Every new tag reopens the assessment
A new cookie, identifier or purpose changes the processing and the record. A fixed data inventory keeps the analytics entry stable while the rest of the stack changes.
Role · DPO and legal
A DPO reviewing an analytics vendor needs to know what is collected, where it is processed, for how long and by whom, and most vendors answer with a policy page. Sealmetrics gives the review a closed scope: an Article 28 DPA whose annexes list the data processed, the retention periods and the sub-processors, no storage on the visitor's device, no stored IP addresses, and visitor data processed in Dublin.
Article 28 DPA · retention by database TTL · no ISO 27001 or SOC 2 claimed · not legal advice
Quick answer
Reviewing web analytics as a DPO means documenting what the tool collects, where and by whom it is processed, how long it is kept and whether the consent requirement applies. Sealmetrics is built to give that review a fixed scope. It writes no cookie or other storage on the visitor's device and keeps no IP address; the country comes from the browser time zone, and a session identifier is pseudonymised server-side with a daily salt destroyed on rotation. Visitor data is processed in Dublin under an Article 28 DPA that lists the data processed, the retention periods and the sub-processors, the only non-EU one sending account emails with no visitor data. Event-level rows are deleted after one day and aggregates after 24 months. Whether a deployment is exempt from consent still depends on its configuration, its purposes and the national authority, and Sealmetrics holds no ISO 27001 or SOC 2 certification.
What the DPO has to document
The questions below are the ones a record of processing and a vendor review need answered for any analytics tool. Each answer points to a document you can read.
| What you document | What to ask any analytics vendor | Sealmetrics, as documented | Where to verify |
|---|---|---|---|
| Data categories | Which fields are collected and which are never stored | Browsing and technical data, country from the browser time zone, a pseudonymised session identifier, UTMs and conversions; no IP, no user ID | DPA Annex 1 |
| Device access | Is anything stored on or read from the device? | No cookies, localStorage or other device storage | What we track |
| Purposes | Is marketing attribution separate from audience measurement? | Listed as separate purposes; attribution is optional and configured by you | DPA |
| Retention | Fixed or configurable, and who enforces it? | Fixed TTLs: event rows 1 day, hourly aggregates 90 days, daily aggregates and conversions 24 months | Data location and retention |
| Location and transfers | Where is visitor data processed, and who processes it? | Dublin, Ireland; the only non-EU sub-processor sends account emails and receives no visitor data | DPA Annex 3 |
| Assurance | Which certifications, audits and assistance? | No ISO 27001 or SOC 2; audit rights and DPIA assistance in the DPA; TPSR package | DPA clauses 4.6 and 4.7 · security |
The field list is public in what we track. How the architecture reads against the CNIL, DSK and AEPD criteria is set out regulator by regulator in GDPR analytics, and the security controls in security.
What an open-ended scope costs
The effort of an analytics review is set by how much of the processing is left to interpretation.
A new cookie, identifier or purpose changes the processing and the record. A fixed data inventory keeps the analytics entry stable while the rest of the stack changes.
When visitor data leaves the EU, the transfer basis has to be revisited each time the framework moves — the scenario in what happens to analytics if the Data Privacy Framework falls.
A banner-dependent tool records only visitors who accept. On a Shopify store measured side by side for 48 days, GA4 did not record 29% of visits. The trade-off between compliance and data is argued in complete data.
The vendor review
Five steps a DPO can run on Sealmetrics or on any other analytics tool. The regulatory gap analysis applies the same questions to your current stack.
Check the data processed and never stored, the retention periods, the security measures and the sub-processors. For Sealmetrics that is the Article 28 DPA 2026-v2.0 and its annexes, published at /dpa.
Open the site with the browser's developer tools and confirm that the analytics script writes no cookie, localStorage or other storage, and that requests go to the expected domain.
Custom properties, conversion values, URLs and campaign parameters are set by your own team. Confirm none of them carries names, emails, phone numbers or customer IDs; the Sealmetrics MCP prompt library includes an audit for this.
