France’s data protection watchdog, the CNIL, has ruled that data transfers from the EU to the US for Google Analytics are illegal.
The CNIL has ordered that the controller must now comply with GDPR. If they don’t, data transfers will have to stop or be in breach of data protection legislation.
The move will have major ramifications across numerous organisations. Since 2019, Google Analytics has been the most popular tool used by websites to analyse traffic to their websites, with around 56.7% of websites using it, more than its closest rival, Facebook Pixel at 11.3%.
Since Google’s service tracks website traffic, every visitor is given a unique identifier. However, this identifier is considered to be personal data, meaning it falls under GDPR.
GDPR requires data transfers to other jurisdictions to maintain the same level of protections as they would in Europe. This prevents companies from bypassing the regulations by simply moving data to areas with less stringent legislation.
The differences between regulations in the EU and US, which has weaker data protection laws, has resulted in tensions between the two blocs. With the majority of big tech companies, like Google, based in the US, they generally prefer to repatriate data on their European customers rather than base data storage infrastructure in GDPR-compliant territory.
In particular, EU authorities have raised concerns about a lack of regulations stopping American intelligence services accessing EU citizens’ personal data.
As such, the CNIL found that, despite Google adopting additional measures to regulate data transfers for its Google Analytics service, these are not sufficient to exclude US intelligence services accessing the data.
This means that data transfers from the EU to the US by Google Analytics violate GDPR.
In addition, the CNIL recommended that tools should only be used to produce anonymous statistical data. This would exempt them from consent if the data controller ensured that there are no illegal transfers.
Recommended
- Comment | Monitoring and surveillance in the workplace and beyond
- Should businesses take a defence-in-depth approach against ransomware?
- Glasgow Uni team beats others to nanosat design competition shortlist
The move comes two weeks after a separate decision by the Austrian Data Protection Authority that also found that the continuous use of Google Analytics violates GDPR. The CNIL said that it had made its decision in cooperation with its European counterparts.
The ruling was prompted by a series of 101 complaints filed by privacy rights group noyb with various data controllers in the EU.
The complaints were made in the wake of the invalidation of Privacy Shield in the Schrems II ruling. Made by the Court of Justice of the European Union in July 2020 it found that Privacy Shield, the rules used to facilitate international data transfers between the EU and US, violated GDPR.
Max Schrems, honorary chair of noyb and the claimant in the case that invalidated Privacy Shield, said: “It’s interesting to see that the different European Data Protection Authorities all come to the same conclusion: the use of Google Analytics is illegal. There is a European task force and we assume that this action is coordinated and other authorities will decide similarly.”
Schrems added: “In the long run we either need proper protections in the US, or we will end up with separate products for the US and the EU. I would personally prefer better protections in the US, but this is up to the US legislator – not to anyone in Europe.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





