ConsentPixel – Privacy · Verified

HomeBlogGDPR & EU Compliance › Google Analytics GDPR Compliance
GDPR & EU Compliance

Google Analytics GDPR Compliance: Is GA4 Legal in the EU in 2026?

Five European regulators ruled Google Analytics unlawful. The Data Privacy Framework resolved the problem they were ruling on — and left the bigger one completely untouched. Here is where GA4 actually stands under EU law today.

By The ConsentPixel Team Updated July 2026 16 min read Tracking Pixel cluster
5+ DPAs
Austria, France, Italy, Denmark and Norway all ruled GA use unlawful
€1M
Fine issued to Tele2 by Sweden's IMY for using Google Analytics (July 2023)
Art. 5(3)
The ePrivacy provision the Data Privacy Framework does nothing about

Why GA4's GDPR risk inverts its CIPA risk

If you have read our companion piece on Google Analytics and CIPA, you will remember its central argument: CIPA is fundamentally an advertising-pixel problem, not an analytics problem. Meta's business model depends on repurposing what its Pixel collects, which is what makes the third-party interception theory land. Google Analytics, in a default configuration with data sharing disabled, is a materially weaker CIPA target.

Under EU law, that analysis turns completely upside down.

Google Analytics is not a peripheral concern under the GDPR. It is the single most-litigated tracking tool in Europe — the only one with an entire body of national regulator decisions declaring its use unlawful, by name, repeatedly, across five countries. No other analytics product carries that history. And the reason it inverts is structural, not incidental:

  • CIPA cares who receives the data and what they do with it. That is why "Google is a service provider processing on our behalf" is a real argument, and why disabling data sharing settings genuinely reduces exposure.
  • ePrivacy Article 5(3) cares about none of that. It governs the act of storing or reading information on the visitor's device. Google's purposes are irrelevant. Whether the data is personal is irrelevant. The cookie is the violation.
The inversion in one line

Under CIPA, the argument that saves you is "Google is only processing this for us." Under ePrivacy, that argument does not exist — because the law regulates the cookie, not the recipient. Every mitigation that lowers your CIPA exposure leaves your GDPR exposure exactly where it was.

So if you read the CIPA piece, concluded GA4 was the least of your problems, and moved on — this article is the correction. For your EU traffic, GA4 is the main event.

The transfer problem: how Google Analytics got ruled illegal

The story starts on 16 July 2020, when the Court of Justice of the European Union decided Schrems II (C-311/18) and invalidated the EU-US Privacy Shield. Standard Contractual Clauses survived, but the Court held they were not sufficient on their own for transfers to US companies subject to American surveillance law — you needed supplementary measures that actually worked.

Max Schrems's NGO noyb then filed 101 model complaints across Europe, each targeting a website that sent EU visitors' data to Google or Facebook. The decisions arrived in sequence, and they all said the same thing.

AuthorityWhenWhat it held
Austria (DSB)Dec 2021 / Jan 2022NetDoktor's use of GA breached Chapter V. IP anonymisation had not been correctly implemented, and would not have saved it anyway.
France (CNIL)Feb 2022Formal orders to French site operators; one month to comply. Art. 44 breach through transfers without adequate protection.
Italy (Garante)Jun 2022Transfers to the US via GA violated the GDPR; a lawful basis and real safeguards were required.
Austria (DSB), againApr 2022Explicitly rejected the risk-based approach — you cannot argue that surveillance is unlikely in your case.
Sweden (IMY)Jul 2023Fined Tele2 approximately €1 million for its use of Google Analytics — the largest GA-specific penalty in Europe.
Denmark, Finland, Norway2022–Jan 2025Same conclusion, extending the line as recently as the Norwegian decision in January 2025.

Two findings from the Austrian decisions matter far more than the headlines, because they survived everything that came afterwards:

The finding that still binds

The Austrian DSB held that the _ga cookie and the Client ID are personal data under Art. 4(1) GDPR. The threshold of identifiability is reached as soon as individualisation occurs — the moment a visitor can be singled out from others — even if nobody can attach a name to them. Every "but it's anonymous, it's just an ID" argument dies on this finding, and the Data Privacy Framework did nothing to disturb it.

The second: the DSB rejected the risk-based approach outright. Arguing that your particular visitors are unlikely to interest US intelligence is not a defence. Either the safeguards are adequate in law or they are not.

The Data Privacy Framework: what it actually fixed

On 10 July 2023 the European Commission adopted its adequacy decision for the EU-US Data Privacy Framework (DPF). Google LLC self-certified. Executive Order 14086 had introduced binding limits on US bulk collection and created the Data Protection Review Court as a redress mechanism for EU individuals.

