Blog
Privacy & GDPR12 min readVisitTrack Team

Is Google Analytics Legal in the EU? The 2026 Answer

Yes, with conditions. The 2022 rulings targeted US data transfers, now covered by the EU-US Data Privacy Framework. What changed, what's pending, what you owe.

As of October 2026, Google Analytics is not illegal in the EU. The wave of 2022 decisions that found it unlawful targeted one specific problem: personal data flowing to Google LLC in the United States without adequate protection. Since 10 July 2023 that transfer has a legal basis again, the EU-US Data Privacy Framework (DPF), and Google LLC is certified under it. You can use GA4 lawfully in the EU, but only if you also get consent for its cookies, configure it carefully and document what you do. And the legal ground under the DPF is less solid than it was a year ago.

This article walks through how we got here, which court cases are still open, and what an EU-facing site owner has to do in practice. It covers data transfers and consent. For the rest of GDPR (lawful basis, privacy policy, processor agreements) see our practical GDPR guide for site owners.

Key takeaways

  • Google Analytics is lawful to use in the EU in 2026: the European Commission's adequacy decision for the EU-US Data Privacy Framework (10 July 2023) covers transfers to Google LLC.
  • The 2022 rulings by the Austrian, French, Italian and other regulators were about transfers under Privacy Shield's replacement gap, not about analytics as such.
  • The EU General Court upheld the Data Privacy Framework on 3 September 2025 (Latombe v Commission, T-553/23), and an appeal (C-703/25 P) is pending at the Court of Justice.
  • A valid transfer basis does not remove the consent requirement: GA4 sets cookies, so EU and UK visitors must opt in before it loads.
  • If the DPF falls the way Privacy Shield did, the transfer problem comes back overnight. Have a fallback ready.

Why was Google Analytics called illegal in the first place?

The story starts with Schrems II. On 16 July 2020 the Court of Justice of the EU (case C-311/18) struck down Privacy Shield, the framework that had legalized most EU-to-US personal data transfers. The court's reasoning was that US surveillance law (Section 702 of FISA and Executive Order 12333) let US intelligence agencies access EU people's data without the limits and the court access EU law requires. Standard Contractual Clauses survived, but only when the exporter could show that supplementary measures closed the gap.

The privacy group noyb then filed 101 complaints against European websites that used Google Analytics or Facebook Connect. The regulators who handled those complaints reached the same conclusion one after another: GA sent pseudonymous identifiers (cookie IDs, IP addresses, device data) to Google LLC, those identifiers were personal data, and Google's supplementary measures did not stop US authorities from reaching them.

DateRegulatorDecision
22 Dec 2021 (published Jan 2022)Austrian DSBA health website's use of GA violated GDPR Article 44 because transfers to Google LLC were not adequately protected.
10 Feb 2022French CNILFormal notice to a site operator to stop using GA in its then-current form or bring transfers into compliance.
23 Jun 2022Italian GaranteOrdered a publisher to stop transferring GA data to the US within 90 days; warned all Italian sites.
Sep 2022Danish DatatilsynetGuidance that GA could not be used lawfully without adjustments that close the transfer gap.
3 Jul 2023Swedish IMYFined Tele2 SEK 12 million and CDON SEK 300,000 over GA transfers, a week before the DPF took effect.
Key regulator decisions on Google Analytics (pre-DPF).

None of these decisions said “analytics is illegal” or even “Google Analytics is illegal everywhere, forever.” They said that a specific set of transfers, made at a specific time, without a valid transfer mechanism, broke Chapter V of GDPR. That distinction is what makes the 2026 answer different.

What did the EU-US Data Privacy Framework change?

On 10 July 2023 the European Commission adopted an adequacy decision for the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795). It rests on US Executive Order 14086, signed in October 2022, which limits US signals intelligence to what is “necessary and proportionate” and creates a two-step redress path ending at a new Data Protection Review Court (DPRC) inside the US Department of Justice.

An adequacy decision means that transfers to a certified US company need no extra mechanism: no Standard Contractual Clauses, no transfer impact assessment. Google LLC self-certified under the DPF, so a site sending GA data to Google today relies on adequacy, the strongest transfer basis GDPR offers. The Commission's first periodic review, published in October 2024, concluded that the US had put the required safeguards in place and that the framework was working.

