Danish Data Protection Agency concludes Google Analytics cannot be used lawfully
datatilsynet.dk
datatilsynet.dk
An important question to ask yourself: _what_ insights?
Want to know which of your pages are popular? Server logs will tell you that.
Want to know how the users move across your website? Server logs can tell you that, albeit in a limited fashion.
Want to know where your users come from? Server logs.
For more advanced use-cases, you may need javascript on the frontend (which you can serve from your own domain, making it harder to block, but still needing to be GDPR compliant, if you serve to GDPR affected users).
Not really. The only actual competitor to GA is Matomo Analytics, the rest are just copies of each other with the same very basic feature set.
We keep a list here:
https://business.adobe.com/products/analytics/compare-adobe-...
One is the Search Console integration, which is the only way to see what Google search queries led people to your site.
The second is Google Ads conversion tracking and remarketing, which is de facto required to advertise with Google because it can easily 10x your Return On Advertising Spend, which is a key metric for digital marketing teams.
Without those two features, Google Analytics would be easy to drop. Many big companies already have other first- or third-party analytics tools they prefer.
Don't most analytic tools have this? I know Plausible has Search Console Integration.
The Google Ads conversion is the killer feature Google Analytics has in my opinion. But the reality is, most use it because it's defacto and free.
Ew
I thought it was just for click tracking on my end.
Ha!
As other posters mentioned, there are numerous GA alternatives, with varying degree of compliance and features.
I can see this on sites without GA just fine. Are there some kind of advanced insights you’re referring to?
On some apps they also give a percentage back to the developer so you'd be supporting them.
There are also some that are open source and can be self-hosted. Those are marked with an "open source" flag.
If you use GA for web analytics it is website operator problem, not Google's.
Laws that aren't enforced, or that have little bite, aren't really laws.
The US is obviously not going to do this, so whatever agreement they come up with is bound to be struck down just like the previous two were.
Simple to use (few features compared to GA, but exactly those I need), respects privacy, and has fair pricing.
Seriously, in terms of a 'segregated' network, we already see giant walled gardens and their pseudo-kin everywhere, and web3's sole focus seems on monetization of anything online, which won't help that one iota.
The US couldn't care less about security. Their approach is "we buy and sell your data and if you are in the US the government can use any and all data at any point for any reason".
European view isn't maximalist in the least. Europe, thankfully, still still remembers lessons learned from data exposure to Stasi police.
Just like international phone calls, don't expect the Internet to solely operate in a border, but do expect nations to care what traverses the boundaries.
More: add additional measures beyond those provided by GA. Hosting a proxy and anonymizing the data before it reaches GA might be an option.
At this point, it is easier and cheaper to find GDPR compliant alternative.
1. Since 2020, it's illegal to send personal data to the US because of the invalidation of the Privacy Shield [2]
2. Google said it was okay in the EU to use anonymized IP addresses
3. The Austrian Data Protection Authority (DSB) [3] ruled differently and waived most of the arguments raised by Google. The DSB ruled that even anonymized IP addresses are personal data.
4. The Data Protection Authority of The Netherlands followed by implying that the use of Google Analytics might be banned in the future [4]
5. In February 2022 The Data Protection Authority of France (CNIL) followed [5]
6. In June 2022 the Data Protection Authority of Italy (Garante) followed [6]
7. Now, September 2022, Denmark – after already banning Google Workspace for municipalities [7] – considers Google Analytics unlawful as well [8]
This is a sound decision, but not a new one. It's a confirmation of what has been ruled in July 2020, but now it seems to have more impact.
PS: I'm the founder of Simple Analytics [9] - the privacy-first analytics tool that, unlike other privacy tools, does not use any identifiers.
[1] https://blog.simpleanalytics.com/will-google-analytics-be-ba...
[2] https://iapp.org/news/a/the-schrems-ii-decision-eu-us-data-t...
[3] https://www.data-protection-authority.gv.at/
[4] https://autoriteitpersoonsgegevens.nl/nl/onderwerpen/interne... (in Dutch)
[5] https://www.cnil.fr/en/use-google-analytics-and-data-transfe...
[6] https://www.gpdp.it/web/guest/home/docweb/-/docweb-display/d...
[7] https://www.simpleanalytics.com/blog/denmark-bans-google-wor... (includes translated version)
[8] https://www.datatilsynet.dk/english/google-analytics/use-of-... (this thread)
Edit: seems GA only masks the last octet of an IP4 address.
More you can find in the NOYB blog post [2]. NOYB is the organization who imitated the complaints towards Google (Analytics).
> While Google has made submissions claiming that has implemented "Technical and Organizational Measures" ("TOMs") [1], which included ideas like having fences around data centers, reviewing requests or having baseline encryption, the DSB has rejected these measures as absolutely useless when it comes to US surveillance (page 38 and 39 of the decision):
> "With regard to the contractual and organizational measures outlined, it is not apparent, to what extent [the measure] are effective in the sense of the above considerations."
> "Insofar as the technical measures are concerned, it is also not recognizable (...) to what extent [the measure] would actually prevent or limit access by U.S. intelligence agencies considering U.S. law."