The effect on the analysis above is real and should not be understated: transferring personal data from the EEA to Google under the DPF is no longer unlawful in itself. The specific defect the Austrian, French and Italian decisions identified — no valid transfer mechanism — has an answer now.

The DPF then faced its first judicial test. French MP Philippe Latombe sought annulment, and on 3 September 2025 the court dismissed his action in Latombe v Commission (T-553/23), finding the Data Protection Review Court sufficiently independent and impartial and US bulk-collection limits adequate.

A detail almost every article gets wrong

The September 2025 ruling came from the General Court, not the Court of Justice. The two together form the CJEU, but the General Court is the junior of the pair and its decisions can be appealed. Latombe appealed on 31 October 2025, and the case is now pending before the Court of Justice as C-703/25 P. If you read that "the CJEU upheld the DPF," the source has collapsed two different courts — and skipped the appeal that is still live.

So the honest 2026 position on transfers: the DPF is valid law and the easiest lawful basis for EU-to-US transfers. But three things sit underneath it that a competent DPO tracks:

  • C-703/25 P is pending at the Court of Justice. If it succeeds on the merits, that would be the third consecutive transatlantic framework invalidated — after Safe Harbour and Privacy Shield.
  • The PCLOB is in legal limbo. The oversight body that reviews the DPF's intelligence safeguards is not functioning normally, and the General Court's reasoning leaned on the Commission's duty to monitor the framework continuously.
  • FISA Section 702 is on a short-term extension while Congress debates renewal — and 702 is the surveillance authority the whole adequacy analysis turns on.

The practical read: keep Standard Contractual Clauses in place as a fallback even while relying on the DPF. Organisations that rely on the DPF alone have a single point of failure with a live appeal attached to it.

Here is where most "is Google Analytics legal now?" articles stop, declare victory, and mislead you. The DPF answers a transfer question. It has nothing whatsoever to say about a consent question — and the consent question was always the bigger one.

Article 5(3) of the ePrivacy Directive requires prior consent before storing information on, or accessing information already stored on, a visitor's device. Note what that provision does not depend on:

Does it matter whether the data is personal?
No — Art. 5(3) governs the device, not the data
Does it matter that Google only processes it for you?
No — the recipient's purpose is irrelevant
Does a GDPR lawful basis rescue you?
No — different law, separate requirement
Does the DPF help?
No — the DPF is about transfers, not storage
What actually satisfies Art. 5(3)?
Prior consent, or a narrow strictly-necessary exemption

This is why the "we use Google Analytics under legitimate interests" argument — which can be perfectly sound for the processing under Art. 6 GDPR — does not get the cookie onto the device. You need consent for the cookie regardless of your lawful basis for the data. Two different laws, two different questions, and only one of them has a legitimate-interest route.

Why this is the durable problem

The transfer problem had a political solution, and politics delivered one in July 2023. The consent problem has no equivalent fix available. It would require amending the ePrivacy Directive — and the ePrivacy Regulation that was supposed to replace it has been stalled for years. Article 5(3) is not going anywhere, which makes prior blocking the one part of GA4 compliance you can safely invest in.

Consent Mode v2: Google's requirement, not the law's

Since March 2024, Google has required Consent Mode v2 for advertisers using its services in the EEA and UK. Without correctly wired signals, remarketing audiences stop populating and personalised measurement degrades. This is a commercial requirement imposed by Google — it is not a GDPR obligation, and satisfying Google does not automatically satisfy a regulator.

Consent Mode v2 carries four signals: ad_storage, analytics_storage, ad_user_data and ad_personalization. The two you need to understand are the modes.

Basic Consent ModeAdvanced Consent Mode
Before consentGoogle tags do not load at allTags load and run in restricted mode
If the visitor declinesNothing is sent — no cookies, no pings, no signalsCookieless pings are sent to Google
Conversion modellingNot available for declined usersFeeds Google's modelling
Art. 5(3) positionStraightforwardly defensibleContested
The Advanced Mode question nobody wants to answer

In Advanced Consent Mode, tags load and cookieless pings transmit to Google before the visitor has consented. Google's position is that these pings carry no cookies, no Client ID and nothing identifying — so no consent is needed. But Art. 5(3) is not limited to cookies: it covers accessing information stored on the device, and a ping that reports browser, country and timestamp has read something from that device to say so. Some supervisory authorities take the view that any transmission from a user's device requires prior consent. DACH practitioners routinely recommend Basic mode where legal certainty matters more than modelling. There is no settled answer, and any vendor telling you Advanced mode is definitively compliant is telling you their opinion.

