Cookie-Based vs Cookieless Analytics: Technical Comparison
TL;DR — Cookie-based analytics loses the visitors who reject or ignore the cookie banner. Technical comparison of cookie vs cookieless tracking: accuracy, compliance, and implementation.
Many EU visitors reject or ignore cookie banners, and the resulting shortfall in your reports is large enough to make traditional cookie-based analytics unreliable for the decisions people make with it. This technical comparison explores how cookieless analytics fundamentally differs from cookie-based approaches and why businesses are migrating to consent-free tracking solutions.
Key Takeaways:
- Cookie-based analytics loses the visitors who reject or ignore the cookie banner, depending on sector, brand strength and traffic sources
- Cookieless analytics measures the traffic lost to the consent banner, without requiring one
- Sealmetrics uses session-based tracking without cookies or IP storage
- The legal footing differs fundamentally: consent, versus storing nothing on the device and no data that identifies anyone, with a session identifier that becomes unrecoverable daily
What Are Cookie-Based Analytics?
Cookie-based analytics tools like Google Analytics rely on third-party and first-party cookies to track user behavior across websites. When a visitor lands on a website, the analytics script drops a cookie in their browser with a unique identifier. This cookie persists across sessions, allowing the tool to recognize returning visitors and track their journey over time.
The technical implementation involves:
- Cookie placement: JavaScript places a tracking cookie with unique ID
- Data collection: Each pageview sends cookie ID + behavioral data to servers
- Cross-session tracking: Same cookie ID links visits over days/weeks/months
- IP address storage: Visitor IP addresses stored (or hashed) for geolocation
- Consent requirement: GDPR mandates explicit consent before cookie placement
Google Analytics, Adobe Analytics, and most traditional analytics platforms use this cookie-based approach. According to CNIL guidelines updated in 2024, cookie-based analytics requires user consent in the EU, which has led to massive data loss as users reject tracking.
The cookie-based model worked well for 20+ years, but regulatory changes and browser privacy features (Safari ITP, Firefox ETP) have made this approach increasingly problematic for businesses that need accurate analytics.
What Are Cookieless Analytics?
Cookieless analytics eliminates cookies entirely, using alternative technical approaches to track visitor behavior while maintaining GDPR compliance. Sealmetrics pioneered consentless analytics by developing a dual tracking system that measures the traffic cookie tools lose to the consent banner, without requiring one.
The technical implementation of cookieless analytics:
- Session identifiers: Computed in the browser, never stored on the device, and re-keyed daily on the server (not persistent cookies)
- Server-side tracking: Data processed on backend, not client-side cookies
- No IP storage: IP addresses are never stored, not even hashed
- Isolated hits: Individual pageviews tracked without cross-session linking
- Ephemeral identifier: the session identifier rotates daily and, once rotated, not even Sealmetrics can reconstruct it; reports are always aggregated
Sealmetrics uses a sophisticated dual approach:
- Session-ID tracking: Links pageviews within a single session for journey analysis
- Isolated Hits: Captures individual metrics without session linking
On our own assessment, this cookieless approach means no consent banner is required for Sealmetrics' own analytics — the ePrivacy rule that mandates them (Article 5(3)) applies to storing or reading information on the device; nothing is stored, and the browser properties read for the session identifier rely on the audience-measurement exemption. In Germany this is an open question — see Germany. According to CNIL's 2020 guidance, tools that don't use cookies and don't store identifying information can operate without consent.
Unlike cookie-based tools, which lose the visitors who reject or ignore the cookie banner, cookieless analytics measures the traffic the banner loses. In the Incapto case (one Shopify store, same site and same days, not a benchmark), GA4 did not record 29% of real visits.
