Is Google Analytics GDPR Compliant in 2026?

Not banned. Not compliant by default. The honest, current answer — Schrems II, the 2022 EU rulings, the Data Privacy Framework, and the cookie-consent problem everyone skips.

By Null Agency · Updated July 2026 · General information, not legal advice

The short version

Is Google Analytics GDPR compliant? It is configurable toward compliance — it is not compliant the moment you paste the tag. Google Analytics is legal to use in the EU in 2026, but only if you do the work around it: a lawful basis, valid cookie consent, a signed data-processing agreement, and correct privacy settings.

If your reason for asking is anxiety rather than curiosity, there's a cleaner path: privacy-first Google Analytics alternatives that store no cookies and no personal data at rest — so there is effectively nothing to consent to. More on that below.

The short, honest answer: configurable toward compliance, not compliant by default

The most accurate answer to "is Google Analytics GDPR compliant" is a frustrating one: it depends on how you set it up. GA is not a compliance product; it's an analytics product that can be operated in a compliant way or a non-compliant way, and the default install leans toward the latter. Pasting the tag onto your site and walking away is almost never enough in the EU or UK.

Compliance is not a property of the tool — it's a property of your configuration, your legal paperwork, and your consent flow taken together. Google supplies the raw materials: a data-processing agreement, IP-handling behaviour, consent-mode controls, and data-retention settings. Whether those materials add up to something a regulator would accept depends entirely on choices you make. That's why two sites running the exact same GA4 property can sit on opposite sides of the line.

There are three distinct questions bundled inside "is GA4 legal in the EU," and conflating them is where most confusion comes from:

You can pass one and fail another. A site can have a perfect cookie banner and still trip on transfers; another can rely on the Data Privacy Framework flawlessly and still fail because it fired GA before consent. "Compliant" only means all three questions resolve in your favour at once. Google Analytics gives you the dials to get there — it does not turn them for you. That is the entire nuance behind every headline that says GA is "banned" or "back to legal." Neither is quite true; the honest word is conditional.

Background: Schrems II and why EU-to-US data transfers were the core problem

To understand the 2022 rulings, you have to understand the 2020 judgment that triggered them. In July 2020, the Court of Justice of the European Union handed down its decision in the case commonly known as Schrems II (brought by privacy campaigner Max Schrems). The court did two things at once: it invalidated the "Privacy Shield" framework that US companies had relied on to receive EU personal data, and it kept Standard Contractual Clauses alive but attached a heavy condition — companies using them must assess whether the destination country actually offers protection "essentially equivalent" to EU law, and add supplementary measures where it doesn't.

The court's concern wasn't Google specifically. It was US surveillance law. The judgment reasoned that certain US government access powers, combined with the lack of effective redress for EU citizens, meant personal data landing on US servers could be exposed to a degree of access that EU law would not permit. Standard contractual paperwork can't bind a national intelligence agency, so contracts alone couldn't cure the gap.

That reasoning is what made ordinary analytics a legal problem. Google Analytics, by design, sent data — including identifiers and IP-derived information that can qualify as personal data — to infrastructure operated by a US company. After Schrems II, doing that under the old Privacy Shield was no longer valid, and doing it under Standard Contractual Clauses required demonstrating that supplementary measures genuinely closed the surveillance gap. For a tool that transmits data continuously from millions of EU visitors, that was a very hard bar to clear.

This is the crucial context: the 2022 enforcement wave was never really a verdict on Google's product quality or even primarily its privacy features. It was fallout from a structural conflict between EU data-protection standards and US surveillance law — with Google Analytics as the most common, most visible example of a transfer that regulators could point at. Understanding that framing matters, because it also explains why the 2023 Data Privacy Framework could shift the picture so quickly: it targeted the transfer mechanism itself, not the tool.

The 2022 DPA rulings explained (Austria, France, Italy) — what they did and didn't say

After Schrems II, the privacy group noyb filed a large batch of complaints across the EU targeting specific websites' use of Google Analytics. Over 2022, several national data protection authorities ruled on those complaints, and the decisions landed in a recognisable sequence.

The Austrian authority (Datenschutzbehörde) issued the first major decision in early 2022, finding that a particular website's use of Google Analytics violated GDPR because it resulted in an unlawful transfer of personal data to the US. Shortly after, France's CNIL reached a comparable conclusion and formally ordered a website operator to bring its use of Google Analytics into compliance — or stop using it under those conditions. Later in 2022, Italy's Garante issued its own decision along the same lines against another site.