One practical note that decides this for many sites regardless of the legal argument: modelling has traffic thresholds. Google requires roughly 1,000 consenting and 1,000 non-consenting users per day for GA4 modelling, and about 700 ad clicks per day per country and domain for Ads. Most SMB stores never reach those numbers — which means they are accepting Advanced mode's legal ambiguity in exchange for modelling that will never actually switch on.

Where national law is stricter than you expect

The GDPR is a regulation, but ePrivacy is a directive — each member state transposed it into national law, and the differences are exactly where GA4 deployments fail.

Germany: no legitimate interest, at all

§ 25 TDDDG (the law formerly called the TTDSG, renamed in May 2024) governs device access and offers precisely two routes: valid consent, or one of two narrow statutory exemptions. There is no balancing of interests available — unlike Art. 6(1)(f) GDPR. Pure reach measurement is not exempt; the statistics exemption floated in the ePrivacy draft never became law. Any GA4 strategy resting on legitimate interest fails in Germany at the first hurdle. See our Germany cookie compliance guide for the full picture, including the private Abmahnung risk that has no equivalent elsewhere in Europe.

Netherlands: an analytics exemption that GA4 doesn't qualify for

The Dutch position is more generous than France's: analytical cookies receive a partial exemption where privacy impact is minimal and results are used only for the site itself. Agencies hear "the Netherlands exempts analytics" and stop reading. The exemption does not cover a standard GA4 configuration, precisely because GA4 shares data with Google for Google's own purposes — which is the opposite of "used only for the site itself." Details in our Netherlands cookie compliance guide.

France: the strictest reading

The CNIL moved first and hardest on GA, and its exemption for audience measurement is narrow — the tool must be strictly limited to first-party statistics with no cross-site tracking and no data sharing. Standard GA4 does not qualify.

What this means operationally

There is no single "EU-compliant GA4 configuration." The floor is set by whichever member state you serve with the strictest rules — which in practice means Germany. If you configure for § 25 TDDDG, you are compliant nearly everywhere. If you configure for the most permissive reading you can find, you are compliant in roughly one country.

The GDPR-compliant GA4 configuration

Five steps. The first one is the whole game; the rest are hygiene that reduces the blast radius if something goes wrong.

Step 1 — Block GA4 until consent, technically

Not a banner. Blocking. The GA4 script must not execute, and no request may reach a Google endpoint, until the visitor has actively consented. This is the Art. 5(3) requirement and it is non-negotiable across every member state. Verify it the way a regulator does — private window, DevTools → Network, filter for google-analytics.com and googletagmanager.com, reload, and watch what fires before you touch the banner.

// Consent Mode v2 defaults — must run BEFORE the GA4 tag loads
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}

// All four signals denied by default. Nothing negotiable here.
gtag('consent', 'default', {
  'ad_storage': 'denied',
  'analytics_storage': 'denied',
  'ad_user_data': 'denied',
  'ad_personalization': 'denied',
  'wait_for_update': 500
});

If analytics_storage defaults to anything other than denied for EEA traffic, nothing downstream matters.

Step 2 — Separate analytics consent from advertising consent

A visitor must be able to accept analytics and refuse marketing. Bundling them into one "Accept all" fails the GDPR's specificity requirement, and it is one of the most consistently cited defects in EU banner enforcement. Map your banner's analytics category to analytics_storage, and your marketing category to ad_storage, ad_user_data and ad_personalization together.

Step 3 — Decide Basic vs Advanced, and write the decision down

This is a documented risk decision, not a default. Basic mode is the defensible choice under Art. 5(3). Advanced mode buys modelling in exchange for legal ambiguity — and only if you clear Google's traffic thresholds. Whichever you choose, record the reasoning: accountability under Art. 5(2) means being able to explain why, not just what.

Step 4 — Disclose what actually happens

Your cookie policy must name Google Analytics, state the purpose, identify Google LLC as the recipient, give the retention period, and — if you run Advanced mode — disclose that non-identifying data may be sent to Google even when the visitor declines. A policy that lists "Google Analytics" with no explanation of its consent-mode behaviour is incomplete under Art. 13.

Step 5 — Keep the transfer paperwork current

Confirm Google LLC's DPF certification is active, keep SCCs in place as a fallback given the pending appeal, and make sure your Transfer Impact Assessment reflects the 2026 position rather than a 2022 template that still says "Privacy Shield invalidated."

See what fires before consent

Our scanner opens any site with a clean session and records every Google endpoint that transmits before the visitor chooses — the same check a supervisory authority runs.

Scan a site free →

Server-side GA4 and the consent bypass myth

Server-side tagging genuinely helps: it improves data quality against ad blockers and Safari's ITP, and it gives you control over what reaches Google. Vendors sometimes market it as a way to sidestep consent entirely. It is not.

