Regulations

Google Analytics 4 and GDPR 2026: Is GA4 Still Legal in Europe?

·8 min read

Quick answer: Google Analytics 4 (GA4) is conditionally legal in most EU countries as of 2026, but only if you obtain valid opt-in consent before loading the tracking script and use IP anonymization. Several DPAs initially ruled Google Analytics (Universal Analytics) illegal, but the EU-US Data Privacy Framework adopted in July 2023 has largely resolved the data transfer issue for GA4 — though consent for cookies remains strictly required.

What Happened: The Google Analytics GDPR Timeline

DateEventImpact
July 2020Schrems II ruling invalidates Privacy ShieldAll US data transfers questioned
Jan 2022Austrian DPA rules Google Analytics illegalFirst EU DPA to ban GA
Feb 2022French CNIL rules Google Analytics illegalGave sites 1 month to comply
Jun 2022Italian Garante rules Google Analytics illegal90-day compliance deadline
Jul 2023EU-US Data Privacy Framework adoptedProvides legal basis for US data transfers
Jul 2023Google sunsets Universal Analytics → GA4GA4 has improved privacy controls
2024-2025DPAs update guidance recognizing DPFGA4 with consent is generally accepted
2026EU Commission proposes one-click cookie rejectConsent enforcement intensifies

Is Google Analytics 4 Legal in the EU Right Now?

Yes, but with conditions. The EU-US Data Privacy Framework provides a legal mechanism for transferring data to certified US companies, including Google. However, two critical requirements remain:

  1. You must obtain consent before loading GA4. GA4 sets cookies (_ga, _gid) that are classified as non-essential under the ePrivacy Directive. Loading GA4 before the user clicks "Accept" is a violation regardless of the data transfer question.
  2. You must disclose GA4 in your privacy policy and cookie notice. Users must know what data is collected, where it goes, and how long it's retained.

Google Analytics GDPR Status by Country

CountryDPAStatus (2026)Notes
FranceCNILLegal with consent + DPFCNIL provides detailed GA4 guidance
AustriaDSBLegal with consent + DPFOriginal ban was pre-DPF
ItalyGaranteLegal with consent + DPFRequires IP anonymization
GermanyState DPAsLegal with consent + DPFSome DPAs still recommend alternatives
NetherlandsAPLegal with consent + DPFStrict enforcement on consent timing
DenmarkDatatilsynetLegal with consent + DPFPreviously issued correction orders
NorwayDatatilsynetLegal with consent + DPFFollows EU guidance
SwedenIMYLegal with consent + DPFFined companies for GA without consent
FinlandOmbudsmanLegal with consent + DPFEmphasizes transparency

How to Use GA4 Compliantly in 2026

  1. Get consent first: Configure your cookie consent banner to block GA4 until the user accepts analytics cookies
  2. Enable IP anonymization: GA4 includes this by default, but verify it's active in your configuration
  3. Set up Google Consent Mode V2: This sends cookieless pings when users decline consent, preserving aggregate data without violating GDPR
  4. Configure data retention: Set the shortest retention period (2 months) in GA4 settings
  5. Disable data sharing: Turn off "Google signals" and advertising features unless needed
  6. Sign a DPA: Accept Google's Data Processing Amendment in your GA4 admin settings
  7. Update your privacy policy: Disclose GA4 usage, cookie names, data exported to US, and retention periods

What If the EU-US Data Privacy Framework Fails?

Privacy activist Max Schrems has challenged the DPF through NOYB.eu. If the Court of Justice rules against it (a "Schrems III" scenario), websites would need to either:

Privacy-Friendly Alternatives to Google Analytics

ToolCookie-Free?EU Data Storage?Consent Required?Pricing
PlausibleYesYes (EU-only)NoFrom €9/mo
FathomYesYes (EU option)NoFrom $14/mo
UmamiYesSelf-hostedNoFree (open-source)
MatomoConfigurableSelf-hosted or EU cloudDepends on configFree self-hosted / from €19/mo cloud
Simple AnalyticsYesYes (EU-only)NoFrom €9/mo

For a detailed comparison, see our Cookie-Free Analytics guide.

Frequently Asked Questions

Is Google Analytics banned in Europe?

No, not anymore. Google Analytics was effectively banned by several DPAs in 2022 due to the lack of a legal framework for EU-US data transfers. Since the adoption of the EU-US Data Privacy Framework in July 2023, GA4 can be used legally — but only with proper cookie consent. The consent requirement is separate from the data transfer question and remains strictly enforced.

Do I need consent for GA4 if I enable IP anonymization?

Yes. IP anonymization addresses data protection concerns about identifiable data, but it does not remove the need for cookie consent. GA4 sets cookies (_ga, _gid) on the user's device, which requires opt-in consent under the ePrivacy Directive regardless of what happens to the IP address.

Can I use Google Analytics without a cookie banner?

No — not if EU visitors can access your website. The only way to track EU visitors without consent is to use a cookieless analytics tool that doesn't set cookies and processes data exclusively in the EU.

How do I check if GA4 loads before consent on my site?

Use PrivacyChecker to scan your website. It detects whether tracking scripts (including GA4) fire before the user interacts with the consent banner. You can also check manually by opening your site in an incognito window and inspecting cookies before clicking anything.

Check your website now — free

Run a complete privacy audit in under 60 seconds. Get your score, find issues, and learn how to fix them.

Start Free Audit