Skip to content
Sealmetrics
Pillar — Consentless analytics

Analytics without consent banners. Lawful by architecture, not by paperwork.

Updated · By , Founder, Sealmetrics

Consent requirements depend on the processing and the applicable rules. Review the technical configuration alongside official guidance to understand when measurement can operate without a consent dialog, and what conditions still apply.

Review the scope and conditions in the CNIL's analytics exemption criteria.

Why cookie banners stopped working

Consent banners were never a measurement strategy — they were a compliance instrument bolted onto a measurement strategy that assumed everyone said yes. Three things broke that assumption, and one regulation in 2026 broke it further.

Rejection rates climbed past the break-even line

When most European visitors said yes, cookie analytics could absorb the loss. Today, in our experience with clients, between 40% and 60% of traffic doesn’t accept cookies, and of those who do, 40% don’t accept on the first pageview. On Incapto’s Shopify store, measured over 48 days, GA4 did not record 29% of visits. Decisions made on what remains are decisions made on a self-selected sample — typically older, less mobile, less privacy-aware. The bias is silent and structural.

Review the consent interface as well as the analytics

If other tools on the site require consent, review their interface and behavior separately. Check whether the choices shown to visitors match the tracking that actually occurs, using the relevant authority guidance linked below.

Measure the effect of your consent interface

Check how your consent interface affects engagement on your own site. Compare page interaction and consent choices using a measurement method that respects those choices. Do not assume a universal abandonment rate or attribute every lost visit to the banner.

The Digital Omnibus would redraw the line

The Commission's proposal of November 2025 would move the terminal-device rules into the GDPR and exempt first-party, aggregated audience measurement from consent. It is still a proposal — adoption is realistically 2027–2028 — but the direction is clear. Read the practical implications in the marketer's guide. Net effect: the legal cost of running cookie-based analytics rose; the legal cost of running consentless analytics is zero.

The architectural route to lawfulness

The exemption is not a clever interpretation; it is the original wording. Three regulatory anchors define the path, and a measurement system either sits inside them by design or it does not.

Anchor 1

GDPR Article 2 — material scope

GDPR applies to “the processing of personal data.” Personal data is any information that relates to an identified or identifiable natural person. If a measurement system processes only aggregate counts — never an identifier, never a fingerprint, never a behavioural profile — the system does not process personal data. The Regulation does not apply to its measurement output. Assess the data processed at every stage, not only the final report.

Anchor 2

ePrivacy Article 5(3) — terminal-device storage

ePrivacy requires consent before storing or accessing information on the user's terminal device. The classic example is a cookie. If the measurement system writes no cookie, reads no localStorage, and uses no device fingerprint, there is nothing on the terminal device to trigger Art. 5(3). No consent dialog is required for that processing path.

Anchor 3

The CNIL analytics exemption criteria

The CNIL describes a conditional exemption for audience measurement. Its scope includes restrictions on purpose, combining data and use across sites, alongside other requirements. Review the complete CNIL guidanceagainst the deployed configuration. A product label alone does not establish that every condition is met.

The technical implementation — first-party server-side collection without identifiers — is documented at cookieless analytics. The architecture diagram and pipeline detail live at How it works.

Authority guidance, by country

Consent rules and exemptions depend on the jurisdiction and the deployed configuration. The official sources below provide starting points for review; they are not product endorsements.

France

CNIL

Review the CNIL guidance on audience measurement and the conditions for a consent exemption. Official guidance.

Germany

DSK / BfDI

Consult the DSK guidance for the rules applicable to the actual German deployment. Official guidance.

Spain

AEPD

Review the AEPD cookie guide and assess the purpose and configuration of measurement. Official guidance.

Italy

Garante

Consult the Garante guidance on cookies and other tracking technologies. Official guidance.

United Kingdom

ICO (PECR)

Review the current ICO guidance on PECR and the conditions relevant to statistical measurement. Official guidance.

Netherlands

Autoriteit Persoonsgegevens

Consult the Dutch authority guidance on cookies and analytics before assessing an exemption. Official guidance.

Country-specific deep-dives — including the CNIL self-assessment, the UK PECR exemption walkthrough, and the Digital Omnibus marketer guide — live on the blog.

