Google Analytics and the GDPR
What the regulation asks of a site that runs Google Analytics 4, what Google states about its own role and the data it holds, and what supervisory authorities have decided.
- checked 2026-09-18
- The table of tools →
What the GDPR asks of a site running Google Analytics 4
Two sets of rules apply at once and ask different questions. The ePrivacy rules govern storing information on a visitor’s device or reading it back, which is what a cookie does. The GDPR governs the processing of personal data, which can include an address that identifies a device. A site can satisfy one and fall short on the other.
Responsibility starts with the site. In the report of the 101 Task Force, dated 28 March 2023, the supervisory authorities set out a common position: an operator’s decision to use a specific tool for specific purposes determines the purposes and means of the processing, so operators are to be regarded as controllers for what the tool does on their site, with liability settled case by case. Google states its own role in the Google Ads Data Processing Terms, which cover Google Analytics: Google is a processor, and the customer is a controller or processor.
This page is not legal advice and does not tell you whether your configuration is lawful. What follows is what each party has put in writing, with dates.
Legal basis and consent
The order of the questions matters. The task force report states that before the lawfulness of a transfer is assessed, controllers must comply with the rest of the regulation, and gives an example: a tool collecting personal data without a legal basis under Article 6(1) makes the processing unlawful even where the transfer rules raise no issue.
Google adds a contractual requirement of its own. Its EU user consent policy, which applies to its advertising and measurement products, requires site owners to obtain legally valid consent from users in the European Economic Area, the UK and Switzerland for the use of cookies or other local storage where legally required, and for the use of personal data for personalisation of ads. It also asks you to keep records of consent and to give users clear instructions for withdrawing it, and states that failure to comply may lead Google to limit or suspend your use of the product.
Consent mode, and what it changes
Consent mode is a signalling mechanism, not a banner. Google describes it as a way to pass the consent status collected by your banner to its tags, which then adjust their behaviour, and states plainly that consent mode does not provide a banner or widget. The parameters are analytics_storage, ad_storage, ad_user_data and ad_personalization, each set to granted or denied.
Google describes the effect this way: when visitors deny consent, instead of storing cookies, tags send pings to Google, and the gaps are then filled with conversion modelling and behavioral modelling. Modelled numbers are estimates with conditions attached. Behavioral modelling requires consent mode on all pages, tags that load in every case rather than only after acceptance, at least 1,000 events a day with analytics_storage denied for at least 7 days, and at least 1,000 daily users with analytics_storage granted on 7 of the previous 28 days, and Google notes that meeting those thresholds still does not guarantee eligibility.
It also leaves a trace in the warehouse: Google states that where consent mode is implemented, cookieless pings appear in the BigQuery export along with customer-provided data such as user_id. The cookies themselves are covered in the guide on Google Analytics cookies.
Where the data goes
Google publishes specific statements about European traffic. It states that Google Analytics does not log or store individual IP addresses from EU, Switzerland or UK users; that it derives coarse location such as city, region and country from the address and then discards it, with the lookups run on servers in those regions; and that data from devices there is collected through domains and on local servers before traffic is forwarded to Analytics servers for processing. Collection in the region and processing in the region are two different statements, and the wording keeps them apart.
Two regional controls sit in the interface. Google signals data can be switched on or off per region, and so can granular location and device data, which covers city, latitude and longitude, the user agent string, device brand and model, screen resolution and minor versions of browser and platform. Google states that disabling either keeps historical data and stops collection from that point on.
For transfers to the United States, Google states that since 1 September 2023 it relies on the EU-U.S. Data Privacy Framework when clients use its advertising and analytics services, and that it may rely on standard contractual clauses where no such framework has been adopted. The framework rests on the European Commission’s adequacy decision of 10 July 2023, and on 3 September 2025 the General Court dismissed an action seeking its annulment in Case T-553/23, Latombe v Commission.
The contract with Google
The processor relationship runs on the Google Ads Data Processing Terms, which Google states supersede the earlier Google Analytics Data Processing Amendment. Where to look depends on where the business is established: Google states that customers in the EEA, the UK or Switzerland already have those terms incorporated, while customers elsewhere have to accept them in Account Settings. The path is Admin, Account settings, Account details, Data Processing Amendment, and it needs the Editor role at account level.
Acceptance is not only a click. Google asks for the legal entity, a primary contact for notices, a data protection officer where one is designated, and an EEA representative where required. Those fields are often left empty.
