GDPR analytics, regulator by regulator.
GDPR analytics in France
The CNIL exemption for analytics: five criteria, a 14-point self-assessment, and the Digital Omnibus impact.
Read the analysis →DSK / BfDIGDPR analytics in Germany
§25 TTDSG, the DSK orientation paper and BfDI guidance — and how a cookieless architecture meets the exemption by design.
Read the analysis →AEPDGDPR analytics in Spain
The AEPD 2024 cookies guide and LSSI-CE Art. 22.2 — the conditions for anonymous audience measurement without consent.
Read the analysis →Which countries are not covered here?
Only France, Germany and Spain have dedicated pages today, because those are the three authorities that published analytics-specific criteria detailed enough to audit against. The UK is covered separately in the PECR analytics exemption, and the EU-wide direction of travel in the Digital Omnibus guide. For the legal reasoning that applies across the EU regardless of member state, start with consentless analytics or run the regulatory gap analysis against your current stack.
Compliance your DPO can actually sign.
Book a demo and we'll walk your DPO through the architecture, the DPA and the regulator criteria for your market.
Built by a founder · supported by a founder · EU-hosted by design