·11 min read

Is Google Analytics illegal? A country-by-country reality check (2026)

Google Analytics is not illegal as a product and there is no EU-wide ban. What happened is narrower: between 2022 and 2023, data protection authorities in Austria, France, Italy, Denmark, Sweden, and others ruled that specific websites using Google Analytics broke GDPR, mainly because of EU to US data transfers. The 2023 EU-US Data Privacy Framework created a new legal basis for those transfers and eased the immediate problem, though privacy advocates question how durable it is. This is general information, not legal advice.

google-analyticsgdprprivacycompliancealternativesanalytics-strategy
Cover graphic asking whether Google Analytics is illegal, with the short answer that there is no outright ban but some uses were ruled unlawful, plus three factors: no product ban, EU rulings from 2022 onward, and an ongoing contested debate

Short answer: no, Google Analytics is not illegal, and there is no EU-wide ban on it. What actually happened is narrower and more interesting. Between 2022 and 2023, several EU regulators ruled that specific websites using Google Analytics broke GDPR, mostly because of how it sent European data to the United States. This is an honest, country-by-country look at what happened and where things stand in 2026.

One important note before we start. I'm a founder, not a lawyer. Everything here is general information to help you understand the landscape, not legal advice. Privacy law is genuinely nuanced, enforcement varies from country to country, and your situation may differ from the general case. For anything that carries real legal weight, talk to a qualified lawyer or your data protection officer (DPO). I'll say it again at the end, because it's the single most important line in this post.

Quick disclosure: I'm the founder of Muro, a privacy-friendly analytics tool. I've worked hard to keep this factual and balanced rather than turning it into a pitch. Muro shows up once, near the end, and I've kept the claims modest on purpose.

So, is Google Analytics illegal?

The most accurate answer is: no, not as a product, and not everywhere. But specific uses of it have been ruled unlawful in parts of the EU, and that is where the "illegal" reputation comes from.

It helps to separate two very different claims. The first is "Google Analytics is banned." That one is false. No country has outlawed the product, and you can install it today in almost any jurisdiction without breaking a specific anti-Analytics law, because no such law exists. The second claim is "using Google Analytics can put you on the wrong side of GDPR." That one has real support, because between 2022 and 2023 a series of European data protection authorities looked at particular websites and concluded that the way those sites used Google Analytics violated European privacy law.

So the honest framing is not "legal or illegal." It's "using it responsibly under GDPR takes work, and for a stretch of time, several regulators decided that common setups were not doing enough." That is a meaningful difference, and it changes what you should actually do about it.

Why do people think Google Analytics is illegal?

Because of one issue that sat at the center of every ruling: cross-border data transfers.

For years, using Google Analytics meant that data about your European visitors could be sent to servers in the United States. Under GDPR, moving personal data outside the EU is only allowed when the destination offers protection that is essentially equivalent to European rules. In July 2020, the Court of Justice of the European Union issued the ruling widely known as Schrems II. It struck down the Privacy Shield arrangement that had been used to justify EU to US transfers, and it raised the bar for relying on the alternative legal mechanisms.

That ruling turned Google Analytics into a live legal question across Europe, almost overnight. If your analytics tool routinely shipped European personal data to a US company, and the main legal basis for doing that had just been invalidated, then your setup was suddenly on shakier ground than it had been the week before.

A privacy organization called noyb, founded by the campaigner Max Schrems, pressed the point. In August 2020 it filed 101 complaints across the EU against websites that were sending data to the US through Google Analytics and Facebook tools. Those complaints are what eventually produced the rulings people now point to when they say Google Analytics is illegal.

The 2022 rulings: what actually happened

Starting in early 2022, national regulators began responding to those complaints, and the decisions landed one after another.

Austria was first. In January 2022, the Austrian data protection authority (the DSB) found that a specific website's use of Google Analytics violated GDPR, because it transferred personal data to the US without adequate protection. A few weeks later, in February 2022, France's regulator (the CNIL) reached a similar conclusion and began issuing formal notices to website operators, telling them to bring their use of Google Analytics into compliance or stop using it. In June 2022, Italy's authority (the Garante) ruled the same way in a case involving a media company, and gave the site 90 days to fix its configuration or discontinue the tool.

Other authorities followed. Denmark's regulator concluded in September 2022 that Google Analytics could not be used lawfully without supplementary measures that most sites were not taking. Finland and Norway signaled similar positions. And by 2023, Sweden's authority (the IMY) went a step further and issued fines to companies for continuing to use Google Analytics in a way it considered unlawful.

It's worth being precise about what these were and were not. Each decision concerned a particular website and a particular configuration. None of them was a nationwide ban on the product. But taken together, they sent an unmistakable signal across the EU: the default way most sites ran Google Analytics was legally risky, and the transfer problem was the reason.

