Google Analytics remains the most popular website tool for snooping on users’ behaviour.
Google’s surprising admission made one thing clear: all data collected on a website using Google Analytics is sent to the US and processed there. Every time.
Why did Google admit this?
It began with a complaint that privacy organisation noyb filed against Google with the Austrian data protection authority. The authority then put more than 20 questions to Google.
Google’s answers were often evasive, dismissive and incomplete. Why Google insisted that Google Analytics data was stored exclusively in the US is fairly easy to explain, but it needs some background.
What was the legal context?
Following the Court of Justice of the EU’s ruling on the Privacy Shield, known as “Schrems II”, the US was considered an unsafe third country. The position set out here is that transferring personal data to the US requires consent.
Website traffic involves transfers of personal data because a user’s network address—their IP address—has been recognised as personal data by the courts.
The US was considered an unsafe third country because its laws allow authorities, including intelligence agencies, to access data held by US companies. If a US company stores customer data relating to people in Germany, US authorities can access it.
The legal powers enabling intelligence agencies to access data covertly include the Foreign Intelligence Surveillance Act (FISA) and Executive Order 12333. In its response to the authority, Google argued that both only permit access to data stored outside the US.
Google’s reasoning was essentially this: we store all data in the US, so FISA and Executive Order 12333 cannot be used to access it. Therefore, the data is safe with us.
That argument does not hold up, but it may be the best Google could offer. Perhaps the creativity of its legal arguments has something to do with its lawyers’ salaries. Either way, Google admitted what many had suspected but had not been able to prove.
Is the data safe in the US?
The more useful question is whether data that Google Analytics sends to the US and stores there is actually safe.
When someone in Europe visits a website using Google Analytics, the analytics data is generated in Europe. Google gathers it through a server known as a collector.
A collector receives data from the user’s device and is located as close to the user as possible. The data is then sent to the US.
This means data is collected around the world. Under FISA and Executive Order 12333, the US intelligence agency NSA can carry out what is known as upstream collection. This involves tapping a transatlantic cable carrying data into the US.
One might dryly observe that doing this without consent is, in itself, unlawful. The people affected should also be informed, which apparently does not happen. Under the GDPR, they must also have a right to object, among other rights. That may be another concept the NSA is unfamiliar with.
Why Google Analytics requires consent
On this reasoning, worldwide data collection and transfers to the US alone would require consent before Google Analytics is loaded.
The standard configuration of Google (Universal) Analytics discussed here uses cookies. Under section 15(3) of Germany’s Telemedia Act (TMG), this requires consent. The reasoning is as follows:
- Google Analytics sets and reads the cookies.
- The cookie values are sent to Google’s servers.
- The cookies are not technically necessary: Google Analytics can also run without them.
- Article 5(3) of the ePrivacy Directive requires consent. It does not matter what the cookies contain; the information does not even have to be personal data.
- Under the German Federal Court of Justice’s ruling of 28 May 2020, case I ZR 7/16 (“Planet49”), the TMG must be interpreted in line with the ePrivacy Directive.
It may also be impossible to enter into a valid data processing agreement with Google. Reasons include its worldwide network of subprocessors and the possibility that requested data deletion may take two months.
Taken together, these points support a general consent requirement for Google Analytics, even when no cookies are used.
Explaining how Google Analytics uses data
If you have read Google’s privacy notices and the Google Analytics contractual terms, you may be none the wiser. The information is so convoluted, vague and scattered across different documents that providing a transparent explanation seems almost impossible.
Yet Article 12 GDPR requires clear, understandable information about data processing with Google Analytics.
Conclusion
Obtaining valid consent for Google Analytics appears difficult. Cookie pop-ups are not just irritating; most also fail to meet legal requirements in practice.
Using Google Analytics without consent would, in turn, require dispensing with cookies. The quality of the resulting data is questionable, however, because Google Analytics is not optimised for that setup.
Tools such as Trackboxx offer a privacy-friendly way to analyse website traffic. Without cookies or substantial fingerprinting, there is no need to ask for consent. The focus is on ease of use—hardly Google Analytics’ strong suit. Even after spending hours in its dashboard, you may still struggle to understand it all.
I also believe we should give preference to German providers and stop handing Google our data for free as soon as possible.
If you have ever contacted a large corporation for support or with a simple question, you probably know what it feels like not to get a proper answer. In my experience, local providers are much more helpful and have a stronger commitment to customer service.
Try Trackboxx free for 30 days now
No payment information required! No automatic renewal! Your Trackboxx ready to go in 1 minute.



