Case Study 28.2 — When Google Analytics itself was ruled unlawful: the 2022 EU decisions
A real, contested, and still-evolving public matter. This study reports the documented public record of regulatory decisions and is explicitly not legal advice. Where the situation later shifted, it says so. No figures are invented; the one count cited is attributed to its source.
Background
Chapter 28 argues that measurement is constrained not only by technology but by law, and that how you may lawfully measure depends on where your users are — and changes. Nothing illustrates that more sharply than a run of European decisions, beginning in 2022, that found ordinary use of Google Analytics to be in violation of the General Data Protection Regulation (GDPR).
The roots go back to July 2020, when the Court of Justice of the European Union, in the case known as Schrems II (brought by the privacy campaigner Max Schrems and his organization noyb), invalidated the EU-US Privacy Shield — the legal framework that had permitted personal data to flow from the EU to the United States. The court's concern was that US surveillance law did not offer EU citizens protection equivalent to GDPR. Overnight, the standard legal basis for sending European users' personal data to US-based services was thrown into doubt — and Google Analytics, which processed EU visitor data on US infrastructure, was squarely in scope.
The issue
Following Schrems II, noyb filed a coordinated wave of complaints — 101 complaints, by the organization's own account — against European websites that used Google Analytics (and a Facebook tool), arguing that the resulting transfers of personal data to the US were unlawful. Data-protection authorities took them up:
- Austria's Datenschutzbehörde (DSB) ruled, in a decision made public in January 2022, that a website's use of Google Analytics violated GDPR because it transferred personal data to the US without adequate protection.
- France's CNIL reached a comparable conclusion in February 2022, formally notifying websites that their Google Analytics configurations were non-compliant.
- Italy's Garante followed in June 2022, with other authorities weighing in over the same period.
The technical crux is instructive for an SEO. Regulators treated identifiers that GA collected — including online identifiers and, at the time, IP-derived data — as personal data, so even "just analytics" was processing that triggered GDPR's transfer rules. Google, for its part, pointed to mitigations (IP handling changes and, in GA4, a design that does not log or store IP addresses) and argued its measures addressed the concerns. But for a period, the plain reading of these decisions was startling: the default use of the world's most popular analytics tool could be illegal for European visitors.
What it shows
This is the mirror image of Case Study 28.1. There, a platform decision (secure search) shrank what analytics could see. Here, the law — and the privacy expectations behind it — did the shrinking, and did it to the tool itself:
- Measurement is a legal act, not just a technical one. Collecting a visitor's behavior is processing personal data, and in some jurisdictions that requires a lawful basis, disclosure, and often prior consent. An SEO who deploys GA4 without regard to where users are and what consent they gave is not merely cutting a corner; they may be exposing the business to real regulatory risk.
- The privacy-first design of GA4 is a response, not a coincidence. GA4's no-IP-storage architecture, its data-retention limits, its Consent Mode and modeling — the very features Chapter 28 describes as the "funnel of loss" — are in large part Google's engineering answer to exactly this legal pressure. The reason your measurement is more constrained than a decade ago is, substantially, this story.
- The ground keeps moving. In July 2023, the European Commission adopted an adequacy decision for a new EU-US Data Privacy Framework, restoring a legal basis for transfers to certified US companies (Google among them) — and noyb has publicly signaled it considers the new framework vulnerable to challenge too. So the "is Google Analytics legal in the EU?" question did not end in 2022; it entered its next phase. Anyone who tells you it's permanently settled, in either direction, is overstating the record.
Outcome
The decisions did not "ban" Google Analytics outright, and they did not stop most of the world from using it. What they did was force a durable change in how careful operators deploy it: cookie-consent gating before analytics loads, Consent Mode, server-side and IP-minimizing configurations, EU-hosted alternatives for the most risk-averse, and a general shift toward privacy-centric measurement — the exact shift Chapter 28 (and the book's §11 guardrails) describes. The 2023 Data Privacy Framework eased the immediate legal jeopardy for many, but the operational habits — consent, minimization, honesty about the gaps — are now permanent fixtures of professional analytics.
The lesson
You cannot separate "measuring SEO" from "handling people's data responsibly," and the responsible, lawful setup is not the maximal one. The professional treats consent, data minimization, and jurisdiction as first-class parts of the analytics build — not obstacles to route around. This is the same ethic the book applies to link building and content: work with the system's genuine intent (here, users' real privacy rights and the law that backs them), because the alternative invites exactly the kind of blowback that a regulator, unlike a ranking algorithm, can make permanent. A measurement setup that is slightly less complete but honest and lawful beats a "complete" one built on data you had no right to take — and, as this case shows, might be ordered to stop taking. (This study describes public regulatory decisions and is not legal advice; for a specific site, consult a qualified professional.)
Discussion questions
- Case Study 28.1 (a platform shrinking measurement) and this one (the law shrinking it) reach a similar place from opposite directions. What do the two have in common about the nature of measurement, and how should that shape how confidently an SEO reports numbers?
- GA4's no-IP-storage design is framed by Google as privacy protection and by critics as damage control after these rulings. Can both be true? How would you decide?
- A US-based client with significant European traffic asks whether they should keep using GA4. Without giving legal advice, what questions and considerations from this case would you raise, and whom would you tell them to consult?
- The book argues that evading consent signals is "the analytics equivalent of a black-hat SEO tactic." Using this case, explain the parallel: what does the operator gain in the short term, and what do they risk that is worse than an algorithmic penalty?