Privacy by Design Principles
Privacy by Design is the framework GDPR Article 25 refers to as data protection by design and by default. Sealmetrics satisfies it the blunt way: by not collecting personal data, so there is no personal data to protect, disclose or lose. The seven principles below map to specific architectural choices rather than to policies.
How does Sealmetrics map to the seven principles?
| Principle | How it shows up in Sealmetrics |
|---|---|
| 1. Proactive, not reactive | Privacy constraints are structural. The system cannot start identifying visitors later without a redesign, because there is no identifier to switch on. |
| 2. Privacy as the default | Anonymous measurement from the first page load. Visitors do not opt in to anything, and there is no less-private mode to fall back to. |
| 3. Full functionality | Traffic, attribution, conversions, revenue and aggregate engagement are all reported without personal data. What is genuinely lost — unique visitors, session duration, cross-session journeys — is documented rather than worked around. |
| 4. End-to-end security | EU-only storage in Dublin, Ireland; encryption in transit and at rest; role-based access control; short retention enforced by database TTLs. See Data Location & Retention. |
| 5. Visibility and transparency | The complete field list and its retention is published in What We Track. The tracker is client-side and inspectable. |
| 6. Respect for user privacy | No cookies, no device storage, no fingerprinting, no cross-session or cross-site linking. Session markers incorporate the publisher account, so the same browser yields different markers on different sites. |
| 7. Accommodate all legitimate interests | Site owners get the measurement they need for business decisions; visitors are not identified to provide it. |
Is privacy by design a certification?
Two claims worth keeping straight, because vendor reviews turn on them: privacy by design is an architectural property, not a certification. Sealmetrics holds no ISO 27001 or SOC 2 certification, and no supervisory authority certifies analytics tools. The pages under compliance are our own self-assessments against published criteria, and a Data Processing Agreement is included at sealmetrics.com/dpa.
In short
- Sealmetrics satisfies GDPR Article 25 (data protection by design and by default) by collecting no personal data, so each of the seven principles maps to an architectural choice.
- Anonymous measurement is the default and only mode: no cookies, no device storage, no fingerprinting, EU-only storage in Dublin with short retention enforced by TTLs.
- Privacy by design is an architectural property, not a certification — Sealmetrics holds no ISO 27001 or SOC 2 and no supervisory authority certifies analytics tools.
Related documentation
- What We Track vs What We Don't — the field-by-field disclosure behind principle 5
- What is Consentless Analytics? — the model and its legal basis
- How Sealmetrics Protects User Privacy — the same protections in plain language
- Data Location & Retention — the security and retention detail behind principle 4
- GDPR and Cookieless Analytics — the regulatory analysis
Was this page helpful?