The reasoning is simple. If the visitor's browser sends anything to your server-side container, something was read from their device — Art. 5(3) is engaged. If it sends nothing, you have no data to forward. Moving the collection point does not remove the collection. Denied-consent data must not be forwarded to Google without a legal basis, and a server-side setup that forwards it anyway has simply relocated the violation to a place that is harder to audit.

The honest version

Server-side GA4 is a data-quality tool with a consent-enforcement opportunity attached — you can enforce consent on infrastructure you actually control, which is genuinely better than trusting a client-side tag. It is not, and has never been, a consent bypass. If a vendor sells it to you as one, they are describing a configuration that would be unlawful in every EU member state.

What about cookieless alternatives?

Tools like Plausible and Matomo (self-hosted) are designed to operate without device storage and without transferring personal data outside the EU. Under most national interpretations they run without a consent banner — which is why a growing number of EU-focused sites have simply left GA4 behind rather than maintain the configuration above. It is a legitimate answer to the question, and worth putting on the table with clients who have modest analytics needs and low appetite for legal ambiguity.

Per-client GA4 GDPR checklist

Run this on every client site serving EU or UK traffic.

GA4 GDPR Compliance Checklist

GA4 technically blocked until consent — verified in DevTools with a clean session, not assumed from the banner's presence
Consent Mode v2 defaults set to denied for all four signals, firing before the GA4 tag loads
Analytics consent separable from advertising consent — visitor can accept one and refuse the other
Reject as prominent and as easy as Accept, on the same layer
Basic vs Advanced mode decision documented, with the reasoning recorded
If Advanced: cookieless pings disclosed in the cookie policy
If Advanced: traffic thresholds checked — 1,000 consenting + 1,000 non-consenting daily for GA4 modelling
Cookie policy names Google Analytics, purpose, Google LLC as recipient, and retention period
Google LLC's DPF certification verified as active
SCCs retained as a fallback given the pending C-703/25 P appeal
Transfer Impact Assessment updated to the 2026 position, not a 2022 template
Data retention set to the shortest period that meets the client's actual reporting needs
Google Signals reviewed — it adds cross-device tracking and materially raises the stakes
German traffic: configuration satisfies § 25 TDDDG with no legitimate-interest reliance
Dutch traffic: not relying on the analytics exemption, which standard GA4 fails
Consent decisions logged with timestamp and banner version, producible on request

The bottom line

Google Analytics is not illegal in Europe in 2026. The transfer defect that produced the 2022 rulings has a real answer in the Data Privacy Framework, and the General Court upheld it — though an appeal is live at the Court of Justice and the framework's foundations are less stable than the headline suggests.

But the transfer problem was never the durable one. ePrivacy Article 5(3) requires prior consent before GA4 touches a visitor's device, and no political agreement is going to change that. It does not care that Google processes the data on your behalf. It does not care that you have a lawful basis under Art. 6. It does not care about the DPF at all.

Which brings the answer back to where it always was, and where our CIPA article landed too, by a completely different route: nothing fires before the click. Get that right and the rest is paperwork. Get it wrong and no amount of correct paperwork will save you.

Find out what your client sites are actually doing

ConsentPixel — Privacy · Verified blocks Google Analytics and 2,000+ other trackers until the visitor consents, wires Consent Mode v2 correctly, and logs every decision with a timestamp. One script tag, every client site, every EU market.

Start 14-day free trial → Scan a site free
CP
The ConsentPixel Team

We build consent infrastructure for agencies and site owners who need CIPA, GDPR and ePrivacy handled from one install. This article is educational and is not legal advice — EU case law in this area is actively developing, and the DPF appeal is pending. Verify your position with a qualified privacy professional.

Frequently asked questions

Is Google Analytics illegal in the EU in 2026?

No — but that answer has an important qualifier. Between 2021 and 2025, data protection authorities in Austria, France, Italy, Denmark, Norway and others ruled that using Google Analytics breached the GDPR, because after Schrems II there was no valid mechanism for transferring EU visitors' data to Google in the US. Sweden's IMY fined Tele2 approximately €1 million over it. The EU-US Data Privacy Framework, adopted in July 2023 and upheld by the General Court in September 2025, resolved that specific transfer defect. So GA4 is not unlawful per se today. But the DPF only ever addressed transfers — it did nothing about the separate requirement under ePrivacy Article 5(3) to obtain consent before GA4's cookie touches a visitor's device. That requirement is unchanged and unaffected.

Does the Data Privacy Framework mean I no longer need consent for Google Analytics?