> Max Schrems: "This is a very detailed and sound decision. The bottom line is: Companies can't use US cloud services in Europe anymore. It has now been 1.5 years since the Court of Justice confirmed this a second time, so it is more than time that the law is also enforced."
[1] https://noyb.eu/sites/default/files/2021-05/2021-04-09_Respo...
[2] https://noyb.eu/en/austrian-dsb-eu-us-data-transfers-google-...
The old GA did.
And now I’ve moved to paid, but basic products (plausible) which do show me those important details, instantly. Traffic trends, sources, referrers, goals.
Poor Google :'(
You could have the right to name an asteroid, but it's not an important right.
Google has received court orders about other user data like Gmail, but have they ever gotten a court order about Google Analytics? That data isn't associated with Google accounts, and I doubt law enforcement would know what to ask for.
No one should hold that much power.
The relevant question is "has anyone had their right to privacy taken from them, as defined in EU law?".
The answer, according to the Danish, French, and Austrian governments (so far), is "yes".
And you know why they hold that much power? Nobody else made a search engine worth a fuck. That's it. Secondly, integrity. Google actually debugs. Meaning until there's no bugs left. I've seen bugs in everything except Google's software, mostly, don't accuse bugs but can't vouch they have none, either. Makes perfect sense their use of Yubikey led to no account compromises among like 100000 accounts, that and the bug-free software are the fruits of integrity. I mean I'm sure I've seen bugs in Google's software but I don't remember them off the top of my head, unlike Apple since like 2021, whom else, well the whole Solarwinds bitch story, American second-tier tech getting fucked wholesale. What happened to "don't share needles"? Everybody is sharing one needle. That needle is the internet. Like if you must share it like burn the tip very carefully with a lighter and pump drano through it. So that's what Google did. And they're doing it as a public service basically, like not exactly but pretty much, today at least I do buy their argument that it's free so it's not harmful to the consumer. But other days I know it hurts businesses, and everybody gets their money from businesses or taxes on businesses, so harm to business is harm to the consumers who earn their money from that business ultimately.
Even though Google has branches in Europe, again the website owners will get in legal trouble and not Google for offering a product which cannot be used legally.
Is there any other industry where the client is responsible for making sure the service or product is legal and not the producer?
Exaggerated example: If I would buy a car which by design isn't road legal, and this design flaw would cause an accident killing someone. Normally the carmaker would be responsible. The carmaker couldn't say, well technically, it's only for use in your backyard, but you have to be a lawyer to know that, and our advertising isn't reflecting that at all. Somehow, Google get's away with such logic.
Pretty much all of them? Let's say you buy a humble walkie-talkie. It is your responsibility to operate it in regions where the specific RF bands it uses are legal.
Radio devices are a good example where it fact is illegal to make, sell or import transmitters that do not conform to permitted RF bands.
IIRC in USA there is an exemption in FCC rules if you're importing a device for personal use by e.g. buying it online from abroad (and then you're responsible to use it properly), but if you'd want to resell that device, you can't just transfer the liability to the user, you are responsible for ensuring that the transmitter follows FCC rules.
For example, last year there was an explicit prohibition on sales of Baofeng UV-5R in Germany (https://www.bnetza-amtsblatt.de/download/72) and Poland and probably other countries due to out of band emissions causing radio interference.
As far as I know they never explicitly say that - they give you all the details you need to make the determination yourself, but never explicitly give you the answer.
[1] https://europa.eu/youreurope/business/selling-in-eu/selling-...
But let's say it is, then still Google should make that very clear or even adapt its script to prevent a connection if an EU ip is recognized.
That's fair play. The user knows exactly that he is breaking the law, and he can be punished. Google advertises Analytics for online-shops, websites etc. Cases in which the product can't be used legally and the user doesn't know it.
For example: I'm also responsible for my car but if it's (by design) not road legal, why should I be responsible to be sure of that and not the carmaker?
There are various kinds of agricultural, recreational and construction vehicle that can't be driven on the roads: you put them on a trailer for moving them from site to site.
Let's remember, for context, that the EU is saying that the US is an "unsafe" third party country. While this is certainly true under a given definition of safe/unsafe, I doubt (m)any European citizens can point to harm as a direct result of their data being subpoenaed under the US CLOUD act. I am not saying there isn't a real problem but as I mentioned in another comment, the US and EU have agreed "in principle" on a third privacy shield to satisfy concerns on both sides and we are now waiting for it to be codified and tested in courts.
I also don't think most Europeans are really worried about US government intrusions into their privacy, thoug I don't know the legal implications the CLOUD act would have in this context. Honestly, I think anybody takes US government intrusions for granted after the Snowden leaks. It's the companies people are worried about. Facebook, Google have a scary amount of power and lack of oversight.
Under GDPR pseudonymisation is considered to be reversible and therefor still falls within the scope of personal data. [source: https://ec.europa.eu/research/participants/data/ref/h2020/gr... ]
The issue is whether US law enforcement has unrestricted access to the data. They are considered to have unrestricted access to any data on Google's servers (even their EU servers). But if re-identification requires a piece of data which only lives outside of US jurisdiction, and accessing that data requires going through appropriate channels, then the data is considered safeguarded.