This document presents the self-evaluation of the Nonli SDK against the criteria published by the CNIL for audience measurement solutions that may be implemented without collecting consent, when the solution is correctly configured.
This self-evaluation covers only the Nonli SDK used to measure editorial content audience on publisher client websites. It does not cover other analytics services that the publisher may install on its own website, nor URL tagging parameters that the customer may configure for its own analytics tools.
In line with the CNIL's recommended wording, Nonli states the following:
Based on our self-evaluation, the Nonli SDK complies with the criteria established by the CNIL for consent-exempt audience measurement solutions, and may be implemented without requiring user consent if it is correctly configured.
This self-evaluation is not a certification, validation or approval by the CNIL. It documents Nonli's own analysis, without prejudice to any analysis the CNIL may carry out as part of its missions.
1. References#
- CNIL page: Cookies: solutions for audience measurement tools
- CNIL self-evaluation tool for implementing a consent-exempt audience measurement solution
- Article 82 of the French Data Protection Act
- Nonli GDPR agreement: GDPR - Data Processing
2. Summary#
| CNIL objective | Nonli assessment | Rationale |
|---|---|---|
| Purpose strictly limited to audience measurement | Compliant | The SDK measures views and editorial metrics aggregated by content, solely on behalf of the publisher. |
| GDPR processing terms | Compliant | Processing, security, confidentiality, assistance and data-return commitments are documented in the Nonli GDPR agreement. |
| No cross-domain tracking | Compliant | The SDK sets no cookie, reads no site cookie, creates no visitor identifier and does not consolidate measurement between clients. |
| Anonymous statistical data | Compliant | Results are aggregated counters by content, brand or domain, with no user identifier. |
| Objection mechanism | Not applicable | The SDK does not process personal data in audience counters; technical infrastructure processing is governed separately. |
3. Purpose Scope#
The Nonli SDK is limited to editorial audience measurement and to the operations necessary to provide that service:
- page-view measurement by content;
- aggregated editorial metrics, such as video views, comments, paywall views or paywall clicks transmitted by the publisher;
- navigation or availability issue detection, such as in-stock or out-of-stock content counters;
- technical optimization and volume estimation;
- analysis of consulted content based on the canonical URL.
The Nonli SDK is not used to:
- measure advertising campaigns;
- create user cohorts;
- personalize an individual journey;
- perform retargeting;
- produce unified reach across several domains;
- enrich data with a CRM, DMP, CDP or third-party identifier.
4. Objective 1 - Single Audience Measurement Purpose#
The Nonli SDK exposes only the calls needed for editorial measurement:
| Call | Role | Processed data |
|---|---|---|
sdk.js | Tag loading | Domain and brand configuration. |
pv.js | Page-view counting | Canonical URL, sampling, brand, publication or modification dates when available. |
mcs.js | Editorial metrics counting | Aggregated numeric metrics, such as video views, comments, paywall events, quantity, amount and currency. |
The SDK does not provide marketing or advertising measurement features. Collected parameters are strictly linked to the analysis of the consulted content.
Campaign or analytics-tagging parameters that may be added to destination links, such as utm_*, at_*, mtm_* or xtor, are not enabled by default by Nonli. When configured by the customer, they belong to the customer's own tagging plan and analytics tools, not to the SDK audience measurement assessed here.
4.1. HTTP Header Minimization#
HTTP headers are not collected to produce audience counters. The User-Agent received with the request is used transiently to exclude bots from counting. Information derived from the User-Agent, such as browser version, operating system or platform, is not persisted in the counters.
No header such as language, screen resolution, IP address, platform or browser identifier is stored in measurement data.
5. Objective 2 - GDPR Processing Terms#
Nonli acts on behalf of the publisher client when providing the SDK. The applicable commitments are described in the GDPR agreement, including:
- data confidentiality;
- technical and organizational measures;
- assistance to the publisher for rights requests;
- personal data breach notification;
- subprocessor rules;
- data return or deletion at the end of the service.
SDK data is isolated by client, brand and domain. Nonli does not pool raw data between publishers and does not reuse client data for its own purposes.
For any question or complaint, the publisher may contact [email protected].
5.1. Infrastructure, TLS and CDN#
The short domains used for the SDK are served on dedicated subdomains. Nonli uses Cloudflare as a technical provider for custom-domain TLS certificate management and, depending on domain configuration, for CDN delivery of the sdk.js file.
TLS certificate generation relies on domain validation and sends Cloudflare the information required for that operation, including the hostname and certificate settings. This operation does not send audience-measurement data.
The sdk.js file is a public, cacheable JavaScript resource. The measurement calls pv.js and mcs.js are served by the Nonli application with private cache headers and CDN no-store headers, and the Cloudflare configuration excludes them from shared CDN caching. Cloudflare protections that could create a browser challenge or a bot-management cookie are excluded from the SDK routes sdk.js, pv.js and mcs.js. They may remain active on other technical flows, including to protect short domains, without being used for SDK audience measurement.
6. Objective 3 - No Cross-Domain Tracking#
The Nonli SDK is designed without cookies and without visitor identifiers:
- no cookie is set;
- no site cookie is read;
- no cross-domain identifier is created;
- no CRM, DMP, CDP or advertising data is imported;
- no fingerprinting is performed;
- no individual session is reconstructed.
The SDK is deployed on a subdomain of the client's main domain. Measurement for one brand or domain is never consolidated with another brand or another client.
6.1. IP Address and Logs#
The SDK application path does not read the visitor's IP address for audience measurement. It does not perform geolocation, IP pseudonymization or IP storage in SDK counters.
At Nonli production reverse-proxy level, access logging is disabled for the domains serving the SDK. Technical transport data may nevertheless be processed by infrastructure providers, including Cloudflare for TLS, routing, security and cache, and by application logs in exceptional error cases. These technical processing operations are not used to produce audience counters and must be governed by the applicable processing agreements, retention periods and security measures.
6.2. HTTP Referrer#
The HTTP referrer may be used transiently to verify that the call comes from the same subdomain as the declared canonical URL. This check limits abuse and does not feed the audience counters.
7. Objective 4 - Anonymous Statistical Data#
Reports produced by Nonli from the SDK contain only anonymous and aggregated statistics:
- number of views;
- in-stock or out-of-stock content views;
- editorial numeric metrics transmitted by the publisher;
- aggregations by content, brand or domain.
No user identifier, browser identifier, cookie, IP address or technical fingerprint is stored with these counters. Filters available in the Nonli interface therefore cannot isolate a person or reconstruct their journey.
The Nonli SDK does not provide session replay, screen recording, individual heatmaps or named behavioral tracking.
8. Objective 5 - Right to Object#
The CNIL states that an objection mechanism must be implemented insofar as personal data processing within the meaning of the GDPR exists.
The Nonli SDK does not process personal data in its audience measurement path:
- no cookie;
- no use of the IP address for audience counters;
- no fingerprinting;
- no visitor identifier;
- no cross-domain consolidation;
- counters aggregated by content and by client.
As a result, no specific objection mechanism is required for SDK measurement. A user who still wishes not to be counted can block the SDK domain through their browser, network or script blocker.
9. Operational Configuration#
To remain within the scope described in this self-evaluation, the publisher must use the Nonli SDK in its standard configuration:
- deployment on the subdomain provided for its brand;
- no tag modification intended to add identifiers or personal data;
- user information in its privacy policy or cookie policy;
- no combination with other processing operations to identify visitors.
Installation terms are described in the SDK FAQ: Nonli SDK (analytics tag) - Q&A.