The banner decides what you can measure
Every visitor who rejects a consent-based tool disappears from its reports. On a Shopify store measured side by side for 48 days, GA4 did not record 29% of visits — the argument behind complete data.
Compliance · GDPR and ePrivacy, regulator by regulator
A cookie banner, a vendor badge or an exemption quoted second-hand does not survive a DPO review or a regulator's question. Sealmetrics is European analytics built to be checked: no cookies, no personal data in the stored dataset, visitor data processed in the EU — with the DPA, the data inventory and a regulator-by-regulator analysis published so your team can verify each claim.
EU-hosted in Dublin · DPA included · no ISO 27001 or SOC 2 claimed · not legal advice
Quick answer
GDPR-compliant analytics is web measurement whose data flows can be shown to meet the GDPR and the national ePrivacy rules, not just described as compliant. Two questions decide it: whether personal data is processed, and whether anything is stored on or read from the visitor's device, which is what triggers the consent requirement under ePrivacy as each country transposed it. Sealmetrics is built to answer both with evidence: it sets no cookies and writes nothing to the device, stores no IP addresses or cross-session identifiers, pseudonymises a short-lived session marker server-side and processes visitor data in Dublin. The DPA lists the fields, retention periods and sub-processors, and the France, Germany and Spain analyses map the architecture to each regulator's published criteria. Whether a specific deployment is exempt from consent still depends on its configuration, its purposes and the national authority, and Sealmetrics holds no ISO 27001 or SOC 2 certification.
The questions a review asks
A compliance review does not ask whether a tool is GDPR compliant. It asks what is collected, where it goes and for how long — and expects an answer it can check.
| The question | Typical cookie-based setup | Sealmetrics, as documented | Where to verify |
|---|---|---|---|
| Is anything stored on or read from the device? | Cookies or client IDs set on the first page | No cookies, localStorage, sessionStorage or other device storage | What we track · DPA Annex 2 |
| Is personal data stored? | Client IDs, IP-derived location, user-level profiles | No IPs, user IDs or raw user agents stored; the session marker is pseudonymised with a daily salt destroyed on rotation | DPA Annex 1 |
| Where does visitor data go? | Often a US provider, relying on a transfer framework | Stored and processed in the EU; the only non-EU sub-processor sends account emails and receives no visitor data | DPA clause 7 · Annex 3 |
| How long is it kept? | Configurable, often left at the default | Fixed TTLs: event log 1 day, hourly aggregates 90 days, daily aggregates 24 months | DPA Annex 1 |
| Against whose criteria? | A generic compliance badge | Analyses against CNIL, DSK and AEPD criteria; no certification claimed | Country analyses below |
None of these answers makes a deployment exempt from consent on its own. The CNIL describes a conditional exemption for audience measurement, and the AEPD cookie guide and the DSK set their own conditions. The field list is public in what we track, and the legal reasoning across the EU is set out under consentless analytics, the ePrivacy Directive and personal data in analytics.
What an unprovable setup costs
Once in legal exposure, and once in the data you give up to reduce it.
Every visitor who rejects a consent-based tool disappears from its reports. On a Shopify store measured side by side for 48 days, GA4 did not record 29% of visits — the argument behind complete data.
Adding a cookie, an identifier or a new purpose changes the processing and can require a new assessment. A fixed, documented data inventory keeps the scope of the analytics review stable.
When visitor data leaves the EU, the transfer basis has to be reassessed whenever the legal framework moves — the scenario worked through in what happens to analytics if the Data Privacy Framework falls.
The review checklist
Five checks your DPO can run on any analytics tool, including this one. The regulatory gap analysis maps the same requirements for your current stack.
List every field, where it is stored and for how long. For Sealmetrics that inventory is Annex 1 of the DPA: browsing and technical data, country from the browser time zone, a pseudonymised session identifier, UTM data and conversions, with fixed retention periods.
Confirm on your own site that no cookie, localStorage or other storage is written, and that no identifier links one visit to the next. The browser's developer tools show it in a minute.
Aggregated audience measurement and marketing attribution are different purposes. The DPA lists them separately, with attribution as an optional purpose you configure, so assess each one against your authority's criteria.