Technical Comparison: Cookie-Based vs Cookieless
| Technical Aspect | Cookie-Based (Google Analytics) | Cookieless (Sealmetrics) |
|---|---|---|
| Tracking Method | Persistent cookies in browser | Session identifiers + isolated hits |
| Requires Cookies | Yes (first-party + third-party) | No cookies used |
| Requires Consent | Yes (ePrivacy 5(3) + GDPR 6(1)(a)) | No (nothing stored on device; audience-measurement exemption, self-assessed) |
| Consent-driven data loss | Varies by site | None - no consent gate |
| IP Address Storage | Stored or hashed | Never stored |
| Cross-Session Tracking | Links visits over months | Limited to session duration |
| Browser Compatibility | Blocked by Safari ITP, Firefox ETP | Works in all browsers |
| Implementation Complexity | Medium (consent management needed) | Simple (2-minute setup) |
| GDPR position | Requires consent banners | Legitimate interest for minimal pseudonymised data, unrecoverable after daily rotation |
| Data Retention | 14 months (GA4 default) | 24 months without consent |
| Geolocation Accuracy | High (IP-based) | Medium (browser timezone) |
| User Identification | Persistent across devices | Single device, single session |
| Script Size | Much larger (GA4 plus consent tooling) | 1.1 KB gzipped (measured) |
| CNIL Exemption Criteria | Requires configuration | Designed to meet criteria (self-assessed) |
Data Collection Accuracy
Cookie-based analytics accuracy has declined dramatically since GDPR enforcement:
- Before consent banners: cookie-based tools saw almost every visitor whose browser ran the script
- With consent banners: partial capture — visitors who ghost or reject the banner are lost
Be careful with published rejection rates. A rejection rate is measured among the visitors who engaged with the banner, and Consent Mode v2 models part of the unconsented traffic back in as estimates. Net of that, cookie-based tools still miss part of your visitors — how many depends on your sector, the strength of your brand and where your traffic comes from.
Cookieless analytics has no such gap, because no consent is required. Sealmetrics measures all the traffic you lose today to the cookie banner, whatever the visitor's consent choice — though an ad blocker can still hide some visits.
Implementation Comparison
Cookie-Based Analytics Setup
Implementing Google Analytics requires:
<!-- Google Analytics 4 -->
<script async src="https://www.googletagmanager.com/gtag/js?id=G-XXXXXXXXXX"></script>
<script>
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
gtag('js', new Date());
gtag('config', 'G-XXXXXXXXXX');
</script>
Plus consent management implementation:
<!-- Consent Banner Required -->
<script src="consent-management-platform.js"></script>
<script>
// Wait for consent before initializing GA
ConsentManager.onAccept('analytics', function() {
gtag('consent', 'update', {
'analytics_storage': 'granted'
});
});
</script>
Total implementation time: 30-60 minutes Ongoing maintenance: Cookie policy updates, consent management Legal review: Required before launch
Cookieless Analytics Setup
Implementing Sealmetrics requires:
<!-- Sealmetrics Cookieless Analytics -->
<script src="https://t.sealmetrics.com/t.js?id=YOUR_SITE_ID" defer></script>
Total implementation time: about 4 minutes Ongoing maintenance: None Legal review: Simplified (no cookies, no data that identifies anyone)
The difference is stark. Cookie-based analytics requires consent management platforms (OneTrust, Cookiebot, etc.) that cost €300-3000/month. Cookieless analytics like Sealmetrics requires one script tag.
GDPR Legal Framework Comparison
Cookie-Based Analytics: Consent Requirement
GDPR Article 6(1)(a) and ePrivacy Directive Article 5(3) require explicit consent for cookie-based analytics:
"The storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user shall only be allowed on condition that the subscriber or user concerned has given his or her consent."
This means:
- Consent banner required before tracking
- Clear opt-in mechanism needed
- Easy withdrawal of consent
- Granular consent per purpose
- Pre-ticked boxes not allowed
- Cookie walls not allowed (mostly)
CNIL's 2024 guidance confirms that Google Analytics requires consent even with IP anonymization. The Schrems II decision further complicated cookie-based analytics by questioning US data transfers.
