Hunor.digital
← All writing
Compliance · GA4 · Analytics honesty

Is Google Analytics illegal in the EU? What the rulings mean

It was ruled unlawful in 2022, then the ground shifted in 2023. Where GA4's EU legality actually stands, what changed, and what risk you still carry.

Lázár HunorDigital Fixer
The short answer

Google Analytics is not illegal in the EU today. The 2022 rulings against it concerned EU-US data transfers before the current adequacy decision; since the 2023 Data Privacy Framework, transfers to certified providers, including Google, have a legal basis. The real risks are your configuration, your consent setup, and the framework's own uncertain future.

Somewhere in 2022, "Google Analytics is illegal in Europe" became a LinkedIn genre. Like most genres, it flattened a complicated story into a slogan, and the slogan outlived the facts. Here is the actual timeline, what is true today, and the honest version of what risk you still carry. One disclaimer up front, because this topic deserves it: I map the technical and factual terrain; conclusions about your legal exposure belong to your lawyer.

How we got here, in four beats

  1. 2020, Schrems II. The EU's top court struck down Privacy Shield, the legal bridge for EU-to-US data transfers, on the grounds that US surveillance law made US-held EU data inadequately protected. Every US cloud service inherited a transfer problem overnight.
  2. 2022, the analytics rulings. Data protection authorities in Austria and France (with Italy and others following) examined complaints (driven by noyb, Max Schrems' organization) and concluded that specific websites' use of Google Analytics unlawfully transferred personal data to the US. This is the era the slogan comes from. Note the shape: rulings against particular websites' configurations of the then-current Universal Analytics, under the post-Schrems-II legal vacuum, not a ban on a product.
  3. 2023, the Data Privacy Framework. The EU adopted a new adequacy decision for the US. Companies certified under the DPF, Google included, regained a lawful transfer basis. The specific legal defect the 2022 rulings identified was, for the moment, repaired.
  4. Since then: an uneasy stability. The DPF faces legal challenge (a Schrems III is widely expected by privacy watchers; whether and when it succeeds is speculation), and using US-based analytics remains lawful while the adequacy decision stands.

So: not illegal, and not settled

Both halves matter. Running GA4 in the EU today, with a compliant setup, is lawful; anyone still saying otherwise is quoting 2022 in 2026. And the lawfulness rests on an adequacy decision with a documented history of being struck down; anyone treating the question as permanently closed is selling comfort. That is the honest, slightly unsatisfying state of things.

What deserves more attention than the transfer saga is this: most real-world GA4 compliance failures I see have nothing to do with Schrems anything. They are ordinary configuration and consent failures, fully within the site owner's control, and they would be violations under any transfer regime:

A site can be on the most sovereign EU-hosted analytics stack and still fail on every bullet above; a GA4 site can pass all four. The tool is one chapter of the compliance story, and rarely the one that bites first.

What to actually do

If you run GA4 in the EU: get the consent implementation verified against real network traffic (not against the banner vendor's dashboard), confirm no personal data rides along in URLs or parameters, align the privacy policy with observed reality, and have your DPO note the DPF dependency in the risk register. That last item is the grown-up version of the panic: a monitored dependency, not an emergency.

If the DPF dependency genuinely troubles your risk posture, or your customers ask sovereignty questions in procurement, that is the legitimate trigger for evaluating EU-owned alternatives, with Matomo the usual first stop. Migrating for that reason is a defensible strategic choice. Migrating because a slogan said the current setup is illegal is spending real money to fix a headline.

And whichever path: the verification is the part that protects you this quarter. Legal frameworks move slowly; your tag container changed last sprint. An afternoon of consent-state testing tells you whether your actual site matches your claimed compliance, and it is the least glamorous, highest-value privacy work available to any EU business right now. It is also, not coincidentally, the first thing I check in every compliance audit.