I'm sure I get Austrian traffic from time to time.
On the more serious side, I guess, the outcome may be that GA will be not allowed to collect certain data in Austria. (Just a personal opinion, not a legal advice.)
Mind that you can add `ga('set', 'anonymizeIp', true);` to any GA embedding script, which should be more in compliance. (My guess is that GA will have to default to this mode anyway.)
Edit: GDPR is about storing and processing personalized data. Meaning, if no personalized data is involved, there shouldn't be any need for even declaring it, nor should it be subject to explicit opt-in. On the other hand, we can't be sure, if `ga('set', 'anonymizeIp', true);` really does what it says. (Again, not a legal advice.)
This feature doesn't do anything for GDPR compliance and almost certainly wouldn't hold up in court, if it ever came to that for a particular site.
"The extraterritorial reach of the GDPR is broadly defined. It applies to a controller or processor of data when they are monitoring the behavior of data subjects within the EU, when they are processing data related to the offering of goods or services to data subjects in the EU, or when they have an establishment in the EU and the processing of data is happening in the context of that EU establishment." [2]
This is not legal advice, etc.
[0] https://www.data-protection-authority.gv.at/ [1] https://en.wikipedia.org/wiki/Judgment_proof [2] https://www.clarip.com/data-privacy/gdpr-united-states/
[0] https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_gui...
This is why most US companies chose to just block the EU entirely. No need to deal with it or bad advice like what you're sharing here.
It's possible. I deal with European customers, their lawyers have signed off on my implementation.
Personally I'm afraid to make anything I'm working on publicly available, in case the server logging at some level isn't compliant. It's hard to be sure something hasn't been overlooked, and the monetary risk is very high.
It's not that hard, unless you're using squillions of third-party services. And that's the kind of thing that GDPR is meant to discourage.
And even if it didn't, the only PII that that would gather is IP addresses (and user agents, but I don't know that those count). It's relatively easy to hit your service from a local IP address with a custom User Agent, then check for that IP address and user agent in all the files on the machine. (Log files are pretty much all plain-text, but you could look for the two obvious byte encodings of the IP address too, if you like. Maybe also check the contents of gz files, but that's starting to get silly.)
¹: Read: I'm basically certain, but I'm not a lawyer and my understanding of the “legitimate interest” basis is not as good as my understanding of the rest of GDPR.
In other words, if there's even a chance that you say no to them (ab)using your data any which way they like, they consider you a net negative to their business.