Identifiers on visitors who may be minors
Cookies and client IDs are set on everyone who reads a programme page, including visitors below the age of digital consent in their country. Your DPO has to assess that processing, whatever the tool reports.
Industry · Universities, schools and EdTech
Universities, business schools and EdTech platforms need to know which channels bring programme enquiries and applications, and the people reading course pages include teenagers. A tool that sets cookies and identifiers applies them to every one of those visitors, and a consent banner removes part of the traffic anyway. Sealmetrics measures enquiries and applications by channel in aggregate, without cookies or stored identifiers, and documents what it stores so your counsel can assess it.
Aggregate counts · no cookies · no age, name or email collected · EU-hosted in Dublin · not legal advice
Quick answer
Analytics for education is web measurement of how prospective students find a programme and send an enquiry or an application, on data an institution can put in front of its DPO. The difficulty is the audience: course and admissions pages are read by adults and by minors, and a tool that sets cookies or identifiers processes data about both without knowing which is which. A consent banner then removes the visitors who reject it, so channels are judged on part of the traffic. Sealmetrics sets no cookies, stores no IP addresses, user IDs or cross-session identifiers, collects no age, name or email, and keeps page views and conversions as aggregate counts processed in Dublin. Whether rules on children's data apply to your site, and whether your deployment needs consent, is for your counsel to decide, and what you send in URLs and properties is part of that assessment.
What a visit leaves behind
An admissions site cannot tell a seventeen-year-old from a parent or a mature student. The practical question is what each visit leaves in the analytics tool, whoever made it.
| What a visit to a programme page leaves | Tag with cookies or identifiers | Sealmetrics, as documented | Where to verify |
|---|---|---|---|
| Something on the device | A cookie or client ID set on the first page | No cookies, localStorage or sessionStorage | What we track |
| An identifier linking visits | A client ID that recognises the visitor on the next visit | No cross-session identifier; the session marker expires after 2 hours of inactivity | What we track · DPA Annex 1 |
| Age, name or contact details | Available to the tool when forms or user IDs are wired into it | Not collected; conversions carry only the generic properties you choose to send | DPA Annex 1 · clause 5 |
| The enquiry or application | An event tied to the visitor's identifier | An aggregate conversion credited to the last click of its session | Conversion tracking |
| Where it is processed | Often a US provider, relying on a transfer framework | Dublin, Ireland; no non-EU sub-processor receives visitor data | DPA clause 7 · Annex 3 |
The field list is public in what we track. How national authorities treat audience measurement is set out country by country under GDPR analytics; none of those analyses addresses rules specific to children's data, which your counsel assesses for your site. The general question of personal data in analytics is covered in the glossary.
What the usual setup costs
Recruitment runs on a long cycle of open days, enquiries, applications and enrolment, and each common workaround removes part of it from view.
Cookies and client IDs are set on everyone who reads a programme page, including visitors below the age of digital consent in their country. Your DPO has to assess that processing, whatever the tool reports.
A consent-based tool loses the visitors who reject its banner. The Sealmetrics documentation puts that at 15–60% of EU visitors depending on sector, brand strength and traffic mix; no figure for education has been published. How that gap forms is explained under data loss in analytics.
Applications often continue on a separate admissions, identity or payment portal. Without configuration, the visit that returns from it is credited to that domain as a referral, not to the campaign that started it, as the external-domain guide explains.
From review to reporting
Five steps from the counsel review to channel reporting. Event-level detail for forms is in conversion tracking.
Share the DPA with its data inventory, retention periods and sub-processors, and the public field list, with the DPO and counsel. Record the purposes you enable: aggregated audience measurement, and marketing attribution as a separate, optional purpose assessed on its own terms.
Fire a conversion when a programme enquiry, open-day registration or application is completed, with generic properties such as programme or campus. Never send names, emails, dates of birth, student or applicant numbers, and check that form URLs carry none. There is no server-side list of allowed properties, so what you send is your decision as controller.
Add the tracker to public programme and admissions pages, which takes 5 to 30 minutes depending on the platform. If applications continue on an external admissions, identity or payment domain, register it as a passthrough referrer through the API. Leave student accounts and learning platforms without the tracker unless your DPO has reviewed them.