The adequacy decision is binding until a court says otherwise

National regulators cannot set an adequacy decision aside on their own. Only the Court of Justice can invalidate it. As long as it stands, a DPA cannot fine you simply for transferring GA data to a DPF-certified Google.

Is the Data Privacy Framework safe from a Schrems III?

Not fully. The framework has passed one court test and faces another, and political events in the US have added uncertainty.

  • General Court, 3 September 2025. French MP Philippe Latombe asked the court to annul the adequacy decision, arguing among other things that the DPRC is not an independent tribunal and that bulk collection is not limited enough. The General Court dismissed the action in full (Latombe v Commission, T-553/23), assessing the framework as it stood when it was adopted.
  • Appeal, 31 October 2025. Latombe appealed to the Court of Justice (case C-703/25 P). As of October 2026 no judgment has been delivered and commentators do not expect one before late 2026 at the earliest.
  • Oversight bodies. In January 2025 the Democratic members of the US Privacy and Civil Liberties Oversight Board were dismissed, leaving the board without a quorum. The PCLOB is one of the oversight mechanisms the Commission relied on.
  • Independent agencies. On 29 June 2026 the US Supreme Court decided Trump v. Slaughter, holding that the president can remove FTC commissioners without cause. The FTC enforces companies' DPF commitments, and critics argue its independence was part of what made the framework adequate.

None of this has invalidated anything. The Commission has said it will keep implementing and monitoring the framework as it stands. But Privacy Shield also stood for four years before Schrems II brought it down in one judgment, with no grace period. If you depend heavily on a US analytics vendor, a fallback plan is reasonable risk management, not paranoia.

Do you still need consent to use Google Analytics?

Yes, and this is the part most “GA is legal again” headlines skip. The transfer question (GDPR Chapter V) and the consent question (the ePrivacy Directive, Article 5(3)) are separate. The DPF solved the first. It did nothing for the second.

GA4 sets first-party cookies such as _ga and _ga_<container-id> to recognize returning browsers. Under Article 5(3), storing or reading information on a user's device requires prior consent unless it is strictly necessary for a service the user asked for. Regulators across the EU treat third-party analytics as not strictly necessary. CNIL's audience-measurement exemption exists but, in CNIL's own words, most large audience measurement offerings do not fall within it whatever their configuration, because the provider uses the data for its own purposes too. In the UK, the Data (Use and Access) Act 2025 added a statistical-purposes exception to PECR from 5 February 2026, but the ICO's guidance requires the provider to act purely as your processor, which is hard to square with Google's terms. We cover the country-by-country picture in Do you need a cookie banner for analytics?.

So the practical rule for GA4 in the EU and UK is: no consent, no GA. Google's Consent Mode v2 helps you comply mechanically (tags wait for a consent signal, and in “advanced” mode send cookieless pings that Google uses for modeling), but even the cookieless pings are a point of debate among regulators. Treat Consent Mode as a way to implement consent, not a way around it.

How do you use GA4 as lawfully as possible in the EU?

If you keep Google Analytics, here is the checklist we would follow. It does not make GA risk-free, but it removes the issues regulators actually cited.

  1. 1.Load GA4 only after opt-in consent. Use a consent management platform that blocks the tag until the visitor accepts, offers “Reject all” as prominently as “Accept all”, and keeps a consent log. Check your banner against the basics with our cookie banner checker.
  2. 2.Implement Google Consent Mode v2 correctly, so Google tags read the consent state instead of firing by default.
  3. 3.Accept Google's data processing terms in the GA admin and record that you did. Google acts as your processor for GA under those terms.
  4. 4.Turn off Google Signals and ads personalization for EU traffic unless you have specific consent for advertising purposes. These features link analytics data to Google accounts and push GA toward advertising use.
  5. 5.Set the shortest data retention that works for you (GA4 offers 2 or 14 months for event-level data) and disable granular location and device data collection for EU regions if you do not need it.
  6. 6.Do not send personal data in URLs, page titles or event parameters: no email addresses in query strings, no user names in custom dimensions.
  7. 7.Name Google, the DPF and the purpose in your privacy policy, and keep a short record of processing that explains why you use GA.
  8. 8.Write down your fallback: which tool you would switch to, and how fast, if the Court of Justice invalidates the DPF.

