Skip to main content

GDPR and ePrivacy

Learn about GDPR and ePrivacy compliance with Sealmetrics. This section addresses the legal framework that enables consentless analytics in the European Union.

Two separate rules decide whether analytics needs consent: the ePrivacy Directive (Article 5(3)) governs what you store on or read from the device, and the GDPR (Article 4(1)) governs the processing of personal data. Nothing is written to the device, and nothing stored identifies anyone; the session identifier is pseudonymised data processed under legitimate interest (GDPR Art. 6(1)(f)) and unrecoverable after its daily rotation. The tracker does read standard browser properties to compute a session identifier (re-keyed daily on the server, never stored as sent), so on the ePrivacy side Sealmetrics relies on the audience-measurement exemption criteria rather than on nothing being read. These pages explain how the session identifier fits into that framework and when a session identifier does require consent.

Available Documentation​

Written and maintained by the Sealmetrics Team