Skip to content
Sealmetrics

Compliance · GDPR and ePrivacy, regulator by regulator

You have to prove
your analytics complies.
Not just say it.

A cookie banner, a vendor badge or an exemption quoted second-hand does not survive a DPO review or a regulator's question. Sealmetrics is European analytics built to be checked: no cookies, no personal data in the stored dataset, visitor data processed in the EU — with the DPA, the data inventory and a regulator-by-regulator analysis published so your team can verify each claim.

EU-hosted in Dublin · DPA included · no ISO 27001 or SOC 2 claimed · not legal advice

Quick answer

GDPR-compliant analytics is web measurement whose data flows can be shown to meet the GDPR and the national ePrivacy rules, not just described as compliant. Two questions decide it: whether personal data is processed, and whether anything is stored on or read from the visitor's device, which is what triggers the consent requirement under ePrivacy as each country transposed it. Sealmetrics is built to answer both with evidence: it sets no cookies and writes nothing to the device, stores no IP addresses or cross-session identifiers, pseudonymises a short-lived session marker server-side and processes visitor data in Dublin. The DPA lists the fields, retention periods and sub-processors, and the France, Germany and Spain analyses map the architecture to each regulator's published criteria. Whether a specific deployment is exempt from consent still depends on its configuration, its purposes and the national authority, and Sealmetrics holds no ISO 27001 or SOC 2 certification.

The questions a review asks

Five questions.
Five documented answers.

A compliance review does not ask whether a tool is GDPR compliant. It asks what is collected, where it goes and for how long — and expects an answer it can check.

The questionTypical cookie-based setupSealmetrics, as documentedWhere to verify
Is anything stored on or read from the device?Cookies or client IDs set on the first pageNo cookies, localStorage, sessionStorage or other device storageWhat we track · DPA Annex 2
Is personal data stored?Client IDs, IP-derived location, user-level profilesNo IPs, user IDs or raw user agents stored; the session marker is pseudonymised with a daily salt destroyed on rotationDPA Annex 1
Where does visitor data go?Often a US provider, relying on a transfer frameworkStored and processed in the EU; the only non-EU sub-processor sends account emails and receives no visitor dataDPA clause 7 · Annex 3
How long is it kept?Configurable, often left at the defaultFixed TTLs: event log 1 day, hourly aggregates 90 days, daily aggregates 24 monthsDPA Annex 1
Against whose criteria?A generic compliance badgeAnalyses against CNIL, DSK and AEPD criteria; no certification claimedCountry analyses below

None of these answers makes a deployment exempt from consent on its own. The CNIL describes a conditional exemption for audience measurement, and the AEPD cookie guide and the DSK set their own conditions. The field list is public in what we track, and the legal reasoning across the EU is set out under consentless analytics, the ePrivacy Directive and personal data in analytics.

What an unprovable setup costs

Compliance you cannot show
costs twice.

Once in legal exposure, and once in the data you give up to reduce it.

01

The banner decides what you can measure

Every visitor who rejects a consent-based tool disappears from its reports. On a Shopify store measured side by side for 48 days, GA4 did not record 29% of visits — the argument behind complete data.

02

Every new tool reopens the review

Adding a cookie, an identifier or a new purpose changes the processing and can require a new assessment. A fixed, documented data inventory keeps the scope of the analytics review stable.

The review checklist

Review it
the way a regulator would.

Five checks your DPO can run on any analytics tool, including this one. The regulatory gap analysis maps the same requirements for your current stack.

  1. Map what the tag collects

    List every field, where it is stored and for how long. For Sealmetrics that inventory is Annex 1 of the DPA: browsing and technical data, country from the browser time zone, a pseudonymised session identifier, UTM data and conversions, with fixed retention periods.

  2. Check device storage and identifiers

    Confirm on your own site that no cookie, localStorage or other storage is written, and that no identifier links one visit to the next. The browser's developer tools show it in a minute.

  3. Separate the purposes

    Aggregated audience measurement and marketing attribution are different purposes. The DPA lists them separately, with attribution as an optional purpose you configure, so assess each one against your authority's criteria.

  4. Check location, sub-processors and transfers

    Read where visitor data is processed and who processes it. Sealmetrics lists its sub-processors in Annex 3 of the DPA; the only one outside the EU sends account emails and receives no visitor data.

  5. Read your national authority's criteria and record the decision

    ePrivacy is transposed country by country, so check the CNIL, DSK, AEPD or ICO conditions that apply to your site, and document how the configuration meets them.

Regulator by regulator

The same architecture,
read against four authorities.

Each analysis states the criteria the authority actually published and how Sealmetrics is built against them. They describe guidance; they are not legal advice.

