compliance instrument bolted onto a measurement strategy that assumed everyone said yes. Three things broke that assumption, and one regulation in 2026 broke it further.
Rejection rates climbed past the break-even line
When most European visitors said yes, cookie analytics could absorb the loss. Today, in our experience with clients, between 40% and 60% of traffic doesn’t accept cookies, and of those who do, 40% don’t accept on the first pageview. On Incapto’s Shopify store, measured over 48 days, GA4 did not record 29% of visits. Decisions made on what remains are decisions made on a self-selected sample — typically older, less mobile, less privacy-aware. The bias is silent and structural.
Review the consent interface as well as the analytics
If other tools on the site require consent, review their interface and behavior separately. Check whether the choices shown to visitors match the tracking that actually occurs, using the relevant authority guidance linked below.
Measure the effect of your consent interface
Check how your consent interface affects engagement on your own site. Compare page interaction and consent choices using a measurement method that respects those choices. Do not assume a universal abandonment rate or attribute every lost visit to the banner.
The Digital Omnibus would redraw the line
The Commission's proposal of November 2025 would move the terminal-device rules into the GDPR and exempt first-party, aggregated audience measurement from consent. It is still a proposal — adoption is realistically 2027–2028 — but the direction is clear. Read the practical implications in the marketer's guide. Net effect: the legal cost of running cookie-based analytics rose; the legal cost of running consentless analytics is zero.
The architectural route to lawfulness
The exemption is not a clever interpretation; it is the original wording. Three regulatory anchors define the path, and a measurement system either sits inside them by design or it does not.
Anchor 1
GDPR Article 2 — material scope
GDPR applies to “the processing of personal data.” Personal data is any information that relates to an identified or identifiable natural person. If a measurement system processes only aggregate counts — never an identifier, never a fingerprint, never a behavioural profile — the system does not process personal data. The Regulation does not apply to its measurement output. Assess the data processed at every stage, not only the final report.
Anchor 2
ePrivacy Article 5(3) — terminal-device storage
ePrivacy requires consent before storing or accessing information on the user's terminal device. The classic example is a cookie. If the measurement system writes no cookie, reads no localStorage, and uses no device fingerprint, there is nothing on the terminal device to trigger Art. 5(3). No consent dialog is required for that processing path.
Anchor 3
The CNIL analytics exemption criteria
The CNIL describes a conditional exemption for audience measurement. Its scope includes restrictions on purpose, combining data and use across sites, alongside other requirements. Review the complete CNIL guidanceagainst the deployed configuration. A product label alone does not establish that every condition is met.
The technical implementation — first-party server-side collection without identifiers — is documented at cookieless analytics. The architecture diagram and pipeline detail live at How it works.
Authority guidance, by country
Consent rules and exemptions depend on the jurisdiction and the deployed configuration. The official sources below provide starting points for review; they are not product endorsements.
France
CNILReview the CNIL guidance on audience measurement and the conditions for a consent exemption. Official guidance.
Germany
DSK / BfDIConsult the DSK guidance for the rules applicable to the actual German deployment. Official guidance.
Spain
AEPDReview the AEPD cookie guide and assess the purpose and configuration of measurement. Official guidance.
Italy
GaranteConsult the Garante guidance on cookies and other tracking technologies. Official guidance.
United Kingdom
ICO (PECR)Review the current ICO guidance on PECR and the conditions relevant to statistical measurement. Official guidance.
Netherlands
Autoriteit PersoonsgegevensConsult the Dutch authority guidance on cookies and analytics before assessing an exemption. Official guidance.
Country-specific deep-dives — including the CNIL self-assessment, the UK PECR exemption walkthrough, and the Digital Omnibus marketer guide — live on the blog.
“Consentless” vs “consent-light” — the distinction that matters for DPOs
A common confusion: lightweight analytics tools that claim “no cookie banner needed” while still setting a first-party cookie or a randomised visitor ID. From a CMP- integration perspective the experience is similar. From a regulatory perspective the two are not in the same category.
Consent-light
- Sets a first-party cookie or visitor ID (often randomised).
- Justifies under “legitimate interest” — a position several authorities have rejected for cross-session tracking.
- Stores the identifier on the terminal device → ePrivacy Art. 5(3) still triggers.
- Argument depends on banner-free interpretation that authorities can challenge case-by-case.
