The ePrivacy Directive requires the user's consent before storing (e.g cookie or mobile ID) or accessing (e.g. pixels) information on the user's terminal, subject to a limited number of exemptions (art. 5.3).
The GDPR requires, when consent is the taken legal basis, that its freely given, specific, informed and unambiguous, and as easy to withdraw as to give (art. 7).
The customer defines the legal basis, what data can be collected and when, and configures Piano products thanks to the following inputs:
For any of the following implementations and configurations, make sure you have involve your internal DPO/Legal team to validate the compliance of it towards your company guidelines.
One consent signal for all solutions
Consent is collected by the customer through the Consent Management Platform (CMP) of its choice.
Piano solutions do not collect consent directly: they receive the resulting signal from the CMP and/or the Data Layer, and adjust the data collection accordingly.
Consent is transmitted to every Piano solution through a single interface, so that a customer using several solutions declares the user's choice once rather than product by product.
Four consent modes are available:
-
Opt-in: the user has consented. Collection and identifiers are complete;
-
Essential: consent has not been obtained, but the purpose benefits from a legal exemption (for audience measurement, see ePrivacy exemption below). Collection is restricted to what is strictly necessary;
-
Opt-out: the user has refused, or has exercised an opt-out. Data is anonymised and excluded; only mandatory trackers are deposited
-
Extended opt-out (Piano Analytics only > see below): the user has refused, but the resulting traffic is anonymised and still used to feed aggregate reporting, rather than being excluded entirely;
Purpose
Consent is declared by purpose, and each solution is attached to the purpose that corresponds to its processing. A user may therefore consent to audience measurement while refusing advertising, without the customer having to reason in terms of products.
|
Product |
Main Purpose |
Standard Legal Basis |
|---|---|---|
|
Analytics, Audience |
Audience and Analytics |
Consent under GDPR or Exemption under ePrivacy |
|
Subscriptions, Amplifier |
Content Personalization or Performance |
Consent under GDPR |
|
Audience |
Advertising (personalized or not) |
Consent under GDPR |
|
Subscriptions, Amplifier |
"One to one relationship" (account management, subscription, newsletter, …) |
Consent or Contract under GDPR |
The allocation of solutions to purposes is itself configurable: a solution may be attached to a different purpose where the customer's own analysis of its processing requires it. A customer using Piano Analytics alone does not need to declare a purpose: the mode it sends is applied directly to audience measurement.
From the choice on the CMP to the mode declared
The consent management platform presents the user with three possible choices: accepting every purpose, refusing every purpose, or selecting purposes individually. Each of those choices is declared to Piano, purpose by purpose, as one of the three modes:
|
Mode |
Effect on data |
Effect on trackers |
|---|---|---|
|
Opt-in |
Collected without restriction; |
Deposited without restriction; |
|
Essential (only for Analytics) |
Restricted to what is strictly necessary for the purpose; |
Only essential trackers are deposited; |
|
Opt-out |
Excluded but collected in an anonymised form. |
Only mandatory trackers are deposited; |
|
Extended opt-out |
Anonymised and used only to feed aggregate reporting; |
Only mandatory trackers are deposited; |
How each solution applies the signal
|
Solution |
Application of the signal |
|---|---|
|
Piano Analytics |
One of several collection modes is applied, according to the signal received, and the mode governs what is collected:
|
|
Piano Subscriptions |
The browser storage used is classified according to whether it is mandatory, essential or optional, and mapped to the corresponding consent modes in Cookies & Consent. The module used to govern that storage is described in Consent Management for Client Storage (Cookies); |
|
Piano Audience |
Collection is governed through consent classes, each covering a category of processing (see Consent Classes Management). Signals issued under the IAB Transparency and Consent Framework are translated into those classes automatically (see TCF 2.0 in Audience). The interfaces available for handling consent programmatically are described in GDPR and cx.js; |
Analytics' Specific
ePrivacy exemption
First party and GDPR compliant audience measurement trackers may be exempted from consent under art. 5.3 of the ePrivacy Directive. This directive was subsequently transposed into the various national laws of the European Union's member states, such as France's Data Protection Act (art. 82), or Germany's Telecommunications and Media Data Protection Act (TTDSG - art. 25), for example.
