Skip to main content

Data Subject Rights (DSAR) and SealMetrics

If you use SealMetrics on your website, sooner or later your DPO will receive a data subject access request (DSAR) and need to answer a simple question: "What does our analytics tool hold about this person?"

With SealMetrics, the answer is structurally simple — and this page explains why, what it means in practice, and where data subject rights do fully apply (your dashboard account).


Two very different data categories

CategoryWho it concernsContains personal data?Rights requests
Visitor analytics dataVisitors to your websiteNo — no identifiers by designCannot be linked to any individual (see below)
Account dataYou and your team (dashboard users)Yes — email, name, billing detailsFully applicable, standard process

Why requests cannot be matched to records

SealMetrics stores no personal data and no identifiers for website visitors:

  • No IP addresses stored (used ephemerally in memory for anti-bot protection, never persisted)
  • No cookies or terminal storage
  • No user IDs, device IDs, or fingerprints
  • No cross-session identifiers — the short-lived session marker (~2h) expires and cannot recognize a returning visitor
  • Country derived from the browser timezone, not from the IP
  • User agent stored as a category signal, never joined to any identity

Because no record in the analytics database relates to an identified or identifiable person, there is no key by which a rights request could be matched to any stored record. If a visitor asks "show me my data" or "delete my data", there is no technical means — for SealMetrics or for you — to determine which rows (if any) were generated by that person's visits.

The legal frame: GDPR Article 11

GDPR anticipates exactly this situation. Article 11 (processing which does not require identification) provides that where a controller's purposes do not require the identification of a data subject, the controller is not obliged to acquire additional information just to identify the data subject for the purpose of complying with the Regulation. Where the controller can demonstrate it is not in a position to identify the data subject, Articles 15–20 (access, rectification, erasure, restriction, portability) do not apply — unless the data subject themselves provides additional information enabling identification, which with SealMetrics is not possible because no identifier exists to match it against.

Not a loophole — a design property

This is not a workaround to avoid answering DSARs. It is the direct consequence of not collecting personal data in the first place: data minimization taken to its logical conclusion. The best DSAR response is having nothing to search.

What this means in practice for your DPO

When a visitor rights request mentions your website analytics:

  1. You can respond substantively — explain that your analytics tool (SealMetrics) stores no personal data or identifiers about visitors, so no stored record can be attributed to the requester.
  2. You do not need to ask SealMetrics to search — there is nothing to search by: no email, no IP, no ID exists in the analytics data.
  3. Document the reasoning — reference your records of processing (ROPA) entry for SealMetrics, which should describe the tool as processing anonymous, aggregate statistics. This page and What We Track vs What We Don't can be attached as supporting documentation.
  4. Remember Article 12(2) — you must still facilitate rights requests in general; the point is that for this specific processing, identification is impossible and Article 11(2) applies.
One caveat: what you send us

This analysis holds for SealMetrics as designed. If your implementation passes personal data into custom event properties (for example, an email address in a conversion property), you have introduced personal data into the system against our configuration guidance, and your DSAR analysis changes. Never send PII in custom properties.


Account-holder rights: fully applicable

Data subject rights apply in full to account data — the personal data of you and your team as SealMetrics dashboard users (email address, name, password hash, billing information, audit logs).

What you can do yourself

RightHow
Access / portabilityExport your data from the dashboard (CSV) or via the API
RectificationEdit your profile and account details in the dashboard
ErasureClose your account — all data deleted within 30 days, backups purged within 90 days

How to submit a rights request

For anything you cannot do self-service, or to exercise any GDPR right formally:

Include the email address associated with your SealMetrics account so we can verify your identity. We respond within the timelines required by GDPR Article 12(3) (one month, extendable in complex cases with notice).

Roles under the DPA

For visitor analytics data, you (the website operator) are the controller and SealMetrics is your processor under the SealMetrics DPA. For account data (your dashboard login, billing), SealMetrics acts as a controller in its own right. Rights requests for account data go directly to us at the addresses above.


Quick reference for DPOs

ScenarioAnswer
Visitor asks your company for their analytics dataNo record can be attributed to them — no identifiers exist (GDPR Art. 11)
Visitor asks for erasure of their analytics dataSame — no record can be located; nothing identifiable is stored
Visitor objects to processingNo individual-level processing occurs; visitors can additionally block the script via browser settings or ad blockers
Dashboard user asks for their account dataStandard DSAR — self-service export or privacy@sealmetrics.com
Regulator asks where analytics data is storedDublin, Ireland (EU), 24-month retention — see Data Location & Retention