“Consentless” vs “consent-light” — the distinction that matters for DPOs

A common confusion: lightweight analytics tools that claim “no cookie banner needed” while still setting a first-party cookie or a randomised visitor ID. From a CMP- integration perspective the experience is similar. From a regulatory perspective the two are not in the same category.

Consent-light

  • Sets a first-party cookie or visitor ID (often randomised).
  • Justifies under “legitimate interest” — a position several authorities have rejected for cross-session tracking.
  • Stores the identifier on the terminal device → ePrivacy Art. 5(3) still triggers.
  • Argument depends on banner-free interpretation that authorities can challenge case-by-case.

Consentless (Sealmetrics)

  • Sets no cookie, writes no localStorage, no visitor ID generated.
  • Review the collection and processing stages to establish whether personal data is involved.
  • Review terminal-device storage and access practices separately from reporting output.
  • Review the deployed configuration against the applicable local guidance and exemption conditions.

For a DPO reviewing vendor risk, the practical question is: does the tool's defence rely on regulatory interpretation, or on the absence of triggering conditions? Consentless architecture is the second answer.

What ships with the platform

The architectural exemption removes the consent burden. The following documentation supports the rest of a vendor review:

DPA

Data Processing Agreement, GDPR Art. 28 compliant, signed by Sealmetrics S.L. as processor. Pre-filled, ready to counter-sign.

TPSR package

Transfer, Privacy and Security Review document. Covers data flows, sub-processors (none outside the EU on visitor data), retention, encryption at rest and in transit, access controls, breach procedure.

Sub-processor list

Full list of sub-processors with their roles, jurisdictions and DPAs ships inside the TPSR package. All EU-only by policy.

Hosting & residency

Review the current hosting and sub-processor documentation, including jurisdictions and access arrangements, when assessing data residency and transfers.

Retention

Fixed and identical for every plan, enforced by automatic database TTLs: event-level technical log 1 day, hourly aggregates 90 days, daily aggregates and conversions 24 months. No raw individual-level data is stored beyond the millisecond-level aggregation window.

Full security and architecture documentation lives at Security. We are not currently certified to ISO 27001 or SOC 2 — the roadmap and the controls we already operate are documented in full.

Common DPO questions

Is consentless analytics actually legal under GDPR?
It depends on the actual processing and applicable rules. Review whether personal data is processed, whether information is stored on or read from a device, and whether an exemption applies. The CNIL describes a conditional exemption for audience measurement. The other official sources linked below should be reviewed on their own terms; they do not establish a uniform exemption or certify a product.
What would the EU Digital Omnibus change?
The Commission proposal COM(2025) 837 addresses changes to the digital legislative framework, including data protection and terminal-device rules. Check the legislative procedure and final text before changing a compliance decision. A proposal is not evidence that a particular analytics deployment qualifies for an exemption.
Do I still need a cookie banner for other reasons?
Possibly — for Google Ads pixels, Meta pixels, A/B testing tools or any third-party script that does set cookies. Sealmetrics removes the analytics-specific reason for the banner, not every reason. Many teams reduce the banner's scope (or eliminate it on pages without ad pixels) once analytics moves to a consentless layer.
How does this differ from "consent-light" or "privacy-friendly" tools?
Product labels are not enough to compare deployments. Check identifiers, purposes, data combination and reporting capabilities against the applicable requirements. Sealmetrics focuses on aggregate measurement; review its current documentation and your configuration before deciding whether consent is required.
What about Schrems II and US transfers?
Review the hosting location, sub-processors, remote access and actual data flows in the current DPA and TPSR package. Assess transfer requirements against that deployment; an EU hosting address alone does not settle every transfer question.
Can the legal basis change if I add CRM or marketing tools later?
Review the combined setup whenever tools, purposes or data flows change. Linking analytics to CRM data or adding advertising tags can change the processing that needs assessment. Recheck the conditions of any exemption and the consent requirements for each tool.

One compliance review. Done.

Book a 30-minute walkthrough with the founder. Bring your DPO. We answer the architecture questions and hand over the DPA + TPSR package on the call.

Built by a founder · EU-hosted by design