We’ve migrated our documentation to a new site, which means some URLs have changed. If you hit a broken link, submit a support ticket.
Compliance Center
English French
English French

Consent Management

The ePrivacy Directive requires the user's consent before storing (e.g cookie or mobile ID) or accessing (e.g. pixels) information on the user's terminal, subject to a limited number of exemptions (art. 5.3).

The GDPR requires, when consent is the taken legal basis, that its freely given, specific, informed and unambiguous, and as easy to withdraw as to give (art. 7).

The customer defines the legal basis, what data can be collected and when, and configures Piano products thanks to the following inputs:

For any of the following implementations and configurations, make sure you have involve your internal DPO/Legal team to validate the compliance of it towards your company guidelines.

Consent is collected by the customer through the Consent Management Platform (CMP) of its choice.
Piano solutions do not collect consent directly: they receive the resulting signal from the CMP and/or the Data Layer, and adjust the data collection accordingly.

Consent is transmitted to every Piano solution through a single interface, so that a customer using several solutions declares the user's choice once rather than product by product.

Four consent modes are available:

  • Opt-in: the user has consented. Collection and identifiers are complete;

  • Essential: consent has not been obtained, but the purpose benefits from a legal exemption (for audience measurement, see ePrivacy exemption below). Collection is restricted to what is strictly necessary;

  • Opt-out: the user has refused, or has exercised an opt-out. Data is anonymised and excluded; only mandatory trackers are deposited

  • Extended opt-out (Piano Analytics only > see below): the user has refused, but the resulting traffic is anonymised and still used to feed aggregate reporting, rather than being excluded entirely;

Purpose

Consent is declared by purpose, and each solution is attached to the purpose that corresponds to its processing. A user may therefore consent to audience measurement while refusing advertising, without the customer having to reason in terms of products.

Product

Main Purpose

Standard Legal Basis

Analytics, Audience

Audience and Analytics

Consent under GDPR or Exemption under ePrivacy

Subscriptions, Amplifier

Content Personalization or Performance

Consent under GDPR

Audience

Advertising (personalized or not)

Consent under GDPR

Subscriptions, Amplifier

"One to one relationship" (account management, subscription, newsletter, …)

Consent or Contract under GDPR

The allocation of solutions to purposes is itself configurable: a solution may be attached to a different purpose where the customer's own analysis of its processing requires it. A customer using Piano Analytics alone does not need to declare a purpose: the mode it sends is applied directly to audience measurement.

From the choice on the CMP to the mode declared

16417363741842

The consent management platform presents the user with three possible choices: accepting every purpose, refusing every purpose, or selecting purposes individually. Each of those choices is declared to Piano, purpose by purpose, as one of the three modes:

Mode

Effect on data

Effect on trackers

Opt-in

Collected without restriction;

Deposited without restriction;

Essential (only for Analytics)

Restricted to what is strictly necessary for the purpose;

Only essential trackers are deposited;

Opt-out

Excluded but collected in an anonymised form.

Only mandatory trackers are deposited;

Extended opt-out

Anonymised and used only to feed aggregate reporting;

Only mandatory trackers are deposited;

How each solution applies the signal

Solution

Application of the signal

Piano Analytics

One of several collection modes is applied, according to the signal received, and the mode governs what is collected:

  • Opt-in, the user has consented, and collection and identifiers are complete;

  • Exempt, consent has not been obtained, and collection is restricted to what is "strictly necessary" for audience measurement;

  • Opt-out, the user has refused, or has exercised an opt-out, and collection ceases;

  • Extended opt-out, the user has refused, and the traffic contributes only to anonymised aggregate reporting.

Piano Subscriptions

The browser storage used is classified according to whether it is mandatory, essential or optional, and mapped to the corresponding consent modes in Cookies & Consent.