What supervisory authorities decided
The chain started on 17 August 2020, when the group noyb lodged 101 complaints about transfers to the United States with European supervisory authorities. The report of the task force set up to handle them records two shared positions on safeguards: anonymisation of the IP address is not suitable where it happens only after the data reaches the importer, and encryption by the importer is not suitable where that importer has legal obligations to hand over the keys. The report names the authorities that had ruled by then, in Austria, Denmark, Estonia, Spain, Finland, France, Hungary and Italy, and notes a decision by the European Data Protection Supervisor about the European Parliament.
The Italian authority published its reasoning in full. In a press release dated 23 June 2022 it stated that a website using Google Analytics without the safeguards set out in the GDPR violated data protection law by transferring user data to the United States, reprimanded the operator Caffeina Media S.r.l., ordered it to comply within ninety days, and stated that an IP address is personal data and would not become anonymous even if truncated.
Then the ground moved. On 31 July 2023 the Danish authority corrected reports that it had declared Google Analytics lawful again: it stated it had taken no position on that, that the new agreement makes transfers possible in certain circumstances, and that basic requirements still have to be met first, among them the legal basis, the processor arrangement and contract, possible joint controllership and data subject rights. Those decisions were taken before the 2023 adequacy decision existed, and each concerned a particular site; they show how authorities read the rules, not how a 2026 setup would be judged.
What to check on your own site
Six facts are worth writing down, and none needs a lawyer. Which Google tags load, and when relative to your banner. What the banner blocks in practice, tested in the browser rather than taken from the consent platform’s dashboard. Whether the data processing terms are accepted and the contact fields filled. The retention setting, and whether anyone chose it. The regional controls. And what your events carry, since parameters are filled by your own code.
If you would rather have a smaller question to answer, the table records where each tool stores data and what it writes to the browser: 33 of the 44 tools state EU storage and 23 are cookieless by default, on the pages for tools that store data in the EU and tools without cookies. Matomo publishes an on-premise edition that runs on your own servers, which moves the storage question to your infrastructure rather than removing it. Simple Analytics states that it sets no cookies and uses no similar technologies, including local storage and IP hashing. Those are vendor statements and directory values with check dates, not conclusions about your obligations.
Questions and answers
Is Google Analytics 4 allowed in the EU?
That question has no single answer, and this directory does not answer it for your site. On the record is a set of components: a legal basis, consent where information is stored on or read from a device, a processor contract, a transfer mechanism, retention settings and your own configuration. The 2022 decisions concerned specific sites under the transfer rules of that time, and the Danish authority stated in 2023 that it had taken no position on the tool as such.
Does consent mode remove the need for a banner?
No. Google states that consent mode does not provide a banner or widget; it carries the choice your banner collects to Google’s tags, which then adjust what they store and send. Whether your site has to ask at all depends on the rules where you and your visitors are and on everything else your pages load.
Who is the controller, the site or Google?
The authorities in the 101 Task Force took the position that an operator choosing a tool for its own purposes determines the purposes and means, and is therefore to be regarded as a controller for that processing, with liability assessed case by case. Google states in the Ads Data Processing Terms that it is a processor and that the customer is a controller or processor. The two statements describe one arrangement from opposite ends.
What happens when someone asks for their data to be deleted?
Google Analytics carries a data-deletion request in Admin, under Data collection and modification. Google states that it deletes text collected by event parameters, replacing the value with (data deleted) while the event is still counted in reports, and that a request can target all parameters, selected parameters, selected events or user properties. The retention setting decides how long user-level and event-level data is kept at all, at 2 or 14 months on a standard property.
Does storing data in the EU settle the matter?
It answers one question out of several. Storage location speaks to transfers; the legal basis, the information you give visitors, what is written to their devices, the vendor contract and the handling of access and erasure requests apply wherever the servers stand. The Danish authority made the same point in 2023.
Tools named on this page
Each card shows the values we check, with the date of the last check.

Google Analytics 4
Cloud web analytics, with an optional cookieless mode.

Matomo
Cloud or self-hosted web analytics, with an optional cookieless mode, open source.

Simple Analytics
Cloud web analytics, cookieless by default.
Values in this guide come from the directory and carry the date they were checked. Seehow we check every value and thefull table of tools.