Audience measurement and marketing attribution are separate purposes. Read the conditions your national authority publishes, such as the CNIL, DSK or AEPD criteria, and decide how each purpose is covered.
Add the processing to your record with Sealmetrics as processor under the DPA, and describe the analytics in your privacy notice. The documentation includes recommended notice text you can adapt.
Who signs off
A vendor review crosses several desks. Each one gets a document it can check rather than a claim.
A record of processing entry that does not change every quarter.
The DPA annexes: data processed, retention, sub-processors and the purposes listed separately.
Read the DPAThe authority's criteria, not a vendor's conclusion.
Analyses against the CNIL, DSK and AEPD criteria, stated as guidance and not as legal advice.
GDPR analytics by countryControls and their boundaries, without claimed certifications.
Encryption, isolation, retention by TTL and the Dublin operating boundary; no ISO 27001 or SOC 2.
Security overviewTo know what can be sent without reopening the review.
An audit of custom properties and campaign parameters for personal data, runnable from an AI assistant.
MCP prompt libraryDocuments, not badges
There is no approved client quote on compliance, so this page points to documents. Sealmetrics also says what it does not hold: no ISO 27001, no SOC 2, and no regulator certification, because authorities do not certify analytics tools.
retention of event-level rows before deletion; aggregates are kept 24 months
the DPA clause committing Sealmetrics to assist with impact assessments and prior consultations
CNIL technical criteria documented one by one in a public self-assessment
What a review still has to decide
These limits belong in the record as much as the answers. The CNIL self-assessment in the documentation shows the criteria it maps.
These pages describe the product and published guidance. Your DPO or counsel decides for your deployment.
Sealmetrics holds no ISO 27001 or SOC 2 certification, and no supervisory authority certifies analytics tools.
Properties, URLs or campaign parameters that carry personal data bring it into the dataset. Keep them out of what the site sends.
Marketing attribution is listed separately from audience measurement in the DPA and has to be assessed on its own terms.
Advertising pixels, A/B testing and chat widgets that store or read data on the device still need consent.
The site owner describes the analytics in its privacy notice; the documentation offers text to adapt, not a finished policy.
Questions DPOs ask
Which data is collected and which is never stored, whether anything is stored on or read from the visitor's device, which purposes the data serves, how long each category is kept, where it is processed and by which sub-processors, and which audits, certifications and assistance the contract provides. Ask for the answers in the processing agreement, not on a marketing page.
Sealmetrics acts as processor for the customer's analytics under an Article 28 DPA; the customer remains controller of its website's processing. The DPA sets out the data processed, the purposes, the retention periods, the security measures and the sub-processors.
That is your assessment to make, based on your processing as a whole. Under clause 4.6 of the DPA, Sealmetrics assists with impact assessments and prior consultations and keeps the technical documentation of the processing available: architecture, data inventory, retention and the AEPD assessment.
That the site uses Sealmetrics for audience measurement, which data it processes and for which purposes, and how visitors can object. The documentation includes recommended text in its CNIL self-assessment that you can adapt to your notice and your national rules.
Sealmetrics builds no individual profile, so there is no personal history to opt out of. Visitors can block analytics through their browser's privacy settings or an ad blocker, and a site can add its own opt-out mechanism, as the CNIL self-assessment in the documentation describes.
Visitor data is stored and processed in Dublin, Ireland. Annex 3 of the DPA lists the sub-processors: the only one outside the EU sends service emails to account users and receives no visitor data, and the managed AI inference for Private AI runs in Paris.
None. Sealmetrics does not hold ISO 27001 or SOC 2 certification and does not claim either. The security measures are listed in the DPA, customers have audit rights under clause 4.7, and a TPSR package is available for procurement reviews.
Compliance walkthrough
Thirty minutes with the person responsible for the implementation: the DPA annexes, the retention periods, the sub-processors and the criteria of your national authority.