Site navigation

Google Analytics Data Transfer Causes GDPR Fine for Swedish Firms

Elizabeth Greenberg

,

google analytics data
Data transfers of EU data to the US via Google Analytics has earned two Swedish companies fresh fines for breaching GDPR. 

The use of Google Analytics has landed two Swedish firms a fine of €1 million (£860k) each for breaches in GDPR, with two other firms receiving a warning for the same.

The Swedish data protection authority fined the companies for how they transferred personal data via Google Analytics to the US. The case found that the data on Google Analytics, which measures and analyses website traffic, is classified as ‘personal’ because it can be linked with other unique data.

Google Analytics tracks website traffic, and provides each user with a unique identifier, which is classified as personal under GDPR.

Further, the ruling found that the technical security measures that the companies took were “not sufficient” to ensure an adequate level of protection that is guaranteed with GDPR.

Companies would have to take these extra precautions as data cannot freely be transferred between the EU and the US – a court ruling called “Shrems II” ruled that the US did not meet GDPR standards and therefore, data could not be freely transferred to the country from the EU.

This ruling has landed major companies, like Meta, with massive fines for breaching GDPR.

Any data transfer – without specific technical and legal protections stipulated by contract for each type of transfer – to the US could be classified as a breach of GDPR.

Data transfers not only include transporting or sending data across the Atlantic – simply accessing and viewing the data in a different country classifies as a transfer, even if this is within the same company.

This is what landed Meta a £1.2 billion fine for the Irish Data Protection Commissioner – transferring EU data to its US servers.

For the Swedish cases, all four companies based their decisions on the transfer of personal data via Google Analytics on standard contractual clauses – which is typically not enough of a legal basis or guarantee to transfer EU data to the US.

Further, the Swedish audit found that none of the companies’ additional technical security measures were sufficient.

This is not the first time Google Analytics has put European companies in jeopardy of breaching GDPR.

In 2022, the French data protection authority warned websites using Google Analytics to come in line with data protection regulations over its transfer of data to the US. Even before this, the Austrian authority found data transfers using Google Analytics to be in breach.

Companies in Europe appear to still be struggling with these rulings, as illustrated by the new fines in Sweden.


Recommended


However, things might change – the EU is currently in talks with the US to create an adequacy agreement which would allow for a more free flow of data between the two countries.

The EU said they were happy with some progress made by the US to ensure the protection of EU data, such as an executive order saying that EU data cannot be viewed by law enforcement without appropriate cause to do so.

The UK is also looking to piggy-back on this adequacy agreement by creating their own US-UK data bridge – however, digital rights groups have said the UK’s draft Data Protection and Digital Information bill will but the UK and EU adequacy agreement in jeopardy.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data