The module used to govern that storage is described in Consent Management for Client Storage (Cookies);

Piano Audience

Collection is governed through consent classes, each covering a category of processing (see Consent Classes Management). Signals issued under the IAB Transparency and Consent Framework are translated into those classes automatically (see TCF 2.0 in Audience). The interfaces available for handling consent programmatically are described in GDPR and cx.js;

Analytics' Specific

ePrivacy exemption

First party and GDPR compliant audience measurement trackers may be exempted from consent under art. 5.3 of the ePrivacy Directive. This directive was subsequently transposed into the various national laws of the European Union's member states, such as France's Data Protection Act (art. 82), or Germany's Telecommunications and Media Data Protection Act (TTDSG - art. 25), for example.

Several EU data protection authorities confirmed this approach in dedicated guidelines:

The exemption applies only where collection is restricted to what is strictly necessary for audience measurement on behalf of the publisher, where the data is not cross-referenced with other processing or passed to third parties, and where the customer keeps an opt-out mechanism available to the data subject despite the absence of consent.

Piano Analytics offers a configuration that meets these conditions, by requesting Piano to:

  1. hide the Visitor ID property,

  2. confirm or setup a rolling data retention to 25 months,

  3. anonymise the IP address.

IMPORTANT: in addition to the above configurations, it is necessary for the customer to:

  1. Implement the right tagging on its platform to pass the right signal to Piano (see above),

  2. Sign the specific exemption appendix to our Data Processing Agreement (DPA).

The Exemption configurations are applied on the entire Organisation/for all sites inside a Data Model.

Hybrid Measurement

In addition to the "stand-alone" Consent Exemption, Piano Analytics also offers a Hybrid Measurement, allowing customers willing to pursue one or more additional purposes to the audience measurement (see Purpose Limitation), to collect the necessary consent for additional Personal Data. This data will be collected in a unified way into the same data model, without any dupplication of Visits, Visitors, etc.

Extended Opt-out

In addition to the above “Exemption” and “Hybrid Meaurement”, Piano offers another alternative for data collection without consent, thanks to the principles of Data Anonymization.

How it works

Data Collection: If an Internet user does not want to opt in to audience measurement, you can trigger the Extended Opt-Out via tagging (see the "Implementation" section). A "_pprv" cookie is set to store the user's choice (this cookie takes the value "opt-out").

Events sent to Piano Analytics will now contain the following information

  • idclient - "optout"

  • visitor_privacy_mode - "extended-optout"

  • All other properties without distinction

Data Processing: For each event with a visitor_privacy_mode set to "extended-optout", the processing will set up different treatments:

  • Creating an Event without a Visitor ID or Visit ID

  • Delete all properties associated with an enabled personal data flag

  • Add an ".optout" suffix to the end of the event name

Data Storage: Events are stored in the all traffic table. They are not linked to other events because they do not have a match key such as "visitor_id" or "visit_id".

They have an ".optout" extension, as seen in the previous step. Extended opt-out "page.display" events are therefore named "page.display.optout".

Example:

image-20241118-114625.png

Type of Analysis available

Globally, all metrics based on properties that do not contain personal data and are not based on a visitor or visit ID are available via the extended opt-out.

This excludes analysis of time spent, sources and visitor retention. Anything that has persistence over time and needs to link events together.

Example of data not available:

  • Time Spent

  • Conversions

  • Bounced visits

  • Bounce Rate

This allows you to analyze data related to your text, audio, and video content. Some e-commerce analytics are also available.

Example of available data:

  • Sales without VAT (Transaction)

  • Impressions

  • Events

  • AV - play time

Implementation

Extended opt-out is enabled from the tag. This is a library configuration.

The prerequisites are:

  • At least version 6.13.0 of the Piano Analytics JS library.

  • Using the Consent Management module

  • Use the "optout" consent mode

To enable Extended opt-out, you must enable the configuration when you initialize the library (see the developers documentation):

enableExtendedOptout

This configuration changes the historical behavior of the Piano Analytics opt-out.

Whenever an event has an "opt-out" mode, we'll treat it in "extended opt-out" mode instead of the historical "strict" opt-out.

Extended opt-out is not a paid feature.

The collected events are still counted as classic events because they are no longer excluded and are processed throughout the analytics chain.

Of course, strict opt-out is still available if you don't enable Extended opt-out from the library.

Last updated: