Google Analytics Illegal in Austria; Other EU Member States Expected to Follow
matomo.org
matomo.org
Also, what's stopping GA from just showing the consent form automatically? Why haven't they done that already or made it an option?
I'm sure I get Austrian traffic from time to time.
On the more serious side, I guess, the outcome may be that GA will be not allowed to collect certain data in Austria. (Just a personal opinion, not a legal advice.)
Mind that you can add `ga('set', 'anonymizeIp', true);` to any GA embedding script, which should be more in compliance. (My guess is that GA will have to default to this mode anyway.)
Edit: GDPR is about storing and processing personalized data. Meaning, if no personalized data is involved, there shouldn't be any need for even declaring it, nor should it be subject to explicit opt-in. On the other hand, we can't be sure, if `ga('set', 'anonymizeIp', true);` really does what it says. (Again, not a legal advice.)
This feature doesn't do anything for GDPR compliance and almost certainly wouldn't hold up in court, if it ever came to that for a particular site.
This is why most US companies chose to just block the EU entirely. No need to deal with it or bad advice like what you're sharing here.
It's possible. I deal with European customers, their lawyers have signed off on my implementation.
Personally I'm afraid to make anything I'm working on publicly available, in case the server logging at some level isn't compliant. It's hard to be sure something hasn't been overlooked, and the monetary risk is very high.
It's not that hard, unless you're using squillions of third-party services. And that's the kind of thing that GDPR is meant to discourage.
And even if it didn't, the only PII that that would gather is IP addresses (and user agents, but I don't know that those count). It's relatively easy to hit your service from a local IP address with a custom User Agent, then check for that IP address and user agent in all the files on the machine. (Log files are pretty much all plain-text, but you could look for the two obvious byte encodings of the IP address too, if you like. Maybe also check the contents of gz files, but that's starting to get silly.)
¹: Read: I'm basically certain, but I'm not a lawyer and my understanding of the “legitimate interest” basis is not as good as my understanding of the rest of GDPR.
In other words, if there's even a chance that you say no to them (ab)using your data any which way they like, they consider you a net negative to their business.
"The extraterritorial reach of the GDPR is broadly defined. It applies to a controller or processor of data when they are monitoring the behavior of data subjects within the EU, when they are processing data related to the offering of goods or services to data subjects in the EU, or when they have an establishment in the EU and the processing of data is happening in the context of that EU establishment." [2]
This is not legal advice, etc.
[0] https://www.data-protection-authority.gv.at/ [1] https://en.wikipedia.org/wiki/Judgment_proof [2] https://www.clarip.com/data-privacy/gdpr-united-states/
[0] https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_gui...
Your probably not at risk for anything, as your using googles service, but I’m not a lawyer. I’d assume if your using google analytics, google would be responsible for following these guidelines?
Google will probably release info on this if they haven’t already. But I find it hard to believe unless your rolling your own analytics anyone would come after you.
IANAL but I doubt that's the case. If GA is being used through your site, you're the data controller and Google are the data processor. [0] At the very least, you're liable as you're the one sending the user's data to GA. This probably holds true even if technically it's the user's own browser making the calls to GA directly, since it was only doing so because your site instructed.
Happy to be corrected if that's not the case.
[0] https://www.gdpreu.org/the-regulation/key-concepts/data-cont...
For GDPR to apply, your website needs some connection to an EU country beyond just being on the internet. What constitutes such a connection isn't an exact science, obviously, which leads and/or allows people to make rather strange claims, the worst of which is probably that such ambiguity makes it entirely impossible to make laws on the subject.
The "official example" is explicitly making accommodations to sell to customers in the EU. The marginal example on the non-GDPR side of the dividing line is a US website, in English, that does sell to EU customers, but only if they sneak their country into the generic second line of the address form.
What gets you to the other side of the line is, for example, a drop-down that lets you chose an EU country for delivery, a switch that allows users to chose to read your website in German (but not Portuguese b/c Brasil), etc.
While there are plenty of cases, as always in life, that straddle the border, one thing is and always was clear: your English-language blog does not fall under GDPR.
It seems to be accurate, though: https://fortune.com/2022/01/13/austria-gdpr-google-analytics... https://www.wired.co.uk/article/google-analytics-europe-aust...
I should start this discussion at work, I'm not sure if we serve customers in Austria but I know we use Google Analytics.
Personally I use GoAccess to visualise this data.
> GoAccess is an open source real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through your browser.
> It provides fast and valuable HTTP statistics for system administrators that require a visual server report on the fly.
Ironically on the other hand, services like Cloudflare are also what makes server logs less useful in some cases - users might not hit your servers at all for you to record them there.
It's still a front-end analytics system which means you'll still lose information from users with tracker blockers, just like with GA.
I've even had developers praising amp as a good thing. It's amazing how even literal poison can be seen as a good thing. Granted, at the time I was working for a company selling ads. They liked everything I disliked, and vice versa
Also there is built-in option for cookie allowance in Google tag manager and Google ads.
This looks like an ad.
The GA case seems to hinge on the IP addresses being send to a US provider, and so is deemed illegal under the Cloud Act (as US gov can compel companies to track etc. based on those IPs)
"Is this accurate?
We have the Schrems II ruling that made some countries think they could not use services like Cloudflare and Azure. Still Cloudflare and Azure are widely used within EU. (Germany is an outcast). One should as always be transparent about what data is collected. From the GA projects I been involved in (in EU) GDPR has never been a concern."
Is GA really illegal in AU?
I think the bigger question is... will anyone enforce it? For you, a random unknown person? probably not.
I didn't know that this works in Alpha-2, a well. :-)
So why can't google analytics simply be served/processed from an EU data center?