Authors: Cécile Auvieux y Gerard Andreu
The EU data protection authorities v. Google Analytics
Google has announced that one of its most successful tools, Universal Analytics (aka Google Analytics), will stop processing data between July and October 2023, and be replaced by Google Analytics 4 (already on the market). This announcement left marketers who have built entire business processes around Google Analytics frustrated and worried. Why is this happening?
Without minimizing Google’s technical and business reasons (according to the company, GA4 proposes new data models, adapted to the Internet of today and, above all, of the future), the explanation also lies in the CJEU’s July 2020 decision invalidating the Privacy Shield continues to unfold its effects, now with the European data protection authorities’ position against the use of Google Analytics.[1]
What is Google Analytics ?
Google Analytics is a widely used online tool developed by Google based on the analysis and tracking of web pages. It allows the owner of the website to monitor the user’s use of and interaction with the website. Ultimately, it allows the website owner to understand the activity of users on his website, and to design more personalized commercial strategies according to the needs detected.
For its measurements, Google assigns an identifier to each Internet user, to refine its statistics and provide advanced services to its customers. However, this identifier is not just another data: it is a personal data, which processing is therefore subject to the GDPR.
What happened ?
One after the others, the European Data Protection Supervisor (“EDPS”)[2], the Austrian[3] and the French data protection authorities (DPAs)[4], have ruled against the use of Google Analytics by the EU Parliament or European businesses. It is worth noting that the French and Austrian decisions are formal notices and that no sanction has been issued – yet. The Dutch DPA has also published a warning against the American tool.
These decisions and positions were taken following the filing of 101 claims by Max Schrems’ NOYB association against data controllers which allegedly transfer personal data to the United States.
What’s wrong with Google Analytics?
Google Analytics is developed by Google, a United-States (US) company subject to the Cloud Act, a U.S. federal law that allows the U.S. government to access data on the servers of companies in its country, regardless of their location.
According to Google, once the user’s data have been collected, they are pseudonymised and analyzed. However, the EU DPAs found that this identifier is combined with data collected via other Google’s tools, such as the user’s Google account, so that the fact of anonymising the user’s IP is irrelevant as it can be associated with an account, which means that the user is still identifiable and the Google Analytics identifier remains a personal data.
As such identifier is systematically transferred to Google’s servers in the US, this is an international personal data transfer which shall, according to the GDPR and Schrem II, be subject to appropriate safeguard, i.e. the new Standard Contractual clauses and sufficient additional security measures[5].
In the cases at hands, the data controllers had signed contractual clauses for the transfer of their personal data to the US with Google, and additional legal, organisational and technical measures to control the transfer of data were implemented by Google. The data controllers stated that they had no evidence to suggest that these clauses had been breached.
However, according to the EU DPAs, the additional measures adopted, as presented by Google, are not effective insofar as none of them solves the specific problems of the case. Indeed, none of them prevents the US intelligence services from accessing the data at issue or renders such access ineffective. Hence the use of Google Analytics violates the GDPR.
What does it mean for businesses transferring personal data to the US ?
Pursuant to Austrian and French DPAs decisions, all websites that use the Google Analytics tool are in violation of the GDPR. But it means the same for any business transferring personal data to the US without ensuring that the data recipient implement additional measures sufficient to prevent the US intelligence services from accessing the said data.
What are these measures? The DPAs do not say so.
But what is suggested is that only the technical inability to access personal data in plain text may be judged adequate – which is incompatible with providing most of the Cloud services. It could therefore be argued that as long as there is legislation in the US allowing access to personal data, any international transfer will be carried out in non-compliance with the GDPR.
In the end, few options remain. US electronic communications service providers such as Google will have to set up their servers in the EU or it will be increasingly necessary to prioritize the use of European providers over foreign ones.
In the meantime, the European Union and the US have reached an agreement in a 3.0 Privacy Shield (that could bring the businesses out of this moment of regulatory uncertainty – provided it passes the test of the European Court, as Max Schrems has already indicated that he will not hesitate to challenge the new text) and Google announced that the new version of Google Analytics, GA4 has been built with a greater degree of privacy.
[1] The ECJ ruling invalided the US Privacy Shield system, considering that it did not comply with the guarantees required by the GDPR when carrying out personal data transfers to the US. The main reasons was the US surveillance programs allowing the authorities to access EU personal data transferred to the US, along with the lack of effective mechanisms to enforce the data subjects rights. The EU Commission had also updated its Standard Contractual Clauses for international transfers, ruling however that in the case of the US, these clauses alone cannot provide a sufficient level of protection insofar as the safeguards they provide are left unapplied in the event of access by the said intelligence services. They must therefore be complemented by additional measures.
[2] EDPS, Case 2020-1013 against the European Parliament
[3] Datenschutzbehörde, 2021-0.586.257 (in German)
[4] CNIL, Mise en demeure (in French)
[5] Recommendations 01/2020 on measures that supplement transfer tools to ensure compliance with the EU level of protection of personal data