Cookieless Analytics: Minimal Data, No Consent Banner
GDPR Recital 26 states that the principles of data protection do not apply to anonymous information, but pseudonymised data is still personal data. A daily-rotating session identifier is a pseudonym while its key and salt exist, so the goal is to keep it minimal and short-lived. Properly implemented cookieless analytics does that:
- Nothing stored on the device, and the browser properties read for the session identifier kept within the audience-measurement exemption = the ePrivacy Article 5(3) consent rule does not require a banner
- No IP addresses stored, hashed or otherwise = nothing that singles out a person
- No cross-session identifiers = no profile can be assembled
- Aggregate output only = non-identifying reports
Sealmetrics relies on legitimate interest, Article 6(1)(f), for the short-lived pseudonymised operational data: the identifier rotates daily and, once rotated, not even Sealmetrics can reconstruct it, and the per-hit log is purged after one day. The IP is handled only transiently, in memory, for bot blocking (Recital 49) and never reaches storage.
CNIL's 2020 guidance states that analytics tools without cookies and without storing identifying information can operate without consent. Sealmetrics' architecture is designed to meet those published criteria. Note that CNIL does not certify, approve, or validate individual analytics tools, and no supervisory authority operates such a scheme — see our CNIL self-assessment for a criterion-by-criterion analysis.
This legal distinction is crucial: cookie-based analytics requires consent, cookieless analytics does not.
Data Loss Analysis: The Consent Gap
Cookie rejection creates massive blind spots in business intelligence:
E-commerce Example
A German e-commerce site with 100,000 monthly visitors:
With Google Analytics (cookie-based), in a privacy-sensitive market at the harder end of the band:
- Consent banner shown: 100,000 visitors
- Measured visitors: ~45,000 (45% capture rate)
- Blind spot: ~55,000 visitors (55% data loss)
With Sealmetrics (cookieless):
- No consent banner: 100,000 visitors
- Measured visitors: 100,000
- Blind spot: none beyond the JavaScript blockers no tool can see
The business impact:
- Revenue attribution: cookie-based misses over half the conversions
- Customer journey: incomplete path-to-purchase data
- Marketing ROI: unmeasurable for a large share of campaigns — and unevenly so, which is worse than uniformly
- A/B testing: results biased by the exclusion of privacy-conscious users
B2B SaaS Example
A French SaaS company tracking trial signups:
Cookie-based analytics shows:
- 1,000 website visitors
- 50 trial signups
- 5% conversion rate
Reality (with cookieless analytics):
- 2,200 actual visitors — the banner was hiding more than half of them
- 50 trial signups
- 2.3% actual conversion rate
The cookie-based data suggested a healthy 5% conversion. The real figure was less than half that. The misattribution led to incorrect pricing decisions and wasted marketing budget.
Browser Privacy Features Impact
Modern browsers increasingly block cookie-based tracking:
Safari ITP (Intelligent Tracking Prevention)
- First-party cookies: Limited to 7 days (24 hours if set via JavaScript)
- Third-party cookies: Completely blocked
- Impact: substantial Google Analytics data loss on Safari, on top of any consent gap
- Market share: 19% desktop, 52% mobile (iOS)
Firefox ETP (Enhanced Tracking Protection)
- Third-party cookies: Blocked by default
- Known trackers: Blocked (includes GA domains)
- Impact: further data loss on top of the consent gap
- Market share: 6% desktop, 3% mobile
Chrome Privacy Sandbox
- Third-party cookies: blocked by Safari and Firefox; Google dropped its plan to remove them from Chrome
- Topics API: Limited interest-based advertising
- Impact: Major change coming for cookie-based tools
Because it doesn't use cookies, Sealmetrics works the same way across Safari, Firefox, Chrome, Brave and other browsers. An ad blocker that stops the script still hides the visit.
