Legal & Compliance
We store nothing on the device and no data that identifies anyone. The session identifier is ephemeral: it rotates daily and, once rotated, not even we can reconstruct it. Reports are always aggregated. On that basis Sealmetrics self-assesses against the ePrivacy audience-measurement exemption, and processes the pseudonymised session data under legitimate interest (GDPR Art. 6(1)(f)). This section collects the self-assessments against CNIL, UK PECR, German TDDDG, Italian Garante and Swiss FADP criteria, plus the DPA, subprocessor and data subject rights documentation used in vendor reviews.
Understanding the legal framework behind consentless analytics is essential for making informed decisions about your analytics stack. We explain the regulatory foundations, why a pseudonymous identifier that becomes unrecoverable every day keeps the GDPR footprint minimal (Recital 26), and how the architecture maps onto the audience-measurement criteria published by authorities such as the CNIL — so you can assess whether your own analytics can run without a cookie banner or a consent management platform (our self-assessment says yes for Sealmetrics; in Germany it is an open question).
Which compliance documents are available?
Core Compliance Guides
- Compliance Overview - How Sealmetrics meets privacy regulations and ensures legal compliance
- CNIL Self-Assessment - Official auto-evaluation against CNIL's 14 criteria for consent exemption
- UK PECR Self-Assessment - Official auto-evaluation against UK PECR analytics exemption under DUAA 2025
- Germany TDDDG Self-Assessment - Auto-evaluation against §25 TDDDG (formerly TTDSG): no cookies, nothing stored on the device; whether a banner is needed in Germany is our reading, an open question
- Italy Garante Self-Assessment - Auto-evaluation against the Garante's cookie guidelines and analytics decisions
- Switzerland FADP Self-Assessment - Auto-evaluation against the revised Swiss FADP (nFADP): no data that identifies anyone, no non-adequate transfers
- GDPR and ePrivacy - Detailed analysis of EU privacy laws and session-based tracking requirements
- GDPR and Cookieless Analytics - The regulatory analysis behind cookieless measurement, and the legal-basis options open to site owners
- Analytics Cookies: Consent Exemption - AEPD and EU DPA requirements for analytics without consent
Data Processing Transparency
- Subprocessors - Who touches what data, where — and why customer analytics data never leaves the EU
- Data Subject Rights (DSAR) - How visitor and account-holder rights requests work with identifier-free analytics
EU Digital Omnibus Regulation
- EU Digital Omnibus Overview - Complete guide to the Digital Omnibus (COM(2025) 837)
- Cookie Consent Reform - Articles 88a/88b and the end of cookie banner fatigue
- Impact on Web Analytics - How the Omnibus affects analytics providers and tracking
- GDPR Amendments - Personal data definition, AI processing, breach notifications
- View All Omnibus Documentation →
- Nothing is stored on the device and no data that identifies anyone; the session identifier rotates daily and, once rotated, not even Sealmetrics can reconstruct it. Reports are always aggregated, and measurement runs without a cookie banner on Sealmetrics' self-assessment (in Germany, an open question).
- Five self-assessments are published: CNIL (14 criteria), UK PECR under DUAA 2025, Germany §25 TDDDG, Italy Garante, and Switzerland nFADP — none is a supervisory-authority certification.
- Vendor-review material includes the subprocessor list, data subject rights (DSAR) handling and the EU Digital Omnibus (COM(2025) 837) analysis.