All articles

7 min read 1374 words

GDPR and analytics: two questions everyone conflates

Whether you need consent for statistics, and whether you may send data to the United States, are two different questions from two different laws. Conflating them costs you either an unnecessary banner or unnecessary risk.

In this article · 5

Any conversation about the legality of analytics veers to the same place: someone invokes the 2022 decisions by European regulators, someone else replies that there is a new transfer framework now, and ten minutes later nobody knows whether a consent banner is required. This happens because the single phrase "GDPR and analytics" hides two independent legal questions, from two different instruments, with different scope and different histories.

They are worth separating properly once, because the answer to one is not the answer to the other, and that is where most of the confusion comes from.

Scroll the table sideways for the remaining columns.

QuestionWhere it comes fromWhat it governs
May I store anything on the user's device?ePrivacy Directive, Article 5(3), transposed separately by each countryCookies, localStorage, any access to device storage
May I send personal data outside the European Economic Area?GDPR, Chapter VWhere processing happens and who can reach the data

You can breach one while satisfying the other, and vice versa. A tool hosted on a European server but writing a cookie without consent has a problem with the first question and none with the second. A tool that stores nothing but ships data to a provider outside Europe has exactly the reverse.

The transfer question: what happened and what changed

The story begins with the Court of Justice's Schrems II judgment in 2020, which invalidated the Privacy Shield, the then basis for sending data to the United States. The organisation noyb subsequently filed over a hundred complaints about specific Google Analytics deployments.

In 2022 the decisions arrived. The Austrian data protection authority went first, holding that transfers through Google Analytics breached Chapter V of the GDPR and rejecting the argument that IP anonymisation was sufficient. Weeks later the French CNIL reached a similar conclusion and ordered website operators to comply. By mid-year the Italian Garante had joined. That is when most of the articles still circulating on this subject were written.

And here is the part those articles are silent about, because they predate it. The legal basis for transfers changed in July 2023. The European Commission adopted an adequacy decision for the EU-US Data Privacy Framework. Transfers to US organisations certified under that framework have had a legal basis ever since, and Google LLC is among them. The argument underpinning the 2022 decisions lost its footing.

The framework was challenged, of course. The French MP Philippe Latombe sought annulment of the adequacy decision. In September 2025 the General Court dismissed the action, finding that on the date the decision was adopted the United States ensured an adequate level of protection. An appeal was lodged at the end of October 2025, so the matter is not finally settled.

The second question stood untouched throughout, and it affects far more websites, because it does not depend on where the server sits.

Article 5(3) of the ePrivacy Directive says, in short, that storing information on a user's device or gaining access to information already stored there requires their consent. Two things about that are easy to miss.

First, the provision speaks of information, not of personal data. It makes no difference whether you store an identifier or a visit counter: what counts is the act of writing to somebody else's device. This is why "but it is an anonymous cookie" has never been an answer.

Second, the provision concerns storing and reading, not collecting. Data the browser sends with every request anyway, such as the IP address or the user agent header, falls outside Article 5(3), because nothing is written to or read from the device. It does fall under the GDPR where it identifies a person, and there you need a legal basis, usually legitimate interests.

The conclusion is simple and, for many, surprising: a tool that stores nothing on the device needs no consent under Article 5(3). Not because it benefits from an exemption, but because the provision does not reach it. It must still satisfy the GDPR for the data it processes, but that is a different and usually much easier conversation.

A concrete checklist rather than general reflection

The French CNIL is the only regulator to have published a checkable list of conditions under which audience measurement is exempt from the consent requirement, together with a self-assessment tool for vendors. It is not law across the Union, but it is the most concrete material that exists on the question and a good yardstick for assessing any tool.

The exemption conditions amount to the tool:

  • serving only audience measurement for the site operator, producing aggregate statistics rather than reports about individuals,
  • not passing data to third parties or combining it with data from other sites,
  • not tracking users across different services,
  • not being used for targeting, content personalisation or building audience segments,
  • limiting geolocation precision, for instance by truncating the IP address,
  • not using user identifiers imported from other systems,
  • limiting the lifetime of any identifier, with the CNIL pointing to thirteen months,
  • offering an opt-out mechanism that works in every browser.

What stands out is that the list says nothing about technology. It is not about whether you use a cookie. It is about what the data is for and whether an individual moving around the web can be reconstructed from it. A tool that writes a cookie may satisfy these conditions, and a cookieless tool may fail them if it builds profiles.

A practical order of questions

Rather than asking "is this tool GDPR-compliant", which is a badly formed question, work through four questions in order. Each has a checkable answer rather than a matter of opinion.

  1. Does the tool write anything to the device? Open developer tools, the Application tab, and inspect cookies and local storage for your domain. If it is empty after a visit, Article 5(3) does not apply and no banner is needed on that ground.
  2. Does data leave the European Economic Area? That is a question for the vendor about server locations and sub-processors. The answer belongs in the data processing agreement, not on a marketing page.
  3. Does the tool build profiles or track across sites? If so, no exemption is available whatever the technology, and consent is required.
  4. How much data do you actually need? Minimisation is an obligation under the GDPR, not a good practice. If you cannot name the decision a given field will inform, there is no basis for collecting it.

Three things worth doing this week

  • Check what your current tool writes to the device. It takes two minutes and very often ends in surprise, because analytics scripts get added by plugins and tag managers without the site owner knowing.
  • Read your data processing agreement. It should name sub-processors and processing countries. If the vendor does not have one, or will not show it, that is an answer in itself.
  • Write down the reasoning behind your decision. Accountability under the GDPR means being able to demonstrate why you considered your setup lawful. A one-page note written now is worth more than reconstructing your thinking in two years.

A closing caveat that is not ritual here. This is not legal advice. ePrivacy is a directive, so every country implemented it in its own statute, and the details differ, as does the practice of national regulators. The above is meant to help you ask the right questions and separate two matters that keep collapsing into one in conversation. Answering them for a particular business is the job of a lawyer who has seen that business's setup.

Sources

Every claim in this article that carries a number links to one of these. Where a study is correlational rather than experimental, the text says so.

  1. 1. Austrian DSB: EU-US data transfers to Google Analytics illegal noyb, 2022
  2. 2. CNIL decides EU-US data transfer to Google Analytics illegal noyb, 2022
  3. 3. Further EU DPA orders stop of Google Analytics noyb, 2022
  4. 4. Press release no. 106/25: judgment in Case T-553/23 Latombe v Commission Court of Justice of the European Union, 2025
  5. 5. Sheet no. 16: Use analytics on your websites and applications CNIL, 2025

Analytics that needs no cookie banner

metuno measures traffic without storing anything on the visitor's device, so it sees the whole audience rather than the half that clicked accept.

Start for free

Read next

enpldees