Table of selected EU data protection rulings on Google Analytics from 2022 to 2023, showing Austria (DSB, January 2022), France (CNIL, February 2022), Italy (Garante, June 2022), Denmark (Datatilsynet, September 2022), and Sweden (IMY, June 2023), all concerning EU to US data transfers

Country-by-country: what the pattern really shows

Look across the whole set and one thing becomes obvious. This was never about Google Analytics being a uniquely evil tool. It was about a legal mechanism, the EU to US transfer, that had been knocked out from under a huge number of products at once.

Google Analytics just happened to be the most visible example. It's on a large share of the web, it clearly sends data to a US company, and it processes information such as IP-derived identifiers that regulators treat as personal data. That combination made it the obvious test case for the post-Schrems II world. The same underlying logic touched plenty of other US-based services too, which is part of why the issue felt so sprawling and hard to resolve.

If you want the deeper mechanics of how GDPR treats cookies, consent, and personal data, and why "compliant" is more of a spectrum than a checkbox, I wrote a companion piece on whether Google Analytics is GDPR compliant that goes through it carefully. This post is about the "illegal" framing specifically; that one is about compliance in general.

Did the 2023 Data Privacy Framework make it legal again?

It helped a great deal, but "legal again" is too strong a phrase to be honest.

In July 2023, the European Commission adopted the EU-US Data Privacy Framework. In plain terms, it created a new, official legal basis for transferring personal data from the EU to US companies that certify under it, and Google is one of the companies that did. For a lot of organizations, that directly addressed the core problem behind the 2022 rulings, because the transfers that regulators had objected to now had a recognized legal footing again.

So the immediate crisis eased. Many teams that had been anxious about Google Analytics in 2022 found the pressure lift through 2023 and beyond.

Here is the honest caveat, though. The framework did not touch the other GDPR requirements around Google Analytics. You still generally need a cookie consent banner in the EU, because the tool still sets cookies and processes personal data. And the framework itself sits under a cloud of legal uncertainty. Privacy advocates, including noyb, have publicly signaled that they may challenge it, exactly as they successfully challenged the two arrangements that came before it (Safe Harbor and Privacy Shield were both struck down). Nobody can honestly promise that this one will survive.

I want to be careful and measured here, the same way I was in the GDPR post. The framework is in force as I write this, and it genuinely changed the calculus. But if your peace of mind depends entirely on that framework never being overturned, that is a risk worth understanding, and worth raising with a lawyer.

Is Google Analytics illegal in the United States?

No, and this is worth stating plainly because a lot of the panic is EU-specific.

The GDPR transfer problem that drove every one of the 2022 rulings simply does not apply the same way inside the US. American privacy law is a patchwork of state rules rather than a single federal regime. Laws like the California Consumer Privacy Act create real obligations around giving people notice and an opt-out, and you should take those seriously if you have California or other covered users. But none of them make Google Analytics illegal to use.

So if your audience is mostly in the United States, the honest answer is that the "Google Analytics is illegal" headlines are largely about a European legal debate that may not be your primary concern. Your obligations are real, but they're different, and they're generally lighter on the specific transfer question that caused all the EU trouble.

So should you keep using it?

That depends less on legality and more on how much ongoing work you want to carry.

If you decide to keep Google Analytics, you can absolutely run it in a defensible way in most places. That means relying on a valid legal basis for the transfer, configuring GA4 thoughtfully rather than trusting the defaults, and collecting genuine cookie consent before Analytics loads. Done properly, that's a reasonable position. The trap is the half-configured middle ground, where you've bolted on a consent banner but never checked that Analytics actually waits for consent. That is the riskiest state of all, because you get the compliance overhead and the legal exposure at the same time.

There's also a quieter cost that has nothing to do with lawyers. Consent banners drive a meaningful share of visitors to click "reject" or ignore them, which means you lose that data anyway. So you carry the full compliance burden and still end up with incomplete numbers. For a lot of small teams, that's the worst of both worlds, and it's a big reason people start looking for something simpler.

The simplest way to sidestep the whole question

Here's the genuinely clarifying part: most of the hard questions above exist only because Google Analytics collects personal data and sends it across borders. Remove those two facts and most of the debate evaporates.

That's the entire idea behind cookieless, privacy-friendly analytics. Tools in this category, including Plausible, Fathom, Simple Analytics, and Muro, are built to measure your traffic in aggregate without tracking individuals. No cookies, no personal profiles, and in most EU contexts no consent banner. There's no transfer problem to worry about when the data was never personal to begin with, and several of these tools host in the EU on top of that. If you want the full rundown of the category, I compared the main options in the best privacy-friendly analytics tools for 2026.

Two honest caveats, the same ones I always give. First, "no cookies, no personal data" shrinks your GDPR surface area a lot, but it doesn't automatically make your whole site compliant, because other scripts (chat widgets, ad pixels, embeds) can still set cookies. Second, each tool words its privacy claims slightly differently, so read the documentation rather than trusting a category label.

If you're leaning toward switching but worried about losing your history, the move is less painful than it sounds. I wrote a step-by-step on how to migrate from Google Analytics 4 that keeps GA4 running as a safety net while you test the replacement, so there's no risky cut-over.