Consentless (Sealmetrics)
- Sets no cookie, writes no localStorage, no visitor ID generated.
- Review the collection and processing stages to establish whether personal data is involved.
- Review terminal-device storage and access practices separately from reporting output.
- Review the deployed configuration against the applicable local guidance and exemption conditions.
For a DPO reviewing vendor risk, the practical question is: does the tool's defence rely on regulatory interpretation, or on the absence of triggering conditions? Consentless architecture is the second answer.
What ships with the platform
The architectural exemption removes the consent burden. The following documentation supports the rest of a vendor review:
Data Processing Agreement, GDPR Art. 28 compliant, signed by Sealmetrics S.L. as processor. Pre-filled, ready to counter-sign.
Transfer, Privacy and Security Review document. Covers data flows, sub-processors (none outside the EU on visitor data), retention, encryption at rest and in transit, access controls, breach procedure.
Full list of sub-processors with their roles, jurisdictions and DPAs ships inside the TPSR package. All EU-only by policy.
Review the current hosting and sub-processor documentation, including jurisdictions and access arrangements, when assessing data residency and transfers.
Fixed and identical for every plan, enforced by automatic database TTLs: event-level technical log 1 day, hourly aggregates 90 days, daily aggregates and conversions 24 months. No raw individual-level data is stored beyond the millisecond-level aggregation window.
Full security and architecture documentation lives at Security. We are not currently certified to ISO 27001 or SOC 2 — the roadmap and the controls we already operate are documented in full.
Deep-dives by jurisdiction and scenario
The legal pattern is portable. The friction points are local.
GDPR analytics without consent
The full Art. 6 / Art. 5(3) reasoning, with worked examples from CNIL, DSK, AEPD enforcement files.
Read →France · CNILThe CNIL self-assessment, published
Walk through the five exemption criteria with Sealmetrics' actual answers, side by side.
Read →UK · PECRUK PECR analytics exemption
Post-Brexit position. ICO guidance. DUAA 2025 walkthrough for a UK-only deployment.
Read →Digital Omnibus 2026The marketer's guide to the Digital Omnibus
What changed for banners, what changed for analytics, and what to action this quarter.
Read →Measurement lossWhat consent banners cost your analytics data
Industry-by-industry rejection rates and the cost of decisions made on the survivor sample.
Read →Compliance roadmapDigital Omnibus marketer roadmap
Quarter-by-quarter actions for marketing leaders in EU-regulated markets.
Read →Common DPO questions
- Is consentless analytics actually legal under GDPR?
- It depends on the actual processing and applicable rules. Review whether personal data is processed, whether information is stored on or read from a device, and whether an exemption applies. The CNIL describes a conditional exemption for audience measurement. The other official sources linked below should be reviewed on their own terms; they do not establish a uniform exemption or certify a product.
- What would the EU Digital Omnibus change?
- The Commission proposal COM(2025) 837 addresses changes to the digital legislative framework, including data protection and terminal-device rules. Check the legislative procedure and final text before changing a compliance decision. A proposal is not evidence that a particular analytics deployment qualifies for an exemption.
- Do I still need a cookie banner for other reasons?
- Possibly — for Google Ads pixels, Meta pixels, A/B testing tools or any third-party script that does set cookies. Sealmetrics removes the analytics-specific reason for the banner, not every reason. Many teams reduce the banner's scope (or eliminate it on pages without ad pixels) once analytics moves to a consentless layer.
- How does this differ from "consent-light" or "privacy-friendly" tools?
- Product labels are not enough to compare deployments. Check identifiers, purposes, data combination and reporting capabilities against the applicable requirements. Sealmetrics focuses on aggregate measurement; review its current documentation and your configuration before deciding whether consent is required.
- What about Schrems II and US transfers?
- Review the hosting location, sub-processors, remote access and actual data flows in the current DPA and TPSR package. Assess transfer requirements against that deployment; an EU hosting address alone does not settle every transfer question.
- Can the legal basis change if I add CRM or marketing tools later?
- Review the combined setup whenever tools, purposes or data flows change. Linking analytics to CRM data or adding advertising tags can change the processing that needs assessment. Recheck the conditions of any exemption and the consent requirements for each tool.
One compliance review. Done.
Book a 30-minute walkthrough with the founder. Bring your DPO. We answer the architecture questions and hand over the DPA + TPSR package on the call.
Built by a founder · EU-hosted by design