What the rulings said: in each case, the regulator concluded that the specific configuration in front of them transferred personal data to the US without adequate protection under the standard then available, and that the "supplementary measures" in place did not close the gap Schrems II identified. The identifiers and IP-derived data involved were treated as personal data. The transfer, not the analytics, was the violation.

What the rulings did not say is just as important, and it's routinely misreported:

The practical takeaway from 2022 was never "GA is banned." It was "GA-as-typically-deployed exposed sites to enforcement risk because of transfers." That's a narrower and more fixable statement — which is exactly what 2023 set out to fix.

What changed: the EU-US Data Privacy Framework adequacy decision (2023)

In July 2023, the European Commission adopted an adequacy decision for the new EU-US Data Privacy Framework (DPF). An adequacy decision is the strongest, cleanest legal basis for sending personal data out of the EU: it's a formal finding by the Commission that a destination provides an "essentially equivalent" level of protection, so transfers there can flow without needing case-by-case supplementary measures.

The Framework works on self-certification. US companies commit to a set of privacy principles and certify their participation; certified organisations then become valid recipients of EU personal data under the adequacy decision. Crucially, the DPF was accompanied by changes on the US side — including new limits and oversight around government access to data and a redress mechanism for EU individuals — designed specifically to answer the concerns Schrems II raised. Google is among the many US companies that certify participation.

For Google Analytics, this is the single most important development since 2020. The specific problem behind the Austrian, French and Italian decisions was that transfers to the US lacked a solid legal footing after Privacy Shield fell. The Data Privacy Framework re-establishes that footing. If your data lands with a DPF-certified recipient, the transfer that regulators objected to in 2022 now has a recognised basis. In plain terms: the biggest single reason GA was found unlawful in those cases was directly addressed.

But — and this is where careful reading matters — an adequacy decision fixes the transfer question and only the transfer question. It does not grant a lawful basis for your processing, it does not exempt you from cookie-consent rules, it does not sign your data-processing agreement, and it does not configure your retention. The Framework moved Google Analytics from "hard to justify" back to "usable if you do everything else right." It reopened the door; it did not carry you through it. Every site still has to handle consent, disclosure and configuration on its own account — which brings us to the part of the story that transfer coverage almost always skips.

The issue transfer talk skips: cookie consent under the ePrivacy Directive

Here's the part that gets lost in years of headlines about US transfers: even with the Data Privacy Framework fully in place, you probably still need a cookie banner for Google Analytics. The two issues are governed by different laws, and solving one does nothing for the other.

GDPR governs how personal data is processed. But the act of storing or reading information on a user's device — which is what setting a cookie is — is governed separately by the ePrivacy Directive (often called the "cookie law"), as implemented in each EU member state. The ePrivacy rule is blunt: with narrow exceptions for cookies that are "strictly necessary" to deliver a service the user asked for, you must obtain the user's prior, informed consent before placing a cookie. Analytics cookies are, in the standard European reading, not strictly necessary — the site works fine without them — so they fall on the consent side of the line.

Google Analytics sets cookies. That single fact means that in the EU (and, under UK PECR, the UK), you generally need consent before GA runs. "Consent" here has teeth: it must be freely given, specific, informed and unambiguous, collected before the tag fires, as easy to refuse as to accept, and never bundled into a pre-ticked box or a "by using this site you agree" line. In practice this is what a real consent banner is for.

This is why the transfer story is only half the picture. Imagine the Data Privacy Framework holds up perfectly forever: your US transfer is airtight. You would still need a compliant consent banner, and you would still lose the data of every visitor who declines — which in the EU is often a large share. The consent requirement is independent of, and survives, every twist in the transfer saga. It's also the single most common reason a well-intentioned GA setup is non-compliant: the site owner fixed the transfer question they read about in the news and never realised the cookie question was a separate, unavoidable obligation sitting right in front of them.

What Google Analytics needs today to be defensible (consent, DPA, IP/data settings, DPF reliance)

If you want to keep using Google Analytics in the EU or UK and be able to defend that choice, treat it as a checklist of four independent obligations. Miss any one and the whole thing wobbles.

1. Valid, prior cookie consent

Deploy a genuine consent mechanism that blocks GA from firing until the visitor opts in. Refusing must be as easy as accepting, with no dark patterns, no pre-ticked boxes, and no "necessary cookies" mislabelling of analytics. Google's Consent Mode is designed to hook into this — when a visitor declines, tags adjust their behaviour accordingly. Consent Mode is a mechanism to respect the visitor's choice, not a substitute for asking; you still need the banner and an honest record of what was agreed.

