"Is Google Analytics legal in the EU?" is a question that keeps coming back. The honest answer is that it depends on how it's set up, and on a court case that hasn't finished.
Between 2020 and 2023, several European regulators found that sending Google Analytics data to the US broke the GDPR. Most of those decisions were about Universal Analytics, before the rules changed. Here's where things stand now, and what's in your control.
Why transfers were a problem.
In 2020 the EU's Court of Justice struck down the Privacy Shield, the arrangement that had allowed personal data to flow to the US. It found that US surveillance law didn't give Europeans enough protection. Transfers to US companies, including Google, lost their easy legal footing.
Regulators in Austria, France, Italy and elsewhere then ruled against specific websites that used Google Analytics, because the data sent to Google in the US included identifiers that counted as personal data.
What changed in 2023.
In July 2023 the European Commission adopted the EU-US Data Privacy Framework. Companies that certify under it, Google among them, can receive personal data from the EU on the basis of an adequacy decision.
The framework has been challenged. In September 2025 the EU General Court upheld it. An appeal to the Court of Justice was filed in October 2025 and hasn't been decided at the time of writing. If the framework falls, transfers would need other safeguards again.
What GA4 does differently.
GA4 was designed with these rulings in mind. Google says that for visitors in the EU:
- IP addresses aren't logged or stored. They're used on servers in the EU to work out a rough location, then dropped before the data goes on to Analytics.
- Location can be made coarser. You can turn off granular location data by region, so city-level detail isn't collected.
- Device detail can be reduced. Granular device data, such as browser version and screen resolution, can be switched off too.
GA4 still sets identifiers in the visitor's browser, and those count as personal data under the GDPR. So transfers still matter, and so does consent. The rules on consent are covered in GA4 and EU consent rules.
What you control.
- Consent first. No GA4 identifiers for EU visitors until they agree.
- Collect less. Turn off granular location and device data for EU regions if you don't use them.
- Keep data for less time. GA4's data retention setting can be 2 months or 14 months on the standard version. Choose the shortest that still covers the comparisons you make.
- Keep personal data out of events. Email addresses in page URLs, names in form parameters and IDs in custom dimensions all turn up in audits. Strip them before they're sent.
- Consider server-side tagging. With server-side GTM, data goes first to a server on your own subdomain, where you decide what's removed before anything reaches Google. It can be hosted in the EU, for example on Stape.
- Keep exports in the EU. If you connect GA4 to BigQuery, create the dataset in an EU region.
- Write it down. Your privacy notice and records of processing should say what GA4 collects, why, and where it goes.
Is it legal?
With the Data Privacy Framework in force, consent handled properly and the data kept lean, many organisations are comfortable using GA4 in Europe. Others, especially in the public sector and in regulated industries, choose other tools or keep GA4 behind server-side tagging.
That's a judgement for your lawyer or data protection officer, and it may change when the Court of Justice rules. What doesn't change is the setup work: consent, data minimisation and clean events are needed whichever way the case goes.
Marc Alexander works with European businesses on exactly that setup. The GA4 mini audit checks what your GA4 collects today, including personal data that shouldn't be there.