Performance Comparison
Page Load Impact
Script weight and load timing are measured, not estimated, in the tracker performance report: the Sealmetrics tracker is 1.1 KB gzipped and loads with defer, while a cookie-based setup also loads a consent management platform and its banner.
Migration Considerations
When to Stay Cookie-Based
Cookie-based analytics may still be appropriate if:
- You only operate in non-EU markets (US, Asia)
- You need cross-device tracking (same user, multiple devices)
- You require 12+ month visitor history
- You already have 80%+ cookie acceptance rates
However, even in these scenarios, cookieless analytics provides more accurate data.
When to Switch to Cookieless
Cookieless analytics is recommended if:
- You have significant EU traffic (>20%)
- Your cookie acceptance rate is less than 50%
- You face GDPR compliance pressure
- You want to measure the traffic you lose today to the cookie banner
- You want to remove consent banners entirely
- You need faster page load times
- You want simplified legal compliance
Migration Process
Switching from Google Analytics to Sealmetrics:
Preparation (Day 1):
- Export historical GA data
- Document current reports/dashboards
- Identify key metrics to preserve
Implementation (Day 1):
- Add Sealmetrics script tag
- Run dual tracking (GA + Sealmetrics) for 7-30 days
- Compare data accuracy
Transition (Day 30):
- Remove consent banner (if only used for analytics)
- Remove Google Analytics script
- Update privacy policy
- Train team on new dashboard
Completion (Day 31+):
- Data capture no longer dependent on consent
- No consent banner for its own analytics (self-assessed; Germany: open question)
- Designed to comply with the GDPR
- Faster page loads
Total migration time: 30 days (with dual tracking period)
Cost Comparison
Cookie-Based Analytics Total Cost
Google Analytics (free) plus required infrastructure:
- Consent Management Platform: €300-3,000/month
- OneTrust: €1,200/month
- Cookiebot: €300/month
- Custom solution: €3,000-10,000 development
- Legal Review: €2,000-5,000 one-time
- Ongoing Compliance: €500-1,000/month (policy updates)
- Data Loss Cost: the visitors who reject the banner go untracked, distorting every channel comparison you make
Annual cost: €6,000-40,000+ plus opportunity cost
Cookieless Analytics Total Cost
Sealmetrics pricing (volume-based):
- Growth: €599/month (5M events) — €499/month with annual billing
- Scale: €1,079/month (15M events) — €899/month with annual billing
- Enterprise: Custom pricing (unlimited events)
- Consent Management: €0 (not needed)
- Legal Review: Minimal (no cookies, no data that identifies anyone)
- Ongoing Compliance: €0 (built-in)
- Consent-driven Data Loss Cost: €0 (no banner)
Annual cost: €2,388-9,588 (with annual billing discount) and no consent-driven data loss
Compare the costs on your own numbers: subscription, consent tooling, and the traffic the banner hides.
Frequently Asked Questions
Is cookieless analytics as accurate as cookie-based analytics?
Cookieless analytics is significantly more accurate than cookie-based analytics in 2026. While cookie-based tools lose the visitors who reject or ignore the cookie banner, cookieless analytics also measures the traffic the banner loses. Sealmetrics provides visitor data without the blind spots created by cookie banners.
The trade-off is cross-session tracking. Cookie-based analytics can track the same user across multiple visits over months. Cookieless analytics measures within sessions but doesn't link returning visitors. For most businesses, complete single-session data beats multi-session data on a partial, self-selected sample.
Does cookieless analytics work with ad blockers?
Partly. Sealmetrics doesn't use tracking cookies or known advertising domains, so it is blocked less often than Google Analytics. An ad blocker can still hide some visits, though.
Can I use cookieless analytics for GDPR compliance?