No, and this is the most consequential misunderstanding in the field. The DPF is a transfer mechanism — it answers whether you may lawfully send personal data to a certified US company. It says nothing about whether you may place a cookie. Those are two different legal questions under two different instruments. Article 5(3) of the ePrivacy Directive requires prior consent before storing or accessing information on a visitor's device, regardless of whether the data is personal, regardless of what the recipient does with it, and regardless of any transfer framework. You needed consent for GA4 before the DPF and you need it now.

Can I use legitimate interest as the basis for Google Analytics?

For the processing under Art. 6 GDPR, potentially — legitimate interest is one of six lawful bases and a properly documented balancing test can support analytics. But it does not get the cookie onto the device. ePrivacy Article 5(3) requires consent for device access and offers no legitimate-interest route. Germany makes this explicit: § 25 TDDDG provides only consent or two narrow statutory exemptions, with no balancing of interests available, and pure reach measurement is not exempt. So even with a solid Art. 6 basis, you still need Art. 5(3) consent before GA4 loads.

Is Google Consent Mode v2 required by the GDPR?

No. Consent Mode v2 is Google's own requirement, mandatory since March 2024 for advertisers using Google services in the EEA and UK — without it, remarketing audiences stop populating and personalised measurement degrades. It is a commercial condition Google imposes, not a legal obligation under the GDPR. Implementing it correctly helps you honour consent signals, but satisfying Google's requirement does not automatically satisfy a supervisory authority. Conversely, you can be fully GDPR-compliant with no Consent Mode at all if you simply block Google's tags until consent.

Is Advanced Consent Mode GDPR compliant?

It is contested, and anyone giving you a definitive yes is offering an opinion rather than settled law. In Advanced mode, Google's tags load and send cookieless pings before the visitor consents. Google's position is that these pings contain no cookies, no Client ID and nothing identifying, so no consent is required. The counter-argument is that Article 5(3) covers accessing information stored on a device — not just cookies — and a ping reporting browser, country and timestamp read something from that device to produce it. Some supervisory authorities take the view that any transmission from a user's device needs prior consent. Practitioners in stricter jurisdictions routinely recommend Basic mode where legal certainty matters more than modelling. Note also that Advanced mode's modelling requires roughly 1,000 consenting and 1,000 non-consenting users daily for GA4 — thresholds most smaller sites never reach, meaning they take on the ambiguity for a benefit that never activates.

Are the _ga cookie and Client ID personal data?

Yes, according to the Austrian DSB, and that finding has not been disturbed. The authority held that the _ga cookie and Client ID qualify as personal data under Art. 4(1) GDPR because the threshold of identifiability is reached as soon as individualisation occurs — the moment a visitor can be singled out from other visitors — even where nobody can attach a name to them. The DSB also expressly rejected the risk-based approach, meaning you cannot argue that your particular visitors are unlikely to be of interest to US intelligence. The Data Privacy Framework changed the transfer analysis; it did not change what counts as personal data.

Does the Dutch analytics exemption cover Google Analytics?

No — and this trips up a lot of agencies. The Netherlands does grant analytical cookies a partial exemption where the privacy impact is minimal and the results are used only for the site itself, which is more generous than France's position. But standard GA4 does not qualify, precisely because it shares data with Google for Google's own purposes, which is the opposite of "used only for the site itself." If you serve Dutch traffic, treat GA4 as requiring consent. Our Netherlands cookie compliance guide covers the AP's current enforcement posture in detail.

Does server-side GA4 remove the need for consent?

No. If the visitor's browser sends anything to your server-side container, something was read from their device and Article 5(3) is engaged. If it sends nothing, there is no data to forward. Relocating the collection point does not eliminate the collection. Server-side tagging is genuinely valuable — better data quality against ad blockers and Safari's ITP, and the ability to enforce consent on infrastructure you control — but denied-consent data must not be forwarded to Google without a legal basis. A server-side setup that forwards it anyway has moved the violation somewhere harder to audit, not removed it.

How does GA4's GDPR risk compare to its CIPA risk?

They invert. Under CIPA, Google Analytics is a comparatively weak target: the theory depends on the recipient independently using the intercepted data, so "Google is processing this on our behalf" is a real argument and disabling data sharing settings genuinely reduces exposure. Under ePrivacy Article 5(3), none of that matters — the law regulates storing and reading information on the device, so the recipient's purpose is irrelevant and there is no equivalent defence. Google Analytics is the most-litigated tracking tool in Europe and the only one with an entire line of national regulator decisions naming it. If you concluded from a CIPA analysis that GA4 was low-risk, that conclusion does not travel to your EU traffic.

Scroll to Top