---
title: "GDPR analytics by country — regulator guidance"
description: "How analytics runs lawfully without a cookie banner in France, Germany and Spain. CNIL, DSK/TTDSG and AEPD guidance, criterion by criterion."
canonical_url: "https://sealmetrics.com/gdpr-analytics/"
lang: "en"
content_type: "product"
owner: "web"
llm_priority: "useful"
last_verified: "2026-08-16"
source: https://sealmetrics.com/gdpr-analytics/
publisher: SealMetrics
---

Compliance by country

# GDPR analytics, *regulator by regulator.*

Quick answer

GDPR is a single regulation, but the rule that decides whether an analytics tag needs a consent banner is ePrivacy, and ePrivacy is transposed nationally. That is why the same setup can be consent-exempt in France and contested in Germany. Each page below works through one national supervisory authority — CNIL, the DSK under §25 TTDSG, and the AEPD — and states the criteria that authority actually published, then which architectures satisfy them. These pages describe regulator guidance and how SealMetrics is built against it. They are not legal advice, and none of them claims a certification SealMetrics does not hold.

[CNIL

## GDPR analytics in France

The CNIL exemption for analytics: five criteria, a 14-point self-assessment, and the Digital Omnibus impact.

Read the analysis →](https://sealmetrics.com/gdpr-analytics/france/)[DSK / BfDI

## GDPR analytics in Germany

§25 TTDSG, the DSK orientation paper and BfDI guidance — and how a cookieless architecture meets the exemption by design.

Read the analysis →](https://sealmetrics.com/gdpr-analytics/germany/)[AEPD

## GDPR analytics in Spain

The AEPD 2024 cookies guide and LSSI-CE Art. 22.2 — the conditions for anonymous audience measurement without consent.

Read the analysis →](https://sealmetrics.com/gdpr-analytics/spain/)

## Which countries are not covered here?

Only France, Germany and Spain have dedicated pages today, because those are the three authorities that published analytics-specific criteria detailed enough to audit against. The UK is covered separately in [the PECR analytics exemption](https://sealmetrics.com/blog/uk-pecr-analytics-exemption/), and the EU-wide direction of travel in [the Digital Omnibus guide](https://sealmetrics.com/blog/eu-digital-omnibus-marketer-guide-2026/). For the legal reasoning that applies across the EU regardless of member state, start with [consentless analytics](https://sealmetrics.com/consentless-analytics/) or run the [regulatory gap analysis](https://sealmetrics.com/reg-gap-analysis/) against your current stack.

## Compliance your DPO *can actually sign.*

Book a demo and we'll walk your DPO through the architecture, the DPA and the regulator criteria for your market.

[Book a demo →](https://sealmetrics.com/demo/)[Start 14-day trial](https://my.sealmetrics.com/register)

Built by a founder · supported by a founder · EU-hosted by design