Several EU data protection authorities confirmed this approach in dedicated guidelines:
-
🇪🇺 European Data Protection Board (EDPB) in 2012 (art. 4.3), confirmed in 2023 alongside the "cookie banner task force" report (par. 30), and the “Guidelines on Technical Scope of art. 5(3) of ePrivacy Directive” (page 4).
-
🇫🇷 French CNIL in 2020 (art. 5, par. 50, 51 & 52).
-
🇮🇹 Italian Garante in 2021 (7.2 First-party analytics cookies)
-
🇩🇪 German DSK in 2022 (paragraph 14. audience measurement)
-
🇬🇧 UK ICO (Cookies and similar technologies)
-
…
The exemption applies only where collection is restricted to what is strictly necessary for audience measurement on behalf of the publisher, where the data is not cross-referenced with other processing or passed to third parties, and where the customer keeps an opt-out mechanism available to the data subject despite the absence of consent.
Piano Analytics offers a configuration that meets these conditions, by requesting Piano to:
-
hide the Visitor ID property,
-
confirm or setup a rolling data retention to 25 months,
-
anonymise the IP address.
IMPORTANT: in addition to the above configurations, it is necessary for the customer to:
-
Implement the right tagging on its platform to pass the right signal to Piano (see above),
-
Sign the specific exemption appendix to our Data Processing Agreement (DPA).
The Exemption configurations are applied on the entire Organisation/for all sites inside a Data Model.
Hybrid Measurement
In addition to the "stand-alone" Consent Exemption, Piano Analytics also offers a Hybrid Measurement, allowing customers willing to pursue one or more additional purposes to the audience measurement (see Purpose Limitation), to collect the necessary consent for additional Personal Data. This data will be collected in a unified way into the same data model, without any dupplication of Visits, Visitors, etc.
Extended Opt-out
In addition to the above “Exemption” and “Hybrid Meaurement”, Piano offers another alternative for data collection without consent, thanks to the principles of Data Anonymization.
How it works
Data Collection: If an Internet user does not want to opt in to audience measurement, you can trigger the Extended Opt-Out via tagging (see the "Implementation" section). A "_pprv" cookie is set to store the user's choice (this cookie takes the value "opt-out").
Events sent to Piano Analytics will now contain the following information
-
idclient - "optout"
-
visitor_privacy_mode - "extended-optout"
-
All other properties without distinction
Data Processing: For each event with a visitor_privacy_mode set to "extended-optout", the processing will set up different treatments:
-
Creating an Event without a Visitor ID or Visit ID
-
Delete all properties associated with an enabled personal data flag
-
Add an ".optout" suffix to the end of the event name
Data Storage: Events are stored in the all traffic table. They are not linked to other events because they do not have a match key such as "visitor_id" or "visit_id".
They have an ".optout" extension, as seen in the previous step. Extended opt-out "page.display" events are therefore named "page.display.optout".
Example:
Type of Analysis available
Globally, all metrics based on properties that do not contain personal data and are not based on a visitor or visit ID are available via the extended opt-out.
This excludes analysis of time spent, sources and visitor retention. Anything that has persistence over time and needs to link events together.
Example of data not available:
-
Time Spent
-
Conversions
-
Bounced visits
-
Bounce Rate
This allows you to analyze data related to your text, audio, and video content. Some e-commerce analytics are also available.
Example of available data:
-
Sales without VAT (Transaction)
-
Impressions
-
Events
-
AV - play time
Implementation
Extended opt-out is enabled from the tag. This is a library configuration.
The prerequisites are:
-
At least version 6.13.0 of the Piano Analytics JS library.
-
Using the Consent Management module
-
Use the "optout" consent mode
To enable Extended opt-out, you must enable the configuration when you initialize the library (see the developers documentation):
enableExtendedOptout
This configuration changes the historical behavior of the Piano Analytics opt-out.
Whenever an event has an "opt-out" mode, we'll treat it in "extended opt-out" mode instead of the historical "strict" opt-out.
Extended opt-out is not a paid feature.
The collected events are still counted as classic events because they are no longer excluded and are processed throughout the analytics chain.
Of course, strict opt-out is still available if you don't enable Extended opt-out from the library.