France · CNIL

A conditional exemption for audience measurement.

Five permitted purposes and the 14 technical criteria of the CNIL self-assessment, mapped to the architecture.

GDPR analytics in France

Germany · DSK

§25 TDDDG decides whether consent is needed.

The DSK orientation and the conditions under which storing or reading information on a device is strictly necessary.

GDPR analytics in Germany

Spain · AEPD

LSSI-CE art. 22.2 and the 2024 cookie guide.

The conditions for anonymous audience measurement without consent, and the AEPD assessment the DPA refers to.

GDPR analytics in Spain

United Kingdom · ICO

The PECR exemption for statistical purposes.

What the exemption covers for analytics in the UK, and how Sealmetrics documents it.

UK PECR analytics exemption

Evidence, not badges

Sealmetrics publishes its compliance position as documents a reviewer can read, and says what it does not hold: no ISO 27001, no SOC 2, and no regulator certification — authorities do not certify analytics tools.

Annex 1

every field processed, what is never stored, and each retention period

Data Processing AgreementOpen
14

CNIL technical criteria documented one by one in a public self-assessment

CNIL self-assessmentOpen
0

sub-processors outside the EU that receive visitor data

DPA Annex 3Open

What this does not settle

Evidence helps a decision.
It does not make it.

Stating the limits is part of the evidence. Security controls, retention and isolation are covered on the security overview, and the DPO's view on analytics for DPOs.

— Not legal advice

These pages describe published guidance and how Sealmetrics is built against it. Your DPO or counsel makes the call for your deployment.

— No certification

Sealmetrics holds no ISO 27001 or SOC 2 certification, and no supervisory authority certifies analytics tools.

— Configuration can change the answer

Custom properties, conversion values or URLs that carry names, emails or other personal data change the assessment. Keep personal data out of what you send.

— Attribution is its own purpose

Marketing attribution is an optional purpose in the DPA, alongside aggregated audience measurement. It should be assessed on its own terms, not assumed to share the same exemption.

— Other tools keep their obligations

Advertising pixels, A/B testing and chat widgets that store or read data on the device still need consent, whatever the analytics does.

— The rules are moving

The Digital Omnibus is a Commission proposal (COM(2025) 837), not law. Check the final text before changing a compliance decision.

Questions DPOs ask

Before you sign
the processing record.

Is Sealmetrics GDPR compliant?

Sealmetrics is built so that the dataset it stores contains no personal data, nothing is stored on the visitor's device and visitor data is processed in the EU under an Article 28 DPA. Compliance, though, is a property of your deployment: its configuration, its purposes and the rules of your national authority. Sealmetrics documents its side and does not claim any certification.

Do I need a cookie banner for Sealmetrics?

For the analytics itself, Sealmetrics sets no cookie and stores nothing on the device, so the ePrivacy storage-and-access rule has nothing to attach to. Whether your site needs a banner depends on the other tools you run and on your national authority's criteria: the CNIL, the DSK and the AEPD each publish their own conditions for audience measurement.

Is Google Analytics legal in the EU?

It can be used lawfully with consent, which is how most EU sites run it: GA4 sets cookies and processes personal data, so it needs prior consent and a transfer assessment because Google is a US provider. Several European authorities found Google Analytics deployments unlawful in 2022 over transfers to the US; those transfers now rely on the EU-US Data Privacy Framework adopted in 2023. The practical cost is the traffic lost to the banner.

Does Sealmetrics process IP addresses?

Only transiently, to handle the request, and they are never stored. The country is derived from the browser time zone, not from the IP address, and the session marker is pseudonymised server-side with a daily salt that is destroyed on rotation.

Where is visitor data hosted, and who are the sub-processors?

Visitor data is stored and processed in Dublin, Ireland, with the default AI inference in Paris. Annex 3 of the DPA lists the sub-processors; the only one outside the EU sends service emails to account users and receives no visitor data.

What documentation can we get for a DPO review?

The Article 28 DPA with its annexes (data processed, retention, security measures, sub-processors, transfer framework), the public field list in the documentation, the country analyses for France, Germany and Spain, a TPSR package for procurement, and assistance with impact assessments under clause 4.6 of the DPA.

Which security certifications does Sealmetrics hold?

No. Sealmetrics does not hold ISO 27001 or SOC 2 certification and does not claim either. The security measures it applies are listed in Annex 2 of the DPA, and customers have audit rights under clause 4.7.

Compliance walkthrough

Bring your DPO.
We bring the documents.

Thirty minutes with the person responsible for the implementation: the data inventory, the DPA, the retention periods and the criteria of your national authority.