2. A data-processing agreement

You are the data controller; Google is a processor acting on your instructions. GDPR requires a written data-processing agreement (Google provides its Data Processing Terms) and it must actually be accepted and in force for your account. This is paperwork, but it's non-optional paperwork.

3. Correct data and IP settings

Use GA4 rather than the retired Universal Analytics — GA4 changed how IP addresses are handled (they aren't logged and stored the way UA did) and gives you consent-mode and retention controls. Set data retention to the shortest window that meets your needs, turn off or carefully weigh any data-sharing and "signals" features you don't require, and disable granular collection you can't justify. Every extra data feature you enable is another thing you must have a basis for and disclose.

4. Rely on the Data Privacy Framework — and say so

Your transfer basis today is Google's participation in the EU-US Data Privacy Framework. Document that you're relying on it, keep your privacy notice accurate about the transfer, and — because the Framework is contested — keep an eye on its status so you're not caught flat-footed if it changes.

Do all four and you have a defensible GA deployment: consent handled, controller-processor relationship papered, data minimised and configured, transfer grounded. It's real work, it has to be maintained, and it still leaves you exposed to the one risk you can't configure away — the legal durability of the Framework itself. If your team wants the step-by-step, our guide on dropping the consent banner with the cookieless approach walks through the alternative to steps 1–4 entirely.

Remaining risks: ongoing legal challenges to the Data Privacy Framework

The Data Privacy Framework restored a lawful transfer route, but it did not end the argument — and the honest way to plan around GA is to assume the argument continues. There's a clear historical pattern here that any risk assessment should account for.

The Framework is the third EU-US data-transfer arrangement of its kind. Its predecessor, "Safe Harbor," was struck down by the Court of Justice in 2015 (in the original Schrems case). Its successor, "Privacy Shield," was struck down in 2020 by Schrems II. Both fell for essentially the same underlying reason: the court concluded US surveillance law and redress mechanisms didn't offer protection essentially equivalent to EU standards. The Data Privacy Framework was rebuilt to answer those specific criticisms, with new limits and oversight on the US side — but privacy advocates, including the campaigners behind the first two challenges, have publicly signalled they consider it vulnerable to the same line of attack, and it has already drawn legal challenge within the EU court system.

What this means in practice for a site owner is not "panic," but "don't treat the Framework as permanent." Two scenarios are worth holding in mind:

You cannot configure this risk away. It sits above your account settings, in the relationship between two legal systems, and it's decided in courtrooms you have no input into. For some teams that's an acceptable, monitored risk. For others — especially anyone who lived through the 2022 fire drill once — the appeal of simply not having a transfer to defend is obvious. That's the case for the cleaner path.

The cleaner path: cookieless analytics that stores no personal data at rest

Every problem above — transfers, consent, the Framework's durability — shares one root cause: Google Analytics collects and retains personal data, and moves it across a border. Remove that root and the branches fall off. If a tool sets no cookies and stores no personal data at rest, there is no cross-border personal-data transfer to justify and, for the analytics itself, little to consent to. You're not passing the GDPR exam more cleverly; you're mostly not sitting it.

This is the design philosophy behind a category of privacy-first, cookieless analytics tools. Well-known names include Plausible, Fathom and Simple Analytics — all lightweight, all built to avoid cookies and personal-data retention. Described neutrally, they occupy the same broad space: measure traffic in aggregate, skip the tracking apparatus, skip the banner. Our own tool, GhostMetrics, sits in that category too, and because we build it, it's the one we can describe precisely.

GhostMetrics — cookieless and IP-less by design

No cookiesNo IPs storedNo consent bannerPublic, auditable tracker

In the product's own words: "No cookies, no consent banner, no visitor IPs, no personal data." The tracker sets zero cookies and writes nothing to localStorage — it uses sessionStorage, which the browser wipes when the tab closes, so there's no persistent identifier left on the visitor's device. Visitor IPs are used only in-memory to derive a session hash and are then discarded; they're never written to the database.

That session hash is deliberately built to be non-reversible and non-linkable: it's SHA-256(daily-rotating salt | siteId | IP | User-Agent) truncated to 64 bits — salted with 32 random bytes, scoped per-site (so the same person on two different sites gets two unrelated hashes; it can never act as a cross-site cookie), and the salt rotates every UTC day and is then deleted (48-hour KV TTL), so yesterday's hashes can't be reversed or correlated with today's. No device fingerprinting — no canvas tricks, no font probing, no persistent ID. Country, region and city are derived from the visitor's location at Cloudflare's edge and the IP is discarded on the spot; city level is the finest location ever seen. Global Privacy Control and Do Not Track are honoured — those visits are never recorded.

