Is Google Analytics Illegal? Part Deux

Is Google Analytics Illegal? Part Deux
Estimated Reading Time: 5 minutes

**Important – This is not legal counsel, the materials provided are for informational purposes only and not for the purpose of providing legal advice. Final decisions must be made by your own legal representation.**

A couple of weeks ago, we discussed the implications and recommendations following the Austrian DPA’s released opinion that the use of Google Analytics (GA) was illegal in the context of a complaint filed in September of 2020. The question of “does the use of GA violate General Data Protection Regulation (GDPR)?” at the time had a bit of a complicated answer. Much of this murkiness has been cleared up due to the recent release by France’s CNIL which very clearly states that the use of GA in its current form is a violation of GDPR.

The CNIL’s statement is in response to their review of similar complaints to those from the Austrian case. Specifically at question are the protections in place for personal data by GA as it relates to international transfers. It is the opinion of both the Austrian and French DPA that the protections in place are not sufficient to satisfy the requirements of Article 44 of GDPR. Therefore, the use of GA is a violation. 

How does this differ from the Austrian opinion?

The Austrian DPA’s opinion issued spoke to a specific set of circumstances and configuration of GA. The circumstances considered in that case were also from September 2020—some of the nuance had changed in the past two years. France’s CNIL statement is based upon a current review of GA and the protections in place for the international transfer of French user’s personal data. The statement is not in reference to a specific set of configurations but rather default, always-happening behavior of GA. This makes the opinion much more broad in applicability and explicit in its position.

So, what is specifically at issue?

Specifically cited in both of these instances is the international transfer of personal data by GA not having sufficient protections to satisfy GDPR requirements. The CNIL has issued the opinion that any unique identifier for a user would fall under this definition of “personal data” and therefore would put GA in scope of GDPR. GA, by default, will always send at minimum a client ID and the IP address of the user. The client ID is a unique identifier specific to a user on a specific domain. The IP address, while potentially obfuscated based upon settings applied, is still collected and initially processed. Due to Google’s storage of GA data in the United States, and no satisfactory lawful transfer agreement in place following the invalidation of the EU-US Privacy Shield in 2020, this architecture violates GDPR. This is regardless of any additional configuration a business may have which could also put GA data in scope of GDPR (such as a user ID). 

What next?

Absent a major architectural change from Google (which has been hinted at), this is the second EU market to explicitly state the usage of GA is illegal. Considering the issues at question, more EU DPAs are likely to follow suit. Unless Google provides a technical mechanism to either not collect any personal data (therefore removing GA from the scope of GDPR—also significantly reducing the use cases which GA could address) or to process and store data collected from EU users only in the EU, the usage of GA would present a compliance risk for organizations using the platform.

Anything else relevant to know?

In the background, there are ongoing discussions between US and EU regulators on the creation of a new standard legal mechanism organizations could use to certify international data transfers to replace the EU-US Privacy Shield. Just last week Google and Meta issued some strong statements in response to similar issues. With the vast business implications of the impact of not just being able to use GA but also any platform which stores or processes personal data in the United States, regulators should be very motivated to get something in place. We will see over the coming months if this motivation brings about a new standard transfer agreement.

We said “more to come” in response to the Austrian DPA’s opinion, this is certain to be just one of the first of many additional opinions from EU DPAs that will be made on this topic in the coming weeks. Stay tuned as the plot continues to thicken.

Interested in discussing a privacy-centric first party data strategy?

We’d love to chat. Reach out to our team of data governance experts!

Author

  • Lucas Long

    Lucas Long is co-author of the Amazon best-selling book, Crawl, Walk, Run: Becoming a Privacy-Centric Marketing Organization. He is also the Director of Privacy Strategy at InfoTrust, working with global organizations at the intersection of digital strategy, privacy regulations, and technical data collection architecture. Through these efforts, Lucas helps companies understand their limitations for data enablement due to privacy challenges and design optimal ways to accomplish core use cases in a compliant manner.

