Skip to main content

Legal & Compliance

We store nothing on the device and no data that identifies anyone. The session identifier is ephemeral: it rotates daily and, once rotated, not even we can reconstruct it. Reports are always aggregated. On that basis Sealmetrics self-assesses against the ePrivacy audience-measurement exemption, and processes the pseudonymised session data under legitimate interest (GDPR Art. 6(1)(f)). This section collects the self-assessments against CNIL, UK PECR, German TDDDG, Italian Garante and Swiss FADP criteria, plus the DPA, subprocessor and data subject rights documentation used in vendor reviews.

Understanding the legal framework behind consentless analytics is essential for making informed decisions about your analytics stack. We explain the regulatory foundations, why a pseudonymous identifier that becomes unrecoverable every day keeps the GDPR footprint minimal (Recital 26), and how the architecture maps onto the audience-measurement criteria published by authorities such as the CNIL — so you can assess whether your own analytics can run without a cookie banner or a consent management platform (our self-assessment says yes for Sealmetrics; in Germany it is an open question).

Which compliance documents are available?​

Core Compliance Guides​

Data Processing Transparency​

  • Subprocessors - Who touches what data, where — and why customer analytics data never leaves the EU
  • Data Subject Rights (DSAR) - How visitor and account-holder rights requests work with identifier-free analytics

EU Digital Omnibus Regulation​

In short
  • Nothing is stored on the device and no data that identifies anyone; the session identifier rotates daily and, once rotated, not even Sealmetrics can reconstruct it. Reports are always aggregated, and measurement runs without a cookie banner on Sealmetrics' self-assessment (in Germany, an open question).
  • Five self-assessments are published: CNIL (14 criteria), UK PECR under DUAA 2025, Germany §25 TDDDG, Italy Garante, and Switzerland nFADP — none is a supervisory-authority certification.
  • Vendor-review material includes the subprocessor list, data subject rights (DSAR) handling and the EU Digital Omnibus (COM(2025) 837) analysis.
Written and maintained by the Sealmetrics Team