The point isn't a compliance guarantee — it's the removal of the question. With no cookies, no stored IPs and no personal data at rest, there's effectively nothing to consent to for the analytics, and no US transfer of personal data to defend. You don't win the GDPR argument; there's mostly no argument to have.

Honest caveats, stated plainly: GhostMetrics is hosted and closed-source in the way Fathom and Simple Analytics are — only the tracker script is public (auditable at /gm.js), not the dashboard. It runs on US Cloudflare by default, with EU data residency available on request (it can be pinned to Cloudflare's EU jurisdiction). If open-source self-hosting or strict EU-only residency is a hard requirement for you, we'll point you to Plausible, Umami or Simple Analytics instead — that's a genuine limitation, not a sales pitch.

Start free — no cookies, no card Audit the live demo

You don't have to take the description on trust, which is the part we care about most. The tracker source is public, so you can read exactly what it does before you decide. And because we dogfood GhostMetrics on our own sites, the live demo shows our real, unfiltered traffic with no signup — including, if you're reading this in a browser, your own visit landing in real time. For a side-by-side on privacy, data handling and price, see how the cookieless tools compare, and if you've decided to move, our guide to privacy-first Google Analytics alternatives covers the switch.

A practical compliance checklist

Two routes, depending on which side of the problem you'd rather manage. Pick one and work the list.

If you keep Google Analytics

If you switch to cookieless analytics

This article is general information about GDPR and analytics — it is not legal advice, and it can't account for your specific circumstances or your jurisdiction's guidance. Data-protection rules and the status of transfer mechanisms change. For decisions with real consequences, confirm the current position with a qualified data-protection professional.

FAQ

Is Google Analytics illegal in the EU?
No — it's not banned. But between 2022 and 2023, several EU data protection authorities (in Austria, France and Italy, among others) ruled that specific websites' use of Google Analytics breached GDPR because of unlawful data transfers to the US under the Schrems II judgment. The situation changed when the EU-US Data Privacy Framework restored a lawful transfer mechanism in 2023. So GA can be used lawfully today with the right configuration, but its compliance is conditional, not automatic. This is general information, not legal advice.
Did the Data Privacy Framework make Google Analytics GDPR compliant?
The EU-US Data Privacy Framework (adopted July 2023) re-established an adequacy basis for transferring personal data to certified US companies, which addressed the specific transfer problem behind the 2022 rulings. It doesn't make Google Analytics automatically compliant for everything else — you still need a lawful basis, appropriate consent for cookies, a data-processing agreement and correct settings. The Framework also faces ongoing legal challenge, so it isn't a permanent guarantee.
Do I need consent to use Google Analytics?
In the EU/UK, generally yes. Google Analytics sets cookies and processes personal data, so under the ePrivacy Directive you typically need prior, informed consent before it runs — which in practice means a consent banner. This requirement exists independently of the data-transfer question, which is why cookie consent is often the sticking point even after the Data Privacy Framework.
Is GA4 more GDPR-friendly than Universal Analytics?
GA4 added privacy-oriented features — IP addresses aren't logged or stored in the same way, and there are consent-mode and data-retention controls. That makes it more configurable toward compliance than the old Universal Analytics, but it still uses cookies and processes personal data, so consent and correct configuration are still required. "More privacy-friendly" is not the same as "compliant out of the box."
What analytics tools don't need GDPR consent?
Cookieless, privacy-first tools that set no cookies and store no personal data at rest generally don't require consent for analytics — examples include GhostMetrics, Plausible, Fathom and Simple Analytics. Because there's no personal data retained and no cross-site identifier, the biggest GDPR obligations don't attach in the same way. Always confirm each tool's exact data handling and your own jurisdiction's guidance.

Related reading

Google Analytics Alternatives

Privacy-first tools compared, 2026

Cookieless Analytics Compared

GDPR, privacy and pricing side by side

Drop the Consent Banner

The cookieless how-to guide

GhostMetrics vs Plausible vs Fathom

Privacy analytics head-to-head

Privacy Analytics Guide

What "privacy-first" really means

Live Demo, No Signup

Our real, unfiltered traffic

Disclosure: GhostMetrics is built and operated by Null Agency, the company that publishes this article — so we have an interest in you trying it. We've described it against its own published data handling and pointed to the public tracker source and live demo so you can verify the claims yourself, and we've named its real limitations. Competing tools (Plausible, Fathom, Simple Analytics, Umami) are described neutrally; nothing here is paid placement. This page is general information, not legal advice.