Skip to content
Sealmetrics
Country — France · CNIL

Analytics in France. Without a cookie banner.

The CNIL has published explicit exemption criteria for analytics since 2020. This is what the exemption requires, how the 2025 self-assessment tool works, and what the proposed Digital Omnibus would change.

The 5 CNIL criteria

The CNIL exemption is not vague. Five operational requirements define the boundary. An analytics tool either meets each one by design or it does not qualify.

01

Strictly limited purpose

CNIL requires

Measurement must serve only audience analytics — no marketing, no advertising, no profiling.

Sealmetrics

Aggregate channel and conversion counts only. No identifier, no profile, no audience export to ad platforms.

02

No cross-site tracking

CNIL requires

The tool must not enable tracking the visitor across other websites.

Sealmetrics

First-party server-side. The pixel runs on your own domain. No third-party cookie, no cross-site identifier.

03

IP anonymisation or non-collection

CNIL requires

Last octet of IP addresses must be removed before processing (or IPs not collected at all).

Sealmetrics

No IP address is ever stored — it has no column in any analytics database. The IP is used transiently in memory during request handling and then discarded. The CNIL requirement is met by exceeding it.

04

No merging with other personal data

CNIL requires

Analytics data must not be combined with personal data from other sources.

Sealmetrics

There is no personal data to merge. Aggregate counts are isolated from any CRM, advertising or marketing identifier.

05

Aggregate-only reporting

CNIL requires

Reports must be aggregate. No individual-level data may be exposed.

Sealmetrics

Every report is aggregate — by channel, campaign, landing page, country, device class. No per-visitor view exists in the product.

The 14-point self-assessment

In July 2025 the CNIL published an auto-évaluation tool translating the five high-level criteria into 14 concrete technical requirements covering data retention, IP anonymisation, cookie use, cross-site behaviour, exports and more. Each must be met for the exemption to apply.

We published our complete answer to each of the 14 points in a public blog post — copy patterns directly into your DPO review, or send the link with our DPA and the TPSR package. Two examples of the shape:

CNIL: Last octet of IP must be removed.

Sealmetrics: No IP address is ever stored — it is used transiently in memory during request handling and then discarded.


CNIL: Cookies must not exceed 13 months retention.

Sealmetrics: No persistent cookies are used.

What the proposed Digital Omnibus would change

The EU Digital Omnibus (COM(2025) 837) was published by the Commission on 19 November 2025. It is a proposal, not law: Parliament and Council have still to agree a text, substantive amendments are likely, and adoption is realistically 2027–2028. Nothing below is in force. Three things in the draft matter for French operators:

  • Reject-all parity would become formal. Banner asymmetry (highlighting “accept” vs hiding “reject”) would be enforceable at EU level rather than through CNIL national action alone, raising the cost of running a defensible banner.
  • Article 5(3) would move into the GDPR. A new Article 88a would carry the terminal-device rules, giving authorities explicit jurisdiction instead of the CNIL reaching for adjacent grounds.
  • The exemption would widen, not close. First-party aggregated audience measurement for the controller’s own use would be consent-exempt EU-wide — the French carve-out generalised. Cookie-based tools that meet the conditions would qualify too, so the differentiator shifts from the banner to what the exempt configuration costs you in measurement.

For the operator’s view of what would change, see the marketer’s guide to the Digital Omnibus.

What it means for your French site

Three practical outcomes for an operator running a French site with Sealmetrics installed:

Banner scope shrinks (or disappears)

If Sealmetrics is the only analytics layer and the only tools that set cookies are strictly-necessary (cart, session, fraud), no consent dialog is required. If you also run ad pixels or A/B testing tools, the banner shrinks to those specific consents.

Privacy policy still required

Transparency obligations apply regardless of consent. The privacy policy must mention the analytics tool, its purpose, data categories, retention, and lawful basis. A template is included in our TPSR package.

100% of French traffic measured

French rejection rates against standard banners run 50–60%. With no banner gate, every visitor is counted on the same anonymous-aggregate basis — no Consent Mode modelling required to fill the gap.

Common DPO questions

Does the CNIL exemption mean no cookie banner at all?
It means no cookie banner is required for the analytics layer specifically. If your site also runs Google Ads pixels, Meta pixels, A/B testing tools or any tool that sets cookies, those tools still require consent. The banner scope shrinks to the tools that actually need it — often substantially. Many French eCommerce teams reduce the banner scope to one or two products instead of the catch-all banner.
Is the CNIL exemption a 'workaround'?
No. The CNIL has published explicit criteria for analytics exemption since 2020, reaffirmed in 2024 and aligned with the EDPB Opinion 5/2019. The exemption is the original carve-out the regulation contemplated for genuine audience measurement that does not enable tracking. Architectures that meet the criteria are not exploiting a loophole; they are using the regulation as written.
How does the 2025 CNIL self-assessment tool work?
In July 2025 the CNIL released an auto-évaluation covering 5 permitted objectives and 14 technical criteria. Operators document how their analytics implementation meets each requirement. We published our complete self-assessment in a public blog post — useful to copy patterns from or share with your DPO.
What if my analytics is hosted in another EU country?
The exemption applies as long as the processing happens in the EU (no third-country transfer). Sealmetrics processes exclusively in Dublin, Ireland — within scope of GDPR adequacy, no Schrems II transfer assessment required.
Would the proposed Digital Omnibus change the CNIL position?
Not adversely, and not yet at all — it is a proposal, not law. The Commission published COM(2025) 837 on 19 November 2025; Parliament and Council have still to agree a text, substantive amendments are likely, and adoption is realistically 2027–2028. As drafted it would move cookie rules into the GDPR under a new Article 88a and exempt first-party, aggregated audience measurement for the controller's own use — generalising the CNIL carve-out across the EU rather than removing it. Until then the CNIL criteria are what apply in France.
What does the privacy policy still need to say?
Transparency is required even when consent is not. The privacy policy must describe the analytics tool, its purpose, the data categories processed (channel, landing page, aggregate counts), the retention period, and the lawful basis (Art. 6(1)(f) legitimate interest, paired with the ePrivacy Art. 5(3) exemption). A privacy policy template is included in our TPSR package.

One CNIL review. Done.

Book a walkthrough with the founder. Bring your DPO. We answer the 14 self-assessment points live and ship the DPA + TPSR package on the call.

Built by a founder · supported by a founder · EU-hosted by design