Between 2022 and 2023, data protection authorities in Austria, France, Italy, Denmark, Finland, Norway and Sweden all reached the same conclusion about the same product: sending European visitors' data to Google Analytics was an unlawful transfer of personal data to the United States.
Then, in July 2023, the European Commission adopted the EU–US Data Privacy Framework, and the legal ground moved again. If you are trying to work out where that leaves your site in 2026, here is the honest position.
What the rulings actually said
The decisions followed from Schrems II, the 2020 Court of Justice judgment that struck down the Privacy Shield. The reasoning ran roughly like this:
- Google Analytics sends identifiers and IP-derived data to servers subject to US law.
- US surveillance law — section 702 FISA and Executive Order 12333 — permits access to that data in ways that European law regards as disproportionate.
- The supplementary technical measures Google offered, principally IP truncation, were held not to prevent identification, because the unique identifier travelled with the data regardless.
- Therefore the transfer lacked an adequate legal basis.
The Austrian DSB got there first, in January 2022. The French CNIL followed a month later, then the Italian Garante, then others. None of them fined a website operator into the ground; most issued orders to bring processing into compliance. But the direction was unambiguous, and it applied to the website operator as controller — not to Google.
What the Data Privacy Framework changed
The adequacy decision of July 2023 declared the United States to provide an adequate level of protection for data transferred to organisations that self-certify under the EU–US Data Privacy Framework. Google is certified. In the ordinary course, that means the transfers those rulings condemned now have a lawful basis again.
Two caveats matter.
Adequacy decisions are not permanent. Privacy Shield lasted four years before it was annulled. Safe Harbour lasted fifteen. The Data Privacy Framework is already the subject of a challenge before the EU courts, and it depends on a US executive order that a future administration can amend. Building a measurement stack on it is a bet on political continuity.
Transfer legality was never the only problem. The rulings addressed the transfer. They did not address the separate questions of whether the consent obtained was valid, whether the processing was proportionate, or whether the cookie was set before consent — all of which are live issues independent of where the servers are.
The question that did not go away
Underneath the transfer argument sits something simpler, and it is the reason many organisations moved anyway.
Google Analytics is provided by a company whose principal business is advertising. Even with data sharing controls turned off, the arrangement asks an organisation to send its visitors' behaviour to an advertising company and trust a configuration switch. Some sectors cannot make that argument to their regulator, their board, or their users — public bodies, healthcare, education, legal services, and anyone whose visitors are in a vulnerable position by virtue of visiting at all.
That question is not resolved by an adequacy decision. It is a question about who you want holding the record of who read what on your site.
What a compliant setup looks like, either way
If you stay on Google Analytics 4 in the EU:
- Obtain valid consent before the tag loads. Not a banner that sets cookies while it renders — the tag must not fire until the visitor has agreed.
- Enable IP anonymisation and disable data sharing with Google products and services.
- Document the transfer basis, and check periodically that the certification is still current.
- Publish a cookie policy that names the cookies, their purposes and their lifetimes.
- Accept that your measurements cover only the visitors who consented, and that this sample is biased.
If you move to a tool that stores nothing on the device:
- The consent question largely resolves itself, because the rule that requires the banner is about device storage.
- The transfer question resolves itself if the data stays in infrastructure you control, in a region you chose.
- You still need a lawful basis for the transient processing of IP addresses, and a written legitimate interests assessment covering it.
- You still need a privacy page that describes the behaviour accurately. That page is not boilerplate; it is a technical description that has to remain true.
What most organisations actually decided
Very few sites were fined. A great many moved anyway, and the reason was rarely fear of enforcement. It was that the answer to "why are we sending this to Google" became harder to give each year — and that the alternatives had become good enough that the question no longer had a cost attached.
That is the practical calculus in 2026. Google Analytics is, on the current framework, lawful in the EU when configured properly and used with valid consent. Whether it is the arrangement you want to be defending in three years is a different question, and it is the one worth answering deliberately rather than by inertia.
This is a description of the legal landscape, not legal advice. If you have a specific obligation — a regulator's letter, a sector-specific rule, a client's contractual requirement — that deserves an answer from someone who has read your situation.
Common questions
Is Google Analytics banned in Europe?
No. Several data protection authorities ruled specific implementations unlawful between 2022 and 2023 on the basis of unlawful transfers to the United States, but the EU–US Data Privacy Framework adopted in July 2023 provides an adequacy basis for transfers to certified organisations, including Google. The tool is lawful when configured correctly and used with valid consent.
What did the Schrems II ruling mean for analytics?
Schrems II annulled the Privacy Shield and held that transfers to the United States required supplementary measures capable of preventing access by US intelligence services. Regulators subsequently found that Google Analytics' measures, principally IP truncation, were insufficient because a unique identifier still accompanied the data.
Does the Data Privacy Framework make Google Analytics permanently safe to use?
It provides a lawful transfer basis today. Adequacy decisions have been annulled twice before — Safe Harbour in 2015 and Privacy Shield in 2020 — and the current framework is already under legal challenge, so it is a basis that could change rather than a settled position.