Keep your current analytics running through at least one campaign or open-day period. Compare measured enquiries and applications with the totals in your CRM or admissions system, by period and by channel, never record by record.
Read enquiries, applications and conversion rate by channel, campaign, landing page and country. No report shows a student: with nothing personal in what the site sends, no stored identifier links a visit to a person.
Who is involved
Recruitment, legal, the web team and leadership look at the same deployment for different reasons.
Know which channels bring enquiries and applications for each programme.
Conversions by source, medium, campaign and landing page, credited to the last click of each session, without consent loss.
Revenue attributionAssess processing on an audience that includes minors.
The DPA data inventory and the public field list as material for your assessment; the country analyses are self-assessments, not rulings.
Analytics for DPOsControl which pages run the tag and what it sends.
Tracker on public pages, generic properties, passthrough referrers for portals; role-based access and 2FA for staff accounts.
Analytics for CTOsAllocate recruitment budget on numbers admissions can reconcile.
Measured enquiries and applications reconciled with the CRM or admissions system before any channel is compared.
Single source of truthEvidence, not a sector case
Sealmetrics has no published case study from a university, school or EdTech platform, and this page does not imply one. The documents below can be checked today. The measured figure comes from an eCommerce parallel run and shows how uneven consent loss changes the channel mix; it is context, not an education result.
every field processed, what is never stored and each retention period
country analyses of audience-measurement criteria (CNIL, DSK, AEPD); self-assessments, not certifications
gap in paid campaigns' share of traffic, 50% in GA4 against 62% measured; eCommerce context, not an education result
What it does not do
These limits come from measuring without identifying anyone. Attribution is last click within each session, by design.
No individual journeys, returning-visitor recognition or profiles. A prospective student who returns after an open day is a new visit.
No lookback across sessions and no multi-touch model. A decision that takes months is credited to the session in which the application is sent.
Sealmetrics does not know or infer a visitor's age, and cannot tell you whether minors use your site.
Nothing here states whether COPPA, national youth-protection rules or the GDPR provisions on children apply to your site. That is for your counsel.
Advertising pixels, chat widgets, video embeds and learning platforms keep their own consent and data protection requirements.
The DPA and the self-assessments support your DPIA and legal analysis; they do not replace them. No ISO 27001 or SOC 2 certification is claimed.
Questions education teams ask
Sealmetrics collects no age, name, email, IP address or cross-session identifier from any visitor, whatever their age, and stores nothing on the device. Whether rules on children's data apply to your site, and what they require, depends on your audience, your services and your jurisdiction. That is for your counsel to assess, with the data inventory in the DPA as input.
For the analytics itself, Sealmetrics sets no cookie and stores nothing on the visitor's device. Whether your deployment is exempt from consent depends on its configuration, the purposes you enable and your national authority's criteria. Advertising pixels, chat widgets and other tools on the site keep their own consent requirements, so a banner may still be needed for them.
Send each completed programme enquiry, open-day registration or application as a conversion with generic properties such as programme or campus. Each one is credited to the last click of its session. If the application continues on an external admissions or payment portal, register that domain as a passthrough referrer through the API so the original channel is kept.
Only after your DPO has reviewed that deployment. Logged-in areas are where URLs and events are most likely to carry student information, and Sealmetrics does not analyse individual users in any case. The acquisition questions sit on public programme pages and admissions flows.
Names, emails, phone numbers, dates of birth, student or applicant numbers, and anything else that identifies a person. The DPA makes keeping direct personal data out of properties, URL parameters and campaign names the controller's obligation, and properties can be read back by anyone with access to the site's reports.
Visitor data is stored and processed in Dublin, Ireland; the only non-EU sub-processor sends service emails to account users and receives no visitor data. The Article 28 DPA covers the data inventory, retention, security measures and sub-processors. A TPSR package is available for technical, privacy and security review, and Sealmetrics assists with impact assessments under clause 4.6 of the DPA.
At least one recruitment campaign or open-day period, with your current tools still running. Compare measured enquiries and applications with the totals in your CRM or admissions system by period and channel before moving budget.
Recruitment measurement review
Thirty minutes with the person responsible for the implementation: the data inventory, what your site should never send, and how enquiries and applications are measured by channel.