Where does Muro fit?

Softly, and honestly: Muro is one of the privacy-friendly options above, built for teams who'd rather read a short summary than babysit a dashboard.

Muro uses no cookies, doesn't need a consent banner in most EU contexts, and is designed to be GDPR-friendly. Instead of tracking individuals, it summarizes your own aggregate data. Every morning it emails your whole team a short, plain-English brief: how many visitors and signups you had, where they came from, your top pages, and how the numbers moved compared to before. There's a full dashboard too, but most days the email is all you open. If you share links, Muro Links track any link you send right through to the signup, and they're included on every plan. Pricing starts at $12 a month (Starter) at 100k pageviews and scales with your traffic, with a Pro plan at $29 a month and unlimited team members, plus a 30-day free trial with no credit card.

I want to be clear about what Muro is and isn't, though. It summarizes what your own data shows. It does not offer legal advice, and choosing a cookieless tool is not, by itself, proof of compliance. It removes a big chunk of the complexity that made Google Analytics a European headache, but your obligations still depend on your whole site and your jurisdiction.

The honest bottom line

Google Analytics is not illegal, and there is no EU-wide ban. The real story is narrower: for a stretch between 2022 and 2023, regulators in Austria, France, Italy, Denmark, Sweden, and elsewhere ruled that specific websites using it broke GDPR, almost entirely because of EU to US data transfers. The 2023 Data Privacy Framework created a new legal basis for those transfers and eased the immediate problem, though it left the cookie and consent requirements in place and sits under a challenge that hasn't fully played out.

If you want to stop thinking about all of this, the most reliable move is the same one that ended the debate in the first place: collect less. Cookieless, privacy-friendly analytics tools were built for exactly that, and they remove most of the transfer, cookie, and consent questions before they can start. That won't make you compliant on its own, but it meaningfully shrinks the surface area you have to worry about.

And to say it once more, plainly: this article is general information, not legal advice. Privacy law is nuanced, it changes, and the right answer for your product depends on details I can't see from here. Before you make a decision that carries legal weight, talk to a qualified lawyer or your data protection officer.

If you'd like analytics that's privacy-friendly by default and lands as a two-minute email each morning instead of another dashboard to manage, try Muro free for 30 days. No credit card, no cookies, and about a two-minute setup. If a different privacy-friendly tool fits you better, use that one. The important step is getting off a setup that makes European privacy law harder than it needs to be.

Frequently asked questions

Not as a blanket rule. There is no EU-wide law that bans Google Analytics as a product. What happened is more specific: between 2022 and 2023, several national data protection authorities ruled that particular websites using Google Analytics violated GDPR, mainly because of EU to US data transfers under the rules at the time. The 2023 EU-US Data Privacy Framework then created a new legal basis for those transfers, which changed the picture. Whether your setup is lawful depends on your configuration and jurisdiction, so confirm with a qualified lawyer.

No country issued a blanket ban on Google Analytics. Regulators in Austria, France, and Italy each ruled in 2022 that specific sites using it broke GDPR, and authorities in Denmark, Finland, Norway, and Sweden reached similar conclusions or issued fines through 2023. These were decisions about particular websites and configurations, not a nationwide product ban. The common thread was EU to US data transfers, which the 2023 Data Privacy Framework later addressed.

No. The GDPR concerns that drove the EU rulings do not apply the same way in the US. The US has a patchwork of state privacy laws, such as the California Consumer Privacy Act, that create their own obligations around notice and opt-out, but none of them make Google Analytics illegal. If your audience is mostly in the US, the legal picture is very different from the EU.

It helped a lot, but 'legal again' overstates it. The 2023 framework created a fresh legal basis for transferring data from the EU to certified US companies, Google included, which removed the core transfer problem behind the 2022 rulings. It did not rewrite the cookie and consent requirements, and privacy advocates have signaled they may challenge the framework, much as earlier transfer arrangements were struck down. It is in force now, but calling the debate permanently closed would not be honest.

In many cases yes, if you configure it carefully, rely on a valid legal basis for the data transfer, and collect proper cookie consent before it runs. The catch is that doing this correctly takes ongoing work, and a half-configured setup is the riskiest state to be in. Many small teams decide the simpler path is a cookieless tool that does not process personal data in the first place. For anything with legal weight, talk to a lawyer or your data protection officer.

Cookieless, privacy-friendly tools sidestep most of the questions that made Google Analytics complicated, because they do not set cookies or process personal data. Plausible, Fathom, Simple Analytics, and Muro all install with one lightweight script in about two minutes and avoid cookies and consent banners in most EU contexts. Muro also emails your team a short plain-English summary each morning instead of asking you to open a dashboard. No tool is legal cover on its own, so still confirm your obligations.

Try Muro on your own product

Setup takes 2 minutes. Your first insight arrives tomorrow morning.

30-day free trial. No credit card. Cancel anytime.