Skip to main content

Legal & Compliance

Sealmetrics needs no consent banner because its stored dataset holds no personal data, which places it outside the GDPR's material scope and leaves nothing on the visitor's device for ePrivacy to require consent for. This section collects the self-assessments against CNIL, UK PECR, German TDDDG, Italian Garante and Swiss FADP criteria, plus the DPA, subprocessor and data subject rights documentation used in vendor reviews.

Understanding the legal framework behind consentless analytics is essential for making informed decisions about your analytics stack. We explain the regulatory foundations, why a dataset holding no personal data falls outside the GDPR's material scope (Recital 26), and how the architecture maps onto the audience-measurement criteria published by authorities such as the CNIL — so you can measure without cookie banners or a consent management platform.

Which compliance documents are available?

Core Compliance Guides

Data Processing Transparency

  • Subprocessors - Who touches what data, where — and why customer analytics data never leaves the EU
  • Data Subject Rights (DSAR) - How visitor and account-holder rights requests work with identifier-free analytics

EU Digital Omnibus Regulation

In short
  • A dataset holding no personal data falls outside the GDPR's material scope (Recital 26), so Sealmetrics measures without cookie banners or a consent management platform.
  • Five self-assessments are published: CNIL (14 criteria), UK PECR under DUAA 2025, Germany §25 TDDDG, Italy Garante, and Switzerland nFADP — none is a supervisory-authority certification.
  • Vendor-review material includes the subprocessor list, data subject rights (DSAR) handling and the EU Digital Omnibus (COM(2025) 837) analysis.
Written and maintained by the Sealmetrics Team