Some teams add a server-side proxy (server-side Google Tag Manager on their own domain) to strip IP addresses and identifiers before data reaches Google. CNIL described this approach in 2022 as a possible supplementary measure. It is real engineering work, and it does not change the cookie consent requirement. Our comparison of server-side vs client-side tracking covers the trade-offs.

What does Google itself say about GA4 and the EU?

Google redesigned parts of GA4 with the 2022 rulings in mind. Google states that GA4 does not log or store IP addresses, and that for traffic from EU-based devices, IP-based geolocation happens on servers in the EU before the data is forwarded to Analytics servers. Those are meaningful changes, but they do not make GA data anonymous: GA4 still assigns a persistent client ID per browser and stores device, behavior and approximate location data against it. Under GDPR, a persistent identifier that singles out one browser is pseudonymous personal data, not anonymous data.

Which alternatives avoid the problem altogether?

The cleanest way out of both questions (transfers and consent) is a tool that stores nothing on the visitor's device and processes data in the EU, or at least does not depend on a single transfer mechanism. Options fall into three groups.

ApproachConsent banner needed (EU)?Transfer exposureTrade-off
GA4 with consent + Consent ModeYesRelies on the DPFData only from visitors who accept; modeled numbers for the rest
Self-hosted analytics (e.g. Matomo) on EU serversDepends on configuration; cookieless setups can avoid itNone if hosted in the EUYou run and update the server
Cookieless hosted analyticsDesigned to avoid it for basic measurementDepends on the vendor's hosting and subprocessorsLess cross-day visitor history

Cookieless tools work by identifying sessions with a short-lived, server-side hash instead of a stored ID. Our technical explainer on cookieless tracking shows how that works and where it stops being enough. If you are weighing a move, our Google Analytics comparison and the list of Google Analytics alternatives lay out the options side by side.

VisitTrack is one of the cookieless options: it offers a cookieless mode that writes nothing to the browser and a hybrid mode that applies it only to EU, EEA, UK and Swiss visitors. It is a hosted service, so you should still review where it processes data, as you would for any vendor.

What happens if the Court of Justice strikes down the DPF?

If the Court of Justice annuls the adequacy decision, transfers to Google LLC fall back to Standard Contractual Clauses plus a transfer impact assessment, which is exactly the situation that produced the 2022 decisions. Executive Order 14086 would probably remain in force, and some argue it would make SCC-based transfers easier to defend than before 2023. Others, including noyb, argue the opposite. Nobody can tell you today which view regulators would adopt.

What you can control is how much depends on that answer. A site that already measures EU visitors with a cookieless, EU-hosted tool, or that can switch within a week, is not exposed. A site whose whole reporting stack, ad conversions and dashboards run through GA4 is.

Not legal advice

This article summarizes public decisions and guidance as of October 2026 for general information. It is not legal advice. Your obligations depend on your audience, your configuration and your national regulator; ask a qualified privacy lawyer about your situation.

Is Google Analytics banned in the EU?

No. No EU law or court bans Google Analytics. Several regulators found specific uses unlawful in 2022 and 2023 because data transfers to the US lacked a valid basis; since 10 July 2023, transfers to DPF-certified Google LLC are covered by an adequacy decision.

Is GA4 GDPR compliant?

GA4 can be used in a GDPR-compliant way, but it is not compliant by default. You need opt-in consent for its cookies, Google's data processing terms, sensible retention and feature settings, and a privacy policy that discloses it.

Does the EU-US Data Privacy Framework mean I don't need a cookie banner for GA4?

No. The DPF covers international data transfers under GDPR. The cookie consent requirement comes from the ePrivacy Directive and applies regardless of where data is sent, so GA4's cookies still need prior consent in the EU.

Was the Data Privacy Framework upheld in court?

Yes, at first instance. The EU General Court dismissed Latombe v Commission (T-553/23) on 3 September 2025. An appeal to the Court of Justice (C-703/25 P) was lodged on 31 October 2025 and was still pending as of October 2026.

Can I use Google Analytics without cookies?

Partly. Google Consent Mode v2 in advanced mode sends cookieless pings when consent is refused, which Google uses to model conversions. Regulators have not clearly endorsed those pings as consent-free, so most EU sites still treat GA as requiring consent.

What should I do if the DPF is invalidated?

Stop relying on adequacy for GA data and either move to Standard Contractual Clauses with a documented transfer impact assessment or switch to an EU-hosted or cookieless analytics tool. Planning that switch in advance turns a crisis into a configuration change.