Read where visitor data is processed and who processes it. Sealmetrics lists its sub-processors in Annex 3 of the DPA; the only one outside the EU sends account emails and receives no visitor data.
ePrivacy is transposed country by country, so check the CNIL, DSK, AEPD or ICO conditions that apply to your site, and document how the configuration meets them.
Regulator by regulator
Each analysis states the criteria the authority actually published and how Sealmetrics is built against them. They describe guidance; they are not legal advice.
A conditional exemption for audience measurement.
Five permitted purposes and the 14 technical criteria of the CNIL self-assessment, mapped to the architecture.
GDPR analytics in France§25 TDDDG decides whether consent is needed.
The DSK orientation and the conditions under which storing or reading information on a device is strictly necessary.
GDPR analytics in GermanyLSSI-CE art. 22.2 and the 2024 cookie guide.
The conditions for anonymous audience measurement without consent, and the AEPD assessment the DPA refers to.
GDPR analytics in SpainThe PECR exemption for statistical purposes.
What the exemption covers for analytics in the UK, and how Sealmetrics documents it.
UK PECR analytics exemptionEvidence, not badges
Sealmetrics publishes its compliance position as documents a reviewer can read, and says what it does not hold: no ISO 27001, no SOC 2, and no regulator certification — authorities do not certify analytics tools.
What this does not settle
Stating the limits is part of the evidence. Security controls, retention and isolation are covered on the security overview, and the DPO's view on analytics for DPOs.
These pages describe published guidance and how Sealmetrics is built against it. Your DPO or counsel makes the call for your deployment.
Sealmetrics holds no ISO 27001 or SOC 2 certification, and no supervisory authority certifies analytics tools.
Custom properties, conversion values or URLs that carry names, emails or other personal data change the assessment. Keep personal data out of what you send.
Marketing attribution is an optional purpose in the DPA, alongside aggregated audience measurement. It should be assessed on its own terms, not assumed to share the same exemption.
Advertising pixels, A/B testing and chat widgets that store or read data on the device still need consent, whatever the analytics does.
The Digital Omnibus is a Commission proposal (COM(2025) 837), not law. Check the final text before changing a compliance decision.
Questions DPOs ask
Sealmetrics is built so that the dataset it stores contains no personal data, nothing is stored on the visitor's device and visitor data is processed in the EU under an Article 28 DPA. Compliance, though, is a property of your deployment: its configuration, its purposes and the rules of your national authority. Sealmetrics documents its side and does not claim any certification.
For the analytics itself, Sealmetrics sets no cookie and stores nothing on the device, so the ePrivacy storage-and-access rule has nothing to attach to. Whether your site needs a banner depends on the other tools you run and on your national authority's criteria: the CNIL, the DSK and the AEPD each publish their own conditions for audience measurement.
It can be used lawfully with consent, which is how most EU sites run it: GA4 sets cookies and processes personal data, so it needs prior consent and a transfer assessment because Google is a US provider. Several European authorities found Google Analytics deployments unlawful in 2022 over transfers to the US; those transfers now rely on the EU-US Data Privacy Framework adopted in 2023. The practical cost is the traffic lost to the banner.
Only transiently, to handle the request, and they are never stored. The country is derived from the browser time zone, not from the IP address, and the session marker is pseudonymised server-side with a daily salt that is destroyed on rotation.
Visitor data is stored and processed in Dublin, Ireland, with the default AI inference in Paris. Annex 3 of the DPA lists the sub-processors; the only one outside the EU sends service emails to account users and receives no visitor data.
The Article 28 DPA with its annexes (data processed, retention, security measures, sub-processors, transfer framework), the public field list in the documentation, the country analyses for France, Germany and Spain, a TPSR package for procurement, and assistance with impact assessments under clause 4.6 of the DPA.
No. Sealmetrics does not hold ISO 27001 or SOC 2 certification and does not claim either. The security measures it applies are listed in Annex 2 of the DPA, and customers have audit rights under clause 4.7.
Compliance walkthrough
Thirty minutes with the person responsible for the implementation: the data inventory, the DPA, the retention periods and the criteria of your national authority.