Yes. Sealmetrics stores no data that identifies anyone: the session identifier rotates daily and, once rotated, not even Sealmetrics can reconstruct it, and reports are always aggregated. For that short-lived pseudonymised data it relies on legitimate interest, Article 6(1)(f). Separately, nothing is written to the device; the tracker does read standard browser properties to compute its session identifier, and for that read it relies on the ePrivacy audience-measurement exemption rather than consent. CNIL's 2020 guidance confirms that cookieless measurement meeting its exemption criteria can operate without consent; Sealmetrics is designed to meet those criteria (CNIL does not certify or approve individual tools).
Unlike cookie-based analytics that requires consent under ePrivacy Directive Article 5(3), Sealmetrics stores no information in user browsers, and the browser properties it reads are covered by the audience-measurement exemption criteria rather than by consent.
What's the difference between cookieless and cookie-free analytics?
These terms are often used interchangeably, but there's a subtle distinction:
- Cookieless analytics: Uses alternative tracking methods instead of cookies
- Cookie-free analytics: May use local storage or other browser APIs instead of cookies
Sealmetrics is both cookieless and cookie-free: its session identifier is computed in the browser but never written to any browser storage mechanism, and is re-keyed daily on the server. This approach is designed for compliance without relying on browser-based tracking technologies.
Does cookieless analytics support conversion tracking?
Yes, Sealmetrics tracks conversions, goals, events, and custom metrics without cookies. E-commerce sites can track purchases, SaaS products can track trial signups, and media sites can track subscriptions—all without a consent banner for its own analytics (our self-assessment).
The implementation is simpler than cookie-based conversion tracking because there's no consent management logic required. Set up goals in the Sealmetrics dashboard, trigger events via JavaScript, and capture every conversion rather than the visitors who accept the banner.
How does cookieless analytics handle returning visitors?
Cookieless analytics doesn't persistently identify returning visitors across sessions. Each session receives a temporary identifier that expires when the visitor closes their browser or after a short period of inactivity (~2 hours in Sealmetrics).
This limitation is intentional for privacy compliance. However, Sealmetrics provides visitor behavior patterns and aggregate return visitor metrics without individual tracking. For most analytics use cases (understanding user journeys, measuring content performance, tracking conversions), session-based data is sufficient.
Can I migrate from Google Analytics to cookieless analytics?
Yes, migration is straightforward. Add the Sealmetrics script tag to your website, run dual tracking for 7-30 days to compare data, then remove Google Analytics. Most businesses complete migration in under 30 days.
The immediate benefit: you'll see meaningfully more visitor data in Sealmetrics than Google Analytics shows — how much more is specific to your site. Export your historical GA data before migration to preserve long-term trends.
Does cookieless analytics work for mobile apps?
Sealmetrics currently focuses on web analytics. Mobile apps have different tracking regulations (IDFA, GAID) that don't involve cookie consent. Cookie-based vs cookieless is primarily a web browser distinction.
For websites accessed via mobile browsers, cookieless analytics works identically to desktop—capture that doesn't depend on consent, regardless of device.
What happens to my data with cookieless analytics?
Sealmetrics stores all analytics data on EU-based servers (Dublin, Ireland) with 24-month retention. Unlike Google Analytics (US-based with Schrems II concerns), cookieless analytics keeps your data within EU jurisdiction.
No IP addresses, no persistent identifiers, no data that identifies anyone, and reports are always aggregated. This architecture is designed to comply with the GDPR, and analytics data is hosted and processed only in the EU (Dublin).
How do I explain cookieless analytics to my DPO?
Tell your Data Protection Officer:
- Nothing stored on the device: no cookies; the ephemeral session identifier rotates daily and is covered by the audience-measurement exemption (self-assessed)
- No IP storage: IP addresses are never stored, not even hashed
- Legal basis: legitimate interest, Article 6(1)(f), for minimal pseudonymised data that becomes unrecoverable after the daily rotation; reports are aggregated
- CNIL exemption criteria: Architecture designed to meet CNIL's published criteria (self-assessed — CNIL does not certify tools)
- No consent required: Removes consent management complexity
Provide your DPO with CNIL's 2020 guidance on cookieless analytics and Sealmetrics' data processing documentation. Most DPOs approve immediately because cookieless analytics is significantly lower risk than cookie-based alternatives.
Can cookieless analytics replace Google Analytics completely?
For most businesses, yes. Sealmetrics provides:
- Real-time visitor tracking
- Pageview and event analytics
- Conversion and goal tracking
- Traffic source attribution
- Device and browser data
- Geographic insights (country/region)
- Data export and API access
The main limitation is cross-session user tracking. If your business requires tracking the same user across multiple visits over months (rare for most companies), you may need supplementary tools. But for 95% of analytics use cases, cookieless analytics provides superior data quality because of 100% capture rate.
Is cookieless analytics more expensive than Google Analytics?
Google Analytics is free, but the total cost of cookie-based analytics includes:
- Consent management platform: €300-3,000/month
- Legal compliance review: €2,000-5,000
- Ongoing policy maintenance: €500-1,000/month
- Data loss opportunity cost: substantial (the visitors who reject the banner go untracked, and not at random)
Sealmetrics plans start at €599/month (€499/month with annual billing) depending on event volume, with no additional infrastructure required. Total cost of ownership is significantly lower than cookie-based analytics systems when you factor in consent management, legal review, and data loss costs.
How does Sealmetrics differ from other cookieless tools like Plausible or Matomo?
Key differences:
Sealmetrics: True consentless analytics
- No cookies
- No IP storage (competitors store hashed IPs)
- No consent required
- 24-month retention without consent
- Designed to meet CNIL's exemption criteria (self-assessed)
Plausible/Matomo: Cookie-free but still store IPs
- No cookies (good)
- Store hashed IP addresses (still personal data)
- May require consent depending on DPO interpretation
- 12-month retention typical
Sealmetrics is the only analytics platform that stores zero identifying information, which is what enables genuinely consentless tracking.
What's the future of analytics: cookie-based or cookieless?
Cookieless analytics is the future. Safari's ITP, Firefox's ETP, consent banners and GDPR enforcement make cookie-based analytics increasingly incomplete.
What to watch:
- How the EU Digital Omnibus proposal on cookie consent evolves
- Browser tracking protections (Google dropped its plan to remove third-party cookies from Chrome)
- Wider adoption of cookieless analytics
Businesses that migrate to cookieless analytics now gain a competitive advantage: they measure the traffic lost to the cookie banner, while competitors make decisions on the visitors their banner happens to let through.
Conclusion: The Case for Cookieless Analytics
The technical comparison is clear: cookieless analytics provides superior data quality, better legal compliance, faster performance, and lower total cost than cookie-based alternatives.
Cookie-based analytics worked for 20 years, but GDPR, browser privacy features, and user behavior have fundamentally broken the model. Losing the visitors who reject the banner — unevenly, and skewed toward your most privacy-aware customers — isn't sustainable for businesses that need accurate analytics to make informed decisions.
Sealmetrics pioneered consentless analytics by eliminating both cookies and IP storage, which, on our own assessment, is what lets it measure all the traffic you lose today to the cookie banner, without one. This technical approach represents the future of privacy-first analytics.
For businesses operating in EU markets, the migration from cookie-based to cookieless analytics isn't optional—it's essential for competitive survival. Start dual tracking today, compare data accuracy, and see all of your visitors instead of the ones your banner selects for you.
Ready to switch to cookieless analytics? Open your free account — your first 1M events are free, with no card — and measure the gap on your own site.
Additional Resources
- Complete Guide to Cookieless Analytics
- GDPR Compliant Analytics Framework
- Sealmetrics vs Google Analytics — Full comparison with data accuracy benchmarks
- Sealmetrics vs Plausible — Privacy-first tools compared
- What Is Consentless Analytics? — How it works under GDPR
- Tracker Installation Guide — Get started in about 4 minutes
- CNIL Guidelines on Analytics (Official)
