Legal & Compliance
Sealmetrics needs no consent banner because its stored dataset holds no personal data, which places it outside the GDPR's material scope and leaves nothing on the visitor's device for ePrivacy to require consent for. This section collects the self-assessments against CNIL, UK PECR, German TDDDG, Italian Garante and Swiss FADP criteria, plus the DPA, subprocessor and data subject rights documentation used in vendor reviews.
Understanding the legal framework behind consentless analytics is essential for making informed decisions about your analytics stack. We explain the regulatory foundations, why a dataset holding no personal data falls outside the GDPR's material scope (Recital 26), and how the architecture maps onto the audience-measurement criteria published by authorities such as the CNIL — so you can measure without cookie banners or a consent management platform.
Which compliance documents are available?
Core Compliance Guides
- Compliance Overview - How Sealmetrics meets privacy regulations and ensures legal compliance
- CNIL Self-Assessment - Official auto-evaluation against CNIL's 14 criteria for consent exemption
- UK PECR Self-Assessment - Official auto-evaluation against UK PECR analytics exemption under DUAA 2025
- Germany TDDDG Self-Assessment - Auto-evaluation against §25 TDDDG (formerly TTDSG): no cookies, no terminal storage access
- Italy Garante Self-Assessment - Auto-evaluation against the Garante's cookie guidelines and analytics decisions
- Switzerland FADP Self-Assessment - Auto-evaluation against the revised Swiss FADP (nFADP): no personal data, no non-adequate transfers
- GDPR and ePrivacy - Detailed analysis of EU privacy laws and session-based tracking requirements
- GDPR and Cookieless Analytics - The regulatory analysis behind cookieless measurement, and the legal-basis options open to site owners
- Analytics Cookies: Consent Exemption - AEPD and EU DPA requirements for analytics without consent
Data Processing Transparency
- Subprocessors - Who touches what data, where — and why customer analytics data never leaves the EU
- Data Subject Rights (DSAR) - How visitor and account-holder rights requests work with identifier-free analytics
EU Digital Omnibus Regulation
- EU Digital Omnibus Overview - Complete guide to the Digital Omnibus (COM(2025) 837)
- Cookie Consent Reform - Articles 88a/88b and the end of cookie banner fatigue
- Impact on Web Analytics - How the Omnibus affects analytics providers and tracking
- GDPR Amendments - Personal data definition, AI processing, breach notifications
- View All Omnibus Documentation →
- A dataset holding no personal data falls outside the GDPR's material scope (Recital 26), so Sealmetrics measures without cookie banners or a consent management platform.
- Five self-assessments are published: CNIL (14 criteria), UK PECR under DUAA 2025, Germany §25 TDDDG, Italy Garante, and Switzerland nFADP — none is a supervisory-authority certification.
- Vendor-review material includes the subprocessor list, data subject rights (DSAR) handling and the EU Digital Omnibus (COM(2025) 837) analysis.