    When not discussing the intricacies of GDPR and cookie laws with clients, Lucas enjoys traveling and exploring new cultures, one bite at a time. Based in Barcelona, he is also a presenter, featured at industry events organized by Google, the Digital Analytics Association, the American Marketing Association, and the Journal of Applied Marketing Analytics.

Facebook
Twitter
LinkedIn
Email
Originally Published: February 11, 2022

Subscribe To Our Newsletter

January 17, 2023
Originally published on February 11, 2022

Other Articles You Will Enjoy

How Data Maturity Can Cultivate a Data-Driven Culture

How Data Maturity Can Cultivate a Data-Driven Culture

Data-driven decisions are a buzz topic in Martech. It is essential for C-suite executives to understand and more importantly, use their data to move…

4-minute read
Predictive Analytics in Google Analytics 4: How to Use Machine Learning to Forecast User Behavior and Outcomes

Predictive Analytics in Google Analytics 4: How to Use Machine Learning to Forecast User Behavior and Outcomes

Google Analytics 4 (GA4) is embracing the power of machine learning by incorporating predictive analytics within the platform so that you can use your…

7-minute read
Leveraging Custom Dimensions and Metrics in Google Analytics 4 for Content Performance Measurement: Best Practices and Real-World Examples

Leveraging Custom Dimensions and Metrics in Google Analytics 4 for Content Performance Measurement: Best Practices and Real-World Examples

In today’s digital landscape where content reigns supreme, understanding how your audience interacts with your content is paramount for success. For news and media…

5-minute read
Is It Time to Upgrade? 4 Signs Your Organization Needs Google Analytics 4 360

Is It Time to Upgrade? 4 Signs Your Organization Needs Google Analytics 4 360

As VP of Partnerships at InfoTrust, I’ve had the opportunity to talk with hundreds of decision-makers about their interest in upgrading to Google Analytics…

4-minute read
How to Integrate Google Analytics 4 with BigQuery for Enhanced Data Analysis and Reporting

How to Integrate Google Analytics 4 with BigQuery for Enhanced Data Analysis and Reporting

Has your business found that its reporting needs require advanced analysis of your analytics data beyond what is practical in the Google Analytics 4…

4-minute read
Google Tag Best Practices for Google Analytics 4

Google Tag Best Practices for Google Analytics 4

After collaborating with several of my colleagues at InfoTrust including Bryan Lamb, Head of Capabilities, Corey Chapman, Senior Tag Management Engineer, Chinonso Emma-Ebere, Tech…

4-minute read
Google Analytics 4 Implementation Checklist: Ensure You’re Tracking Everything You Need

Google Analytics 4 Implementation Checklist: Ensure You’re Tracking Everything You Need

In the dynamic landscape of digital marketing, data is supreme. Understanding user behavior, preferences, and interactions on your website is crucial for making informed…

4-minute read
How Does BigQuery Data Import for Google Analytics 4 Differ from Universal Analytics?

How Does BigQuery Data Import for Google Analytics 4 Differ from Universal Analytics?

All Google Analytics 4 (GA4) property owners can now enable ‌data export to BigQuery and start to utilize the raw event data collected on…

2-minute read
Tracking User Behavior with Events in Google Analytics 4: Examples and Use Cases

Tracking User Behavior with Events in Google Analytics 4: Examples and Use Cases

So you’ve created your Google Analytics 4 (GA4) properties, created your data stream(s), and followed all the necessary steps to configure your property. Now…

5-minute read

Get Your Assessment

Thank you! We will be in touch with your results soon.
{{ field.placeholder }}
{{ option.name }}

Talk To Us

Talk To Us

Receive Book Updates

Fill out this form to receive email announcements about Crawl, Walk, Run: Advancing Analytics Maturity with Google Marketing Platform. This includes pre-sale dates, official publishing dates, and more.

Search InfoTrust

Leave Us A Review

Leave a review and let us know how we’re doing. Only actual clients, please.