How did Google Analytics become a legal problem?
The story starts with a court case that had nothing to do with analytics. In July 2020, the Court of Justice of the EU struck down Privacy Shield -- the agreement that allowed personal data to flow from the EU to US companies -- in a case known as Schrems II. The court's reasoning: US surveillance law gives American intelligence agencies access to data held by US companies, and EU citizens have no effective remedy against it.
That ruling put every transfer of EU personal data to a US company under scrutiny. And Google Analytics transfers a lot of it: IP addresses, cookie identifiers, device fingerprints, browsing behaviour -- all processed by a US corporation.
The privacy group noyb, founded by Max Schrems, filed 101 complaints across EU member states targeting websites that used Google Analytics. The decisions started landing in 2022.
Which countries ruled against Google Analytics?
The Austrian data protection authority went first, in January 2022, finding that a website's use of Google Analytics violated GDPR because the data transfer to the US lacked adequate protection. France's CNIL followed in February 2022 with the same conclusion, ordering affected websites to stop using the tool or make it compliant. Italy's Garante ruled in June 2022, and authorities in Denmark and Norway issued similar guidance. None of these were fines against Google -- they were findings that the websites using Google Analytics were breaking the law.
The practical message across Europe in 2022 was blunt: standard Google Analytics, as installed on a normal website, was unlawful.
What changed with the Data Privacy Framework?
In July 2023 the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (DPF), the successor to Privacy Shield. US companies that certify under the framework -- Google among them -- can again lawfully receive EU personal data. The US side added new safeguards, including a redress court for EU citizens and limits on intelligence collection.
That decision is why nobody can accurately say "Google Analytics is illegal in the EU" today. With the DPF in place, the specific defect the 2022 rulings identified -- an unlawful US transfer -- currently has a legal remedy.
So is the question settled?
No, and this is the part that matters for planning. The DPF is the third attempt at an EU-US transfer agreement; the courts struck down both predecessors (Safe Harbor in 2015, Privacy Shield in 2020) for essentially the same underlying reason. Legal challenges to the DPF are already moving through the system, and many privacy lawyers expect the Court of Justice to examine it eventually -- the case people informally call Schrems III. If the DPF falls the way its predecessors did, every site relying on it inherits the 2022 problem overnight.
And separately from the transfer question, GA4 still carries its full GDPR and ePrivacy workload even while the DPF stands:
- Consent banner required. GA4 stores cookies and processes personal data, so you must collect prior consent -- with all the data loss that brings, since 20-40% of visitors typically decline.
- Privacy policy obligations. You must disclose the processing, the transfer, and the legal basis.
- Records and assessments. Depending on your situation, records of processing and a transfer impact assessment remain part of the compliance file.
"Not illegal" is not the same as "no obligations". GA4 remains one of the heavier compliance items a small website can carry.
What should a website owner actually do?
You have three realistic options.
Option one: keep GA4 and do the compliance work. Maintain the consent banner, keep the privacy policy current, and accept both the data loss from declined consent and the risk that the DPF's legal ground shifts. Rational if you depend on Google Ads integration or GA4-specific features.
Option two: keep GA4 but harden it. IP anonymisation, EU data collection settings, shortened retention. This reduces exposure but does not remove the transfer, the cookies, or the banner.
Option three: switch to analytics that never raises the question. A cookieless, EU-based tool processes no personal data, transfers nothing to the US, and needs no consent banner. The legal analysis collapses to almost nothing because there is no personal data in the system. This is how privacy-first analytics works, and it is the approach TrackTrendy takes: anonymous, aggregated statistics, EU-focused, from €4/month -- with the side benefit that you count 100% of your visitors instead of the consenting minority.
For most small businesses, option three is less work than options one or two -- which is rare in compliance.