Most of my projects are non-commercial, but they still usually have GA, GA tends to be the only thing I have that requires GPDR attention, that I'm aware of anyway.
Most of my projects are non-commercial, but they still usually have GA, GA tends to be the only thing I have that requires GPDR attention, that I'm aware of anyway.
If you go out of your way, you can implement GA, by itself, the "old way"--which is GDPR compliant out of the box. It's Tag Manager and DoubleClick that are not.
<!-- Global site tag (gtag.js) - Google Analytics -->
<script async src="https://www.googletagmanager.com/gtag/js?id=[ID]"></script>
<script>
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
gtag('js', new Date());
gtag('config', '[ID]');
</script>
Is that the "old way" or the "new way"? Maybe it's an even newer way, which is essentially similar to the old way?The old way would load the JS from https://ssl.google-analytics.com/ga.js instead, and set different options.
Here is how to implement Google Analytics by itself:
https://developers.google.com/analytics/devguides/collection...
I can't talk for other countries, but for France, the local DPA explicitely said so[0]!
Loose translation: "The analytics tool do not fit within the consent exemption when their provider reuse data for their own profit. That includes most big analytics service available (see for exemple Google Analytics confidentiality policy)"
[0]https://github.com/LINCnil/Guide-RGPD-du-developpeur/blob/ma...