Google Analytics is injected with Stripe.js when enabling Google Pay
twitter.com
twitter.com
[0]: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Co...
(Though in this case B and C are both Google, and in a slightly different world both Google Pay and Google Analytics could be hosted on the same domain.)
This isn’t stripe doing this, rather it’s google doing it.
For payment processing. Not for tracking.
Privacy laws allow you to keep the data only for as long as legally necessary and required. Google Analytics may keep this data indefinitely.
> [...] DSB issued a second decision, declaring the use of Google’s IP anonymisation a useless protection measure for data transfers between the EU and the United States.
https://noyb.eu/en/update-further-eu-dpa-orders-stop-google-...
Alas there are no payment processors that don't do tracking. As I understand it, VISA and Mastercard were some of the originators of this business model.
My tech stack is built on various products, including no-code site building tools, and I believe these tools employ JavaScript/cookies at layers which are inaccessible to me. Some of these may cavort with GA.
How liable am I?
If my tools are gathering data behind my back and not telling me, that is troubling. I should not be liable for this, as it is an abuse of trust that would result in me no longer using the tool had I known prior.
If you can't ensure the tools you use are not fucking your customers over, you shouldn't be using those tools.
Sure if you did the due diligence, and they actually hid that they use cookies[0], both in their documentation and technically while you were developing, then enabled them in production, where you missed them, sure. But most don't hide they use cookies, not in documentation and not while developing.
[0] By cookies I mean anything that would require consent
Well, you can sue tool makers if they lied to you.
But ability to just say "but I didn't know" would be catastrophic to any accountability, as nobody would even read a manual to be able to plausibly claim that they didn't knew.
In similar way you can't go shoplifting then claim you didn't know that was a crime.
Your responsibility is making sure that data processed under the terms of that agreement conforms to GDPR. Your primary responsibilities are the articles in Chapter 3 "Rights of the Data Subject" under GDPR, and making sure you can do that for data sent to the third-party.
Their responsibility is making sure that data is only processed how they describe it in the DPA. If they surreptitiously add Google Analytics, that's their violation.
If the contract is too vague to tell what processing is going on, then that is your violation for choosing to engage with them as a processor. In practice this might be your biggest risk.
Under GDPR you are the data controller of you decide what data is collected and for what purposes.
I would expect this to cover you as the operator of the website (or other service). Your agreements with your tool providers probably specify that they are data processors for you.
If data was being collected and accessed without lawful basis (by eg GA embedded somewhere in your stack), this would count as a data breach. You would have to inform your data regulator (eg ICO in the UK) within 72 hours of becoming aware of it, and tell them among other things what remedial action you are taking. You could also be fined for failing to do due diligence.
(I used to work in this general area, but don't anymore.)